Kultra
Back to Home
Google API User Data Policy Compliant

Privacy Policy

Operator: Kultra (Ouarzazate, Morocco)Effective Date: September 16, 2026Last Updated: September 2026

1. Service Operator & Unified Contact Information

This Service is operated exclusively by Kultra, headquartered and operated out of Ouarzazate, Morocco. Kultra provides real-time automated catalog feed monitoring, policy violation diagnostics, and disapproval alerting for e-commerce merchants utilizing Google Merchant Center via https://www.usekultra.com.

Our unified, centralized point of contact for all legal inquiries, privacy questions, security disclosures, and data deletion requests is: support@usekultra.com.

2. Google API Sensitive Scope Disclosure (https://www.googleapis.com/auth/content)

Google classifies the https://www.googleapis.com/auth/content permission as a sensitive scope. When you authenticate via Google OAuth 2.0 and connect your Google Merchant Center account with Kultra, our platform requests access strictly to retrieve read-only catalog status telemetry.

Read-Only Catalog Health Telemetry & Disapproval States

Kultra retrieves specific, read-only data points: unique product IDs (Offer IDs), product titles, approval statuses (approved, disapproved, pending), servability states (eligible vs. blocked from shopping ad traffic), and policy disapproval error codes (such as GTIN errors, pricing mismatches, tax configuration discrepancies, or promotional policy violations).

Merchant Center Account (GMC) Metadata

Merchant Center Account ID, registered store name, verified store domain URL, and account hierarchy (standalone merchant account vs. Multi-Client Account / MCA child accounts).

User Authentication Profile

User email address, Google unique identifier (sub), and display name, used solely to authenticate and identify your tenant workspace session.

PASSIVE DIAGNOSTIC MONITOR: NON-MUTATION GUARANTEE

"Kultra functions purely as a passive diagnostic monitor and never writes, alters, creates, updates, or deletes product data, pricing, inventory, listings, feeds, or feed configurations in the merchant's Google Merchant Center account."

3. Mandatory Google Limited Use Compliance

Kultra strictly adheres to Google's API Services User Data Policy, specifically the Limited Use requirements.

LIMITED USE REQUIREMENTS VERBATIM DISCLOSURE
"Kultra's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements."

In strict adherence to these requirements:

  • Google user data is used strictly to provide and improve customer-facing features prominent in Kultra's dashboard (real-time catalog health monitoring, incident alerting, and disapproval diagnostics).
  • Google user data is never transferred to third parties, except as strictly necessary to deliver the Service (e.g., transmitting an alert payload to your user-configured Slack webhook), to comply with applicable laws, or as part of a corporate transaction with prior affirmative notice.
  • Google user data is never used or transferred to serve advertisements, including personalized, targeted, or retargeted advertising.
  • Humans are prohibited from reading Google user data unless you have given explicit consent for troubleshooting, it is required for security incident response, or it is required by applicable law.
  • Google user data is never used, leased, or transferred to train generalized artificial intelligence (AI) or machine learning (ML) models.

4. Data Storage, Encryption & Security

Kultra applies rigorous cryptographic protections and defense-in-depth safeguards to protect all merchant data and credentials:

AES-256 Encryption at Rest

All OAuth 2.0 refresh tokens, access credentials, API keys, and customer webhook URLs are encrypted at rest using industry-standard AES-256 (AES-256-GCM) encryption before being committed to persistent database storage. Encryption keys are managed in isolated environment boundaries.

TLS 1.3 / HTTPS in Transit

All communications between user browsers, Kultra servers, and Google APIs are transmitted exclusively over encrypted HTTPS connections using modern Transport Layer Security (TLS 1.3) protocols with strict HTTP Strict Transport Security (HSTS) enforcement.

5. Zero Commercialization & No Model Training

NON-NEGOTIABLE COMMERCIAL INTEGRITY GUARANTEE

"Google user data is never sold, leased, rented, or transferred to third-party data brokers. Google user data is never used for serving advertisements, retargeting, or training general AI or machine learning models under any circumstances."

6. Technical Sub-Processors

To deliver real-time monitoring and high-reliability data pipelines, Kultra utilizes vetted infrastructure sub-processors:

Sub-ProcessorRole & Function
Vercel Inc.Edge network hosting, SSL termination, and serverless application execution
Neon Inc.Managed cloud PostgreSQL database with AES-256 encrypted persistent storage
Google Cloud PlatformCloud Pub/Sub push subscription infrastructure for real-time Merchant Center push events
Slack Technologies / SalesforceOutbound delivery of Block Kit alert payloads strictly to user-configured webhook destinations

7. Data Retention, Revocation & Deletion

You maintain complete sovereignty over your Google Merchant Center data and can revoke access or request full deletion at any time:

Revoking Access via Google Account Security Settings

You can revoke Kultra's access permissions at any time directly through your Google Account Security Settings (under "Third-party apps & services") by visiting: https://myaccount.google.com/permissions. Revoking access immediately invalidates our OAuth credentials and halts all API data retrieval.

Disconnecting Store Inside Kultra Dashboard

You can disconnect your store at any time via your dashboard settings. Disconnecting immediately removes your store from the active polling loop and terminates live monitoring.

Permanent Data Deletion by Email Request

Users can request complete, irreversible deletion of their stored catalog metadata, incident logs, store records, and authentication credentials at any time by emailing support@usekultra.com. All deletion requests are verified and processed within 30 business days, with all corresponding records permanently purged from our active databases and backup retention cycles.

8. Single Point of Contact

For all questions, compliance inquiries, privacy disclosures, or data deletion requests, please contact our unified support channel:

Operator: Kultra
Headquarters: Ouarzazate, Morocco
Support Email: support@usekultra.com
Official Website: https://www.usekultra.com
Privacy Policy | Kultra