Operator: Napp Solutions. Contact: guilherme@nappsolutions.com.
Napp Expert syncs the customer's own catalog — product, price, availability and
per-store inventory — with the Google Merchant Center account that the customer
controls. That data passes through our infrastructure, hosted on Google Cloud, and is
delivered to the customer's own Merchant Center account. Today that infrastructure runs
in the us-east1 region; the managed Google services it uses may replicate
data according to each service's default configuration.
When the customer sends us sales made outside their website (offline) or browsing events from their own website, that submission may include an end consumer's email address or phone number. Instead of keeping that data in plain text, we apply a SHA-256 hash as soon as it arrives: the original value is never persisted or published, only the hash.
https://www.googleapis.com/auth/content — access to the products and local inventory of the
Google Merchant Center account that the customer themselves authorizes.
https://www.googleapis.com/auth/userinfo.email — the email address of the Google account that granted the
authorization, and nothing else from the profile. It identifies which Google account is
connected: it is shown back to the customer on the connection confirmation page, and
recorded in our audit trail for that connection.
The refresh_token obtained during authorization is stored in Google Secret
Manager, encrypted at rest, in one secret per tenant and channel. It is never returned to
the customer and never cached. Only the resulting access_token and its
expiry are cached, with a TTL; that access_token cache is shared between
different tenants whose credential points to the same Google account and the same
channel — the refresh_token secret, by contrast, is always one per tenant
and channel. If Google rotates the refresh_token during an exchange, the new
version is written to the same secret.
When a channel is deactivated, we delete the credential secret in Secret Manager
entirely, with all of its versions. The access_token already derived from it
and held in cache is not deleted at that moment: it remains until it expires by TTL,
within 50 minutes, and then ceases to exist. Revoking access on Google's side has a
different effect: it invalidates the token, but does not delete what we stored; the
secret remains stored until the channel is deactivated on our side.
Napp Expert's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements: data obtained through the scopes above is used exclusively to provide the service the customer contracted. It is not sold, does not feed advertising, and is not used to train artificial intelligence models.
We share Google user data with exactly two recipients, and both are Google:
us-east1 region: Cloud Run and
Compute Engine run the application, Cloud SQL stores catalog and configuration,
Secret Manager stores the credential, Pub/Sub carries messages between components,
and Cloud Logging keeps operational logs. Google Cloud processes this data on our
behalf, as a hosting provider.
There are no other recipients. We do not share Google user data with advertising networks, data brokers, analytics vendors, AI model providers or any other third party, and we neither sell nor rent it. Inside Napp Solutions, access is limited to the personnel who operate the service. We would disclose data only when legally compelled — for example, by a court order.
The customer can revoke Napp Expert's access to their Google account at any time at https://myaccount.google.com/permissions. Once revoked, catalog delivery for that channel stops working. To connect again — or to move the channel to a different Google account — the customer authorizes once more through a single-use connection link issued by Napp Expert, in the browser; the new authorization replaces the stored credential.
Questions about this policy can be sent to guilherme@nappsolutions.com.
Operadora: Napp Solutions. Contato: guilherme@nappsolutions.com.
O Napp Expert sincroniza o catálogo do próprio cliente — produto, preço, disponibilidade
e inventário por loja — com a conta do Google Merchant Center que o cliente controla.
Esse dado trafega pela nossa infraestrutura, hospedada no Google Cloud, e é entregue à
conta Merchant Center do próprio cliente. Hoje essa infraestrutura roda na região
us-east1; os serviços gerenciados do Google usados nela podem replicar
dados conforme a configuração padrão de cada serviço.
Quando o cliente nos envia vendas feitas fora do site (offline) ou eventos de navegação do próprio site dele, esse envio pode incluir e-mail ou telefone do consumidor final. Em vez de guardar esse dado em texto puro, aplicamos hash SHA-256 assim que ele chega: o valor original nunca é persistido nem publicado, só o hash.
https://www.googleapis.com/auth/content — acesso aos produtos e ao inventário local na conta do
Google Merchant Center que o próprio cliente autoriza.
https://www.googleapis.com/auth/userinfo.email — o endereço de e-mail da conta Google que concedeu a
autorização, e nada mais do perfil. Serve para identificar qual conta Google está
conectada: é mostrado de volta ao cliente na página de confirmação da conexão e
guardado no nosso registro de auditoria daquela conexão.
O refresh_token obtido na autorização é armazenado no Google Secret Manager,
criptografado em repouso, em um secret por tenant/canal. Ele nunca é devolvido ao
cliente nem é cacheado. Apenas o access_token resultante da troca e sua
expiração são cacheados, com TTL; esse cache de access_token é
compartilhado entre tenants diferentes cuja credencial aponte para a mesma conta Google
e o mesmo canal — o secret do refresh_token, por outro lado, é sempre um
por tenant/canal. Se o Google rotaciona o refresh_token durante uma troca,
a versão nova é gravada no mesmo secret.
Quando um canal é desativado, apagamos o secret da credencial no Secret Manager por
completo, com todas as versões. O access_token já derivado que estava em
cache não é apagado nesse momento: ele permanece até expirar por TTL, em até 50
minutos, quando deixa de existir. Revogar o acesso pelo Google tem um efeito diferente:
invalida o token, mas não apaga o que guardamos; o secret continua armazenado até o
canal ser desativado do nosso lado.
O uso e a transferência, pelo Napp Expert, de informações recebidas das APIs do Google obedecem à Google API Services User Data Policy, incluindo os requisitos de Limited Use: o dado obtido pelos escopos acima é usado exclusivamente para prestar o serviço contratado pelo cliente. Não é vendido, não alimenta publicidade e não é usado para treinar modelos de inteligência artificial.
Os dados do Google são compartilhados com exatamente dois destinatários, e os dois são o próprio Google:
us-east1: Cloud Run
e Compute Engine executam a aplicação, o Cloud SQL guarda catálogo e configuração, o
Secret Manager guarda a credencial, o Pub/Sub transporta as mensagens entre os
componentes e o Cloud Logging mantém os logs operacionais. O Google Cloud trata esse
dado em nosso nome, na condição de provedor de hospedagem.
Não há outros destinatários. Não compartilhamos dados do Google com redes de publicidade, corretores de dados, fornecedores de analytics, provedores de modelos de inteligência artificial nem qualquer outro terceiro, e não os vendemos nem alugamos. Dentro da Napp Solutions, o acesso é restrito às pessoas que operam o serviço. Só divulgaríamos dados sob obrigação legal — por exemplo, ordem judicial.
O cliente pode revogar o acesso do Napp Expert à sua conta Google a qualquer momento em https://myaccount.google.com/permissions. Ao revogar, a entrega de catálogo para aquele canal para de funcionar. Para conectar de novo — ou para trocar a conta Google do canal — o cliente autoriza outra vez por um link de conexão de uso único emitido pelo Napp Expert, no navegador; a autorização nova substitui a credencial guardada.
Dúvidas sobre esta política podem ser enviadas para guilherme@nappsolutions.com.