Privacy Policy
Last updated: July 3, 2026
The Gordo Group, Inc., doing business as GO Digital (“GO Digital,” “GO Digtl,” “we,” “us,” or “our”), provides the GOdigtl AI Visibility Audit dashboard at https://audit.godigtl.com (the “Service”). This Privacy Policy explains what information we collect, how we use it, and the choices you have, including specific information about how we access and use Google user data.
This policy applies to https://godigtl.com and https://audit.godigtl.com.
If you have questions, contact us at support@godigtl.com.
1. Information We Collect
1.1 Account & Business Information
When you create an account, we collect your name, email address, and a securely hashed password. To generate your audit, we also collect the business details you provide or confirm: business name, website URL, industry and category, business address, target buyer, geographic market, services, and the names of any competitors you want compared. Payments are processed by Stripe; we store a Stripe customer and subscription identifier so we can manage your billing — we do not store your full card details.
1.2 Usage Data
We collect information about how you use the Service — pages visited, features used, and similar diagnostic data — to operate, maintain, and improve the Service.
1.3 Google Account Data (Search Console & Analytics)
If you choose to connect your Google account, we access limited, read-only data as described in detail in Section 2 below. We do not access any Google data unless and until you explicitly authorize the connection.
1.4 Cookies and Similar Technologies
Our dashboard at audit.godigtl.com uses a single essential cookie to keep you signed in. Our marketing site at godigtl.com uses Google Analytics, which sets analytics cookies that help us understand site traffic. We do not use advertising, retargeting, or cross-site tracking pixels. You can control cookies through your browser settings, and you can opt out of Google Analytics using Google’s opt-out browser add-on at https://tools.google.com/dlpage/gaoptout.
2. Google User Data — What We Access, Why, and How
This section specifically addresses our use of Google APIs and Google user data, as required by the Google API Services User Data Policy.
2.1 What we access
If you connect your Google account from your dashboard’s account menu (“Google” connector), we request the following read-only OAuth scopes:
|
Scope |
What it accesses |
|
https://www.googleapis.com/auth/webmasters.readonly |
Read-only access to your Google Search Console properties and search-analytics data (including AI-overview/AI-appearance performance data where available) |
|
https://www.googleapis.com/auth/analytics.readonly |
Read-only access to your Google Analytics (GA4) reporting data |
We do not request edit, delete, or management access to your Search Console or Analytics properties — only the minimum read-only scopes needed to power the feature described below.
2.2 Why we access it / how it’s used
When you connect your Google account, the Service:
- Lists the Search Console properties associated with your Google account and matches the one corresponding to your site.
- Runs read-only search-analytics queries against that property, including data about your site’s visibility in AI-generated search experiences (such as AI Overviews), to power your AI Visibility Audit.
- Pulls a read-only Google Analytics (GA4) report for your property.
- Displays this data back to you, inside your own dashboard, to generate AI-visibility insights and recommendations for your site.
This processing happens via our backend endpoints (/api/tech/gsc and /api/tech/analytics) solely to provide this feature to the same Google account holder who granted access. We do not use this data to make decisions about, or display this data to, any other user.
2.3 Storage and retention
We store the OAuth access and refresh tokens generated when you connect your Google account, encrypted at rest, so we can maintain the connection and fetch data on your behalf without requiring you to re-authenticate every time. We do not cache or store the Search Console or Analytics report data itself — every time your dashboard displays this data, we fetch it live, directly from Google, for that view only.
- If you disconnect your Google account (dashboard account menu → “Google” → Disconnect): we immediately revoke our access and delete the stored OAuth tokens.
- If you cancel your subscription: you keep access — including your Google connection — until the end of your current billing period. When your access ends, we revoke and delete your Google OAuth tokens, and we retain your other account data for 90 days so that you can reactivate without losing your history. After 90 days, that data is anonymized — identifying details are removed and your individual audit history is deleted — though de-identified, aggregated data may be retained to improve our industry benchmarks, consistent with the Limited Use requirements below.
- If you delete your data (dashboard → Data & Preferences → “Delete my data,” or by emailing support@godigtl.com): we permanently delete your account and revoke and delete your Google OAuth tokens right away, with no grace period. We complete emailed deletion requests within 30 days.
2.4 Sharing and disclosure
We do not sell, rent, or trade your Google user data. We do not transfer Google user data to any third party except:
- Service providers who help us operate the Service (e.g., our hosting provider, Railway, and our email provider, Resend), strictly to the extent needed to provide the Service, and bound by confidentiality obligations.
- Where required by law, regulation, legal process, or enforceable governmental request.
- In connection with a merger, acquisition, or sale of assets, subject to this Privacy Policy continuing to apply to previously collected data.
We do not use Google user data for serving advertisements, and we do not allow any employee, contractor, or system to read Google user data except as strictly necessary to provide, maintain, or troubleshoot the Service, or as otherwise permitted under the Limited Use requirements below.
2.5 Google API Services User Data Policy — Limited Use Disclosure
GO Digital’s use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
Specifically:
- We only use Google user data to provide or improve the AI Visibility Audit features described in this policy.
- We do not use Google user data for serving advertisements, including retargeting, personalized, or interest-based advertising.
- We do not allow humans to read Google user data unless: (a) we have your affirmative consent for specific messages, (b) it is necessary for security purposes (e.g., investigating abuse), (c) it is necessary to comply with applicable law, or (d) it is aggregated and anonymized and used for internal operations in accordance with applicable privacy laws.
- We do not transfer Google user data to any third party except as described in Section 2.4, or as otherwise permitted by the Limited Use requirements.
2.6 How to revoke access
You can disconnect your Google account at any time from inside your GO Digital dashboard (account menu → “Google” → Disconnect). You can also revoke GO Digital’s access directly from your Google Account at: https://myaccount.google.com/permissions
Revoking access stops all future data collection from your Google account; see Section 2.3 for what happens to already-stored data.
3. How We Use Information (General)
We use the information described above to:
- Provide, operate, and maintain the Service
- Authenticate you and secure your account
- Generate your AI Visibility Audit and recommendations
- Communicate with you about your account or the Service (via Resend)
- Monitor and improve the Service’s performance and reliability
- Comply with legal obligations
4. Third-Party Service Providers
We use a number of third-party services to operate the Service. Each processes only the data necessary for its specific function, and each is subject to its own privacy policy and terms, which we encourage you to review.
|
Provider |
Role |
|
Google (Search Console, Analytics/GA4) |
Powers your Google data connection, as described in Section 2 |
|
Stripe |
Processes payments and subscription billing |
|
Railway |
Hosts our application infrastructure (in the United States) |
|
Resend |
Sends transactional and product emails (e.g., account, billing, and report notifications) |
|
FireCrawl |
Crawls and analyzes your website’s public content to inform your AI Visibility Audit |
|
WordPress.com |
Optional: when you connect your WordPress site, we publish content recommendations you approve to that site on your behalf |
|
Anthropic (Claude), OpenAI (ChatGPT), Perplexity, Google (Gemini) |
We query these AI assistants via their official APIs to analyze how your business appears in AI-generated responses. We send only your business’s public details as part of these prompts — your business name, industry/category, likely competitor names, and service descriptions. We do not send your Google Search Console or Analytics data, or your personal account information. |
We do not sell your personal data to any of these providers, and we only share what each provider needs to perform its function for you.
5. Data Security
We use commercially reasonable administrative, technical, and physical safeguards designed to protect your information. In particular: account passwords are stored using a memory-hard hashing algorithm (scrypt) and never in plaintext; your Google OAuth tokens are encrypted at rest (AES-256-GCM); data is transmitted over encrypted connections (TLS); and access to production systems is restricted. No method of transmission or storage is 100% secure, and we cannot guarantee absolute security.
6. Your Rights and Choices
Depending on your location, you may have rights to access, correct, export, or delete your personal data, and to opt out of certain processing. You can update much of your information and your email preferences directly in your dashboard (Data & Preferences), and you can permanently delete your account and data there or by emailing support@godigtl.com. We will respond within a reasonable time and in any event within 30 days of an explicit deletion request, per Section 2.3. See Sections 7 and 8 for region-specific rights.
7. California Privacy Rights (CCPA/CPRA)
If you are a California resident, you have the right to know what personal information we collect and how we use it, to request access to or deletion of your personal information, to correct inaccurate personal information, and to not be discriminated against for exercising these rights. We do not sell or share your personal information, and we do not use it for cross-context behavioral advertising. To exercise your rights, email support@godigtl.com; we may need to verify your identity before completing your request. You may use an authorized agent to submit a request on your behalf.
8. European & UK Users (GDPR)
If you are in the European Economic Area, the United Kingdom, or Switzerland, The Gordo Group, Inc. is the controller of your personal data. Our legal bases for processing are: your consent (for connecting your Google account and for optional communications), performance of our contract with you (to provide the Service), and our legitimate interests (to secure, maintain, and improve the Service and prevent abuse). You have the right to access, rectify, erase, restrict, and port your personal data, to object to processing, and to withdraw consent at any time without affecting prior processing.
Our servers are located in the United States. Where we transfer personal data from the EEA, UK, or Switzerland to the United States, we rely on appropriate safeguards for such transfers. To exercise your rights or raise a concern, email support@godigtl.com. You also have the right to lodge a complaint with your local data protection supervisory authority.
9. Children’s Privacy
The Service is not directed to individuals under 18, and we do not knowingly collect personal information from children. If you believe a child has provided us personal information, contact support@godigtl.com and we will delete it.
10. International Users
The Service is operated from, and your information is stored and processed in, the United States. If you access the Service from outside the United States, you understand that your information will be transferred to and processed in the United States, where data-protection laws may differ from those in your jurisdiction. See Section 8 for EEA/UK/Swiss transfer safeguards.
11. Changes to This Policy
We may update this Privacy Policy from time to time. We will post the updated version at this URL with a new “Last updated” date. For material changes that affect how we handle your personal data or Google user data, we will provide notice to connected users (for example, by email) before the changes take effect, where required.
12. Contact Us
The Gordo Group, Inc. (d/b/a GO Digital)
2379 Stephens Circle, Gainesville, GA 30506, USA
Email: support@godigtl.com
Website: https://godigtl.com