Google API Services Privacy Policy
Google API Services Privacy Policy
This policy explains how Gootium's internal reporting application accesses, uses, stores and shares data obtained through Google APIs. It covers that application only. Personal information collected from shoppers on gootium.com is covered separately by our store privacy policy.
The application is described here: Google API Integrations.
What Google user data we access
The application authenticates as the owner of Gootium's own Google accounts and reads only Gootium's own business data:
- Google Search Console — aggregate search performance for the website gootium.com: search queries, impressions, clicks, click-through rate and average position. Read-only.
- Google Analytics 4 — aggregate website traffic and conversion statistics for our own property, such as sessions, traffic sources and events. Read-only.
- Google Ads — performance data for the single advertising account we own: campaigns, keywords, search terms, impressions, clicks, cost, conversions and impression share. The application may also write changes to campaign budgets and keyword bids within that same account.
All of this is aggregate business reporting data. The application does not request, and has no access to, the contents of anyone's email, files, contacts, calendar or photos, and it does not access data belonging to any account other than our own.
How we use it
The data is used for one purpose: to measure and improve the performance of Gootium's own website and advertising. Specifically, to see which search queries and advertisements bring visitors to our store, to calculate whether our advertising spending is profitable, and to adjust our own advertising budgets and bids accordingly.
Who we share it with
We do not share, sell, transfer or disclose data obtained through Google APIs to any third party. The data is read by our own staff only. It is not passed to advertising networks, data brokers, analytics vendors or any other outside party, and it is never used for targeted advertising to individuals, for credit assessment, or for lending purposes.
How we store and protect it
Reports are written to local files on computers controlled by Gootium staff. There is no public server, no shared database and no multi-tenant storage. Access credentials (OAuth refresh tokens and developer tokens) are held in a local environment file that is excluded from version control, and all communication with Google APIs takes place over encrypted HTTPS connections. Access to those machines is limited to the two members of our in-house marketing team.
How long we keep it and how it is deleted
Generated reports are retained only as long as they are useful for marketing analysis, and are deleted when no longer needed. Data obtained through Google APIs is not retained in any external system. Authorization can be withdrawn at any time from the Google Account permissions page at myaccount.google.com/permissions, which immediately ends the application's access. To request deletion of any data the application holds, write to contact@gootium.com.
Limited Use
Gootium's use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
We do not use data obtained through Google APIs to develop, improve or train generalized or non-personalized artificial intelligence or machine learning models.
Changes to this policy
If the application's use of Google APIs changes, this page will be updated before the change takes effect.
Contact
Gootium — contact@gootium.com