Overview
JMP Technologies(“JMP,” “we,” “us”) operates JMP Dashboard (the “portal”) at portal.jmptech.dev. The public product page for this app is https://jmptech.dev/jmp-dashboard. This policy describes how we handle personal and usage data when you sign in, when we connect Google services on behalf of our agency, and when client websites send analytics and leads to our backend.
Questions: support@jmptech.dev
Who this applies to
- Portal users: JMP staff, agency admins, and invited client users who sign in to view dashboards and manage content.
- Website visitors:people who browse client websites that use JMP analytics or contact forms. Those sites should publish their own privacy policy. JMP processes visitor data on the client's behalf as a service provider.
Portal account data
When you create or use a portal account, we may store:
- Name and email address
- Authentication credentials (hashed passwords; we do not store plain-text passwords)
- Session tokens and sign-in timestamps
- Role and website access assignments
We use this data to authenticate you, enforce access controls, send account-related email (password reset, invitations), and operate the service.
Google services (agency administrators only)
JMP agency administrators may connect one agency Google account to the portal. Client users never complete Google OAuth and never grant Google permissions directly. Clients only see aggregated Search Console and Google Analytics reports inside the dashboard.
JMP's use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
When an administrator connects Google, we request these OAuth scopes:
- Google Search Console (https://www.googleapis.com/auth/webmasters): Read search performance data and manage site properties for client domains in the agency account.
- Google Site Verification (https://www.googleapis.com/auth/siteverification): Request DNS TXT verification tokens so client domains can be verified in Search Console.
- Google Analytics (read-only) (https://www.googleapis.com/auth/analytics.readonly): Read aggregated GA4 reports so clients can view Google Analytics charts in the dashboard without signing in to Google.
Google user data we access
Our application will access Google user data associated with the connected agency Google account, including:
- Google account email address used to authorize the connection
- Search Console site properties, ownership/verification status, and search performance data (such as queries, pages, clicks, impressions, country, and device)
- Site Verification DNS TXT tokens used to verify client domains
- Google Analytics 4 property identifiers and aggregated reports (such as sessions, page views, and top pages)
We do not request Gmail, Drive, Contacts, Calendar, or other unrelated Google user data.
How we use Google user data
We will use Google user data only to provide and improve JMP Dashboard features you asked for:
- Display Google Search performance for linked client domains
- Add and verify client domains in Search Console (including DNS TXT records)
- Link GA4 properties and show read-only analytics charts to authorized portal users
- Suggest blog topics from Search Console queries when AI blog automation is enabled for that client site
We do not use Google user data for targeted advertising, personalized or interest-based ads, retargeting, selling to data brokers, providing data to information resellers, determining credit-worthiness, lending, or building unrelated databases.
We do not use Google Workspace APIs or Google user data to develop, improve, or train non-personalized AI and/or ML models. Optional AI blog drafts use Search Console query strings only as topic seeds for that client's site. That processing is to operate the feature the client enabled. It is not used to train a general or non-personalized model.
How we store Google user data
We store OAuth refresh and access tokens, the connected Google account email, Search Console property mappings, GA4 property IDs, and cached report summaries needed to render the dashboard. Tokens stay on our servers.
How we share Google user data
We do not sell Google user data. We do not transfer or disclose Google user data to third parties except:
- Hosting, database, and infrastructure providers that process data solely to operate JMP Dashboard
- Our AI provider, only when AI blog automation is on, and only Search Console query strings and related performance metrics needed to draft posts for that client site
- When required by law
Those providers process data under contracts that require appropriate safeguards. We do not share Google user data with advertisers, data brokers, or information resellers.
How we protect Google user data
Security procedures are in place to protect the confidentiality of Google user data. We use encryption in transit (HTTPS/TLS) and encryption at rest provided by our hosting and database providers. Access is restricted by role. We monitor for abuse.
Google user data retention and deletion
We store Google user data for a period consistent with operating JMP Dashboard: OAuth tokens while the agency connection is active, and cached report summaries while they are needed to render charts. When the retention period ends, or when an administrator disconnects Google, we delete or destroy the tokens and associated cached Google report data.
You may request deletion of Google user data we hold by emailing support@jmptech.dev. Administrators can also disconnect the agency Google account in Admin settings, or revoke the app under Google Account → Third-party access.
Google's own processing is described in the Google Privacy Policy.
Website analytics and leads (client sites)
Client websites integrated with JMP may send page views, session metrics, and contact events to our API. Depending on configuration, this can include page paths, referrer URLs, approximate country, device category, UTM campaign parameters, and contact form fields (name, email, phone, message). Session identifiers may be stored in the visitor's browser session storage on the client site, not in analytics cookies.
We retain analytics and lead data according to our agreements with each client and operational needs (reporting, support, and security). Clients can request export or deletion through their JMP contact.
Sharing and subprocessors
We do not sell personal information. We share data only with service providers that help us operate the portal (for example hosting, email delivery, database, and the AI provider used for optional blog drafts), under contracts that require appropriate safeguards, and when required by law. Sharing of Google user data is limited to the cases listed in “How we share Google user data.”
Security and retention
We use encryption in transit and at rest, restrict access by role, and monitor for abuse. Account data is kept while your account is active and for a reasonable period afterward for legal and operational purposes. Google OAuth token and cache retention is described above.
Your choices
- Update account details in portal settings.
- Request access, correction, or deletion of personal information, including Google user data we store, by contacting support@jmptech.dev.
- Agency admins: disconnect Google in Admin settings or revoke access in Google Account permissions.
Changes
We may update this policy from time to time. We will revise the “Last updated” date at the top of this page. If we change how we use Google user data, we will update this policy before that change takes effect. Continued use of the portal after changes constitutes acceptance of the updated policy.
