Privacy
Privacy policy
Last updated: September 14, 2026
This page describes how getMax (published by the company GETMAX) collects, uses and protects your personal data, including when you use authentication via Google (OAuth).
1. Data Controller
Data is processed by GETMAX (hereinafter "GETMAX"), as publisher of getMax. Address: 212 avenue de Tivoli, 33110 Le Bouscat, France. Email: [email protected]
2. Data Collected
Depending on your usage, we may collect:
- Contact data: name, first name, email address, company, message content (for example via the contact form).
- Technical data: technical logs (e.g. IP address, user-agent, timestamp, pages visited) necessary for operation, security and diagnosis.
- Authentication data: if you use Google OAuth connection, we receive certain information from your Google account according to the permissions (scopes) you accept.
3. Purposes and Legal Bases
- Service provision (contract performance / pre-contractual measures).
- Support and communication (legitimate interest / pre-contractual measures).
- Security (legitimate interest: fraud prevention, abuse, incidents).
- Statistics and improvement (legitimate interest and/or consent depending on trackers used).
4. Google Data (OAuth): scopes, use and protection
If you connect getMax to a Google account, the data obtained through Google APIs is used only to provide the feature you asked for. This section describes, scope by scope, what we read, why, and how we protect it.
4.1 Scopes requested and the reason for each
analytics.readonly: list the Google Analytics properties you have access to so you can pick the one to connect, then read its audience statistics to display them in your getMax reports.webmasters: read the search performance of the Search Console property you designate, submit its sitemaps and inspect its URLs.adwords: read and manage, from the getMax interface, the campaigns of the Google Ads account you designate.business.manage: read and update the Google Business Profile you designate (information, hours, posts, reviews).
4.2 How Google data is protected
- Encryption in transit: all exchanges, between your browser and getMax as well as between getMax and Google APIs, use HTTPS (TLS 1.2 or above). The application is served with HSTS.
- Encryption at rest: Google OAuth tokens (access token and refresh token) are never stored in clear text. They are encrypted by the application with AES-256-GCM before being written to the database, using a key held outside the database and supplied to the service at runtime. The database and its backups are also encrypted at rest by the hosting provider.
- Tenant isolation: every Google connection belongs to one user and one organization. The server revalidates on each request that the authenticated identity does have access to the target organization and project; no identifier sent by the client is used without that check.
- Restricted human access: in normal operation our staff does not access customers' Google data. Access remains possible for a small number of authorized people, on named accounts and under least privilege, solely for maintenance, support at your request, or incident response.
- Redacted logs: tokens, secrets and authorization headers are masked in our technical logs, which do not contain the content of your Google documents.
- Hardened authorization flow: the OAuth consent uses PKCE (S256) and a single-use state parameter, which protects the exchange against interception and request forgery.
- Secret management: client credentials and encryption keys are held in our infrastructure runtime secrets, never in source code or in a repository.
- Hosting: the application and its database are hosted in France (Scaleway).
4.3 Retention, deletion and withdrawal of access
- Google tokens are kept for as long as the connection stays active. They are erased from our systems as soon as you disconnect the integration from your getMax settings or delete your account.
- You can revoke getMax's access at any time from myaccount.google.com/permissions.
- Data derived from Google APIs and stored in getMax (for example the statistics shown in your reports, or the context extracted from your documents) is deleted when you delete your account, or upon request at [email protected], within 30 days at the latest.
4.4 Limited Use
getMax's use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
- We do not sell or rent data obtained through Google APIs.
- We do not use it for advertising, nor for profiling unrelated to the feature you requested.
- We do not use any data obtained through Google APIs, including Google Workspace APIs, to develop, improve or train generalized artificial intelligence or machine learning models. Where Google data enters a content production you requested, the model provider processing it acts as a processor, does not retain it beyond the processing, and is not allowed to use it to train its models.
- We transfer this data to third parties only to provide the feature you requested, to comply with a legal obligation, or as part of a merger or acquisition after notifying users.
5. Data Sharing
We may share data with technical providers (hosting, email, analytics, security) acting as sub-processors, only to the extent necessary for service delivery. Data may also be disclosed if required by law or to protect our rights (fraud prevention, security, legal requests).
6. Retention
We retain personal data for the duration necessary for the purposes described above, then delete or anonymize it, except where contrary to legal obligation.
7. Security
We protect all the data you entrust to us, and in particular sensitive data such as credentials and access tokens for your third-party services, with the following measures:
- In transit: HTTPS with TLS 1.2 or above on every interface, and HSTS on the application.
- At rest: encryption at rest of the database and its backups, plus application-level AES-256-GCM encryption of the most sensitive secrets (OAuth tokens, API keys for your integrations), with the key held outside the database.
- Access control: session authenticated by an httpOnly cookie, authorization revalidated server-side on every request against the target organization and project, and least privilege for internal access.
- Isolation: each organization's data is isolated; a request cannot reach another organization's data.
- Hardening: rate limiting on sensitive entry points, systematic input validation at controllers and webhooks, secret redaction in logs, secrets kept out of source code.
- Sub-processors: our providers are bound by a data processing agreement and selected for their security posture; primary hosting is located in France.
- Incidents: the service is monitored and logged; in the event of a data breach we notify the competent authority and the individuals concerned within the timeframes set by the GDPR.
For any security question, or to report a vulnerability: [email protected].
8. Your Rights
Under applicable regulations (including GDPR), you have rights of access, rectification, erasure, objection, restriction and portability. To exercise your rights, or for any question regarding your personal data, you can contact our Data Protection Officer (DPO), Thibault Petit Jean, at [email protected]. You may also lodge a complaint with the CNIL: https://www.cnil.fr/.
9. Cookies and Tracers
getMax may use tracers (cookies) necessary for site operation and, where applicable, audience measurement tracers. Depending on the tools used, these tracers may be subject to your consent. For audience measurement, we use PostHog, hosted in the European Union (eu.i.posthog.com). This includes navigation and interaction measurement (clicks) and, if you accept separately, anonymized session recording (input fields are masked). None of this data is collected until you give consent, which you can withdraw at any time via the cookie management banner.
10. Changes
We may update this policy. The "last updated" date shown at the top reflects the current version.