LEGAL
Privacy policy
What we read. A website from the outside — its home page and a handful of public files — and, when you buy a roadmap and connect Google, your Analytics and Tag Manager settings plus 28 days of event and traffic totals. Everything we ask for is read-only. We cannot change a tag, a property or a report.
What we keep. Your email address, your order, your scores, your finished roadmap, and what a scan pulled. That last part sits in private storage because it is how we check our own work and correct a roadmap if we got something wrong.
What we never do. Sell it, use it for advertising, hand it to a data broker, write anything to your Google account, or run an analytics or advertising tag of our own on this app. There is not one on any page of it.
Who we are
The Clean Data Roadmap is run by Measure Holdings Group LLC, trading as MeasureU, at 254 Chapman Rd, Ste 208, Newark, DE 19702, United States.
Questions about anything here, or a request about your own data — write to us at app@measureu.com.
What this policy covers
This policy covers scan.measureu.com and the Clean Data Roadmap product: the free scan, the paid roadmap, the emails we send you about them, and the Google connection you can grant us.
It does not cover the rest of the MeasureU site.
This policy is published at https://scan.measureu.com/privacy.
What we collect, and when
When you run a free scan
You type a website address. We then fetch, from the outside, as any visitor could:
- the home page;
robots.txt,ai.txt,llms.txtand the site's own sitemap;- one plain
http://request to that address; - the public Tag Manager container file that Google serves for the container IDs on the page;
- public DNS records — the address records, mail records, and the SPF, DKIM and DMARC records — over Cloudflare's public DNS service.
We also load the home page once in a real browser to take a picture of it for your results page. That visit runs the site's own scripts, so the site's analytics will record it the way it records any other visit.
We store the result: which tracking tools we found and their account IDs, the container IDs, whether a consent platform was detected, the DNS and security-header findings, the score, and the home-page picture. There is one stored result per website address, and a new scan replaces the old one. We do not store the page's HTML, and we do not keep a log of the network requests a free scan saw.
One detail we would rather state than let you discover: that home-page picture is served from a plain web address with no sign-in on it. It is a photograph of a public page, so it holds nothing a visitor could not see — but it is not behind a lock, and calling it private would be wrong.
About you, at this point, we hold nothing. No account, no email address. Your IP address is used for two things and stored for neither: a short-lived limit on how many scans one visitor can run, and the anti-bot check on the scan form, which sends it to Cloudflare Turnstile.
If you save a scan or sign in
We store your email address and a record of the sign-in links we have sent you. Sign-in is by emailed link, so there is no password and we never hold one.
When you buy
Payment is taken by Stripe, on Stripe's own checkout page. Card details never reach us. We receive and store your email address, the amount paid, a promo code if you used one, Stripe's identifiers for the payment, and the website address you bought the roadmap for.
Google user data
This is the section that matters most, so it is the most specific.
What we ask for
Two read-only permissions, and nothing else.
https://www.googleapis.com/auth/analytics.readonly— view your Google Analytics datahttps://www.googleapis.com/auth/tagmanager.readonly— view your Google Tag Manager containers
Neither can write. There is no code path in this application that adds a user, edits a tag, changes a property, or publishes anything to your Google account. We do not request permission to see your name, your Google profile or your email address, so in most cases we do not learn which Google account approved us — only that one did.
What we read with it
- Your Google Analytics 4 property settings: the property name, currency and time zone; your data streams and their enhanced-measurement settings; your Google Ads links; your BigQuery links; your custom dimensions and custom metrics; your key events.
- Two aggregate Analytics reports covering the last 28 days: event names with their event counts and event values, and session source, medium and campaign with session counts.
- Your live Google Tag Manager container — its tags, triggers and variables, as published.
Those two reports are totals. We do not request, and the permissions we hold do not give us, any report about an individual person: no user IDs, no client IDs, no page-by-page browsing history, no demographics, no audience membership.
How we use it
To produce the roadmap you bought, and to check and correct it afterwards. Nothing else. It is not used to build a profile of you, it is not used to target advertising, and it is not combined with data from any other customer except as anonymous counts — how many of the sites we have scanned have no consent platform at all, say. Never named, and never in a group smaller than ten sites.
How we store it
Your Google refresh token, the credential that lets us read again later, is encrypted before it is written down, under a key held separately from the database. The short-lived access token is never written down at all: it is requested when needed and kept in memory. If the encryption key is unavailable, the Connect button does not appear and the connection is refused. We do not store a credential in the clear.
The settings and report totals we read are stored in private Cloudflare storage, along with your finished roadmap. There is no public link to any of it. Nothing is published, and nothing is shared outside the providers named under "Who else can see it".
How long we keep it
We keep it until you ask us to delete it. There is no automatic expiry today, and we would rather say that than imply one.
How we share it
We do not sell it. We do not transfer it to anyone for advertising, for credit or lending decisions, or to any data broker. The only third parties involved are the infrastructure providers listed below, who process it on our behalf so the product can run.
Who reads it
Our own team, and only to build, check or correct your roadmap, or to answer a support request from you. Nobody outside the team has access.
Whether it trains AI models
No. No part of this application sends your data to any AI or machine-learning service, and it is not used to develop or improve one.
How you end it
- The Disconnect Google button on your site's page in the app. That asks Google to revoke our token, then deletes the credential, the list of your properties and containers, and every link from a scan to it. It does not delete a roadmap you already received, or the data behind it — the delete button on the same page does that, and so does an email to us.
- Or revoke it yourself at any time from your Google account's security settings. It is your grant and you do not need us to end it.
Limited Use
Our use of Google user data follows the Google API Services User Data Policy, including its Limited Use requirements. That policy is at https://developers.google.com/terms/api-services-user-data-policy.
Emails we send you
Sign-in links, a setup email after you buy, access reminders, and the email that delivers your roadmap. We keep a record of each one, including its contents, so we can tell whether it was sent and send it again if it failed. A sign-in link is removed from that stored copy before it is written, so the record cannot be used to get into your account.
Websites that are not yours
We also run the same outside-only check on websites nobody asked us to check, so we can research how common tracking and consent problems are, and so our sales team can open a conversation with a real finding rather than a guess.
For those sites we read only public pages, one page per site, and only what any visitor could see. It is a plain fetch, with no browser and no picture. We store the result and the findings. We never store a name, an email address or a phone number from a page we read, and we never build a contact list out of one. How that scanner identifies itself, and how to ask us to stop, is on how the scan works.
What we never do
- Sell your data, or anyone's.
- Use what we read for advertising, ours or anyone else's.
- Give it to a data broker, a credit reference agency or a lender.
- Write to your Google account. We hold no permission that could.
- Run analytics, tag managers or advertising pixels on this app. There is not one on any page of it, which is the least we can do given what the product is about.
Who else can see it
These providers process data for us so the product works. Each one sees only what its job needs.
| Provider | What it handles |
|---|---|
| Cloudflare | Hosting, the database, file storage, the browser that loads a page to check it, the anti-bot check on our forms, and public DNS lookups |
| The Analytics and Tag Manager data you grant us access to, and the sign-in that grants it | |
| Bento | Sending our emails |
| Stripe | Taking payment. Card details go to Stripe, not to us |
Some outside checks are run from an ordinary home internet connection, in a normal browser, rather than from our hosting. That reading holds no account data, and what it reads is stored exactly as any other check's result is.
How long we keep things
| What | How long |
|---|---|
| Your account and order records | While you have an account, then as long as tax and accounting rules require |
| Sign-in links | 15 minutes to use; the record is deleted a day after it expires |
| Your session | 30 days from last use |
| Your finished roadmap | Until you delete it or ask us to. We do not promise to keep it forever |
| The Google settings and report totals behind a roadmap | Until you delete that roadmap, or ask us to delete them |
| Your Google credential | Until you disconnect, or Google expires it |
| Free-scan results, including for sites we checked without being asked | Indefinitely, unless you ask us to remove them |
| Our copy of an email we sent you | Until you ask us to delete it |
Several of those rows say "until you ask us" rather than naming a number, and that is deliberate. Outside of the delete button and the two rows with real numbers on them, nothing expires on a schedule today. A limit we do not enforce would be worse than saying so.
Your choices
You can ask us to:
- show you what we hold about you;
- delete your roadmap — there is a button for this on your site's page in the app, and it is immediate. It removes the PDF, the online version, and the stored run data behind them: the Google settings and report totals we pulled, and the screenshots from the consent check. Your scores and this site's history stay, so the page still tells you what it found;
- delete everything we hold about you, including your account;
- correct anything that is wrong;
- stop scanning a website you are responsible for, and remove what we have stored about it;
- end our Google access, from the app or from your own Google account.
Write to us at app@measureu.com. A person handles every one of these except the delete button, so it is not instant.
If you are in the UK or the EU, you have these rights under the GDPR and can complain to your national data-protection authority. If you are in California, you have rights under the CCPA, including the right to know and the right to delete. We do not sell personal information and we do not share it for cross-context behavioural advertising — for either law's meaning of those words.
Security
Everything runs over HTTPS. Your Google credential is encrypted before it is stored. Report links sent by email are signed and expire. Report files are in private storage with no public address, and a request for one is checked against your sign-in before the file is handed over. Access to our own systems is limited to a named list of people on our team.
No system is perfect, and we would rather say that than claim otherwise. If you find a problem, write to us at app@measureu.com and we will act on it.
Children
This is a business tool, not a service for children, and we do not knowingly collect anything from a child.
Where the data sits
Our infrastructure providers are US companies, so your data may be processed in the United States and in other countries where they operate.
Changes
We will change this page when the product changes. The date at the top will say when. If a change affects what we do with data you have already given us, we will email you before it takes effect.
Contact
Write to us at app@measureu.com.
254 Chapman Rd, Ste 208, Newark, DE 19702, United States
Two other pages go with this one: our terms of service, and how the scan works, which is where a site owner can ask the scanner to leave them alone.