Connecting a Google Ads account to HonestTag
By the HonestTag team ยท Published August 23, 2026
Connecting Google Ads is one OAuth consent plus one account choice. HonestTag asks Google for four permissions, uses them for exactly the features described on this page, and binds everything to the single ad account you pick. This page explains each permission, what you see afterward, and how to disconnect.
What happens when you click "Connect Google Ads"
Inside the HonestTag app in your Shopify admin, the setup screen has a "Connect Google Ads" button. Clicking it opens a Google sign-in window on accounts.google.com, outside the Shopify admin frame, so you can see Google's real address bar and confirm who you are granting access to. You sign in with the Google account that has access to your Ads account, and Google shows you a consent screen listing exactly what HonestTag is requesting. Nothing is granted until you approve that screen, and you can walk away from it with no effect.
The permissions we ask for, and what each one does
- Basic identity (openid and email). We read the email address of the Google account you connect. It is used for two things: showing "connected as your@email" in the app, and noticing when a reconnect uses a different Google user so we can re-check which ad accounts the new login can reach. Nothing else.
- Google Ads. Two uses. Reading: your own campaign spend, clicks, and Google-reported conversions, shown next to your store's actual Shopify orders. Writing: creating and maintaining HonestTag's own conversion actions in the account you select, and correcting them when you refund an order. HonestTag never creates, edits, or pauses campaigns, ad groups, ads, or budgets, and never touches a conversion action it did not create unless you choose, from the app's setup screen, to send purchases into one; even then, HonestTag never changes that action's own settings.
- Data Manager. This is Google's API for server-side conversion uploads. HonestTag uses it to deliver your store's verified conversions into the HonestTag conversion actions, unless you choose, from the app's setup screen, to send purchases into one existing conversion action you pick instead; even then, HonestTag never changes that action's own settings. It is a separate permission because Google runs it as a separate API with its own scope.
Google issues HonestTag a long-lived credential at this step so the connection keeps working without you re-approving it every session. The credential is stored encrypted, scoped to your store, and revoked when you disconnect.
Choosing the ad account
After consent, HonestTag lists the Google Ads accounts your login can use: accounts you access directly, plus client accounts one level under any manager (MCC) account you have. Manager accounts themselves are never offered as a destination, and canceled or closed accounts are filtered out. If an account had to be skipped (for example, your login lists it but cannot actually use it), the picker says so rather than hiding it.
You pick one account. That choice is the binding: spend is read from that account, conversion actions are created in that account, and conversions are delivered to that account. Your data is never shared with other merchants and never used to build profiles across stores.
What HonestTag sets up after you pick an account
On a paid plan, HonestTag creates its conversion-action suite in the account you chose, automatically and idempotently (running setup again never creates duplicates). On the free Mirror plan nothing is created; the suite is created when you move to a paid plan. All of them are created as secondary actions, meaning they record data but do not change what your campaigns bid on unless you promote them yourself in Google Ads or add them to a campaign's custom conversion goal. The full list, and what HonestTag will and will not touch, is on the conversion actions page.
What the free plan does
The free tier (the Mirror) is read-only. It shows platform-claimed numbers next to your store truth and never writes anything to your Google Ads account: no conversion actions are created and no conversions are uploaded.
Reconnecting, or switching Google users
If your connection expires or you reconnect on purpose, you go through the same consent flow again. If the reconnect uses a different Google user, HonestTag checks whether the new login can reach the ad account you had selected. If it can, the connection continues against the same account. If it cannot, the account selection is cleared and you pick again from what the new login can access. Nothing historical is deleted either way: your reports, evidence records, and audit history stay.
How to disconnect
Disconnect from the HonestTag setup screen, or uninstall the app. On disconnect or uninstall, HonestTag cleans up after itself: the conversion actions it created are marked removed in your Google Ads account (Google's reference for a removed action: "Conversions will not be recorded."), and HonestTag revokes its own access token so it stops appearing with live access under myaccount.google.com/linkedapps. You can also revoke access from that Google page directly at any time. If you do, HonestTag stops delivering to Google and asks you to reconnect; the HonestTag actions stay in your account until you reconnect and disconnect, or remove them yourself.
How we handle data received from Google's APIs is stated in section B9 of our privacy policy.