Privacy

What we collect, how long we keep it, and how to get rid of it

This page describes how Webshop Vitals handles data. It is a plain language summary of the actual implementation, not a substitute for legal advice for your own business.

Last updated August 2026

01

Google user data we access

If you use Sign in with Google, we receive your Google profile identifier, name and email address. We use these fields only to create or sign in to your Webshop Vitals account.

If you separately connect Google Merchant Center, we access the Merchant Center accounts available to you, the account you select, processed product data, product and account diagnostics, eligibility status, and product performance metrics. We use this data only to build your audit, compare it with your storefront, show your reports, and run monitoring you request.

If you separately connect Google Search Console, we access the properties available to you and, for the property associated with your store, read search analytics, sitemap status, and URL inspection results. We use this data only in your technical audit and monitoring.

Google Sign-In, Merchant Center, and Search Console permissions are requested in separate steps. Connecting one feature does not authorize the others.

02

Other data we collect

Store data: the URLs we crawl on stores you ask us to scan, the HTML those URLs return, and the product information we extract from it.

Usage data: counts of scans, pages crawled, products analysed, AI requests and exports, used to enforce plan limits.

03

What we do not collect

We never store raw IP addresses for anonymous scans. We store a salted hash so we can enforce a per day limit and nothing else.

We never store your Google access or refresh tokens in readable form, and we never display them in the interface.

We do not place orders, submit forms, enter payment details or create accounts on the stores we scan.

04

How we protect Google user data

Google OAuth refresh tokens are encrypted at rest with authenticated AES-256-GCM encryption using a dedicated application encryption key. Tokens and encryption keys are never rendered in the interface or written to application logs.

Google user data is encrypted in transit with HTTPS/TLS. Access to stored data is enforced on the server: authenticated users may access only organizations and stores of which they are members. Production systems and secrets are restricted to authorized personnel and service accounts that need them to operate the service.

OAuth requests use PKCE, a signed and time-limited state value, and secure, HTTP-only session cookies. We request the minimum Google scope available for each feature and keep Merchant Center and Search Console authorization separate.

We monitor application failures without logging OAuth tokens. If you disconnect Google, we delete the stored credential and attempt to revoke it with Google. You can also revoke access from your Google Account security settings.

05

How we share or disclose Google user data

We do not sell Google user data. We do not use or disclose it for advertising, retargeting, credit decisions, lending, data brokerage, or to train generalized or non-personalized artificial intelligence or machine-learning models.

We disclose Google user data only when necessary to provide or secure Webshop Vitals, when you direct us to do so, or when required by law. We do not transfer or disclose it to third parties for purposes other than those described in this policy.

Our infrastructure service providers process limited Google user data on our behalf: Vercel hosts the web application, and Railway hosts background processing, the application database, and queues. They act as service providers and may process data only to deliver those services to us.

When you explicitly request an optional AI-generated fix, the configured AI API provider receives only the issue and limited product fields needed to return that suggestion. The request is made solely to provide that user-facing feature, not for advertising or generalized model training. No OAuth token is sent to the AI provider.

We send data back to Google only to call the Google APIs you authorize, to revoke access when you disconnect, or, if you separately consent to measurement cookies, to provide Google Analytics and Google Ads conversion measurement for this site. Stripe receives payment information and Resend receives email delivery information; neither receives your Google Merchant Center or Search Console data.

We may disclose information if required to comply with law, enforce our terms, or protect users and the service. If ownership of Webshop Vitals changes, data may transfer to the successor subject to this policy and applicable law.

06

Retention

Raw and rendered page HTML is deleted after 7 days. It exists only so a report can show you the exact markup we saw.

Google Merchant Center and Search Console data normalized into audit results, such as issues, scores, product snapshots and performance summaries, is retained for as long as your account exists so historical trends remain meaningful.

Google OAuth refresh tokens are retained only while the integration is connected. Disconnecting Google deletes the stored credential. Short-lived access tokens are held only in server memory while a Google API request is made and are not stored in the database.

Unclaimed anonymous scans and the throwaway workspaces holding them are deleted after 7 days.

07

Deletion

You can delete your account from Settings. Deleting an organization removes its sites, scan data, stored HTML, product snapshots, OAuth tokens, reports and every other row that belongs to it. This is enforced by database level cascades, not by a cleanup script that might not run.

Disconnecting Google deletes the stored refresh token and attempts to revoke it with Google. Historical scans are kept so your trend data survives.

08

Cookies and analytics

The product itself sets no tracking cookies. Signing in sets a session cookie, which is required for the application to work and is not used for analytics.

Our own funnel measurement records steps such as "scan started" or "opened pricing", with the page, the referring site and any campaign tag, and no cookies. For visitors who are not signed in it holds no personal identifiers. When you are signed in, these steps and any errors you run into are linked to your account so we can see where the product fails you. Steps are kept for 13 months and errors for 90 days, and both are unlinked from you when you delete your account.

We use Google Consent Mode v2. The Google tag can load in a denied state so conversions can be modelled without storing analytics or ads cookies. Cookies are set only after you accept. You can reject optional cookies; measurement storage then stays denied. Personalisation storage stays off either way.

You can change your mind via Cookie settings in the footer, which reopens the banner.

09

Contact

Questions about any of the above: support@webshopvitals.com.

Core safeguards are implemented in the product: deletion runs on database cascades, Google refresh tokens use authenticated encryption with a key the interface never exposes, organization access is checked on the server, and anonymous scan limits use a salted hash instead of a stored address.