Privacy Policy
Last updated: August 1, 2026
This policy describes the data GClimb collects when you use gclimb.io and the application available from your dashboard, and how that data is used, stored, shared and deleted. It covers in particular the data GClimb accesses when you connect your Google Merchant Center account.
1. Data controller
- Publisher: DMINC LLC, a single-member Limited Liability Company organized under the laws of New Mexico, USA
- Registration: New Mexico Secretary of State, file no. 3187822, filed on April 16, 2026
- Address: 1209 Mountain Road Pl NE, Ste R, Albuquerque, NM 87110, USA
- Service operated: GClimb (gclimb.io)
- Contact: contact@gclimb.io — Support: support@gclimb.io
2. Data we collect
GClimb only collects the data required to operate the service:
- Account: email address, technical identifier, creation date. Authentication is handled by Supabase. If you sign in with Google, we only receive your email address and your Google account identifier.
- Service usage: the URLs you submit for analysis, the public content of those pages retrieved by our crawler, analysis results, and your credit history.
- Payment: transaction identifier, amount and status provided by Stripe. Your card details never pass through our servers and are never stored by GClimb.
- Technical data: server logs (IP address, timestamp, endpoint called) kept for security and rate-limiting purposes.
3. Google data (Merchant Center and Google Ads)
Connecting a Google account is optional: the compliance audit works without any Google authorization. Two optional features rely on separate connections, which you grant independently and can revoke at any time.
GMC Cross-Check compares your Merchant Center configuration with what your website actually publishes, in order to surface the inconsistencies that typically trigger a suspension. Permissions requested:
- https://www.googleapis.com/auth/content — read the configuration of your own Merchant Center account: the list of accounts you have access to, the account name, business information (address, phone), shipping settings and delivery times, online return policies, account status and issues reported by Google, aggregate product statuses, and data source health. The only non-read call performed is the developer registration (developerRegistration) that Google requires before granting Merchant API access. GClimb never modifies or deletes any product, feed or setting in your account.
- https://www.googleapis.com/auth/userinfo.email — read the email address of the Google account you connect, so that it can be linked to your GClimb account and displayed to you.
- https://www.googleapis.com/auth/adwords — used only by Profit Guardian, our advertising profitability tool, to read your campaigns, performance metrics (spend, clicks, conversions) and search terms, and match them against your product costs to compute your net margin. Read-only: GClimb never creates, edits or pauses any campaign, ad or budget. This feature uses a separate connection: if you do not use it, this permission is never requested.
GClimb's use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
4. How this Google data is used and stored
- Use: solely to produce the features intended for you — the GMC Cross-Check section of your audit report, and the Profit Guardian profitability dashboards. The website-to-Merchant-Center comparison is performed by a deterministic engine, with no artificial intelligence involved: your Merchant Center and Google Ads data is never sent to a language model or to any AI provider.
- Tokens: OAuth access and refresh tokens are encrypted with AES-256-GCM before being stored in our database. They are never displayed, exported or shared with any third party.
- Cache: data read from your Merchant Center account is cached for at most 24 hours, to avoid calling the Google API every time you open your report.
- Sharing: this data is never sold, rented, transferred, used for advertising, or used to train an artificial intelligence model.
- Retention: tokens and cache are deleted immediately when you click "Disconnect" in your dashboard, or when you delete your GClimb account. You can also revoke access at any time from myaccount.google.com/permissions.
5. Purposes and legal bases
- Performance of the contract: account creation, running analyses, billing, support.
- Legitimate interest: service security, fraud prevention, rate limiting, improving analysis quality.
- Consent: optional Google Merchant Center connection, non-essential communications.
- Legal obligation: retention of accounting records.
6. Recipients and processors
GClimb does not sell or rent your data. We rely on the following providers, each limited to what its role requires:
- Supabase — authentication and database (accounts, analyses, encrypted tokens).
- Hostinger International Ltd — website and API hosting.
- Stripe — payment processing.
- Anthropic — AI analysis of the public content of your website pages. Data from your Google Merchant Center account is never sent to this provider.
- Google — for the API calls you have explicitly authorized, and for website analytics (Google Analytics, Google Tag Manager).
- Meta Platforms — measuring the performance of our advertising campaigns.
- Crisp — support chat displayed on the website.
- Brevo — sending transactional emails.
- FirstPromoter — affiliate program tracking: clicks on a referral link, linking a signup and a purchase to the referrer, and commission calculation.
7. Transfers outside the European Union
Some of our providers are established in the United States. The corresponding transfers are governed by the European Commission's Standard Contractual Clauses or by an equivalent compliance mechanism offered by the provider concerned.
8. Retention periods
- Account and analyses: until you delete your account.
- Google tokens and Merchant Center cache: until disconnection or revocation, or 24 hours for the cache.
- Technical logs: 12 months maximum.
- Accounting records: as required by applicable law.
9. Security
- AES-256-GCM encryption of OAuth tokens at rest.
- Mandatory HTTPS, HSTS and security headers across the service.
- Per-user data isolation at the database level (Row Level Security).
- Rate limiting and authentication token verification on every API call.
10. Your rights
Under the General Data Protection Regulation you have the right to access, rectify, erase, restrict, object to and port your data, and to withdraw your consent at any time. Write to contact@gclimb.io: we reply within 30 days. You may also lodge a complaint with your data protection authority.
11. Cookies and trackers
The following cookies and trackers may be set during your visit:
- Service operation: keeping you signed in, remembering your language, and protecting the Google connection against cross-site request forgery.
- Analytics: Google Analytics 4 and Google Tag Manager (_ga and _ga_* cookies, up to 13 months).
- Advertising measurement: Meta pixel (_fbp cookie, up to 3 months), to assess the performance of our campaigns.
- Support: Crisp, for the chat displayed on the website.
- Affiliation: FirstPromoter sets the _fprom_ref, _fprom_tid and _fprom_details cookies on gclimb.io, kept for up to 60 days, so that whoever referred you to the service can be credited. They are only set if you arrive through a referral link.
12. Minors
The service is intended for professionals and is not directed at people under 18. We do not knowingly collect data about minors.
13. GClimb Chrome extension
The GClimb Chrome extension, which is separate from the web application, analyses pages locally in your browser: it does not collect, store or transmit any personal data to our servers and uses no Google permission.
14. Changes
Any change to this policy is published on this page with a new update date. If the way we use your Google data changes materially, you will be notified and asked to consent again.
To revoke access or delete your data: Data deletion.