Privacy policy

Pending completion

This policy is an initial template. It must be completed with the real controller details, purposes, legal bases and providers.

Controller

Add the controller identity, address, contact email and, where applicable, data protection officer details.

Data we process

Describe data collected through forms, browsing, commercial communications, contracting or professional relationships.

Purposes and legal basis

Detail each purpose, its legal basis and whether processing depends on consent, contract, legitimate interest or legal obligation.

Recipients and providers

List providers, processors, analytics tools, advertising tools, CRM, hosting and international transfers where applicable.

Retention and rights

Explain retention periods and how to exercise access, rectification, erasure, objection, restriction, portability and withdrawal of consent.

Google user data

Specific update: 2 August 2026. This section explains how Nömad accesses, uses, stores, shares, protects, and deletes data obtained through Google APIs.

Access and requested data

Nömad accesses Google data only after an authorized brand owner or administrator starts OAuth and expressly grants permission. We use incremental authorization and request only the scopes needed to read selected Google Analytics 4 metrics, read Google Tag Manager inventory, manage selected Google Business Profile listings, read YouTube channels and video metadata, and upload videos to YouTube. The authorized person selects the property, container, listing, or channel connected to the brand.

Use

We use this data only to display the selected accounts and resources in Nömad, provide requested metrics and inventories, maintain the connection, and publish to YouTube only user-created videos explicitly approved and scheduled for the chosen channel. Nömad does not sell Google user data, use it for personalized advertising, or use it to train general-purpose artificial intelligence models.

Storage, retention, and protection

OAuth tokens are encrypted at application level and are accessible only to authorized server services. We use HTTPS, brand role-based access, strict tenant isolation, and row-level security. Normalized metrics are retained for no more than 25 months and operational delivery detail for 180 days, unless a shorter period, a user deletion request, or a legal obligation applies.

Sharing

We do not share Google user data except with service providers acting on Nömad's behalf that are required to host, secure, and operate the platform, or where required by law. Those providers may not use the data for their own purposes.

Disconnecting, revocation, and deletion

A brand owner or administrator can disconnect each integration from Nömad's Connections section. When the last connection under an authorization is removed, we attempt remote revocation and delete stored tokens. When YouTube authorization is revoked, expires, or is disconnected, we immediately delete or anonymize authorized YouTube API data, including remote identifiers, metrics, and provider responses. You may also revoke Nömad from your Google Account permissions or request access or deletion by emailing legal@nomad.ooo.

Nömad's use and transfer to any other app of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.