WSAnalytics

WSAnalytics privacy policy

Last updated:

This policy explains what data WSAnalytics handles, where it goes and how to remove it. It covers:

  • the WSAnalytics WordPress plugin (WordPress.org slug wsanalytics-google-analytics-and-dashboards), and
  • the WSAnalytics sign-in relay at https://connect.shivaatripathi.com.

WSAnalytics is made by Shivaa Tripathi, referred to below as "we" or "us". Contact: [email protected].

The short version

  • Your analytics data goes from Google straight to your own WordPress site. It never passes through our servers.
  • Our relay only takes part when you connect your Google account and when your site refreshes its access token. It passes sign-in codes and tokens along, and it does not store or log them.
  • The plugin sends us no telemetry and adds nothing of ours to your visitors' browsers.
  • You can disconnect, revoke access and delete everything at any time.

1. The WordPress plugin

The plugin runs on your WordPress site, which you (the site owner) control. Everything it keeps is stored in your own WordPress database:

  • Settings, such as your GA4 Measurement ID, property, Search Console site, consent settings and which roles may see reports.
  • Your Google connection: the Google account email address that connected, the granted scopes, and the OAuth refresh and access tokens, encrypted with keys derived from your site's own WordPress salts. If you use your own Google client, its client secret is stored encrypted too. Its client ID is stored as-is, because it is not a secret (Google shows it in every sign-in link).
  • Cached reports (temporary copies of the numbers Google returned), kept for minutes to days so pages load fast.
  • A per-user flag recording that you dismissed the 2.0 upgrade notice.

We have no access to your WordPress database, and the plugin sends us no usage data, error reports or other telemetry.

Calls the plugin makes. When you view reports, your site calls Google's APIs directly (the Google Analytics Data API, the Google Analytics Admin API, the Search Console API, and Google's OAuth token and revoke endpoints). Those requests carry your access token and describe the report you asked for. Google's responses come back to your site only. In the default sign-in mode, token refreshes go through our relay (see below). In tracking-only mode, or with your own Google client, the plugin never contacts us at all.

Your website's visitors. When tracking is on, the plugin adds Google's gtag.js to your pages, and your visitors' browsers send page views and events to Google Analytics under your GA4 property. For that data, you are the controller and Google is your processor, under your agreement with Google. We receive none of it. The plugin supports Google Consent Mode v2 and the WP Consent API so you can respect your visitors' choices. Tell your visitors about Google Analytics in your own privacy policy.

2. The sign-in relay

Google does not allow a plugin to ship the client secret that one-click "Connect with Google" needs, so a small relay service that we run holds it. The relay is used in exactly two situations.

When you connect. Your browser visits the relay, which shows a confirmation page naming your site, then sends you to Google. After you approve, Google sends your browser back to the relay with a one-time authorization code. The relay exchanges that code with Google for tokens and immediately passes them to your WordPress site in your browser (a form that posts directly to your site's wp-admin/admin-post.php). During this, the relay processes:

  • your site's address (where to send you back),
  • a random, single-use state value created by your site,
  • the authorization code from Google,
  • the tokens Google issues: an access token, a refresh token and an ID token. The relay reads your Google account email address from the ID token so your site can show which account is connected, and does not forward the ID token itself.

When your site refreshes its access token (roughly once an hour while reports are being viewed, and about once a week when WordPress's Site Health runs its background checks, which include the WSAnalytics connection check), your site sends its refresh token to the relay, which adds the client secret, asks Google for a new access token and returns it to your site.

What the relay does not do:

  • It has no database and does not store codes, tokens, email addresses or site addresses. They exist only in memory for the length of the request.
  • It does not log tokens, codes, email addresses, request bodies or query strings. Its logs contain only the route, the response status, the time and how long the request took.
  • It never calls Google's Analytics or Search Console APIs, and never sees your analytics data.
  • It sets no cookies and uses no analytics or tracking.

IP addresses. The relay uses your IP address, in memory only, to limit how many requests one address can make per minute (to prevent abuse). Rate-limit entries expire within minutes and are never written to disk.

Where the relay runs. On a server in Germany (Hetzner), behind Cloudflare, which protects the service and passes traffic to it. Cloudflare processes network data such as IP addresses to do this, under its own privacy policy.

Legal basis (GDPR). We process this data because you asked us to connect your Google account (performance of the service you requested), and for rate limiting, in our legitimate interest in keeping the service secure and available.

3. Google user data

WSAnalytics requests these Google permissions, and uses them only as described:

Permission What we use it for
openid, email To show which Google account is connected, in your WordPress settings
analytics.readonly To list the GA4 properties and web streams you can access, and to read your reports for display in your WordPress admin
webmasters.readonly (only if you turn on Search Console) To list your Search Console sites and read search queries and pages for display in your WordPress admin

All access is read-only. WSAnalytics never changes your Analytics or Search Console data or settings.

How Google user data is used, stored and shared.

  • Data from Google APIs is used only to show reports to the people you allow in your own WordPress admin, and for nothing else.
  • It is stored only in your WordPress database (as short-lived cached reports), never on our servers.
  • We do not sell it, share it with or transfer it to anyone, or use it for advertising, credit decisions, or building user profiles.
  • We do not use it to develop, improve or train generalized artificial intelligence or machine learning models.
  • No person reads your Google user data. The only exception would be if you explicitly asked us to look at something while helping you, if needed for security purposes, or if required by law.

Limited Use. WSAnalytics' use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

4. How to disconnect, revoke and delete

Disconnect from Google. In WordPress, go to WSAnalytics, Settings, Connection, and click Disconnect. The plugin asks Google to revoke its access and deletes the stored tokens.

Revoke access from your Google account (works even if your site is gone): open https://myaccount.google.com/permissions, choose WSAnalytics, and remove its access. Your site will show "Reconnect required" until you connect again.

Delete everything the plugin stored. In WordPress, go to Plugins, deactivate WSAnalytics, then click Delete. By default this removes all of its settings, the encrypted connection, cached reports and user flags, and revokes its Google access. (If you turned off "Delete all WSAnalytics data when the plugin is deleted" under Settings, Advanced, turn it back on first.)

Data held by us. The relay keeps nothing to delete. If you still want to ask about your data or exercise your rights (access, correction, deletion, objection or complaint), email [email protected]. You can also complain to your local data protection authority.

Data in Google Analytics (your visitors' data, and your reports) belongs to your Google account and is governed by Google's Privacy Policy. Manage or delete it in Google Analytics itself.

5. Children

WSAnalytics is a tool for website owners and is not directed at children.

6. Changes to this policy

If we change how WSAnalytics handles data, we will update this page and the "Last updated" date, and describe significant changes in the plugin's changelog on WordPress.org.

7. Contact

Shivaa Tripathi
Email: [email protected]
Plugin support: WordPress.org support forum