Google user data
If you choose to connect a Google account, Brixels requests access to Google Analytics, Google Tag Manager and Google Search Console so that, when you publish a website, we can create and configure an Analytics property and a Tag Manager container for it, add the site to Search Console, verify your ownership of it and submit its sitemap, and show you which account is connected. We access only the data these features need: your Google account email address, the list of Analytics accounts/properties, Tag Manager accounts/containers and Search Console properties you can manage, and the verification tokens Google issues for your sites.
What we store: the connection token Google issues when you connect, your Google account email address, and the identifiers and names of the Analytics account, Tag Manager account and Search Console properties you chose, plus the property, container and verification token created for each website. We do not store Analytics report data. We never use Google user data for advertising, profiling, or training AI models. Google user data is not sold and is not shared with third parties except as required to provide these features.
How we protect it: the connection token is encrypted at rest with AES-256-GCM before it is written to our database. The encryption key is held only in our server environment and is never sent to a browser, written to logs, or stored alongside the data it protects. The token is decrypted only inside server-side functions, for the moment a request to Google is made, and is never displayed to anyone, including you. All traffic between your browser, our servers and Google's APIs is encrypted in transit with TLS. Access to the systems that hold this data is limited to named administrators using multi-factor authentication, and our staff do not read Google user data except for support you ask for or as required by law. Our infrastructure providers hold SOC 2 Type II certification. Every access token we request from Google is short-lived and is not stored.