Back to User Town

Privacy Policy

Privacy Policy

Effective 30/07/2026

Overview

User Town turns your website and app analytics into a shareable city visualization. This policy explains what information we collect, how we use it, and the choices available to account owners and visitors.

Information We Collect

We collect account information such as name, email address, authentication identifiers, workspace settings, brand details, and configuration entered in the dashboard.

When you connect analytics or status providers, we store the integration settings needed to fetch metrics. API keys and service credentials are treated as secrets and are not exposed through public city links.

We may collect basic usage, device, log, and diagnostic information to operate, secure, and improve the service.

Analytics And Status Data

User Town processes aggregated usage metrics such as total users, active-user percentage, and platform status. Public city pages are designed to expose visualization output and non-secret brand/profile information only.

You are responsible for ensuring that the analytics sources you connect are permitted for this use and do not send unnecessary personal data to User Town.

Google User Data (Google API Services)

What we access. If you choose to connect Google Analytics, User Town accesses your Google Analytics 4 data through the Google Analytics Data API and Admin API using the read-only https://www.googleapis.com/auth/analytics.readonly scope. We read only (1) the list of GA4 properties your Google account can access, so you can pick one, and (2) two aggregate metrics for the property you select — total users (past 365 days) and active users (realtime). Using the openid and email scopes we also receive your Google account email address to show which account is connected. We do not access user-level, event-level, or personally identifiable Analytics data.

How we use it. This Google data is used solely to power your city visualization — the aggregate user counts drive the city’s size and activity — and to display which Google account is linked in your dashboard. It is never used for advertising, credit/lending decisions, or any purpose other than providing this user-facing feature.

What we share. We do not sell or transfer Google user data to third parties. It is processed only by the infrastructure providers that host and operate User Town on your behalf. Your Google credentials and account email are never exposed on public city pages; a published city shows only the resulting aggregate numbers and weather.

How we protect it. The Google OAuth refresh token is encrypted at rest (AES-256-GCM) and used only server-side — it is never sent to browsers or public pages, and all transfers occur over HTTPS.

Retention and deletion. We keep the OAuth token and your selected property only while the connection is active. You can disconnect at any time from the dashboard, which immediately deletes the stored token, and you can also revoke access from your Google Account permissions. Deleting your User Town account removes associated Google connection data.

Limited Use. User Town’s use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.

How We Use Information

We use information to provide the dashboard, generate public city views, authenticate users, save configuration, fetch connected metrics, troubleshoot issues, prevent abuse, and communicate service-related updates.

Payments And Billing Data

Paid subscriptions are processed by Razorpay Software Private Limited, an RBI-authorised payment aggregator, acting as our payment processor. When you subscribe you are taken to Razorpay's checkout and provide your payment details directly to them.

We never receive or store your card number, CVV, UPI PIN, or bank credentials. Those are handled entirely by Razorpay under their own privacy policy and PCI DSS obligations.

What we do store against your account is limited to: the Razorpay subscription and customer identifiers, your plan and its status, the current billing period end date, and whether a cancellation is scheduled. We use this only to decide whether your city may be published and to show your billing history.

Your invoices are raised and hosted by Razorpay. The “Download” links in your dashboard open Razorpay’s hosted invoice — we neither generate nor store invoice documents ourselves.

Razorpay processes your data as an independent controller for payment purposes. See Razorpay’s privacy policy.

Approximate Location For Pricing

We price in Indian Rupees for customers in India and in US Dollars elsewhere. To apply the right currency, our servers read the country code that our hosting provider derives from your IP address when you view pricing or start checkout.

We use only the two-letter country code, and we do not store it against your account or use it for any purpose other than choosing the billing currency. We do not use IP-based location for tracking, profiling or advertising.

Sharing

We do not sell personal information. We may share information with service providers that help us host, authenticate, store, monitor, or operate User Town, and when required by law or to protect the service and users.

The processors we rely on are: Vercel (hosting), Google Firebase (authentication and database), Razorpay (payments), and, if you connect them, the analytics or status providers you choose. Where assets are served from a content delivery network, that provider processes only the request needed to deliver static 3D files.

Security

We use reasonable technical and organizational safeguards for account data and integration secrets. No system is perfectly secure, so account owners should rotate provider credentials if they suspect unauthorized access.

Retention

We retain account and configuration data while an account is active or as needed to provide the service, comply with legal obligations, resolve disputes, and enforce agreements. Account owners may request deletion where applicable.

Your Choices

You can update brand settings, remove integration credentials, change public links by changing brand configuration, or stop using connected providers from the dashboard. You may also contact us to request access, correction, or deletion where applicable law provides those rights.

Children

User Town is not intended for children under 13, and we do not knowingly collect personal information from children.

Changes

We may update this policy from time to time. If changes are material, we will take reasonable steps to notify account owners.

Contact

For privacy requests or questions, contact User Town at support@theusertown.com.