Effective July 17, 2026
Privacy Policy
Who operates this application
Galavanteer operates the Galavanteer Client Portal. Questions, access requests, and deletion requests may be sent to jason@galavanteer.com.
Information we collect
- Account information: name, email address, identity-provider identifier, verification status, workspace membership, role, and sign-in activity.
- Google authorization information: OAuth access and refresh tokens, granted scopes, the connected Google account, and the property or account selected for a workspace.
- Google Search Console data: authorized sites and reporting data such as clicks, impressions, queries, pages, countries, devices, click-through rate, and average position.
- Google Analytics data: authorized account and property identifiers and GA4 reporting metrics used for traffic, acquisition, engagement, content, geography, events, and historical comparisons.
- Google Merchant Center data: authorized account, product, data-source, inventory, issue, and performance-reporting information.
- Operational information: report runs, data-through dates, errors, audit history, and technical logs needed to operate and secure the service.
How we use information
We use the information described above to:
- authenticate users and enforce workspace-level access;
- connect the Google property or account explicitly selected by an authorized user;
- produce private dashboards, snapshots, historical comparisons, KPI reports, and monitoring views;
- maintain data quality, diagnose failed report runs, prevent abuse, and support authorized users; and
- meet security, legal, and compliance obligations.
Google user data is not used for advertising, sold, or used to create advertising profiles.
Read-only Google access
The Galavanteer Client Portal uses its Google connections for reporting and monitoring. It does not modify Google Analytics accounts, properties, settings, events, or users; it does not modify Search Console properties; and it does not create, update, or delete Merchant Center resources. If an API does not provide a narrower read-only OAuth scope, read-only behavior is enforced in server-side application code.
Storage and security
OAuth tokens are stored in encrypted form and are used only by server-side services. We apply access controls, workspace separation, encrypted network connections, audit records, and other reasonable safeguards designed to protect stored information. No method of storage or transmission can be guaranteed to be completely secure.
Sharing and service providers
We disclose information only as needed to operate the portal, comply with law, protect the service, or follow an authorized user’s direction. Infrastructure and identity providers may process limited information on our behalf, including Vercel for application hosting, Neon for database infrastructure, Auth0 for authentication, and Google for the Google APIs and authorization services selected by the user. These providers process information under their respective terms and privacy commitments.
We do not sell Google user data or share it with data brokers or advertising networks.
Retention, disconnection, and deletion
Connection credentials are retained while the integration remains connected or as needed to provide the service. Reporting records and snapshots may be retained to preserve authorized historical comparisons. A user can revoke access in their Google Account permissions or ask Galavanteer to disconnect the integration and delete associated stored Google-derived data. We may retain limited audit, security, backup, or legal records when required, and remove them under our normal retention process.
Google API Services User Data Policy
The Galavanteer Client Portal’s use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including its Limited Use requirements.
Your choices
You may revoke Google access from Google Account permissions. To request access, correction, disconnection, or deletion, email jason@galavanteer.com. We may need to verify your identity and authority over the relevant workspace before completing a request.
Policy changes
We may update this policy as the portal or its integrations change. The effective date at the top of this page identifies the current version. Material changes will be communicated through the portal or another appropriate channel.