Privacy Policy
Last updated: 25 September 2026
This policy explains how Granite Signals (www.granitesignals.com), operated by Granite ("we", "us"), handles data. Granite Signals is an internal platform used by Granite staff to manage and report on the websites and digital marketing we run for our clients. It is not offered to the public.
1. Who this applies to
- Granite staff, who sign in to Granite Signals.
- Our clients, and anyone who connects a Google account to Granite Signals so that we can report on that client's marketing performance.
2. Data we receive from Google
Granite Signals only requests access when someone chooses to connect a Google account. It requests read-only access to:
- Google Analytics (
analytics.readonly): website traffic, engagement, conversion and e-commerce figures, and the list of Analytics properties the account can see. - Google Search Console (
webmasters.readonly): search clicks, impressions, positions and queries, and the list of sites the account can see. - Google Ads (
adwords): campaign structure, spend, performance and audience breakdowns. We use this access for reporting only. Granite Signals never creates, changes, pauses or removes anything in a Google Ads account. - Your email address (
userinfo.email): to label the connection so our team knows which login it came from.
Staff who sign in with Google share only their name, email address and profile picture, which we use to identify them in the application.
We do not request access to Gmail, Google Drive, Calendar, Contacts or any other Google service through these connections.
3. How we use Google data
Data received from Google APIs is used only to:
- produce monthly performance reports and dashboards for the client whose account it is;
- let the Granite team working on that client's account see how the client's website and campaigns are performing;
- link each client to the correct Analytics property and Search Console site.
We do not:
- sell Google user data, or transfer it to anyone for their own purposes;
- use it for advertising, retargeting or building profiles of individuals;
- use it to determine creditworthiness or for lending;
- use it to develop, improve or train generalised or non-personalised AI or machine learning models;
- let people read it except where needed to provide reporting to the client, for security, to comply with the law, or where the client has agreed.
Google API Services User Data Policy
Granite Signals' use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
4. Who we share data with
We share data only with the service providers we need to run Granite Signals, under contracts that restrict them to processing it on our behalf:
- Amazon Web Services (Ireland, eu-west-1): hosting and database.
- Anthropic and OpenAI: to draft the written commentary in client reports. Only the aggregated report figures are sent (for example, monthly sessions or spend), never login credentials. Under our agreements with them, this data is not used to train their models.
- Mailgun: to deliver email sent from the application.
Finished reports are shared with the client they belong to. We may also disclose data where the law requires it.
5. Storage and security
- Data is stored on servers in the European Union (Ireland).
- Google access and refresh tokens are encrypted at rest and never shown in the application.
- All traffic to Granite Signals is encrypted in transit (HTTPS).
- Access is limited to signed-in Granite staff, and marketing data is limited further to staff whose role requires it.
6. Retention and deletion
- Report data is kept for as long as we provide services to the client, so that month-on-month and year-on-year comparisons remain possible.
- When a Google connection is removed, we delete its stored tokens and stop fetching data. Anyone can also revoke our access at any time from myaccount.google.com/permissions.
- To ask us to delete data received from your Google account, email [email protected]. We will confirm deletion within 30 days.
7. Your rights
Under the GDPR you can ask to access, correct or delete personal data we hold about you, object to or restrict how we process it, and ask for a copy of it. To do so, email [email protected]. You can also complain to the Data Protection Commission in Ireland (dataprotection.ie).
8. Changes to this policy
If we change how we use Google data, we will update this page and change the date at the top before the change takes effect.
9. Contact
Granite, [email protected]