Privacy policy
Last updated 16 August 2026.
Not yet reviewed by counsel. Working draft. Have a lawyer review it before taking real money or submitting for Google OAuth verification.
Who we are
Tantragyan Technologies Pvt Ltd, A-103, Jai Estate, MIDC Phase 1, Dombivli, Maharashtra 421201, India. Privacy contact: privacy@tantra-gyan.com.
What we collect
- Free scans — the store address you enter, and the public catalogue data at that address. No account needed.
- Lead capture — your email address, if you ask us to send a full report.
- Accounts — name, email, and password hash.
- Connected sources — the data described in the scope table below.
- Usage — pages viewed and features used, to work out what to build next.
- Payments — handled by Paddle. We never see or store your card details.
Google API scopes and how each is used
We request the narrowest scope that answers the question, and only read-only scopes. We never request write, billing, or account-management access.
| Scope | Access | What we use it for |
|---|---|---|
| https://www.googleapis.com/auth/content | Merchant Center, read-only | Read your product feed, item-level issues, and click data so we can identify which disapprovals cost revenue and verify whether a fix worked. |
| https://www.googleapis.com/auth/webmasters.readonly | Search Console, read-only | Read query and page performance so we can find organic demand your catalogue does not answer. |
| https://www.googleapis.com/auth/yt-analytics.readonly | YouTube Analytics, read-only | Read video performance, only if you choose to connect a channel. |
RevenueCue’s use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. We do not use Google user data for advertising, we do not sell it, and we do not allow humans to read it except where you have explicitly asked us to help with a support issue, where required by law, or for security investigation.
What we never do
- Sell or rent your data.
- Use your data to train models sold to anyone else.
- Write to your store, feed, or ad account.
- Share identifiable data with other customers. Benchmarks are aggregated and anonymised.
How long we keep it
- Scan results — kept so shareable links keep working and change over time is visible.
- Account data — while your account is open, then deleted within 30 days of closure.
- OAuth tokens — deleted immediately when you disconnect a source.
- Invoices — retained as long as tax law requires.
How it is protected
OAuth tokens and credentials are encrypted at rest with AES-256-GCM and decrypted only in memory for the call they were issued for. Credentials never appear in logs, error reports, or API responses. See Security.
Sub-processors
- Paddle — payments and merchant of record
- Resend — transactional email
- Railway — hosting and database
- Google — only the APIs you connect
Your rights
Access, correction, deletion, export, and objection. Email privacy@tantra-gyan.com and we will respond within 30 days. You can revoke Google access at any time at myaccount.google.com/permissions without going through us.
Changes
Material changes are announced by email at least 30 days before taking effect.