Privacy Policy

How Central collects, stores, processes, and shares product and account data.

Google data: Limited Use and AI processing

Updated 21 September 2026. These Google-specific disclosures form part of Central's Privacy Policy and take precedence over any more general description below where Google user data is concerned.

Central's use of information received from Google APIs, and its transfer of that information to other applications, adheres to the Google API Services User Data Policy, including the Limited Use requirements. These restrictions apply to original Google user data and to aggregated, anonymized and derived data.

Central does not use Google Workspace APIs or data obtained through them to develop, improve or train generalized or non-personalized AI or machine-learning models. We do not sell or transfer Google user data for that purpose. Our AI features use existing models to perform the analysis, extraction, translation or content creation you request; this is separate from training a model.

For AI requests sent through OpenRouter, Central requires routing that excludes providers which collect request content for model training. This restriction also applies when a request switches to a fallback model. It is not a promise of zero data retention: processing, security, legal and operational records may be retained as described below and in the applicable provider terms.

Google Merchant Center data

When you connect Google Merchant Center, you authorize Central through Google OAuth. Central receives access and refresh tokens, the permissions granted, and token expiry information. These credentials are stored encrypted and associated with your Central project.

Central reads the Merchant accounts you can access, the store you select, its product sources, and product status and issue information. We use this information to check your connection, prepare channel setup, publish and update the product listings you authorize, and show delivery results and diagnostics. Connecting a store alone does not publish products.

When you authorize publication, Central sends the selected catalog content to Google, including product identifiers, titles, descriptions, attributes, prices, availability, product-page links and image links. Google processes these listings under its own terms and privacy policy. Central retains connection settings and publication records so you can review and troubleshoot the integration.

You can revoke Central's Google access in your Google Account's connections settings. Revoking access prevents further authorized API access; it does not delete listings already sent to Google or records already stored in Central. Manage published listings in Merchant Center. For deletion of retained Central integration data, contact legal@central.to; we will explain any records that must be retained and why.

The Google Merchant connection requests permission to manage Google Shopping product listings and accounts. It does not request access to Gmail or Google Drive. Google Drive, if connected separately, uses a separate authorization flow.

Who receives Google user data

These disclosures apply to both Google integrations described on this page. Imported content and integration records are available to authorized members of your Central organization and project according to their access permissions. Central personnel and contractors may read Google user data only with your affirmative agreement to access specific data for support, when necessary to investigate a security issue or abuse, or to comply with applicable law. We may use aggregated data for internal operations in accordance with applicable privacy requirements.

Our infrastructure provider, Hetzner, hosts Central's application, database and file storage and processes stored Google integration data to provide those services. When you request AI analysis or enrichment of imported files, OpenRouter and the model providers used for that request receive the relevant file content and product context to generate the result. Google OAuth access and refresh tokens are not included in AI requests.

Google receives catalog content when you authorize a Merchant Center publication or update. If you choose to publish or export content derived from imported files through another Central integration, the destination you choose receives that content. Connecting Google Drive by itself does not publish its files to another channel.

Central does not sell Google user data or disclose it to advertising networks, data brokers or information resellers. We do not use this data for ad targeting, credit-worthiness or lending decisions. We use and transfer it to provide the features you request with your consent, to protect the service, or where required by law.

AI services and the data they receive

OpenRouter routes requests to the model providers used by Central. Our configured model families include Google Gemini, OpenAI GPT, Anthropic Claude and xAI Grok. Depending on the feature and routing availability, the provider serving the selected model receives the relevant prompt, product context, document or image content, and produces a response. A model developer and the provider hosting its model may be different organizations. Google Gemini document and image analysis can be served through Google's AI Studio API via OpenRouter.

When you request image generation or editing, fal.ai receives the prompt and any selected reference images or image URLs, and may pass them to the API provider serving the selected model. This is a separate service from OpenRouter. Its API Services Terms describe restrictions on training and identify exceptions for models designated as excluded; OpenRouter's routing restriction does not control fal.ai.

AI processing is used for the feature you request. It does not grant a provider permission to use Google user data for generalized model training. Google OAuth access and refresh tokens are not sent as AI prompt content. Connecting Merchant Center alone does not request file analysis or image generation.

For provider processing and retention details, see OpenRouter's data collection policy, OpenRouter's provider policies, and fal.ai's privacy policy. Central's Google-data restrictions continue to apply where a provider's general terms describe broader uses.

How we protect Google user data

Central requires HTTPS for its production application, protecting data in transit between your browser and Central using TLS. Connections to Google's APIs also use HTTPS. Google OAuth access and refresh tokens are encrypted in the database using application-level encryption; Central account passwords are stored as one-way password hashes.

Central encrypts its production database, stored files and backups at rest. Encryption does not remove the need for the access restrictions described here or mean that authorized processing cannot read the data.

Access to integration settings and imported project content requires authentication and project authorization. Each Google connection is associated with a specific Central project. Central uses that connection's granted permissions to access the Google account you authorized; connecting your account does not authorize other Central customers to use it.

You control whether to connect each Google service, start or schedule a Drive sync, request file analysis, and publish catalog content. You can revoke Google's authorization at any time using the account settings linked above. Contact legal@central.to about access, deletion or a suspected data-security issue.

Retention and deletion of Google data

Central retains imported files, derived product content, connection settings and publication records to provide your project workflows. Diagnostic records may include request or response content where needed to troubleshoot processing; these records are subject to the same Google-data use and access restrictions. Disabling an integration or revoking Google access does not automatically erase previously imported data.

To request deletion of Google integration data, including imported files and derived content, contact legal@central.to. We will identify the records in scope and explain any legal or security retention requirement. Copies in backups may remain until those backups expire under our backup lifecycle. Listings already published to Google must also be managed in Merchant Center.

Google Drive data

Google Drive is an optional, separate connection. After you authorize read-only access through Google OAuth, Central stores encrypted access and refresh tokens with your project. Central reads your Drive account information to check the connection. Connecting alone does not scan or download your files.

When you start a sync, Central reads file and folder metadata and downloads supported documents and images from the folder you configure. If you leave the folder empty, the integration scans My Drive. The read-only permission is account-wide; a configured folder limits the integration's scan, not the permission Google grants. Central reads changes to keep imported files up to date when you request another sync or enable scheduled sync. Central does not create, edit or delete files in your Google Drive.

Downloaded files, source metadata and sync records are stored in your Central project for your product-content workflow. If you enable automatic analysis or explicitly request analysis or enrichment using these files, relevant file content and product context are sent to our AI processing providers through OpenRouter to extract product information. You can leave automatic analysis off to import files without this analysis.

You can stop scheduled sync in the connection settings and revoke Google access in your Google Account's connections settings. Revocation stops further authorized Drive access; it does not erase files already imported into Central. For deletion of retained files, derived content and integration records, contact legal@central.to. The retention and deletion provisions below also apply to these records.

Cannot read the document above? Open the full document on iubenda.com.

Questions? legal@central.to