GTM Composer is operated by New North Digital (the Netherlands). This page describes what personal data the tool stores, why, how long, and how to request access or deletion. Last updated 2026-05-25.
To sign you in and let you compose + deploy containers, we store the following per user:
When you sign in and authorise the app, we request the following scopes:
openid email profile — identifies your account.https://www.googleapis.com/auth/tagmanager.edit.containers — lets the tool create variables, triggers, tags, templates, and workspaces in the GTM containers you choose. The tool never auto-publishes — every deploy lands in a fresh, non-live workspace, and publishing remains a human action in the GTM UI.https://www.googleapis.com/auth/tagmanager.readonly— read access used by the wizard's account / container picker and by the conflict-detection pre-flight that checks your live workspace for name collisions before deploy.Limited Use.GTM Composer's use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements. Specifically: we use the data only to power the compose + deploy features you see in the app, we do not transfer the data to third parties except as necessary to render those features, we do not use the data for advertising, and no human reads your data unless you explicitly ask for support, we are legally required to, or we need to investigate a security incident.
The composed container is statically linted before it's shown to you or shipped to GTM. The linter looks for both correctness smells (unresolved variable references, dead triggers) and abuse signals — for example: server-side GTM URLs outside the Stape / Taggrs allowlist, non-HTTPS endpoints, or suspicious URL schemes (javascript:, data:) in tag parameters. A deploy that emits a security-category finding is flagged for manual review before its workspace publish helper unlocks. Review actions are logged to the per-deploy audit trail and visible to you on the history page.
We rely on the following lawful bases under Article 6 GDPR:
We use the following sub-processors to deliver the service. All access is bound by data-processing agreements; none use your data for their own purposes.
Several of the processors above are headquartered in the United States. Where transfers of personal data outside the EEA occur, they are protected by the European Commission's Standard Contractual Clauses (SCCs) and, where applicable, the EU-US Data Privacy Framework. We minimise the personal data transferred — most of what we store is configuration (profile JSON) and operational logs, not personal data about your end users.
You can:
GET /api/account/export while signed in to download a JSON bundle of every row tied to your email (composes, deploys, encrypted token metadata).POST /api/account/delete while signed in (or email hello@newnorth.nl). We erase your history rows and stored tokens within 14 days; the request is logged for compliance.New North Digital, the Netherlands. Questions, deletion requests, or data-protection concerns: hello@newnorth.nl.