Privacy Policy

Last updated: 2026-10-09

This Privacy Policy explains how [OPERATING ENTITY LEGAL NAME] ("we", "us") handles data when merchants on our platform connect their Google Analytics, Google Ads, or Meta advertising accounts through our merchant dashboard.

1. What we access from your Google account

When a merchant clicks "Connect Google Analytics" or "Connect Google Ads" in our merchant dashboard and completes Google's own OAuth consent flow, we request: (a) Google Analytics (GA4) — read-only access (analytics.readonly) to the merchant's own GA4 property, used to display aggregate traffic and conversion statistics inside their dashboard; we do not read or store personally identifiable visitor-level data. (b) Google Ads — read/write access (adwords) used to (i) display the merchant's own Google Ads campaign reports inside their dashboard, and (ii) upload offline conversion events (inquiry submissions, completed orders) generated on our platform back to the merchant's own Google Ads account. We never create, edit, or delete the merchant's ad campaigns or bids on their behalf.

2. What we access from your Meta account

Separately from Google, merchants may also connect a Meta advertising account (scopes: ads_read, read_insights, ads_management) for the same purpose — displaying ad performance and sending conversion events back to Meta's Conversions API.

3. How we use this data

Data obtained through these connections is used only to: display the merchant's own report data inside their own dashboard; automatically forward conversion events the merchant's own platform activity generated back to their own ad account; and troubleshoot connection issues a merchant reports to us. We do not sell, rent, or share this data with third parties for advertising or marketing purposes, and we do not use it to train machine-learning or AI models.

Our use and transfer of information received from Google APIs to any other app adheres to the Google API Services User Data Policy, including the Limited Use requirements.

4. Storage and security

OAuth access and refresh tokens are stored encrypted in our production database, isolated per merchant — no merchant can see another merchant's connection data. A merchant can disconnect at any time from their dashboard, which immediately deletes the stored tokens for that account.

5. Data retention

Tokens are deleted immediately upon disconnection. Report data fetched from Google/Meta APIs is displayed to the merchant and is not retained beyond what is needed to render their dashboard, except where explicitly cached for performance, in which case the cache expires automatically.

6. Your rights

Merchants may disconnect a connected account at any time from our dashboard, or revoke our app's access directly from their Google Account security settings. To request deletion of any data we hold, contact us using the details below.

7. Contact

Questions about this policy can be sent to [PRIVACY_CONTACT_EMAIL].

← Back to home