Pioneer Vision Consulting

Privacy Policy

Last updated July 2026

This policy explains what Pioneer Vision Consulting collects when you use our client portal, what we do with it, and what we do not do with it. It covers the Google account data our clients choose to connect, which is the part most people want to read.

Who we are

Pioneer Vision Consulting, 10503 Angeline Rd E, Bonney Lake, WA 98391. Questions about anything here go to ravneet@pioneervisionconsulting.com, and we answer them.

Google account data

Our clients can connect their own Google accounts so their marketing reports build themselves instead of being assembled from screenshots. Connecting is optional, and nothing here happens without a client explicitly approving it on Google's own consent screen.

What we access

Only the services a client selects when they connect:

  • Google Analytics — visitor counts, traffic sources, conversions. Read-only.
  • Search Console — impressions, clicks, search queries, average position. Read-only.
  • Tag Manager — which containers and tags exist. Read-only.
  • Business Profile — listing details, reviews, calls and direction requests.
  • Google Ads — spend, clicks, conversions and campaign performance.
  • Gmail (send only) — we send email from the connected account: report notifications, invoices, proposals and booking confirmations. This permission does not allow us to read, search, or list any message in the mailbox, and we do not do so.
  • Google Drive (read-only) — opens files a client has explicitly chosen to attach to their portal, so a document can be shown without being re-uploaded. We do not browse, index, or copy the wider Drive.
  • Google Calendar — reads busy times so appointment scheduling does not offer a slot that is already taken, and writes an event when a meeting is booked. We create and update only events that originate from this portal.

Exact permissions we request

For completeness, these are the OAuth scopes a client may be asked to approve. A client only ever sees the ones relevant to the services they are connecting.

  • analytics.readonly — read Google Analytics reporting data
  • webmasters.readonly — read Search Console performance data
  • tagmanager.readonly — list Tag Manager containers and tags
  • business.manage — read Business Profile listings and reviews, and post review replies a client has approved
  • adwords — read Google Ads campaign performance
  • gmail.send — send mail on the client's behalf; no read access
  • drive.readonly — read files the client has specifically attached
  • calendar and calendar.events — read availability and create booked meetings

Google publishes no read-only permission for Business Profile or Google Ads. Approving either one grants broader access than viewing, and we say so on the connection screen before anyone approves. We use them only to read reporting data.

What we do with it

We use it to produce the reports and dashboards the client is paying us for, and for nothing else. Specifically, we do not:

  • sell it, rent it, or share it with data brokers;
  • use it for advertising, profiling, or building audiences;
  • use it to train machine-learning or AI models;
  • let humans read it, except where a named member of our team needs to investigate a specific problem, or where the law requires it.

Our use of information received from Google APIs adheres to the Google API Services User Data Policy, including its Limited Use requirements.

How it is stored

Access tokens are encrypted before they are written to our database. We never receive or store a Google password. Reporting figures are stored so that a report published in March still shows the March numbers in June — reports are frozen at publication rather than recalculated afterwards.

Taking it back

A client can disconnect any account from the Connected accounts page in their portal at any moment. Access can also be revoked directly at myaccount.google.com/permissions, which works whether or not they tell us. When access is removed we stop collecting new data and delete stored tokens; already published reports keep the figures they were published with, because a client's historical record should not silently change.

Other information we hold

  • Account details — name, email, phone, and the company you belong to.
  • Work records — projects, tasks, requests, documents and messages you send us.
  • Agreements — proposals and contracts, including the signature record: who signed, when, from which IP address and browser, and a fingerprint of the exact document. That exists so both sides can prove what was agreed.
  • Billing — invoices and payments. We never see or store card numbers. Card details are entered on a form served by our payment processor, Authorize.Net, and we hold only a token, the card brand, the last four digits and the expiry date.
  • Technical logs — IP address, browser, and pages visited, kept for security and troubleshooting.

Who else sees it

We share information only with the services needed to run this system:

  • Hosting — our servers and database.
  • Authorize.Net — payment processing.
  • Email delivery — Google or Microsoft, to send the mail this system generates.
  • AI providers — Anthropic and Google, where a feature drafts text. We do not send Google Analytics, Search Console, Ads or Business Profile data to them.

We do not sell personal information. We disclose it to authorities only where the law compels us.

How long we keep it

For as long as you are a client, and afterwards only as long as we must — typically seven years for financial and contractual records, because tax and contract law require it. Google tokens are deleted as soon as access is revoked. Ask us to delete anything else and we will, unless we are legally required to keep it, in which case we will tell you which part and why.

Your rights

You can ask for a copy of what we hold about you, ask us to correct it, or ask us to delete it. Washington State residents, and anyone covered by GDPR or CCPA, have these rights in law; we extend them to everyone because keeping two standards is worse than keeping one. Email ravneet@pioneervisionconsulting.com and we will respond within 30 days.

Security

Traffic is encrypted in transit. Credentials and access tokens are encrypted at rest. Administrator accounts can require two-factor authentication. No system is perfectly secure, and we would rather say that plainly than imply otherwise — if a breach affects you, we will tell you.

Children

This is a tool for businesses. It is not intended for anyone under 18, and we do not knowingly collect their information.

Changes

If we change this policy we will update the date at the top. If a change materially affects how we handle your data, we will email you rather than rely on you noticing.

Contact

Pioneer Vision Consulting
10503 Angeline Rd E, Bonney Lake, WA 98391
ravneet@pioneervisionconsulting.com

Terms of Service · Pioneer Vision Consulting