← Back

Privacy notice

The GA4 Audit Tool is operated by New North Digital (the Netherlands). This page describes what personal data the tool stores, why, how long, and how to request deletion. Last updated 2026-05-14.

What we store

To run audits and let you sign in, we store the following per user:

  • Email address — used to identify your account and to send scheduled reports if you configure them.
  • Google sub (opaque identifier)— Google's stable user ID, used only to link a session back to a user record.
  • OAuth refresh + access tokens for Google Analytics and Google Ads, encrypted at rest with AES-256-GCM.
  • CMS API credentials (Shopify / WooCommerce / Magento) when configured, AES-256-GCM encrypted at rest. Shopify offline access tokens obtained via the Shopify Partner OAuth flow are stored the same way.
  • Audit results — aggregated metrics from your GA4 property (counts, percentages, sample URLs). No individual visitor data is stored.
  • Session cookie — an iron-session encrypted cookie identifying your active sign-in. Cleared on logout.
  • Share-link tokens— when you generate a public client link, the token is an HMAC-signed URL embedding the tenant and property id plus a 30-day expiry. We don't separately store the token; it verifies against the same signing key used for email unsubscribe links.

Google user data — what we access and why

When you sign in with Google and authorise the app, we request the following scopes:

  • openid email profile — identifies your account.
  • https://www.googleapis.com/auth/analytics.readonly — lets us read your GA4 properties, reports, event names, and configuration so we can produce the audit. No writes are performed with this scope.
  • https://www.googleapis.com/auth/adwords — requested when you open the Ads Conversion audit tab, so we can compare Google Ads conversion counts with your GA4 and backend numbers. Read-only usage.

Limited Use.The GA4 Audit Tool's use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements. Specifically: we use the data only to provide the audit features you see in the app, we do not transfer the data to third parties except as necessary to render those features, we do not use the data for advertising, and no human reads your data unless you explicitly ask for support, we are legally required to, or we need to investigate a security incident.

What we don't store

  • Individual visitor data from your GA4 property. We aggregate metrics and discard the row-level data after analysis.
  • Backend order CSVs you upload — kept only in browser memory for the duration of the audit. Never written to our servers.
  • Tracking or analytics on this tool itself without your consent. No ad pixels, no marketing tags. Product analytics (Google Tag Manager + GA4) only load after you accept them in the cookie banner — see "Cookies" below.

Cookies

We use as few cookies as we can get away with. Two categories:

  • Essential— the encrypted iron-session cookie that keeps you signed in. Always on; the tool can't function without it. Cleared on sign-out.
  • Analytics (optional)— Google Tag Manager + GA4 to measure anonymous product usage. Default-denied via Consent Mode v2 for visitors from the EU / UK; loads only after you click "Accept" or enable it in Customize. You can change your mind at any time from the "Cookie preferences" link in the footer.

Retention

  • Audit results: default 180 days, configurable per tenant from 30 to 1825 days. Older rows are auto-pruned by a daily cron.
  • Activity log: 90 days.
  • Property Health / Consent Mode caches: 30 days.
  • OAuth tokens, CMS credentials, and Shopify offline tokens: stored until you sign out, revoke the grant at your Google / Shopify account, or request account deletion.
  • Session cookie: 7 days, refreshed on activity.
  • Share-link tokens: default 30 days; not revocable server-side, but expire automatically at the embedded timestamp.

Who can access your data

  • You — full access to your own audits and stored credentials.
  • Other users in your tenant— if you're part of a shared tenant (e.g. an agency workspace), other members can see audit results but not OAuth tokens or CMS credentials.
  • Recipients of share links you create— anyone who opens a link you generated sees a read-only summary of that one property's latest audit until the token expires. They do not see other properties or the tenant list.
  • NND administrators — limited operational access for support and audit-trail review (security events, schedules, CMS connections). Tokens and credentials remain encrypted; admins do not see plaintext values.
  • Google— the audit reads from and writes to GA4 / Google Ads via official APIs using your OAuth grant. Google's privacy policy applies to data flowing through their APIs.

Lawful basis (GDPR)

We rely on the following lawful bases under Article 6 GDPR:

  • Contract (Art. 6(1)(b)) — for the core audit service, including storing your account, running audits against your GA4 / Google Ads / CMS data, and rendering results.
  • Legitimate interest(Art. 6(1)(f)) — for operational security (rate-limit + audit-log retention), error monitoring, and aggregated anonymous benchmarks computed across all audited stores. You can object — see “Your rights”.
  • Consent (Art. 6(1)(a)) — for the optional monthly digest email. Toggle off in Subscriptions to withdraw at any time.
  • Legal obligation (Art. 6(1)(c)) — to retain audit logs of security-relevant actions (e.g. cron auth failures) for a reasonable period.

Third-party processors

We use the following sub-processors to deliver the service. All access is bound by data-processing agreements; none use your data for their own purposes.

  • Vercel Inc. (USA) — application hosting, edge network, function execution. Vercel may process limited request metadata (IP, user agent) to operate the platform.
  • Neon Inc. (USA, with EU regional deployment) — managed Postgres database. All persistent data (user records, audit results, encrypted credentials) is stored here.
  • Resend (USA) — transactional email delivery for scheduled reports and the monthly digest, only when you opt in.
  • Sentry (USA, with EU residency available) — server-side error monitoring. We deliberately scrub OAuth tokens and CMS credentials before reporting; payload metadata may still include user-agent and request shape.
  • Google LLC— Google Analytics, Google Ads, and identity (OAuth). The audit reads from your own Google account via your authorised grant; Google's privacy policy applies to data flowing through their APIs.

International transfers

Several of the processors above are headquartered in the United States. Where transfers of personal data outside the EEA occur, they are protected by the European Commission's Standard Contractual Clauses (SCCs) and, where applicable, the EU-US Data Privacy Framework. We minimise the personal data transferred — most of what we store is aggregated audit results, not individual-visitor data from your end users.

Your rights

You can:

  • Sign out any time via the sidebar — clears your session cookie. Your stored OAuth tokens remain so scheduled reports keep working; revoke at Google Account → Third-party apps to break the audit's ability to read GA4.
  • Request account deletion by emailing hello@newnorth.nl. We delete the user row and all dependent rows within 14 days; CASCADE deletion in the schema removes audit history, schedules, OAuth tokens, CMS credentials, and Shopify offline tokens.
  • Request a copy of your data via the same address. We respond within 30 days per GDPR.
  • Shorten your tenant's retention window— ask and we'll adjust your tenant row, which cascades to the next daily prune.
  • Lodge a complaint with a supervisory authority. If you're in the EU, the Dutch supervisory authority is Autoriteit Persoonsgegevens; in other EU member states your local DPA applies. You can also raise the issue with us first via the contact below — we'd like the chance to resolve it.

Contact

New North Digital, the Netherlands. Questions, deletion requests, or data-protection concerns: hello@newnorth.nl.