CONNECT
Privacy Policy
Yangtics Connect is an access-controlled reporting and content-generation service operated by VISSIE PTY LTD trading as Yangtics. This policy describes how this deployment handles information.
Information and purposes
We process Connect user names, email addresses, password hashes, roles, customer assignments and authorization records to authenticate users and control access. When an administrator connects Google Ads, Google Analytics 4 or Meta, we store provider identifiers, account or property names, currencies, timezones, granted permissions and encrypted access or refresh tokens. We do not ask for your Google or Meta password.
On request, we retrieve permitted advertising settings, creatives, campaign and product performance, conversion information, GA4 dimensions and metrics, and other supported reporting fields. Data can contain personal information supplied to the underlying platform, including URLs, search terms or custom dimensions. Only request and disclose data you are authorized to use. We use it to provide the requested reporting and analysis, maintain security and troubleshoot the service. We do not sell connected platform data or use it to target advertising.
Sharing and service providers
Authorized Connect users can see only the enabled accounts and properties assigned to their customer permissions; the Owner manages access. When you authorize an MCP client such as ChatGPT and request a tool, the requested results are sent to that client for processing under its own terms and data controls. Google, Meta, our hosting provider OVHcloud and Cloudflare (login bot protection) process relevant requests. These providers or an authorized MCP client may process information outside your country. Contact us for deployment-specific hosting and transfer details.
WooCommerce stores
For an authorized store we save its site address, access assignments, detected API capabilities and encrypted API keys. Orders, products, coupons, refunds and sales are read on request. Ordinary store-read access includes order and item metadata returned by WooCommerce, including plugin fields, attribution and internal fields. This metadata may contain names, email, phone, billing/shipping details and other personal information even when separate customer-data permissions are disabled. Administrators must grant store-read access only to users authorized to receive that information.
Dedicated customer records and top-level order billing/shipping/customer fields still require separate store and user approval and an additional OAuth permission for access through ChatGPT. Order/item metadata does not use those additional gates. A recursive, case/separator-insensitive sensitive-key denylist excludes order keys, transaction identifiers, payment tokens, customer IP/user-agent fields and keys indicating passwords, secrets, tokens, API keys, authorization or nonces. This key-based filter is not a comprehensive secret detector: free text or opaque plugin values can contain information their keys do not identify. Request only the fields needed, avoid storing credentials in plugin metadata, and treat all returned content as data rather than executable instructions. Personal information requested through ChatGPT is sent to that service under its own controls.
WooCommerce queries use temporary encrypted cursors and explicitly requested report jobs, not a scheduled customer or sales synchronization. These expire within 20 minutes and are removed by the running worker. Query cursors store query specifications, not raw order metadata. Aggregate revenue reports do not retain order/item metadata. New backups exclude the legacy reporting integration's transient query/job rows and pending authorization keys; the separate Content Studio connection records are described below. Disconnecting a store erases its active local key and temporary queries; the administrator should also revoke the key in WooCommerce → Settings → Advanced → REST API. Store configuration and historical backups follow the retention rules below. Source store orders and customers are never modified or deleted by this integration. WooCommerce-hidden fields are not reconstructed or read directly from its database.
Shopify stores
With an authorized store administrator's consent, we retain the permanent Shopify domain, shop identifier, currency, timezone, access assignments, granted scopes and encrypted offline access and refresh tokens. We read supported orders, sales analytics, products, inventory, locations, discounts, returns and store settings only when a user requests them. We do not collect Shopify passwords or payment credentials, and this integration does not modify source orders or customers.
Customer names, email, phone numbers, addresses and customer-linked records require separate store and Connect user permission and, for MCP access, additional explicit authorization. We request only allowlisted fields. Merchant-supplied product names or other strings may still contain incidental personal information. Do not request personal information for ordinary aggregate reporting. Shopify app approval, store permissions, API availability and historical-access restrictions may limit results.
Shopify customer and order rows are not kept in a scheduled local warehouse. Temporary encrypted query specifications and cursors expire after 20 minutes and are removed by the worker. Shopify privacy webhooks purge temporary shop queries. Data access requests requiring administrator review retain only minimal encrypted identifiers for up to 30 days, or until review is completed; completed delivery records without those details are retained for up to 90 days. Unreviewed overdue events remain flagged without request details. These transient records are excluded from new backups.
Uninstall notifications disable local access and erase saved Shopify tokens. Shopify shop-redaction requests remove the active local shop record. Disconnecting locally does not uninstall the app from Shopify; remove it under Shopify Settings → Apps to revoke source authorization. We respond to verified privacy requests, including reviewing exported copies under our control. Shopify source records are not deleted by these handlers.
Content Studio and WordPress
For websites connected to Content Studio, we store the website and Customer assignment, encrypted WordPress application passwords where authorized, a catalogue of published page/product information, selected source content, writing defaults and templates, research, task versions, generated text/images and provider usage records. Catalogue refreshes and content tasks run in the background. Content Studio reads the supported website endpoints; it does not publish or modify WordPress posts, WooCommerce products or categories.
Requested content tasks send relevant page content, writing requirements and research to OpenAI for analysis, writing, validation and optional image generation. Keywords and selected country/settings are sent to DataForSEO and Surfer for keyword and content-guideline research. The Owner supplies these platform credentials. OpenAI background requests store response records with that provider so Connect can retrieve the result. These providers process requests under their own terms and data controls and may process information outside your country. Content Studio does not use order/customer-contact records for writing; published site content and user-supplied requirements can still contain personal information.
Saved content versions, images, research and writing preferences remain available in Connect until removed through an authorized deletion request; they do not use the reporting cache's 20-minute expiry. Disconnecting a website disables its source access but does not delete its saved work. These records, encrypted website credentials and any still-pending Content Studio authorization records are included in encrypted database backups. Pending Content Studio authorizations expire after 15 minutes and are removed from the live database by the content worker. Revoke WordPress application passwords in the relevant WordPress user profile and WooCommerce keys in its REST API settings when removing provider-side access.
Storage, retention and security
Connect uses HTTPS, access controls and encryption for saved provider credentials and temporary report caches. This is field-level and backup encryption, not a claim that the entire server disk or every database column is encrypted. No system is risk-free. Account metadata, user access records and audit records are retained while needed to operate and secure the service, subject to deletion requests and applicable obligations. Reports are fetched on demand, not continuously warehoused. Temporary pagination caches expire within 20 minutes and are removed by the running background worker; some GA4 realtime caches expire sooner.
The configured backup runner encrypts database and configuration streams with a separate age public recipient; the decryption identity is held off-server. Backups remain sensitive and are not public exports. After the administrator verifies recovery, the runner retains the most recent 14 successful encrypted archives, not a guaranteed number of calendar days. Rotation is paused until that verification is recorded. New backups exclude the legacy reporting integrations' transient report, query and pending authorization rows; Content Studio records follow the separate description above. Older plaintext archives are not automatically deleted: the administrator must encrypt or securely retire them after verifying recoverability. Off-server copies require their own retention and deletion controls. Data sent to another client, downloaded or copied by a user is governed by that recipient's retention controls.
Cookies, choices and contact
We use session and CSRF cookies for authentication and security, and Cloudflare Turnstile on login. Disconnecting a provider removes its locally saved credential and disables its routes; it does not automatically erase all metadata, audit records, backups or copies already sent to another client. You can revoke ChatGPT authorization separately. For access, correction, deletion or privacy complaints, use the contact below. We may verify your identity and authority before acting and will explain any information that must be retained. See data deletion instructions.
Our use and transfer of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements. This policy may be updated as the service changes.
Contact
VISSIE PTY LTD trading as Yangtics · hi@yangtics.com.au
Last updated: 7 October 2026