Privacy Policy

Last updated: August 13, 2026

Information We Collect

  • Account information (name, email, company)
  • Product feed data you upload to our platform
  • Usage data and analytics
  • Technical information (IP address, browser type)
  • Communication preferences

How We Use Your Information

We use your information to provide and improve our services, process your requests, send service-related communications, and ensure the security of our platform. We do not sell your personal information to third parties.

Data Retention

We retain your personal information for as long as your account is active or as needed to provide you services. You may request deletion of your data at any time by contacting our support team.

Your Rights

  • Access your personal data
  • Correct inaccurate data
  • Request deletion of your data
  • Object to data processing
  • Data portability
  • Withdraw consent

Cookies and Tracking

We use cookies and similar technologies to enhance your experience, analyze usage patterns, and deliver personalized content. You can manage your cookie preferences through your browser settings.

Third-Party Services

We may share your information with trusted third-party service providers who assist us in operating our platform, conducting our business, or servicing you. These parties are obligated to keep your information confidential.

Google User Data We Access

  • Google Analytics 4 (scope: analytics.readonly) — read-only. We read product-level report metrics (item views, add-to-cart, checkouts, purchases, item revenue and the conversion rates derived from them) for the single GA4 property you select when you connect. The only dimension we request is the product identifier. We do not read user profiles, user identifiers, audiences, demographic reports or any other GA4 data.
  • Google Merchant Center (scope: content) — we read and write product data for the Merchant Center account you select, so that we can deliver your own product feed to your own account. Within that account we also create the data source (the feed registration) that carries your feed, once, when you first point an export at that account, and we read the data quality feedback Google returns for that feed so we can show you its disapproval reasons. We do not list or delete data sources, and we do not change your Merchant Center account settings.
  • Google Ads (scope: adwords) — read-only. We call two endpoints, both reads: listAccessibleCustomers, which returns the accounts your Google account can reach, and a customer_client search query, which expands a Manager (MCC) account into the individual accounts beneath it so you can pick one that can actually receive an audience. We read only account IDs, account names and whether an account is a manager. We do not read campaigns, keywords, budgets, spend or performance data, and we perform no mutate operations. Google publishes no narrower scope for these calls.
  • Google Data Manager (scope: datamanager) — write-only. We upload SHA-256 hashed email addresses and phone numbers, derived from your own customer records, into a Customer Match audience in the Google Ads account you selected.
  • Optifeed’s use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.

How We Use Google User Data

  • Google Analytics metrics are used to calculate OptiScore, our product performance score, and to power the filter and enrichment rules that decide which of your products enter an export and how their attributes are set.
  • Google Merchant Center access is used to deliver your own product feed to your own Merchant Center account and to report back the errors Google raises against it.
  • Google Ads account data is used only to present the account picker, so that you can choose which of your accounts receives an audience.
  • Google Data Manager is used only to create and update the Customer Match audiences you ask us to build from your own customer segments.
  • We use Google user data solely to provide and improve these user-facing features. We do not use it for advertising, for lending or credit decisions, or for any purpose you have not asked us to perform. We do not sell it.

Google User Data Sharing and Transfer

  • We do not sell Google user data, and we never transfer it to data brokers, advertising networks, or information resellers.
  • Raw Google user data is written back only to your own Google accounts — your Merchant Center account and the Google Ads account you selected. It is never sent to another customer of Optifeed. There is one transfer of derived data, described in the last point below.
  • Our service providers are limited to those needed to run the platform: cloud hosting, error tracking (Sentry) and performance monitoring (Scout APM). They act on our instructions and are bound to keep the data confidential.
  • Our AI rule suggestion feature sends aggregate statistics derived from your Google Analytics metrics — such as median and percentile purchase, view and revenue figures across your whole catalogue, and counts of how many products match a condition — to Anthropic, our large language model provider, in order to propose rules for your review. No individual product rows, no customer data and no Google account identifiers are included. This data is not used to train any model.

How We Protect Google User Data

  • OAuth tokens for Google Analytics, Merchant Center and Google Ads are encrypted at rest in our database using application-level encryption, and are never written to logs.
  • All traffic between Optifeed, your browser and Google APIs is encrypted in transit with TLS.
  • Data is isolated per company. Every query is scoped to the account that connected the integration, so no Optifeed customer can reach another customer’s Google data.
  • Access to production systems is limited to authorised Optifeed engineers.

Google User Data Retention and Deletion

  • Google Analytics metrics are stored only in the aggregated, product-level form described above, and are replaced on each synchronisation, so the stored set reflects the most recent sync window rather than an accumulating history.
  • When you disconnect a Google integration, the stored OAuth token is deleted immediately and Optifeed stops all access to your Google account. You can also revoke Optifeed’s access at any time from your Google Account permissions page.
  • When you delete your Optifeed account, the associated Google data is deleted along with it.
  • You may request deletion of any remaining Google-derived data at any time by contacting privacy@optifeed.com. We action such requests within 30 days.

International Data Transfers

Your information may be transferred to and processed in countries other than your own. We ensure appropriate safeguards are in place to protect your data in accordance with applicable laws.

Contact Us

If you have any questions about this Privacy Policy, please contact us at privacy@optifeed.com.