Help & policies
Google account integration
Our staff can connect a Google account to the SwadAura admin panel so that our own analytics appear alongside our orders. This page explains exactly what that connection reads, and what it cannot do.
What the application is
SwadAura & Packaging sells printed flexible packaging to food brands and packs its own range of teas, spices, sweets and dry fruit. The website you are on is that shop.
Behind it is a private admin panel used only by our own staff to manage the catalogue, orders and dispatch. One screen in that panel — Analytics — can connect to a Google account so the figures we already have in Google Analytics and Search Console appear next to our orders, instead of requiring a separate browser tab. That screen is the only part of this application that uses Google sign-in.
What it reads, and why
| Scope | Access | Why we ask for it |
|---|---|---|
| analytics.readonly | Read-only access to Google Analytics 4 | To show sessions, orders and revenue for our own store inside our admin panel, and to list the GA4 properties the signed-in account can choose from. |
| webmasters.readonly | Read-only access to Google Search Console | To show which search queries and pages bring visitors to swadaurapackaging.com, so we can see whether our own product pages are being found. |
| openid, email | The signed-in account's email address | So the panel can display which Google account is connected, and so each staff member's connection is kept separate from anyone else's. |
Every scope is read-only. The application cannot change a Google Analytics property, edit a Search Console setting, submit a sitemap, request indexing, or alter anything at all in the connected account. It can only read.
Who can connect
Only a signed-in SwadAura administrator, from inside our own admin panel. There is no public sign-in with Google anywhere on this website — customers create an account with an email address and password, and that flow does not involve Google.
Each administrator connects their own Google account. One person’s connection is never shared with another, and each can disconnect independently.
What we store, and for how long
We store the access and refresh tokens Google issues, the email address of the connected account, and the identifier of the GA4 property the administrator chose to report on. Nothing else.
Both tokens are encrypted at rest using AES-256-GCM, with a key held in the server’s environment rather than in the database, so a copy of the database alone cannot be used to reach anyone’s Google account.
The analytics figures themselves are not stored. They are fetched from Google when the screen is opened and shown; nothing is copied into our database, and nothing is retained after the page is closed.
What we never do
- We do not write, modify or delete anything in the connected Google account.
- We do not read Gmail, Drive, Calendar, Contacts or any other Google service.
- We do not sell, rent or share this data with anyone.
- We do not use it for advertising or profiling.
- We do not use it to train, or to develop, any artificial intelligence or machine learning model.
- We do not transfer it to third parties for any purpose.
How to revoke access
An administrator can press Disconnect on the Analytics screen. That deletes our stored tokens and also asks Google to revoke the grant, so it disappears from the account’s permissions page as well.
Access can also be withdrawn at any time from Google’s own settings at myaccount.google.com/permissions, without needing us.
Limited Use
SwadAura & Packaging’s use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
Contact
Questions about this integration or the data it touches: info@swadaurapackaging.com.
See also our privacy policy and terms.
