Tài liệu nền tảng

Google user data

Last updated: 27 July 2026. This notice describes how Elevale ("we", "us", "our") accesses, uses, stores, shares, and deletes Google user data obtained through Google OAuth APIs when you connect optional Google integrations in the Elevale application.

{tradingStyleDisclaimer} In this notice, "Elevale", "we", "us", and "our" mean that registered company trading as Elevale.

It supplements our Privacy Policy, which covers all personal data we process across the Elevale platform, marketing website, and related services. This document applies only to data received from Google APIs when you use Google Analytics or Google Ads integrations.

Elevale's use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. We do not sell Google user data.

Google OAuth integrations we offer

Elevale is an integration platform. Workspace admins enable individual third-party data sources under a least-privilege authorisation model: each Google integration is connected separately, requests only the single OAuth scope required for that integration, and is used only for the user-facing features described in this notice. Google user data is accessed only when a workspace admin or authorised user explicitly connects one of these optional integrations:

  • Google Analytics integration: lists authorised GA4 properties and syncs web analytics reporting metrics into Connected KPIs, dashboards, health scores, and OKR views
  • Google Ads integration: identifies authorised Google Ads customer accounts and syncs advertising performance metrics into Connected KPIs, dashboards, health scores, and OKR views

We do not use Google Sign-In for Elevale account authentication. We do not request access to Gmail, Google Drive, Google Calendar, Google Contacts, or other Google account data. We never combine Google Analytics and Google Ads scopes into a single consent request.

Setup guides: Google Analytics integration · Google Ads integration

OAuth scopes requested (principle of least privilege)

Consistent with the Google API Services User Data Policy principle of least privilege, Elevale requests only the narrowest Google OAuth scopes critical to implementing the production features above. When you connect an integration, we request only that integration's scope:

  • Google Analytics: https://www.googleapis.com/auth/analytics.readonly: the narrowest Google Analytics reporting scope. It is required so Elevale can (1) list Google Analytics accounts and properties you can access via the Google Analytics Admin API, and (2) read aggregated reporting metrics (such as sessions, users, page views, traffic sources, engagement, and conversions) via the GA4 Data API runReport method for properties you select when creating Connected KPIs. Those values are displayed in KPIs, dashboards, health scores, and OKR views and refreshed on the sync schedule you configure. Why narrower permissions cannot be used: this scope is already read-only Analytics reporting access; we do not request Analytics edit/write scopes or any broader Google account scopes.
  • Google Ads: https://www.googleapis.com/auth/adwords: required by the Google Ads API for API access to advertising data. It is required so Elevale can (1) identify Google Ads customer accounts you can access, and (2) read campaign and account performance metrics (such as impressions, clicks, cost, click-through rate, average cost per click, conversions, conversion rate, conversion value, cost per conversion, and return on ad spend) via Google Ads API search/GAQL for customer IDs you authorise when creating Connected KPIs. Those values are displayed in KPIs, dashboards, health scores, and OKR views and refreshed on the sync schedule you configure. Elevale uses this access for performance reporting only and does not create, edit, pause, or otherwise manage Google Ads campaigns, ads, or budgets. Why narrower permissions cannot be used: the Google Ads API does not provide a separate read-only OAuth scope; adwords is the standard scope required for Ads API access, including read-only reporting.

Data accessed

We access Google user data only within the OAuth scopes you approve during connection, and only for integrations you enable per workspace.

Google Analytics (when connected): Google Analytics account and property identifiers; aggregated web analytics metrics you map to KPIs, such as sessions, users, page views, traffic sources, conversion rates, channel performance, and related reporting dimensions and metrics; OAuth access and refresh tokens needed to maintain the connection.

Google Ads (when connected): Google Ads customer, campaign, and ad group identifiers; advertising performance metrics such as impressions, clicks, cost, click-through rate, average cost per click, conversions, conversion rate, conversion value, cost per conversion, and return on ad spend; OAuth access and refresh tokens needed to maintain the connection.

We do not collect Google account profile information (such as your Google name or email address) through these integrations beyond what is necessary to identify connected accounts and properties within the authorised API responses.

Data usage

We use Google user data obtained through Google OAuth APIs only to provide and improve the user-facing features in Elevale that you explicitly request when you connect an integration and create Connected KPIs:

  • Pull authorised Google Analytics and Google Ads metrics into KPIs, dashboards, health scores, OKR views, and related in-app reporting (the maximum extent of our use of each scope)
  • Refresh OAuth tokens and maintain integration connections you configured
  • Troubleshoot sync errors, display integration status, and maintain reliability of connected integrations

We do not use Google user data obtained through Google OAuth APIs for:

  • Advertising, retargeting, interest-based profiling, or personalised advertising
  • Selling, renting, or licensing data to third parties
  • Creditworthiness decisions or lending purposes
  • Building unrelated marketing databases or audience segments
  • Training, fine-tuning, or improving machine learning or artificial intelligence models
  • Any purpose unrelated to providing or improving Elevale functionality you explicitly request

Raw Google Analytics and Google Ads API responses are not sent to AI providers (including Google Gemini). Synced metric values displayed in Elevale are stored as KPI and dashboard data; they are not automatically included in AI chat prompts.

Limited human access to Google-sourced integration data may occur only for user support, security investigation, compliance, or legal requirements, and not for unrelated marketing or research.

Data sharing

We do not sell Google user data. We share Google user data obtained through Google OAuth APIs only as follows:

  • Google: Elevale calls Google APIs on your behalf using the OAuth tokens you authorised. Google processes those API requests under its own terms and privacy policy
  • Platform subprocessors: Supabase (encrypted database storage), Fly.io (application hosting), and other infrastructure providers listed at Subprocessors and integrations store or process integration data solely to operate Elevale on our instructions under contractual safeguards
  • Workspace members: Users with permission in your workspace can view synced metrics and dashboards within that workspace. This is access within your organisation, not a sale or disclosure to unrelated third parties
  • Legal and safety: We may disclose data if required by law, court order, or to protect rights, safety, and security, as described in our Privacy Policy

We do not share Google user data with advertising networks, data brokers, information resellers, or analytics resellers. We do not transfer Google user data to third parties for their own advertising, AI training, or unrelated commercial purposes.

Data storage and protection

Google OAuth access and refresh tokens are encrypted server-side before storage. Synced metrics and related integration metadata are stored in our Supabase database with row-level security, role-based access controls, and TLS 1.2+ encryption in transit. Access is limited to authenticated users with appropriate workspace permissions and to platform systems that need access to deliver the service. API keys and OAuth encryption keys are managed using documented rotation practices. See Security and data protection for more detail.

Data retention and deletion

  • While connected: We retain OAuth tokens and synced Google metrics while the integration remains connected and your workspace is active, refreshing data on the sync schedule you configure
  • Disconnect integration: When you disconnect Google Ads or Google Analytics in workspace integration settings, we revoke and delete stored OAuth tokens, stop new syncs, and no longer call Google APIs for that connection. Previously synced metric values may remain in KPIs and dashboards until you delete those records
  • Workspace or account deletion: When you delete your account or a workspace is permanently deleted, Google integration data is removed according to our Data retention and deletion schedule (including anonymisation at 60 days and permanent deletion at 90 days after access ends, unless a shorter period applies to tokens on disconnect)

How to request deletion of Google user data:

  1. Disconnect the Google integration in your workspace integration settings
  2. Delete synced KPIs or dashboards that contain Google data, if you no longer need them
  3. Use Profile → Security → Delete my account for full account erasure, or Profile → Privacy → Submit a request for targeted deletion
  4. Email contact form with the subject line "Google data deletion request"

We aim to respond to deletion requests within 30 days. If your organisation administrator controls the workspace, we may coordinate with them to fulfil your request.

Marketing website analytics (separate from OAuth integrations)

Our marketing website may use Google Analytics, Google Ads, and remarketing technologies to measure site traffic and ad performance. Those cookies and tags are described in our Cookie Policy and Privacy Policy: Advertising and analytics. They are not connected to the Google Analytics or Google Ads OAuth integrations described in this notice, which pull data from your authorised Google accounts into your workspace KPIs.

Related documents