GALAVANTEERCLIENT PORTAL

Effective July 17, 2026

Privacy Policy

This policy explains how the Galavanteer Client Portal accesses, uses, stores, and shares information when an authorized user uses the private client-reporting portal.

Who operates this application

Galavanteer operates the Galavanteer Client Portal. Questions, access requests, and deletion requests may be sent to jason@galavanteer.com.

Information we collect

  • Account information: name, email address, identity-provider identifier, verification status, workspace membership, role, and sign-in activity.
  • Google authorization information: OAuth access and refresh tokens, granted scopes, the connected Google account, and the property or account selected for a workspace.
  • Google Search Console data: authorized sites and reporting data such as clicks, impressions, queries, pages, countries, devices, click-through rate, and average position.
  • Google Analytics data: authorized account and property identifiers and GA4 reporting metrics used for traffic, acquisition, engagement, content, geography, events, and historical comparisons.
  • Google Merchant Center data: authorized account, product, data-source, inventory, issue, and performance-reporting information.
  • Operational information: report runs, data-through dates, errors, audit history, and technical logs needed to operate and secure the service.

How we use information

We use the information described above to:

  • authenticate users and enforce workspace-level access;
  • connect the Google property or account explicitly selected by an authorized user;
  • produce private dashboards, snapshots, historical comparisons, KPI reports, and monitoring views;
  • maintain data quality, diagnose failed report runs, prevent abuse, and support authorized users; and
  • meet security, legal, and compliance obligations.

Google user data is not used for advertising, sold, or used to create advertising profiles.

Read-only Google access

The Galavanteer Client Portal uses its Google connections for reporting and monitoring. It does not modify Google Analytics accounts, properties, settings, events, or users; it does not modify Search Console properties; and it does not create, update, or delete Merchant Center resources. If an API does not provide a narrower read-only OAuth scope, read-only behavior is enforced in server-side application code.

Storage and security

OAuth tokens are stored in encrypted form and are used only by server-side services. We apply access controls, workspace separation, encrypted network connections, audit records, and other reasonable safeguards designed to protect stored information. No method of storage or transmission can be guaranteed to be completely secure.

Sharing and service providers

We disclose information only as needed to operate the portal, comply with law, protect the service, or follow an authorized user’s direction. Infrastructure and identity providers may process limited information on our behalf, including Vercel for application hosting, Neon for database infrastructure, Auth0 for authentication, and Google for the Google APIs and authorization services selected by the user. These providers process information under their respective terms and privacy commitments.

We do not sell Google user data or share it with data brokers or advertising networks.

Retention, disconnection, and deletion

Connection credentials are retained while the integration remains connected or as needed to provide the service. Reporting records and snapshots may be retained to preserve authorized historical comparisons. A user can revoke access in their Google Account permissions or ask Galavanteer to disconnect the integration and delete associated stored Google-derived data. We may retain limited audit, security, backup, or legal records when required, and remove them under our normal retention process.

Google API Services User Data Policy

The Galavanteer Client Portal’s use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including its Limited Use requirements.

Your choices

You may revoke Google access from Google Account permissions. To request access, correction, disconnection, or deletion, email jason@galavanteer.com. We may need to verify your identity and authority over the relevant workspace before completing a request.

Policy changes

We may update this policy as the portal or its integrations change. The effective date at the top of this page identifies the current version. Material changes will be communicated through the portal or another appropriate channel.