This privacy policy describes how Sense Data Lab PTY LTD (ABN 50617014687) ("we", "us", "our") collects, uses, stores, shares, and protects your information when you use the GA4 Audit Tool at audit.sensedatalab.com.au (the "Service").

1. Information We Collect

1.1 Google Account Information

When you sign in via Google OAuth 2.0, we receive and store:

1.2 Google Analytics Configuration Data

We request read-only access to your GA4 property administrative configuration via the analytics.readonly scope. This includes property settings, linked services, enhanced measurement settings, data retention settings, attribution settings, Google Signals status, audiences, key events, and custom dimensions/metrics.

We do not access, collect, or store your actual analytics data (website traffic, user behaviour, event data, or any personally identifiable information about your website visitors).

1.3 Audit Results

When you run an audit, the results (configuration findings, score, severity, and recommendations) are stored in our database linked to your account.

2. How We Use Your Information

We use the information collected solely to:

3. Sharing, Transfer, and Disclosure of Google User Data

3.1 Third-Party AI Service — OpenAI

To generate AI-powered audit summaries, we send GA4 property configuration data (property name, audit scores, configuration settings, and identified issues) to OpenAI (OpenAI, L.L.C.) via their API. This data does not include your email address, OAuth tokens, or any analytics traffic/user data.

OpenAI processes this data under their API data usage policy, which states that data submitted via the API is not used to train their models.

3.2 Infrastructure Providers

Our Service runs on Google Cloud Platform (Cloud Run, Cloud SQL). Your data is processed and stored within Google Cloud's infrastructure in the australia-southeast1 (Sydney) region.

3.3 No Other Sharing

We do not sell, rent, trade, or otherwise share your Google user data with any other third parties, advertisers, or data brokers. We do not use your Google user data for advertising or marketing purposes. We only disclose information if required by law or to protect our legal rights.

4. Data Retention and Deletion

4.1 OAuth Tokens

Your encrypted Google OAuth refresh token is stored for as long as your account exists. It is used exclusively to access the Google Analytics Admin API on your behalf when you run audits.

4.2 Audit Results

Audit results are retained in our database so you can review past audits. These contain only GA4 configuration data — never analytics traffic or user data.

4.3 Deleting Your Data

You may request deletion of all your data (account, tokens, and audit history) at any time by emailing info@sensedatalab.com.au. Upon receiving a verified request, we will permanently delete all your data within 30 days.

4.4 Revoking Access

You can revoke our access to your Google account at any time from your Google Account permissions page. Once revoked, we can no longer access your GA4 data. To also delete stored data, please contact us as described above.

5. Data Protection and Security

We implement the following measures to protect your data:

6. Google API Services User Data Policy

This application's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.

7. Changes to This Policy

We may update this privacy policy from time to time. Material changes will be noted by updating the "Last updated" date at the top of this page. Continued use of the Service after changes constitutes acceptance of the updated policy.

8. Contact Us

If you have questions about this privacy policy or wish to exercise your data rights, contact us: