Privacy Policy
Last updated: 2026-09-30
This Privacy Policy describes how Shambix handles data for Shambix Growth Console (the WordPress plugin) and Growth Cloud (the prepaid credits portal and API at https://growthcloud.shambix.com/; fallback https://sgc-portal.pages.dev/).
1. Who we are
Shambix operates Shambix Growth Console and Growth Cloud. Contact: info@shambix.com · www.shambix.com.
2. Google user data (OAuth / APIs)
When a WordPress administrator uses Connect with Google in Shambix Growth Console Settings, the plugin requests Google OAuth access. This section discloses how we access, use, store, share, and delete that Google user data.
2.1 What we access
- Google account email (and related openid identity) to show which account is connected in Settings
- Search Console: list of sites/properties you can access; search analytics (queries, pages, clicks, impressions, countries, devices); URL inspection; sitemaps for the property you select
- Google Analytics 4: list of accounts/properties and web data streams (to match your site host); report data for the property you select (for example sessions, channels, sources, landings, countries, events)
Scopes are readonly (Search Console and Analytics readonly, plus openid/email for the Connected label). We do not request write access to change your Google properties.
2.2 How we use it
- Only to provide and improve user-facing Shambix Growth Console features on the customer’s WordPress site: property pickers, connection test, Refresh / scheduled refresh, dashboards, and optional Advisor tools that call the same readonly APIs
- We do not use Google user data for advertising, selling to data brokers, credit scoring, or training non-personalized AI/ML models
- Optional Growth Cloud AI uses aggregated digests prepared on WordPress; it does not receive your Google OAuth refresh tokens
2.3 Storage
- OAuth refresh tokens, connected email, and selected Search Console / GA4 property identifiers are stored on the customer’s WordPress installation (encrypted at rest in WordPress options)
- Short-lived access tokens may be cached briefly on that same site
- Growth Cloud servers do not store long-lived Google tokens
2.4 Sharing and processors
- Google: API calls for Search Console and GA4 run from the customer’s WordPress site to Google
- Growth Cloud Worker: during Connect, Google redirects to our Worker with a short-lived authorization
codeso we can exchange it for tokens and return a sealed payload to WordPress. The Worker does not keep Google refresh tokens or run GSC/GA4 reports - We do not sell Google user data or transfer it to third parties for advertising or model training
2.5 Protection
- Encryption at rest on WordPress for stored Google credentials
- TLS in transit
- WordPress admin capability checks (
manage_options) and CSRF protections on Connect / Disconnect
2.6 Retention and deletion
- Google OAuth data is kept while the site remains Connected
- Administrators can Disconnect in Settings (we revoke the Google token when possible and clear local secrets)
- Uninstalling the plugin removes plugin settings and stored keys from that WordPress site
- For Growth Cloud account deletion or other requests: info@shambix.com
3. Growth Cloud account data (portal + API)
- Account: email, password hash (not the plaintext password), optional Stripe customer IDs
- Sites: home URL, label, API key hashes, credit balance, usage events (AI turns, purchases, transfers)
- AI: when you use Cloud AI, request payloads needed for the job (for example digests from WordPress) go to our Worker and Anthropic. Optional Google Trends in the plugin uses your own DataForSEO credentials (not Growth Cloud). We do not intentionally collect visitor personal data from your site
- Payments: card details are processed by Stripe; we store payment-related IDs and top-up amounts, not full card numbers
We process this data to provide accounts, authenticate API keys, debit and transfer credits, process payments, prevent abuse, and improve reliability.
4. Processors (Growth Cloud)
- Cloudflare (Workers / Pages hosting)
- Neon (database)
- Stripe (payments)
- Anthropic (AI completion when Cloud AI is used)
- Email provider (optional; password-reset messages only)
- Google (OAuth code exchange on Connect only, as above)
5. Retention (Growth Cloud accounts)
Account and usage records are kept while your account is active and for a reasonable period afterward for billing/audit. You may request account closure by contacting us.
6. Your choices
In the portal you can change your password, create or rotate site API keys, and move credits between your sites. In the WordPress plugin you can Disconnect Google and uninstall the plugin. For data access or deletion requests, email info@shambix.com.
7. Plugin Help
Additional local-storage notes appear in the plugin under Help → Data & privacy on your WordPress site.
8. Changes
We may update this Privacy Policy. The “Last updated” date above will change when we do. Material changes that affect Google user data handling will be reflected here and, where required, in the Google OAuth consent configuration.
9. Contact
info@shambix.com · shambix.com · Product home: Shambix Growth Console