For the GTM MCP application. Effective August 23, 2026.
GTM MCP is operated by Vitality Marketing Firm. Questions about this policy or about data handled by the application can be sent to jason@vitalitymarketingfirm.com.
This policy describes how GTM MCP accesses, uses, stores and shares information when you sign in with your Google account. It applies only to the GTM MCP application. It does not cover the Vitality Marketing Firm public website or any other service.
When you authorize GTM MCP, you grant it access to your Google Tag Manager data through the Google Tag Manager API. The specific permissions requested are:
| Permission | What it allows |
|---|---|
tagmanager.readonly | View your Tag Manager containers and their contents |
tagmanager.manage.accounts | View and manage your Tag Manager accounts |
tagmanager.edit.containers | Create and edit tags, triggers and variables in a container |
tagmanager.edit.containerversions | Create and manage container versions |
tagmanager.publish | Publish a container version |
tagmanager.delete.containers | Delete containers |
tagmanager.manage.users | View and manage container and account user permissions |
We also receive the basic account identifier Google provides during sign in so the application knows which account issued the authorization.
Google user data is used for one purpose only: to perform the Tag Manager configuration work you or your organization has asked Vitality Marketing Firm to perform. That includes reading container configuration to audit it, writing tag and trigger changes, creating versions, and publishing versions once approved.
We do not use Google user data for advertising, for training machine learning or AI models, for profiling, or for any purpose unrelated to the requested work.
GTM MCP’s use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
GTM MCP stores the OAuth tokens issued by Google so that authorized sessions do not have to be re-established for every action. Tokens are held in encrypted storage and are used only to call the Google Tag Manager API.
Tag Manager container data is read on demand to carry out a requested task. We do not maintain a standing copy of your container data beyond what is needed to complete that task and to keep a record of changes made on your behalf.
Tokens and any retained working data are deleted when you revoke access, when the engagement ends, or on request to jason@vitalitymarketingfirm.com, whichever comes first.
We do not sell Google user data and we do not share it with third parties for their own purposes. Data is accessible only to Vitality Marketing Firm personnel working on your account. Data may be disclosed where required by law.
Access to credentials and tokens is restricted to authorized personnel. Connections to Google APIs use encrypted transport. No system is perfectly secure, and we cannot guarantee absolute security, but we take reasonable measures appropriate to the sensitivity of the data involved.
You can revoke GTM MCP’s access to your Google account at any time at myaccount.google.com/permissions. Revoking access immediately prevents any further API calls on your behalf.
GTM MCP is a business tool and is not directed to anyone under 18. We do not knowingly collect data from children.
If this policy changes we will update the effective date at the top of this page. Material changes affecting how Google user data is handled will be communicated to authorized users directly.
Vitality Marketing Firm
jason@vitalitymarketingfirm.com