Effective date: 23 July 2026.
PrestaInsight is operated by Prestachamps SRL, the small team behind prestainsight.com. We treat your shop data, your team's data, and any Google account data you connect the same way we'd want our own to be treated. The short version: we collect what we need to make the dashboard work, we keep it on servers in the European Union, we do not sell or resell it, we do not use it for advertising, we do not train AI models on it, and you can export, disconnect, or delete it at any time.
What we collect from your shop
Order rows, line items, customer rows, products, categories, manufacturers, and the relationships between them. We do not collect customer payment data. We do collect customer emails because PrestaShop stores them on the order; we hash them at rest and use them only for cohort grouping.
Google user data
If you connect Google Analytics 4, Search Console, Google Ads, or Google Merchant Center, PrestaInsight receives data from Google's APIs on your behalf. You always choose which properties or accounts to link, and you can disconnect at any time from your PrestaInsight settings or from your Google account permissions page.
Here is exactly what each connection reads and why:
- Google Analytics 4 — scope
analytics.readonly. We read reports from the GA4 properties you select: sessions, users, events, conversions, traffic sources, landing pages, device and geo dimensions. We use this to show your GA4 traffic alongside your PrestaShop orders inside PrestaInsight. Read-only; we cannot change your GA4 configuration. - Search Console — scope
webmasters.readonly. We read your verified site list and Search Analytics data: queries, pages, impressions, clicks, CTR, and average position. We use this to show which search queries and pages send visitors to your shop. Read-only. - Google Ads — scope
adwords. The Google Ads API does not offer a read-only variant, so the scope grants full access, but PrestaInsight only reads: campaigns, ad groups, keywords, spend, clicks, impressions, and conversion metrics for the accounts you link. We use this to attribute paid traffic to orders. We do not create, edit, pause, or delete anything in your Ads account. - Merchant Center — scope
content. The Shopping Content API does not offer a read-only variant, so the scope grants full access, but PrestaInsight only reads: account info, product feed, product status (approvals and disapprovals), and product performance. We use this to surface feed health next to catalogue coverage. We do not push, edit, or delete products or feeds. - Sign-in profile — scopes
openidandemail. Used once at consent to identify which Google user connected the account. We store the Google user id and email so you can reconnect later and so audit logs are meaningful.
How Google tokens and profile data are stored
Access tokens and refresh tokens are encrypted at rest with AES-256-GCM and decrypted only in memory when a background refresh or an authorised request needs them. Encryption keys are held only on our application servers and are not stored in the database. The Google account email and user id are stored in plaintext so you can see which Google account is linked and so we can show you sensible reconnect prompts. Scopes and connection status are stored alongside.
Limited Use of Google user data
PrestaInsight's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements. In plain language, that means:
- We use Google user data only to provide and improve user-facing features that are prominent in PrestaInsight — the dashboards, reports, and chat answers you see after connecting.
- We do not transfer Google user data to third parties except as needed to provide or improve those features, to comply with applicable law, or as part of a merger or acquisition with prior notice to you and an opportunity to delete your data before the transfer takes effect.
- We do not use Google user data for advertising, including retargeting, personalised advertising, or interest-based advertising.
- Humans on our team do not read Google user data unless you have given us specific permission for a support case, we need to for security or to comply with law, or the data is aggregated and anonymised for internal operations.
Things we explicitly do not do
- We do not sell, rent, or trade Google user data or shop data.
- We do not use Google user data for advertising or ad personalisation.
- We do not use Google user data to train generalised or third-party AI or machine-learning models. When you use our AI chat feature, prompts and Google data snippets sent to the model provider are covered by that provider's zero-retention API terms and are not used for model training.
- We do not share Google user data with data brokers, ad networks, or affiliate programmes.
Where the data lives
Your data is stored and processed exclusively within the European Union — currently on a primary server hosted with Contabo GmbH in Nuremberg, Germany, with encrypted backups kept on the same Contabo infrastructure in Germany. We do not transfer your data outside the EU.
Sub-processors
A small set of vendors help us run the service. The categories that can touch Google user data are:
- Hosting — Contabo GmbH (Germany) for the primary application and database server.
- Model providers for the AI chat feature — OpenAI, Inc. and Anthropic, PBC, called via their zero-retention API endpoints. Only the specific rows and metrics needed to answer a question are sent, and providers are contractually barred from using the content for training.
- Transactional email — Resend (Resend, Inc.), used for account and billing notifications; Google user data is never included in these messages.
We do not use analytics or advertising trackers on the dashboard itself, and Google user data is never sent to any third party outside this list.
Who on our team can see it
You and the teammates you invite. Two members of our team have scoped, audited read access for support. They do not open Google connections or export Google data unless you have asked us for help with a specific case, and every such action is logged.
Retention and deletion
We keep Google user data for as long as your PrestaInsight account is active and the corresponding Google connection is live. Cached report data is refreshed on a rolling window and older cached rows are pruned automatically.
You can act on your data in three ways, at any time:
- Disconnect a Google integration from PrestaInsight settings, or revoke it at myaccount.google.com/permissions. Either action stops future access, and we delete stored tokens plus cached data for that integration within 30 days.
- Delete your shop's data from settings. Rows are removed from active storage within 24 hours and from encrypted backups within 30 days. This does not affect your Google account itself, only what PrestaInsight has stored.
- Close your account. This automatically triggers deletion of shop data and Google connections on the same 24-hour / 30-day timeline.
Your rights
Because most of our users are in the EU we apply GDPR rights to everyone. You can request access to the data we hold about you, ask us to correct it, export shop data as CSV or JSON from settings, and request deletion. You can revoke PrestaInsight's access to any Google product independently of your PrestaInsight account by using your Google account permissions page — you do not need to contact us first. To exercise any other right, email privacy@prestainsight.com and we will respond within 30 days.
Security
Traffic to and from prestainsight.com is served over TLS. Google refresh and access tokens are encrypted at rest as described above. Database access is restricted to the application servers, and administrative access requires SSH keys and multi-factor authentication. If we discover a breach that affects your data we will notify you without undue delay and, where required, within 72 hours.
Changes to this policy
If we make a material change to how we handle your data or Google user data we will update this page and the effective date at the top, and notify account owners by email before the change takes effect.
Contact
PrestaInsight is operated by Prestachamps SRL, a Romanian limited-liability company registered with the Mureș Trade Registry under number J26/992/2020, fiscal code (CUI) 42884751, with its registered office at Str. De Jos nr. 45, sat Corunca, com. Corunca, jud. Mureș, cod poștal 547367, Romania. For privacy questions, data-subject requests, or Google data concerns, email privacy@prestainsight.com. Our data protection contact is Tamas Barta, reachable at the same address.