מדיניות פרטיות
Effective: 20 August 2026
Clarvix Connect ("Clarvix", "we") lets an authorized customer ("you") grant Clarvix limited, read-only access to their own advertising, analytics, and business accounts through each provider's standard OAuth consent screen. Clarvix never asks for or stores passwords.
What Google user data we access
Depending on which sources you choose to connect, Clarvix requests only the following Google OAuth scopes, each granted separately and incrementally:
analytics.readonly— lists your Google Analytics 4 properties and reads aggregated performance reports (sessions, conversions, revenue) for the one property you select.webmasters.readonly— lists your verified Search Console sites and reads search performance data for the one site you select.tagmanager.readonly— lists your Tag Manager accounts/containers so we can confirm the correct tracking container is installed.adwords(Google Ads) — lists the Google Ads accounts you can access and reads campaign/ad group/metrics reporting data via read-only GAQL queries.- Google Sheets:
drive.metadata.readonly(file names only, never file contents) andspreadsheets.readonly(only the one sheet you explicitly bind). - Google Business Profile: read-only listing of your business locations and public listing information.
- Google Calendar: read-only listing of upcoming events, used only to verify booked meetings.
No scope in this list permits creating, editing, publishing, or deleting anything in your Google account. This is enforced in code, not only by policy: the integration only calls read/list/search endpoints, and an automated check rejects any scope containing write, admin, manage, delete, or mutate keywords before it can ever be requested.
How we use this data
Data read through these scopes is used only to produce the reporting, dashboards, and revenue-leak diagnostics you requested when you connected the account. It is not used to train generalized AI models, and it is not used for any purpose beyond delivering the service to the same customer whose account it came from.
Who we share it with
Clarvix does not sell, rent, or transfer your Google user data to any third party. It is accessible only to the Clarvix personnel and internal systems that directly produce your reporting, and only for as long as your connection remains active. We do not share Google user data with advertisers, data brokers, or any other external party.
How we protect it
OAuth tokens are encrypted at rest with AES-256-GCM in a per-customer vault with a rotatable key. Only an opaque internal reference to that vault entry is ever passed to reporting logic — the raw token itself is never logged, rendered, or exposed. All traffic to and from Clarvix Connect is encrypted in transit (HTTPS/TLS). A connector is only ever shown as "connected" after a real, successful read-only API call, never merely after consent.
Retention and deletion
Data and credentials are retained only while your connection is active and only as needed to provide the service, meet legal obligations, ensure security, and maintain backups. You may disconnect any provider at any time from your Connect page; disconnecting immediately deletes the locally stored credential and requests revocation of the token with the provider itself. Backups are purged on their normal rotation schedule after deletion. Requests for access, correction, deletion, or retention information can be sent to contact@clarvix.net and will be honored within a reasonable time.