← Back

Privacy notice

GTM Composer is operated by New North Digital (the Netherlands). This page describes what personal data the tool stores, why, how long, and how to request access or deletion. Last updated 2026-05-25.

What we store

To sign you in and let you compose + deploy containers, we store the following per user:

  • Email address — used to identify your account and to scope your composes and deploy history.
  • Google OAuth access + refresh tokens for the GTM API, encrypted at rest with AES-256-GCM. The refresh token lets us call the GTM API on your behalf when you trigger a deploy.
  • Client profiles you submit through the wizard — the CMS, dataLayer, platforms, and CMP selections that drive what gets composed.
  • Credentials inside profiles (CAPI tokens, sGTM container API keys, pixel IDs, etc.) — encrypted at rest with AES-256-GCM. We need these to emit valid tag parameters; we never transmit them anywhere except into the GTM container you deploy to your own GTM account.
  • Compose + deploy history — a per-user log of every compose and every deploy attempt, including resource counts, workspace URLs, status, and any errors that surfaced.
  • Cleaner summaries— per container-cleaner run we keep the container name, resource counts, and finding counts (plus what you applied). Never the container's contents — see “What we don't store”.
  • Session cookie — an HMAC-signed cookie holding just your email so we can look up your stored tokens. Cleared on sign-out.

Google user data — what we access and why

When you sign in and authorise the app, we request the following scopes:

  • openid email profile — identifies your account.
  • https://www.googleapis.com/auth/tagmanager.edit.containers — lets the tool create variables, triggers, tags, templates, and workspaces in the GTM containers you choose. The tool never auto-publishes — every deploy lands in a fresh, non-live workspace, and publishing remains a human action in the GTM UI.
  • https://www.googleapis.com/auth/tagmanager.readonly— read access used by the wizard's account / container picker and by the conflict-detection pre-flight that checks your live workspace for name collisions before deploy.

Limited Use.GTM Composer's use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements. Specifically: we use the data only to power the compose + deploy features you see in the app, we do not transfer the data to third parties except as necessary to render those features, we do not use the data for advertising, and no human reads your data unless you explicitly ask for support, we are legally required to, or we need to investigate a security incident.

What we don't store

  • Anything from your GTM container beyond what the wizard reads during conflict-detection (existing variable / trigger / tag names in the workspace you target). We don't mirror, archive, or analyse your container.
  • Containers you audit or reconcile. When the hygiene audit or the reconcile feature fetches a live container version (or you upload an export file), the JSON passes through our server only as a proxy to the GTM API — all analysis runs in your browser, and the container is never written to our database or logs.
  • Your end-users' visitor data. The tool composes the container that will collect tracking on your site; we never see what that container later collects.
  • Tracking or analytics on this tool itself without your consent. No ad pixels, no third-party marketing tags.

Retention

  • Compose + deploy history: auto-deleted 90 days after creation (and capped at the 20 most recent per user), or sooner if you request deletion. Rows held for manual abuse review are kept until reviewed, then deleted 90 days after the decision (and in all cases no longer than one year).
  • OAuth tokens: deleted automatically after 90 days of inactivity (and re-minted when you next sign in), or sooner if you sign out, revoke the grant at your Google account, or request account deletion. Encrypted profile credentials follow the history row they belong to.
  • Session cookie: 7 days, refreshed on each successful OAuth round-trip.

Who can access your data

  • You — full access to your own composes, deploy history, and stored credentials.
  • NND administrators — limited operational access for support, manual review of flagged deploys (see below), and audit-trail review. Tokens and credentials remain encrypted; admins do not see plaintext values.
  • Google— the deploy path writes to your own GTM container via the official API using your OAuth grant. Google's privacy policy applies to data flowing through their APIs.

Abuse prevention + manual review

The composed container is statically linted before it's shown to you or shipped to GTM. The linter looks for both correctness smells (unresolved variable references, dead triggers) and abuse signals — for example: server-side GTM URLs outside the Stape / Taggrs allowlist, non-HTTPS endpoints, or suspicious URL schemes (javascript:, data:) in tag parameters. A deploy that emits a security-category finding is flagged for manual review before its workspace publish helper unlocks. Review actions are logged to the per-deploy audit trail and visible to you on the history page.

Lawful basis (GDPR)

We rely on the following lawful bases under Article 6 GDPR:

  • Contract (Art. 6(1)(b)) — for the core compose + deploy service, including storing your account, encrypting your credentials, and writing to GTM on your behalf.
  • Legitimate interest(Art. 6(1)(f)) — for operational security (rate-limit logs, audit trail of who deployed what to which container, abuse review). You can object — see “Your rights”.
  • Legal obligation (Art. 6(1)(c)) — to retain audit logs of security-relevant actions for a reasonable period.

Third-party processors

We use the following sub-processors to deliver the service. All access is bound by data-processing agreements; none use your data for their own purposes.

  • Vercel Inc. (USA, EU regional execution) — application hosting, edge network, function execution. Vercel may process limited request metadata (IP, user agent) to operate the platform.
  • Neon Inc. (USA, with EU regional deployment) — managed Postgres database. All persistent data (compose history, encrypted credentials, OAuth tokens) is stored here.
  • Google LLC— Google Tag Manager API and identity (OAuth). The deploy writes to your own Google account via your authorised grant; Google's privacy policy applies to data flowing through their APIs.

International transfers

Several of the processors above are headquartered in the United States. Where transfers of personal data outside the EEA occur, they are protected by the European Commission's Standard Contractual Clauses (SCCs) and, where applicable, the EU-US Data Privacy Framework. We minimise the personal data transferred — most of what we store is configuration (profile JSON) and operational logs, not personal data about your end users.

Your rights

You can:

  • Sign out any time — clears your session cookie. Your stored OAuth tokens remain so you can sign back in without re-authorising; revoke at Google Account → Third-party apps to break the tool's ability to write to GTM.
  • Export a copy of your data — call GET /api/account/export while signed in to download a JSON bundle of every row tied to your email (composes, deploys, encrypted token metadata).
  • Delete your account — call POST /api/account/delete while signed in (or email hello@newnorth.nl). We erase your history rows and stored tokens within 14 days; the request is logged for compliance.
  • Lodge a complaint with a supervisory authority. If you're in the EU, the Dutch supervisory authority is Autoriteit Persoonsgegevens; in other EU member states your local DPA applies. You can also raise the issue with us first via the contact below — we'd like the chance to resolve it.

Contact

New North Digital, the Netherlands. Questions, deletion requests, or data-protection concerns: hello@newnorth.nl.