Privacy Policy for Dukkan
Effective Date: September 1, 2026
Website: https://dukkanwoocommerce.com
Application: Dukkan (Mobile Application)
Dukkan (“we,” “our,” or “us”) provides a mobile application designed to assist store owners in managing their WooCommerce stores, setting up analytics, and integrating web services. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use the Dukkan mobile application and our website (https://dukkanwoocommerce.com).
Please read this policy carefully. If you do not agree with the terms of this Privacy Policy, please discontinue access and use of the application.
1. Information We Collect
Account & Store Information: When connecting your WooCommerce store to Dukkan, we process your store URL, WooCommerce REST API keys (Consumer Key and Consumer Secret), and basic administrative profile details.
Authentication Data: If you sign in using third-party services (such as Google OAuth), we receive token credentials required to authorize requested API operations.
Technical & Usage Information: Basic device data, operating system version, and error logs collected solely to maintain app stability and troubleshoot bugs.
2. Google API Data & Tag Manager Integration
Dukkan allows store owners to integrate their WooCommerce store with Google Tag Manager (GTM) to automate the deployment of web measurement tags, triggers, and variables.
A. Scopes Requested
To provide this functionality, Dukkan requests access to specific Google Tag Manager API scopes via OAuth 2.0:
https://www.googleapis.com/auth/tagmanager.manage.accounts: Read-only access to view and retrieve your available Google Tag Manager accounts so you can select which account to configure.https://www.googleapis.com/auth/tagmanager.edit.containers: Permission to create, configure, and manage web containers, workspaces, tags, triggers, and variables for your WooCommerce store.https://www.googleapis.com/auth/tagmanager.publish: Permission to publish approved workspace versions to activate tracking on your store.
B. How We Use Google User Data
Data retrieved through Google APIs (account lists, container IDs, workspace status) is accessed strictly to carry out direct user-initiated actions within the app.
We configure e-commerce tracking tags, variables, and triggers according to standard WooCommerce measurement requirements.
Dukkan does not read, monitor, or alter any GTM containers, tags, or configurations unrelated to your connected WooCommerce store setup.
C. Storage and Protection of Google Credentials
OAuth access and refresh tokens are stored securely in encrypted local storage on your mobile device (using platform-level secure storage: Android Keystore / iOS Keychain).
Dukkan does not transmit your Google OAuth tokens, customer analytics, or GTM credentials to external third-party servers.
Communication with Google APIs is carried out over encrypted HTTPS connections directly from the application.
D. Google API Services User Data Policy (Limited Use)
Dukkan’s use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
Specifically:
We never sell, rent, or trade Google user data to third parties, data brokers, or advertisers.
We never use Google user data to serve targeted advertisements.
We never use or transfer Google user data to train generalized AI or machine learning models.
Human access to Google user data is strictly prohibited unless required by applicable law or authorized by you to resolve a specific technical support request.
3. Data Sharing & Third Parties
We do not sell, license, or disclose your store data or personal information. Data is transferred only in the following scenarios:
Direct Integration Services: Directly between your device and authorized endpoints (your WooCommerce store server and Google APIs) to perform requested actions.
Legal Compliance: When required by applicable law, court order, or governmental regulation.
4. Data Retention and Revocation
Local Data Removal: Disconnecting your store or signing out of Dukkan removes stored API keys and cached tokens from your local device.
Revoking Google Access: You can revoke Dukkan’s access to your Google account at any time by visiting your Google Account Permissions Page. Once revoked, Dukkan will immediately lose all ability to access or modify your Google Tag Manager containers.
Data Deletion Requests: To request the deletion of any stored support logs or user records, contact us at the email provided below.
5. Security
We implement commercially standard physical, technical, and administrative safeguards to protect your information against unauthorized access, loss, or alteration. All communication with WooCommerce REST APIs and Google Cloud APIs utilizes TLS/SSL encryption.
6. Updates to This Policy
We may update this Privacy Policy periodically to reflect changes in our legal obligations or application features. Updated versions will be posted directly to this URL with a revised “Effective Date.”
7. Contact Us
If you have questions, feedback, or requests regarding this Privacy Policy or our data practices, please contact us at:
Email: support@dukkanwoocommerce.com
Website: https://dukkanwoocommerce.com