Loading

Privacy Policy

Your data, clearly explained

Privacy at Digital Apps

This policy explains how Digital Apps handles personal information across digitalapps.com, our products and support services, and the managed Google Analytics connection provided for WP Global Site Tag.

Last updated: 20 July 2026

Read-only access

WP Global Site Tag requests only read-only Google Analytics access. It cannot edit your Analytics account, properties, or data streams.

Reports stay on your site

Analytics report requests and responses travel directly between your WordPress installation and Google. They do not pass through the Digital Apps connection service.

Disconnect any time

Disconnecting in the plugin asks Digital Apps to revoke the Google grant and removes the managed connection record and locally cached reports.

Scope of this policy

Digital Apps ("we", "us", or "our") develops WordPress software and operates digitalapps.com and related services. This policy applies when you visit our website, create an account, buy or use a product, request support, or use a Digital Apps managed connection.

When WP Global Site Tag is installed on a customer website, that website owner controls the Analytics configuration and report data held on that WordPress installation. This policy covers information handled by Digital Apps. The website owner's own privacy policy applies to information collected from that site's visitors.

Information we collect

Information you provide

Depending on how you use our services, you may provide your name, email address, account and order details, license information, support messages, and any files or technical details you choose to include in a request.

Website and device information

Our website and infrastructure may process standard technical information such as your IP address, browser and device type, requested pages, timestamps, cookie identifiers, and security or diagnostic events. We use this information to operate, secure, and improve the website.

Transactions

Payment providers process payment details under their own privacy terms. We receive the transaction and account records needed to fulfil purchases, manage licenses, provide support, prevent fraud, and meet accounting or legal obligations.

Third-party tags installed by customers

WP Global Site Tag can place tags selected by a website owner. A visitor's browser may then send information directly to Google or another configured service. Digital Apps does not receive that visitor information merely because the plugin is installed. The website owner is responsible for its tag configuration, consent choices, and privacy disclosures.

Google Analytics data and the managed connection

WP Global Site Tag lets a WordPress administrator connect a Google account and display Analytics information inside WordPress. The plugin requests the analytics.readonly permission so it can list accessible Analytics accounts, properties, and website data streams, and retrieve the reports chosen by the administrator. This access does not permit the plugin to create, edit, or delete Google Analytics resources.

Managed connection data flow

  1. Your WordPress site sends Digital Apps the site URL, hostname, plugin and protocol versions, callback URL, locale, and short-lived security values needed to begin authorization.
  2. Google returns an authorization code to the Digital Apps connection service. The service exchanges that code and retains the Google refresh token, encrypted with AES-256-GCM, while the connection remains active.
  3. Your site receives a short-lived Google access token and an opaque, site-bound connection token. Digital Apps stores only a cryptographic hash of the opaque connection token.
  4. Your WordPress site uses the short-lived access token to call the Google Analytics Admin and Data APIs directly. Analytics property, stream, request, report, and response data is not routed through or stored by the Digital Apps connection service.

Because the managed service holds the refresh token, it is technically able to request Google Analytics access while the connection is active. Digital Apps uses this capability only to renew the short-lived access needed for the administrator-requested plugin features. The service does not add telemetry.

The managed connection is hosted on Cloudflare infrastructure. Application logging and Worker observability are disabled for the connection service so OAuth codes, tokens, and Analytics data are not copied into application logs.

Self-managed connection

Advanced administrators can use their own Google OAuth application instead. In that mode, OAuth credentials, refresh tokens, access tokens, and cached reports stay encrypted on the WordPress installation and the managed Digital Apps connection service is bypassed.

Google API Limited Use

Digital Apps handles information received through Google APIs in accordance with the Google API Services User Data Policy, including its Limited Use requirements. We use Google user data only to provide or improve the user-facing Analytics features that the user has chosen.

  • We do not sell Google user data or transfer it to advertising platforms, data brokers, or information resellers.
  • We do not use Google user data for advertising, retargeting, lending, credit decisions, or surveillance.
  • Digital Apps personnel do not read Google Analytics report data through the managed service because that report data does not pass through it. If you choose to share report data in a support request, we use it only to provide that support.

How we use information

  • Provide, maintain, secure, and troubleshoot our website, products, accounts, licenses, updates, and support.
  • Complete transactions and communicate about purchases, service changes, security, and support requests.
  • Prevent fraud, abuse, unauthorized access, and technical failures.
  • Comply with legal, tax, accounting, and regulatory obligations and enforce our terms.
  • Improve our user-facing products and services using information we are permitted to use.

Sharing and service providers

We share personal information only when needed to provide a requested service, operate our business, protect users, comply with law, or complete a business transaction subject to applicable safeguards.

  • Google: Google processes authorization and the Analytics API calls made by your WordPress site under Google's Terms of Service and Privacy Policy.
  • Cloudflare: Cloudflare supplies hosting, network, database, and security infrastructure for the managed connection.
  • Business service providers: Hosting, payment, email, support, monitoring, and professional service providers may process only the information needed for their contracted services.
  • Legal and safety: We may disclose information where reasonably necessary to comply with law, protect rights and safety, investigate abuse, or defend legal claims.

Retention, disconnection, and deletion

We keep personal information only for as long as needed for the purposes described in this policy, including to provide services, maintain security, resolve disputes, and meet legal obligations.

  • Managed authorization sessions and one-time exchange records expire within 10 minutes and are deleted after use or expiry cleanup.
  • The encrypted Google refresh token and managed connection record remain until the administrator disconnects, the Google token expires, or Digital Apps deletes the connection in response to a valid request.
  • Managed connection audit events contain the operation, time, result, product, and a non-reversible connection reference. They are retained for up to 90 days. Rate-limit records are retained for up to 24 hours.
  • Analytics report caches and local connection tokens remain on the WordPress installation and are removed on disconnect. Plugin uninstall also removes local data unless the site administrator has explicitly enabled its data-preservation option.

To revoke managed access and delete the broker-held refresh token, use Disconnect Google Analytics in WP Global Site Tag before uninstalling the plugin. You can also remove Digital Apps access from your Google Account connections. If you cannot disconnect, submit a deletion request through our contact page and identify the connected site URL.

Security and international processing

We use administrative, technical, and organisational safeguards appropriate to the information we handle. The managed connection encrypts Google refresh tokens at the application level using AES-256-GCM, stores its encryption key separately as a restricted service secret, and stores opaque connection credentials only as hashes. Access to production systems is restricted and audited.

No system can guarantee absolute security. Please contact us promptly if you believe your account or connection may have been compromised.

Digital Apps operates from Australia and uses service providers that may process information in other countries. Where required, we use contractual and other safeguards intended to protect information during international processing.

Your choices and rights

Depending on where you live, you may have rights to request access to, correction of, deletion of, restriction of, or a copy of personal information we hold about you, and to object to certain processing. We may need to verify your identity before acting on a request.

  • You can decline Google authorization and still use the plugin's tag-management features.
  • You can use the self-managed OAuth option so Digital Apps does not hold the Google refresh token.
  • You can disconnect Google Analytics at any time or revoke access from your Google Account.
  • You can control cookies through your browser and any consent controls provided on our website.

Children

Our products and managed Analytics connection are intended for businesses and website administrators, not children. We do not knowingly use the managed connection to collect personal information from children.

Changes to this policy

We may update this policy when our products, data practices, or legal obligations change. We will update the date at the top of this page and provide additional notice where a change materially affects how we use Google user data.

Contact us

Contact Digital Apps with privacy questions, concerns, or requests to access or delete information. For a managed Google connection deletion request, include the connected WordPress site URL so we can identify the correct non-reversible connection record.

Contact Digital Apps