Legal
Privacy policy
Last updated: August 2026
Overview
Conversion Console ("we", "our", "the platform") is a software-as-a-service application operated at conversionconsole.com. We provide SEO, AIO, PPC, and CRO intelligence and management for authorized business users. This policy describes how we collect, use, store, share, and protect data accessed through our service.
Google API Services User Data Policy
Conversion Console's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
1. Google user data we access
When you connect Google, Conversion Console requests delegated OAuth 2.0 permissions. Depending on the features you use, we may access data from:
- Google account identity (
openid,email,profile): your Google account email and basic profile information to sign you in and associate connectors with your workspace. - Google Ads (
adwords): campaign and ad-group structure, ad creative text (including responsive search ads), performance metrics (impressions, clicks, cost, conversions), and account metadata for reporting and in-product campaign controls. - Google Analytics 4 (
analytics.edit): property and reporting data (sessions, events, conversions, landing-page metrics) and, when you use tagging features, GA4 Admin key-event configuration for events you choose to mark as conversions. - Google Tag Manager (
tagmanager.edit.containers,tagmanager.edit.containerversions,tagmanager.publish): container inventory, tags, triggers, variables, versions, and publication status; and, when you use tagging or on-page injection features, the ability to create or update container versions and publish changes you approve in the product. - Google Search Console (
webmasters.readonly/https://www.googleapis.com/auth/webmasters.readonly): verified property list, search performance queries, page-level clicks, impressions, CTR, and average position for SEO reporting. We do not request the Google Indexing API scope (https://www.googleapis.com/auth/indexing), do not submit URLs for indexing through Google, and do not request write access to Search Console. - Google Business Profile (
business.manage): view and manage local business listing information and performance metrics.
Google OAuth scopes requested at sign-in: openid, email, profile, webmasters.readonly, analytics.edit, adwords, tagmanager.edit.containers, tagmanager.edit.containerversions, tagmanager.publish, and business.manage. The Indexing API scope is not requested by this application.
We request only the scopes needed for the connectors and actions you enable. Some scopes are read-only; others allow edit or publish operations when you explicitly trigger them in Conversion Console (see below).
2. How we use Google user data
Google user data is used solely to provide, operate, and improve Conversion Console features for the user who granted access. We use it to:
- Sync and display multi-channel marketing performance in unified dashboards, reports, and opportunity queues.
- Join organic, paid, analytics, and on-site signals on shared page and campaign views inside your workspace.
- Read operations: pull Search Console, GA4, Google Ads, and GTM inventory and metrics for analysis, alerts, and planning.
- Write and publish operations (only when you initiate them in the product): pause or enable Google Ads campaigns; push approved ad copy changes to Google Ads; create or update GTM tags, triggers, variables, and container versions; publish GTM container versions; and mark GA4 custom events as key events (conversions) for the property you selected.
We do not use Google user data for advertising, remarketing, interest-based targeting, credit eligibility, or building profiles unrelated to providing the service.
3. Sharing, transfer, and disclosure
- No sale or commercial transfer: We do not sell, rent, trade, or otherwise transfer Google user data to third parties for their own commercial purposes.
- No advertising use: We do not use Google user data for ads, remarketing, or interest-based targeting.
- No external AI training: Google user data is not shared with, disclosed to, or used to train third-party AI or machine-learning models. Product AI features, when enabled, operate on your workspace context to generate suggestions for you; they do not transfer Google API payloads to model providers for training.
- Infrastructure providers: Google user data is processed by Conversion Console and stored in our application database (MySQL) on infrastructure we operate (currently Hostinger) solely to run the service — authentication, sync jobs, reporting, and user-initiated write actions. These providers process data only as our infrastructure hosts, not as independent controllers of your Google data.
- Legal and safety: We may disclose information if required by law, to protect rights and safety, or to prevent fraud or abuse.
- Human access: We do not allow humans to read Google user data unless required for security, compliance, or with your explicit consent for support troubleshooting.
Other integrations
If you connect non-Google services (for example Meta Ads, Microsoft Clarity, Bing Webmaster, or CRM tools), those providers' data is handled under the same workspace access controls and is used only to provide Conversion Console features you enable. Non-Google integration credentials are encrypted at rest when ENCRYPTION_KEY is configured.
Data retention
We store your personal information for a period consistent with our business purposes. We retain personal information for as long as needed to fulfill the purposes in this policy unless a longer period is required or permitted by law.
Account, workspace, and connector records are kept while your account is active so we can provide sign-in, project access, synced metrics, and features you use. Google user data obtained through Google APIs is retained only as needed to provide Conversion Console to the user who granted access.
When retention expires for a given data type, we delete, destroy, or anonymize it so it can no longer be associated with you. Backup copies may persist for a limited time until backup rotations overwrite them.
Data deletion and revocation
You can disconnect Google integrations in Conversion Console at any time (Connections), which stops further syncing with those credentials.
You may request account and data deletion by emailing [email protected] from your registered account email. After we verify the request, we delete or destroy personal information and cached Google API data we hold on your behalf, unless retention is legally required.
You can also revoke Conversion Console's Google permissions at any time in your Google Account permissions.
Security
Conversion Console uses a multi-tenant architecture with owner-scoped access checks on mutations. Integration API keys and Clarity tokens are encrypted at rest with AES-256-GCM when ENCRYPTION_KEY is configured. Content and metrics are access-controlled and transmitted over HTTPS/TLS. Cron jobs require a strong CRON_SECRET. Aggregate analytics are processed at parameter level — we do not ingest PII from analytics platforms for optimization features.
Contact
Questions about privacy: [email protected]
See also our Terms of Service.