Privacy Policy

Effective date: 14 August 2026

Who we are

TagWatch is a tag monitoring service operated by Grip Analytics, based in the Netherlands. If you have questions about this policy, contact us at [email protected].

What data we collect

Account data. When you register, we collect your name, email address, and billing information (processed by Stripe). We use this to operate your account and send you alerts and invoices.

Usage data. We log activity such as monitor runs, incidents, and API calls. This data is used to operate the service and is not shared with third parties.

Aggregated event counts. When your website sends data to TagWatch via GTM, only anonymous event names and counts are transmitted. No visitor information reaches our servers.

Advertising and analytics accounts you connect

TagWatch can watch conversion numbers in your Google and Meta advertising accounts, and the template versions in your Google Tag Manager containers. Connecting an account is always your choice, and every connection is read only.

Google. With your permission we request read access to Google Analytics 4, Google Ads and Google Tag Manager. We store the access and refresh tokens Google issues, the email address of the connected account, and the identifiers and names of the properties, accounts and containers you choose to watch.

Meta. With your permission we request read access to your Meta advertising data. We store the access token Meta issues, the name and identifier of the connected Meta account and business, and the identifiers and names of the ad accounts and conversions you choose to watch.

What we read. Aggregated performance numbers only: how many conversions an account recorded on a day, and their total value. We compare those numbers against their own history so we can tell you when tracking breaks.

What we never read. We do not access customer lists, custom audiences, contact details, or any personal data about the people who saw or clicked your ads. We do not create, change, pause or delete anything in your advertising accounts, and we cannot: the access we ask for is read only.

What we never do with it. Data obtained through these connections is used solely to operate the monitoring you asked for. We do not sell it, we do not use it for advertising or profiling, we do not combine it with data from other customers, and we do not transfer it to anyone beyond the service providers listed below.

You can disconnect any account at any time in Settings. Disconnecting immediately revokes our access and deletes the stored token. You can also revoke access from your Google account settings or your Meta business tools settings.

What we do not collect

TagWatch does not collect any personal data about visitors to your website. The GTM tag template transmits event names and counts only. No IP addresses, cookies, device fingerprints, or any other personal information from your visitors ever reach TagWatch.

Because we collect no personal data about third parties, no consent banner is required for the TagWatch GTM tag under the GDPR.

How we use your data

We use the data we collect to:

  • Provide and operate the TagWatch service
  • Send monitoring alerts and weekly digest emails
  • Process payments and send invoices
  • Respond to support requests
  • Improve the service

We do not sell your data or use it for advertising purposes.

Data sharing

We share your data only with the following service providers, to the extent necessary to operate TagWatch:

  • Stripe for payment processing
  • Clerk for authentication
  • Resend for transactional email
  • Railway for hosting and infrastructure
  • Trigger.dev for running scheduled monitoring jobs

We do not share your data with any other third parties, and we never share data obtained from your Google or Meta connections with anyone outside this list.

Requests from public authorities

Authorities sometimes ask companies to hand over user data. We treat every such request the same way, whether it concerns your account or data from a connected advertising account.

  • We check whether it is lawful. We verify who is asking, the legal basis they cite, and whether the request is binding on us under Dutch and EU law. Nothing is disclosed before that review is done.
  • We push back when it is not. A request without a valid basis, or one that reaches wider than its basis allows, is refused and, where a procedure exists, formally challenged.
  • We give the least that answers it. Only the data the request actually covers, never a broader export because it is easier.
  • We write it down. Every request, our assessment, what we decided and what we disclosed is logged and kept.

We tell you when your data is involved, unless the law forbids us from saying so.

How we protect your data

We apply the following measures to protect your data against unauthorised access, loss, or disclosure:

  • Encryption in transit. All communication between your browser and our servers takes place over HTTPS (TLS 1.2 or higher). Data sent from your website to TagWatch via the GTM tag is also transmitted over HTTPS.
  • Encryption at rest. Account data, aggregated event counts, and configuration data are stored in a managed database hosted on Railway, which applies encryption at rest by default.
  • Access controls. Access to production systems is restricted to authorised personnel only. API keys are stored as hashed values and never in plaintext. Authentication is handled by Clerk, a dedicated identity provider.
  • Data minimisation. We collect only the data necessary to operate the service. No visitor data is collected or stored at any point.
  • Third-party sub-processors. We use only sub-processors (Stripe, Clerk, Resend, Railway) that maintain their own security certifications and data protection obligations.

If you discover a potential security vulnerability, please report it to [email protected] and we will respond promptly.

Data retention

Account data is retained for as long as your account is active. When you close your account, your data is deleted within 30 days, except where we are required to retain it for legal or tax purposes.

Raw event bucket data is deleted after 48 hours. Aggregated daily counts are retained for up to 12 months.

Access tokens for connected Google and Meta accounts are kept only while the connection exists and are deleted immediately when you disconnect the account or delete your workspace. The conversion numbers we read are stored as part of your monitor history and are removed with the rest of your account data.

Your rights under the GDPR

If you are located in the European Economic Area, you have the right to:

  • Access the personal data we hold about you
  • Correct inaccurate data
  • Request deletion of your data
  • Restrict or object to processing
  • Data portability
  • Withdraw consent at any time (where processing is based on consent)

To exercise any of these rights, contact us at [email protected]. We will respond within 30 days. You also have the right to lodge a complaint with the Dutch Data Protection Authority (Autoriteit Persoonsgegevens).

Deleting your data

You can delete the data TagWatch holds about you at any time, in three ways depending on how much you want removed.

  • Disconnect one account. Open Settings, find the Google or Meta connection, and remove it. The stored access token is deleted immediately and we lose all access to that advertising account.
  • Delete a monitor. Deleting a monitor removes its configuration and its stored history of readings.
  • Delete everything. Open Settings and use Delete workspace. This removes your account, your monitors, their history, every connected account and its tokens, and all incidents. It cannot be undone.

You can also email us at [email protected] from the address on your account and ask us to delete your data. We confirm within 30 days, and in practice much sooner. Data is removed from our production systems immediately and from encrypted backups within 30 days, except where we must keep invoices for tax purposes.

Cookies

TagWatch uses a session cookie for authentication. No tracking cookies or third-party advertising cookies are set by this application.

Changes to this policy

We may update this policy from time to time. If we make material changes, we will notify you by email. Continued use of TagWatch after changes are posted constitutes acceptance of the revised policy.

Contact

Questions about this privacy policy? Email us at [email protected].