1. Introduction
This Privacy Policy describes how IT Design International ("we", "us") handles information accessed through the IT Design application (the "App") — our integration tools that connect to your Google accounts through Google APIs to read and manage your marketing data at your direction. The App is operated by IT Design International, a Google Partner agency based in Gqeberha (Port Elizabeth), South Africa.
This policy applies specifically to data the App obtains from Google APIs. It supplements, and does not replace, our general website privacy policy.
2. Google services and OAuth scopes we access
The App connects to your Google accounts only after you sign in with Google and explicitly grant access on Google's consent screen. You choose which of the following you authorise; we request access only to the scopes needed for the features you use:
- Google Ads — read and manage campaigns, budgets, ads, keywords, conversions and recommendations in the Google Ads accounts you control (
adwords). - Google Analytics & Tag Manager — read GA4 reports and manage GA4 configuration and Google Tag Manager containers (
analytics.readonly,analytics.edit,tagmanager.edit.containers,tagmanager.publish). - Google Search Console — manage sites and sitemaps, inspect URLs, verify site ownership and submit indexing requests (
webmasters,siteverification,indexing). - Google Merchant Center — read and manage accounts, products, data sources and reports (
content). - YouTube — read and manage videos, playlists, captions and comments, upload videos, and read YouTube Analytics and Reporting data for channels you control (
youtube.force-ssl,youtube.upload,yt-analytics.readonly,yt-analytics-monetary.readonly). - Your email address — your Google account email (
userinfo.email), used solely to identify which account a stored authorisation belongs to.
We only ever access accounts and data that the signed-in Google user already has permission to access.
3. How we use the data
Data accessed through Google APIs is used only to perform the specific actions you request through the App — for example, reading a report, creating or updating a campaign, or uploading a video. We do not use it for any other purpose. Specifically, we do not:
- sell, rent or trade your Google data;
- use it for advertising, profiling, or building marketing or audience lists of our own;
- transfer it to third parties except as needed to provide the feature you requested, to comply with law, or as part of a merger/acquisition with equivalent protections;
- allow humans to read it, except where you give explicit consent for a specific support request, where it is necessary for security or to comply with law, or where the data has been aggregated/anonymised and is used for internal operations in line with applicable requirements.
4. Limited Use disclosure
IT Design's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements. Where applicable, our use of data obtained through restricted scopes also complies with any additional product-specific requirements (including those for the YouTube API Services).
5. YouTube API Services
Where you use YouTube features, the App uses YouTube API Services. By using those features you also agree to the YouTube Terms of Service, and Google's handling of data is governed by the Google Privacy Policy. You can review and revoke the App's access to your data at any time via the Google security settings page.
6. Storage, security and retention
To act on your behalf without asking you to sign in each time, the App stores the OAuth refresh token issued by Google. Refresh tokens are encrypted at rest using AES-256-GCM and held either on the server's encrypted storage or in a private database accessible only to the App. We do not store your Google password.
We retain a stored authorisation only for as long as you keep the connection active. We also keep an internal audit log of write operations (the action, timestamp and Google request identifier) so changes can be traced; this log does not duplicate the substance of your Google data. When you revoke access (see below), the stored token is deleted and can no longer be used.
7. Revoking access and deleting your data
You can disconnect the App at any time by either:
- removing its access on the Google security settings page; or
- emailing us at info@itdesign.co.za to request that we delete the stored authorisation and any associated records.
Once revoked, any encrypted token we hold is invalidated and removed. Under South Africa's Protection of Personal Information Act (POPIA) you may also ask to see, correct or delete personal information we hold about you.
8. Service providers
The App runs on infrastructure we control. We do not share Google user data with advertising networks, data brokers, or any third party for their own purposes.
9. Changes to this policy
We may update this policy from time to time. The current version is always published at this URL with the effective date below. Material changes that affect how we handle Google user data will be reflected here before they take effect.
10. Contact us
Questions about this policy or about data the App handles can be sent to info@itdesign.co.za, or by post to IT Design International, 6 Nederburgh Crescent, Gqeberha (Port Elizabeth), 6025, South Africa.
Effective date: 22 June 2026