Privacy Policy for GA4 Support API

Privacy Policy for GA4 Support API

Effective Date: October 4, 2026

Welcome to GA4 Support API (“we”, “us”, “our”), operated by Attributions / GA4 Support, the Netherlands. We are committed to protecting your personal information and your right to privacy. If you have any questions about this privacy policy or our practices, please contact us at p.gudde@attributions.nl.

This privacy policy describes how we use, process and store your information when you connect your Google account to our application (“GA4 Support API”). It was previously published under the application’s former name, Attributions Support API.

1. Information We Collect

Personal information provided by you: your name, email address and contact preferences, which we need in order to run your account and to email you about your own setup.

Information collected automatically: standard technical information such as IP address, browser and device characteristics and operating system. This does not identify you by name.

Google user data that you choose to make available by granting the permissions listed in section 3.

2. How We Use Your Information

We use this information to deliver the service you asked for, and for nothing else. Specifically:

  • To configure and verify your Google Tag Manager and Google Analytics 4 setup.
  • To grant our service account the access it needs to keep recurring checks working, on the property or container you point us at.
  • To answer your questions about your own measurement, advertising and search data.
  • To comply with our legal obligations.

We do not use your data for advertising, we do not sell it, and we do not combine it with data from other customers.

3. Google User Data: Scopes, Retention, and Deletion

This section covers our use of Google user data accessed through Google APIs. You choose which permissions to grant; we request only what the service needs.

Requested scopes:

  • openid, .../auth/userinfo.email, .../auth/userinfo.profile — to identify the signed-in user.
  • .../auth/analytics.readonly — to read your GA4 configuration and reports, so we can check your measurement setup and answer questions about it.
  • .../auth/analytics.manage.users — to add our service account as a Viewer on the property you point us at, so recurring checks do not depend on your personal sign-in.
  • .../auth/tagmanager.readonly — to read your container configuration and verify tags, triggers and consent settings.
  • .../auth/tagmanager.manage.users — to add our service account to the container you point us at, for the same reason.
  • .../auth/adwords — to read campaign cost and conversion figures from Google Ads, so advice covers both advertising and analytics.
  • .../auth/webmasters.readonly — to read impressions and positions from Search Console for the site you point us at.
  • .../auth/bigquery.readonly — to query your own GA4 export where the Analytics reporting API cannot answer the question.

We deliberately do not request cloud-platform or any write access to Google Ads, Search Console or BigQuery.

Data retention (no storage of Google user data): we do not store your Google user data. The access token Google issues when you sign in is held in a session in your own browser and expires within 24 hours. We do not request or keep a refresh token, which means we cannot reach your Google account when you are not actively using the service. Reports, campaign figures and query results are read at the moment you ask a question and are discarded when the session ends; we keep no copy.

What we do keep: your name and email address, for as long as you are a customer — and afterwards only in invoicing records, which Dutch tax law requires us to retain for seven years. We also keep aggregate counts about your own setup, such as the number of events measured, for as long as your subscription is active; you can ask us to delete these at any time.

Data deletion: because we do not store your Google user data, there is no archive of it to delete. You can revoke our access to your Google account at any time at https://myaccount.google.com/permissions, which takes effect immediately. You can separately remove our service account from your Analytics property or Tag Manager container; the checks that rely on it will then stop, and we will tell you rather than silently continue. If you ask us to delete your account, we remove your name, email address and aggregate counts, except where invoicing records must be retained by law.

Limited Use disclosure: our use and transfer of information received from Google APIs to any other app adheres to the Google API Services User Data Policy, including the Limited Use requirements. We do not share your Google user data with any third parties, nor do we use it for advertising purposes.

4. Will Your Information Be Shared With Anyone?

We do not share your personal information or Google user data with third parties, except in these limited situations:

  • Infrastructure: our application runs on Google Cloud in the europe-west1 region (the Netherlands), and we send service email through our mail provider. These parties process data on our behalf and for no other purpose.
  • Legal obligations: we may disclose information where we are legally required to do so in order to comply with applicable law, a governmental request, a judicial proceeding, a court order or legal process.

5. How Do We Keep Your Information Safe?

We have implemented appropriate technical and organizational security measures designed to protect the information we process. Access to Google APIs runs over encrypted connections, and our credentials are held in a managed secret store rather than in code or configuration files. However, despite our safeguards, no electronic transmission over the Internet or information storage technology can be guaranteed to be 100% secure.

6. Changes to This Privacy Policy

We update this privacy policy whenever the permissions we request change, and the Effective Date above will tell you when that last happened. The updated version is effective as soon as it is accessible here.

7. Contact Us

If you have questions or comments about this policy, or if you want us to delete your data, you may contact us at p.gudde@attributions.nl.

Meer weten of hulp nodig?

We doen geen directe inschrijvingen of online-checkouts — alles gaat via een kort intake-gesprek. Stuur je vraag en we reageren binnen 1 werkdag.