Your data, clearly explained

Privacy at Digital Apps.

How Digital Apps handles personal information across digitalapps.com, products, support services, and the managed Google Analytics connection for WP Global Site Tag.

Last updated 20 July 2026

Read-only access

WP Global Site Tag requests only Google Analytics read-only access and cannot edit Analytics resources.

Reports stay on your site

Analytics report requests go directly between WordPress and Google instead of passing through the Digital Apps connection service.

Disconnect any time

Disconnecting revokes the managed grant and removes the managed connection record plus local cached reports.

01

Scope of this policy

Digital Apps develops WordPress software and operates digitalapps.com and related services. The policy applies when someone visits the website, creates an account, purchases or uses a product, requests support, or uses a Digital Apps managed connection.

For WP Global Site Tag installations, the website owner controls Analytics configuration and report data stored on that WordPress site. Digital Apps' policy covers information handled by Digital Apps, while the website owner's own policy covers information collected from that site's visitors.

02

Information we collect

Information you provide

This can include name, email, account and order details, licence information, support messages, files, and technical details supplied in a request.

Website and device information

Standard technical data such as IP address, browser/device type, requested pages, timestamps, cookie identifiers, and security or diagnostic events may be processed to operate, secure, and improve the website.

Transactions

Payment providers process payment details under their own privacy terms. Digital Apps receives the transaction and account records needed to fulfil purchases, manage licences, provide support, prevent fraud, and meet accounting or legal obligations.

Third-party tags installed by customers

WP Global Site Tag can place tags selected by a website owner. Visitor browsers may then send information directly to Google or another configured service. Digital Apps does not receive that visitor information merely because the plugin is installed.

03

Google Analytics data and the managed connection

WP Global Site Tag can connect a Google account and display Analytics information inside WordPress. It requests the analytics.readonly permission to list accessible Analytics accounts, properties, website streams, and retrieve administrator-selected reports.

WordPress starts authorisation The site sends connection metadata plus short-lived security values to begin OAuth.
Digital Apps holds the refresh token The refresh token is encrypted with AES-256-GCM while the managed connection is active.
WordPress calls Google directly Short-lived access is used by the WordPress site to call Google Analytics APIs directly.

Analytics property, stream, request, report, and response data is not routed through or stored by the managed Digital Apps connection service. The service is hosted on Cloudflare infrastructure, with application logging and Worker observability disabled for this connection service.

Self-managed connection

Advanced administrators can instead use their own Google OAuth application. In that mode, credentials, refresh/access tokens, and cached reports remain encrypted on the WordPress installation and the managed Digital Apps connection service is bypassed.

Google API Limited Use

Google user data is used only to provide or improve the user-facing Analytics features selected by the user. Digital Apps does not sell Google user data or use it for advertising, retargeting, lending, credit decisions, or surveillance.

04

How we use information

  • Provide, maintain, secure, and troubleshoot the website, products, accounts, licences, updates, and support.
  • Complete transactions and communicate about purchases, service changes, security, and support requests.
  • Prevent fraud, abuse, unauthorised access, and technical failures.
  • Comply with legal, tax, accounting, and regulatory obligations and enforce terms.
  • Improve user-facing products and services using information Digital Apps is permitted to use.

05

Sharing and service providers

Personal information is shared only when needed to provide a requested service, operate the business, protect users, comply with law, or complete a business transaction subject to applicable safeguards.

Google

Processes authorisation and Analytics API calls under Google's own terms and privacy policy.

Cloudflare

Provides hosting, network, database, and security infrastructure for the managed connection.

Business providers

Hosting, payment, email, support, monitoring, and professional services may process only what their contracted service requires.

06

Retention, disconnection, and deletion

Personal information is kept only as long as needed for the purposes in the policy, including providing services, maintaining security, resolving disputes, and meeting legal obligations.

Up to 10 minutesManaged authorisation sessions and one-time exchange records expire and are deleted after use or cleanup.
Until disconnectThe encrypted Google refresh token and managed connection record remain while the managed connection is active.
Up to 90 daysManaged connection audit events may retain operation, time, result, product, and a non-reversible connection reference.
Up to 24 hoursRate-limit records may be retained for this period.

Analytics report caches and local connection tokens remain on the WordPress site and are removed on disconnect. Plugin uninstall also removes local data unless the administrator has enabled the data-preservation option.

07

Security and international processing

Digital Apps uses administrative, technical, and organisational safeguards appropriate to the information handled. The managed connection encrypts Google refresh tokens at application level with AES-256-GCM, stores its encryption key separately as a restricted service secret, and stores opaque connection credentials only as hashes.

No system can guarantee absolute security. Digital Apps operates from Australia and may use service providers that process information in other countries, with contractual or other safeguards where required.

08

Your choices and rights

Depending on location, users may have rights to request access to, correction of, deletion of, restriction of, or a copy of personal information, and to object to certain processing. Identity verification may be required.

Decline Google authorisationTag-management features can still be used without authorising Analytics access.
Use self-managed OAuthKeep OAuth credentials and refresh tokens on the WordPress installation.
Disconnect any timeDisconnect Google Analytics or revoke access from the Google Account connection settings.
Control cookiesUse browser settings and the consent controls available on the website.

Children

Digital Apps products and the managed Analytics connection are intended for businesses and website administrators, not children.

Changes to this policy

The policy may be updated when products, data practices, or legal obligations change. The date at the top is updated when changes are made.

09

Contact us

Contact Digital Apps with privacy questions, concerns, or requests to access or delete information. For a managed Google connection deletion request, include the connected WordPress site URL so the correct non-reversible connection record can be identified.

Managed Google connection deletion: include the connected WordPress site URL in the request.
Contact Digital Apps

Project enquiry

Tell us about your project.

Share what you are building, improving or connecting, and Digital Apps will reply with the most useful next step.