Privacy policy
ninjatools is an internal reporting tool built and run by Digital Ninjas ("we", "us"). It reads marketing data from Google Analytics 4, Google Ads and Meta Ads on behalf of Digital Ninjas and its clients and presents it as dashboards. This policy explains what the tool accesses, what it stores, who can see it and how to have it removed. Questions go to our contact address.
Who uses ninjatools
Digital Ninjas staff, who sign in with their Digital Ninjas Google Workspace account, and client contacts who have been invited to a specific dashboard. Nobody else can sign in.
Data from Google
When a Digital Ninjas staff member connects a Google account, ninjatools asks Google for read-only access and uses it as follows.
| Scope | What we read | Why |
|---|---|---|
| Google Analytics (read only) | The list of GA4 properties the account can see, and aggregated report data from the properties added to a client (sessions, users, key events, revenue, ecommerce items, by date, channel, source, medium, campaign and device). GA4 reports are aggregated; ninjatools never receives individual visitor records. | To build and refresh client dashboards. |
| Google Ads (read only) | The list of accessible Google Ads accounts and daily campaign performance (impressions, clicks, cost, conversions) for the accounts added to a client. | To build and refresh client dashboards. |
| Email address (openid, userinfo.email) | The email address of the Google account being connected. | To label the connection so staff can tell connected accounts apart. |
ninjatools' use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. Google data is used only to provide and improve the dashboards inside ninjatools. It is not used for advertising, not sold, and not transferred to anyone except as needed to run the tool (see "Who else processes data") or as required by law.
Data from Meta
Meta Ads data is read with a Meta Business System User token held by Digital Ninjas: the list of ad accounts it can see and daily campaign performance for the accounts added to a client. Access is read only.
Data about people who sign in
For every sign-in we receive the signed-in email address from Google Identity-Aware Proxy (and, where enabled, Google Identity Platform). We store email addresses in access lists: staff roles, and which dashboards have been shared with which client contacts. We do not store passwords.
What we store
- Connections: the refresh token Google or Meta issues, the account email, who connected it and when. Kept in Google Secret Manager.
- Configuration: which GA4 properties, Google Ads accounts and Meta ad accounts belong to which client.
- Dashboards: the layout, its version history, the conversation with the dashboard assistant, and who it is shared with.
- Report data: fetched live from the platforms when a dashboard is opened and kept in memory for up to ten minutes. It is not written to a database unless a client's account has been explicitly set to export to BigQuery.
- Logs: standard request logs and error reports, kept for 30 days.
Everything is hosted on Google Cloud in the australia-southeast1 (Sydney) region, encrypted in transit and at rest.
The dashboard assistant
Dashboards are built by an AI assistant powered by Anthropic's Claude API. To do its job it receives the request typed by the user, the names and IDs of candidate accounts, the dashboard layout, and, when asked about conversions or donations, aggregated summary figures (for example totals by item category or key event). It does not receive individual visitor data. Anthropic processes this data to return a response and, under its commercial terms, does not use it to train models.
Who else processes data
- Google Cloud: hosting, storage, secrets, sign-in (Identity-Aware Proxy, Identity Platform).
- Anthropic: the dashboard assistant, as described above.
- Google and Meta: the platforms the data comes from, under their own terms.
We do not sell data and do not share it with anyone else.
Who can see what
Digital Ninjas staff can see the clients and dashboards their role allows. A client contact sees only the dashboards shared with them, and can edit one only within the accounts it already contains. Access can be withdrawn at any time by Digital Ninjas.
Retention and deletion
- A Google or Meta connection is kept until a staff member removes it in ninjatools, or until access is revoked at the platform. You can revoke ninjatools' access to a Google account yourself at myaccount.google.com/permissions.
- Dashboards are kept until deleted; a deleted dashboard is recoverable for 30 days and then removed for good.
- Cached report data expires within ten minutes. Logs expire after 30 days.
To have data about you or your organisation removed, or to ask what we hold, contact us. We respond within 30 days.
Changes
If this policy changes we update this page and the effective date above.