Local Vitals

Privacy Policy

Effective October 7, 2026

Local Vitals is a reporting tool that reads a company's Google Analytics 4 data and explains, in plain language, what is happening across its locations, why, and what to do about it. It is built and operated by Will Newton. This policy describes what data the tool accesses and how it is handled.

What we access

When you connect a Google account, Local Vitals requests read-only access to Google Analytics (the analytics.readonly scope). With that permission it reads aggregated reporting data from the GA4 properties you choose: sessions, users, events, conversions, revenue, and their breakdowns by page, channel, campaign, location, device, and date. It does not read or modify your Analytics settings, and it never writes to your Google account.

Local Vitals does not collect names, email addresses, or other personal information about your website visitors. GA4 reporting data is aggregated by Google before we receive it.

How we use it

We do not sell your data, use it for advertising, or share it with anyone other than the service providers named below.

Where it is stored

Reporting data and the summaries written from it are stored in a database on servers we control (Amazon Web Services, United States). Your Google sign-in token is stored encrypted at rest and is used only to refresh the data on a schedule. Access to the dashboard is password-protected.

Service providers

Google API Services User Data Policy

Local Vitals's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. Google user data is used only to provide and improve the features described above, is not transferred to third parties except as needed to provide those features, and is never used for advertising or sold.

Retention and deletion

Reporting data is kept for up to 13 months so that year-over-year comparisons work, then removed. You can revoke Local Vitals's access at any time at myaccount.google.com/permissions; after revocation no new data is read. To have your stored data deleted, contact us at the address below and it will be removed within 30 days.

Changes

If this policy changes, the effective date above will be updated. Material changes will be communicated to connected accounts before they take effect.

Contact
Will Newton · newtonw910@gmail.com