Privacy Policy
Effective date: 21 March 2026 | Last updated: 21 July 2026
NodeNarrative ("we", "us", or "our") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your personal information when you visit our website at nodenarrative.io (the "Website") and use our marketing attribution platform (the "Platform", and together with the Website, the "Services").
We are based in Brisbane, Queensland, Australia. This policy is designed to comply with the Australian Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs), the EU General Data Protection Regulation (GDPR), and the California Consumer Privacy Act as amended by the California Privacy Rights Act (CCPA/CPRA).
By using our Services, you acknowledge that you have read and understood this Privacy Policy. If you do not agree with our practices, please do not use our Services.
1. Who we are
NodeNarrative is a marketing attribution software company headquartered in Brisbane, Queensland, Australia. We provide a knowledge graph-based attribution platform that helps e-commerce businesses understand their customer journeys and optimise marketing spend.
| Entity | NodeNarrative |
| Address | Brisbane, Queensland, Australia |
| Website | nodenarrative.io (official site) |
| Privacy contact | privacy@nodenarrative.io |
2. Information we collect
2.1 Information you provide directly
When you interact with our Services, you may provide us with:
- Contact information: name, email address, phone number, and company name (e.g. when you submit our contact form or request a demo)
- Account information: email address, password, and organisation details when you create a Platform account
- Communications: any messages, feedback, or support requests you send us
- Payment information: billing details processed securely by our payment processor, Stripe. We do not store your full credit card number on our servers.
2.2 Information collected automatically
When you visit our Website or use our Platform, we may automatically collect:
- Device and browser information: IP address, browser type, operating system, device type, and screen resolution
- Usage data: pages visited, time spent on pages, referring URLs, and navigation paths
- Performance data: page load times, errors encountered, and interaction metrics
- Campaign attribution data: UTM parameters (such as source, medium, and campaign) from the link you followed to reach our Website. These are stored in your browser and attached to form submissions and email signups so we know which campaign referred you.
2.3 Platform customer data
When you use our Platform, you may integrate your e-commerce and marketing data sources. This "Customer Data" may include:
- Marketing touchpoint data (ad clicks, email opens, social interactions)
- E-commerce transaction data (order IDs, product information, revenue)
- Customer journey data that may contain personal information of your end customers
Our Platform includes a built-in privacy engine powered by Microsoft Presidio for automated PII detection and handling. We process Customer Data as a data processor on your behalf (under GDPR) or as a service provider (under CCPA). You remain the data controller or business with respect to your Customer Data.
3. Information from Google APIs
When you connect your Google marketing data sources to NodeNarrative, we access read-only data from up to four Google services so we can build your marketing-attribution reports: Google Analytics 4 (GA4) and its linked BigQuery export, Google Ads, and Google Search Console. We request only read-only (“sensitive”) scopes and use the minimum scope necessary to provide the Service. We access only the accounts, properties, and datasets you explicitly authorise at OAuth consent time.
3.1 What we access
We request the following Google OAuth scopes, each read-only. We access only the accounts, properties, and datasets you explicitly authorise at OAuth consent time:
- Google Analytics (
analytics.readonly): the list of GA4 properties you manage (so you can choose which to connect) and that property’s linked BigQuery export configuration (project and dataset), discovered via the GA4 Admin API. We read property/account identifiers and the export-link configuration only. - BigQuery (
bigquery.readonly): your GA4→BigQuery export tables (the dailyevents_*tables in the dataset identified above): event-level page views, sessions, conversions and traffic sources, and the pseudonymous identifiers GA4 records (for exampleuser_pseudo_id, anduser_idwhere you have set one). We use these identifiers solely to connect one customer’s touchpoints across devices into a single attribution journey. All reads use read-only query jobs (jobs.query); the scope grants no write access. We query only the GA4 export dataset you selected, apply a server-side byte cap, and never modify your BigQuery data. - Google Ads (
adwords): your campaign performance via the Google Ads API (read-only): campaign, ad-group and ad structure, cost, clicks, impressions, conversions, and click-to-ad mappings, used to attribute paid-search cost to conversions (ROAS). We never create or modify campaigns. - Search Console (
webmasters.readonly): your organic-search performance: queries, pages, clicks, impressions and average position, used to attribute organic-search traffic within the customer journey.
3.2 What we do not access
- Google account profile information beyond your name and email (used for account linking only).
- Any write or management permission: we never request scopes that edit Google Ads campaigns, write to or modify BigQuery, or manage your Analytics or Search Console properties.
- Any restricted-scope data: all four scopes above are read-only “sensitive” scopes; we do not request Google’s restricted scopes.
- Google data from any account, property, or dataset you have not explicitly connected.
3.3 How we use Google API data
Solely to compute multi-touch marketing attribution across your customer journey, alongside data from other sources you have connected (Shopify, Meta Ads, etc.). The pseudonymous identifiers from your GA4 export are used only to stitch the same customer’s interactions across devices into a single journey; they are tenant-isolated, encrypted at rest, and are not used to identify individuals beyond producing your own attribution analytics. The data is processed in our knowledge graph and presented as attribution insights, channel-performance reports, and journey visualisations within your authenticated dashboard.
3.4 Limited Use compliance
NodeNarrative's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements. Specifically:
- We do not use Google API data to serve advertisements (including retargeting, personalised, or interest-based advertising).
- We do not transfer Google API data to third parties except: (a) service providers strictly necessary to deliver the Service (listed in section 6 (How we share your information)); (b) where required by law; or (c) where you have given explicit, opt-in consent.
- We do not allow humans to read your Google API data except: (a) with your explicit, opt-in consent for specific data; (b) for security investigations, abuse prevention, or compliance with applicable law; or (c) where the data has been aggregated and anonymised so that it can no longer be associated with an identified or identifiable individual.
- We do not sell Google API data.
3.5 How to revoke access
You may disconnect any connected Google data source (Google Analytics / BigQuery, Google Ads, or Search Console) at any time from within the NodeNarrative dashboard (Settings, then Connectors, then the connector, then Disconnect). You may also revoke access directly via Google Account, Security, Third-party apps with account access.
After revocation, we immediately invalidate and delete the OAuth refresh token. Imported Google data is retained per the schedule in section 9 (Data retention) so that historical attribution analyses you have already run remain available; you may request earlier deletion of historical data per section 11 (Your privacy rights).
3.6 Retention of Google API data
See section 9 (Data retention). Google data imported into the Platform follows the "Customer Data: raw events" retention schedule (365 days standard, 730 days on Enterprise) and the "Customer Data: aggregated analytics" rules (indefinite, de-identified). De-identified aggregates contain no Google user identifiers.
4. How we use your information
We use your personal information for the following purposes:
| Purpose | Categories of data |
|---|---|
| Providing and maintaining our Services | Account info, Customer Data |
| Responding to enquiries and providing support | Contact info, communications |
| Processing payments and managing subscriptions | Account info, payment info |
| Sending transactional communications (e.g. confirmations, updates) | Contact info |
| Sending marketing communications (with your consent) | Contact info |
| Building remarketing audiences and measuring advertising conversions for our own marketing (with your consent, via the cookie banner) | Usage data, device info, Google advertising identifiers |
| Improving our Services and developing new features | Usage data, performance data |
| Ensuring security and preventing fraud | Device info, usage data |
| Complying with legal obligations | As required by law |
We will not use your personal information for purposes materially different from those described above without notifying you and, where required, obtaining your consent.
5. Legal basis for processing (GDPR)
If you are in the European Economic Area (EEA), United Kingdom, or Switzerland, we process your personal data under the following lawful bases:
| Lawful basis | Processing activities |
|---|---|
| Contract performance (Art. 6(1)(b)) | Providing the Platform, processing payments, account management |
| Legitimate interests (Art. 6(1)(f)) | Website analytics, service improvement, security, fraud prevention |
| Consent (Art. 6(1)(a)) | Marketing communications, non-essential cookies |
| Legal obligation (Art. 6(1)(c)) | Tax compliance, responding to lawful requests |
Where we rely on legitimate interests, we have conducted a balancing test to ensure our interests do not override your fundamental rights and freedoms. You may request details of these assessments by contacting us.
6. How we share your information
We do not sell your personal information. We may share your information with the following categories of third parties:
| Third party | Purpose | Location |
|---|---|---|
| Cloudflare | Website hosting, CDN, DDoS protection, analytics | Global (US-headquartered) |
| Google Cloud Platform | Platform infrastructure and data processing | Australia (primary), US (backup) |
| Resend | Transactional email delivery | United States |
| Chatwoot (self-hosted) | Customer support ticketing, live chat, knowledge base | Australia (Google Cloud Platform) |
| Stripe | Payment processing | United States |
| PostHog | Website product analytics (cookieless, memory-only persistence) | United States |
| Google (Tag Manager) | Delivery and management of our Website analytics tags | Global (US-headquartered) |
| Google (Analytics 4, Google Ads) | Website measurement and, with your consent via the cookie banner, advertising features (Google Signals cross-device measurement, remarketing audiences and conversion measurement) used for our own marketing. | Global (US-headquartered) |
Each of these providers is bound by data processing agreements and is required to handle your data in accordance with applicable privacy laws. We may also disclose your information where required by law, regulation, or legal process.
6.1 Advertising platforms (server-side conversion sharing)
Where a business customer (the "advertiser") connects an advertising platform to NodeNarrative and enables conversion sharing, we transmit conversion and event data to that platform server-side, on the advertiser's behalf and at their direction. NodeNarrative acts as a data processor (GDPR) / service provider (CCPA) for these transmissions; the advertiser is the controller/business responsible for establishing a lawful basis for their end customers' data.
Meta (Facebook): Conversions API. When an advertiser enables Meta conversion sharing, we send conversion events to Meta's Conversions API. The data categories transmitted are:
- Hashed identifiers: email address, phone number, first and last name,
and an internal customer reference (
external_id), each irreversibly hashed with SHA-256 before transmission (see "Pseudonymisation" below); - Technical data: IP address and browser user-agent of the end customer's session;
- Meta cookie and click identifiers: the
_fbpbrowser identifier and_fbcclick identifier, where present.
Meta processes this data under its own terms. See Meta's Privacy Policy and Meta's Business Tools Terms.
Google: GA4 Measurement Protocol. Where an advertiser enables Google Analytics event forwarding, we send event data server-side to Google Analytics 4 via the Measurement Protocol on the advertiser's behalf.
Klaviyo. Our Klaviyo integration retrieves marketing engagement data from Klaviyo on the advertiser's behalf; we do not transmit end-customer data to Klaviyo.
Pseudonymisation, not anonymisation. Identifiers sent to advertising platforms are hashed with SHA-256 prior to transmission. Hashing is a pseudonymisation measure under GDPR Article 4(5). It reduces risk, but the data may remain personal data in the hands of a party able to match the hash. We disclose this so the protection is not overstated.
Affirmative limits on data sharing: Other than the advertiser-directed conversion transmissions described in section 6.1 above (which we perform solely as a processor/service provider on a business customer's instruction, for that customer's own measurement), we do not sell, rent, or trade Customer Data, including data obtained from Google APIs, to any third party, and we do not share Customer Data with third parties for advertising, marketing intelligence, competitive benchmarking, or any purpose other than providing the Service. The third-party processors listed above access Customer Data only as strictly necessary to perform their contracted role under a data processing agreement that limits their use to providing infrastructure or service functions to NodeNarrative.
7. Cookies and tracking technologies
Our Website uses the following technologies:
| Technology | Type | Purpose |
|---|---|---|
| Cloudflare Analytics | Essential / Analytics | Privacy-preserving site analytics (no personal data collection) |
nn_site_consent | Essential | Stores your cookie preferences from the banner below (12-month expiry). Shared, via
a cookie on the nodenarrative.io domain, with our dashboard at
app.nodenarrative.io so you are not asked twice across our own properties.
Holds only your category choices (essential/functional/analytics/marketing) and a decision
timestamp: no tracking identifier. |
| PostHog | Analytics | Product analytics for our Website, hosted in the United States. Only loads once you grant Analytics consent in the cookie banner. Collects usage events (such as page views and clicks) together with your IP address and browser information. Runs in cookieless mode with memory-only persistence: no cookies are stored on your device and no identifier persists beyond the current page visit. No cross-site tracking. |
| Google Tag Manager | Analytics (tag delivery) | Delivers and manages our analytics tags. Only loads once you grant Analytics consent in the cookie banner. When the container loads, Google receives standard request data such as your IP address and browser information. Google Tag Manager itself does not set cookies on our Website. |
| Google Analytics 4 with Google Signals | Advertising | Only loads once you grant Analytics consent (it is delivered via the Google Tag Manager container above). Enables Google advertising features: Google Signals (cross-device measurement), remarketing audiences and conversion measurement. These set Google advertising cookies and may share data with Google Ads to build audiences for our own marketing. |
Cloudflare operational cookies (e.g. __cf_bm) | Essential | Bot management and security protection, set by Cloudflare |
| Chatwoot live chat widget | Functional | Customer support chat. Loads after the initial page render and may store a session identifier to maintain conversation continuity. |
Cookie consent. When you first visit our Website, a cookie banner lets you
Accept All, Reject Non-Essential, or manage each category (Functional, Analytics, Marketing)
individually. Google Analytics 4 (including Google Signals and advertising features) and PostHog
only load after you grant Analytics consent: nothing beyond essential/security cookies runs
before you decide. You can change your choice at any time via Cookie preferences in the footer of every page. Your decision is stored in the nn_site_consent cookie
described above and, for compliance record-keeping, logged to our server with the category choices
you made (no browsing history or content of your visit).
The Platform's measurement pixel, deployed by our business customers on
their websites, may read advertising platform cookies and click identifiers (such as
Meta's _fbp/_fbc and Google's gclid) where the
advertiser has enabled the relevant integration. See section 6.1 (Advertising platforms).
You can also control cookies through your browser settings, independently of the banner above. Most browsers allow you to block or delete cookies. However, blocking essential cookies may affect the functionality of our Services.
For visitors in the EEA, UK, and Switzerland: the cookie banner described above is our consent mechanism for the ePrivacy Directive and UK PECR: no non-essential cookie (including Google advertising cookies) is placed on your device until you consent. Swiss visitors' personal data is protected under the FADP.
8. International data transfers
As an Australian company with global infrastructure, your personal information may be transferred to and processed in countries outside your country of residence, including:
- Australia: primary data processing, Platform infrastructure, and customer support (Google Cloud Platform, Sydney region)
- United States: email delivery (Resend), payment processing (Stripe), CDN and security (Cloudflare), website analytics (PostHog), analytics tag delivery (Google Tag Manager), and website advertising measurement and remarketing (Google Analytics 4 / Google Ads)
- Global edge locations: Cloudflare CDN nodes for Website performance
Safeguards for international transfers
Under Australian law (APP 8):
Before disclosing personal information to an overseas recipient, we take reasonable steps to ensure the recipient does not breach the Australian Privacy Principles in relation to your information. We remain accountable for the handling of your information by overseas recipients.
Under GDPR:
Where we transfer personal data outside the EEA, we rely on appropriate safeguards including EU Standard Contractual Clauses (SCCs) approved by the European Commission, or the recipient's participation in recognised frameworks. Australia has been granted partial adequacy status by the European Commission.
Under CCPA:
We ensure all service providers handling California residents' personal information are bound by contractual obligations that meet CCPA requirements.
9. Data retention
We retain your personal information only for as long as necessary to fulfil the purposes described in this policy:
| Data category | Retention period |
|---|---|
| Contact form submissions | 2 years from submission, or until you request deletion |
| Account information | Duration of your account plus 30 days after account closure |
| Customer Data: raw events (Platform) | Per your plan's retention window (365 days standard, 730 days on Enterprise). Deleted within 30 days of account termination unless you request an export. |
| Customer Data: aggregated analytics (Platform) | Indefinite. De-identified, aggregated summaries (channel performance, conversion rates, attribution scores) are retained for trend analysis and year-over-year comparisons. These contain no personal information and cannot be used to identify individuals. Deleted within 30 days of account termination. |
| Payment records | 7 years (Australian tax law requirements) |
| Website analytics (PostHog, Cloudflare Analytics) | Aggregated / cookieless; no individual-level data retained |
| Google Analytics 4 advertising features (enabled regions only) | User-level event data retained per Google's GA4 data-retention setting (up to 14 months); remarketing audiences managed in Google Ads |
| Support communications | 3 years from last interaction |
When personal information is no longer required, we securely delete or de-identify it using industry-standard methods.
10. Data security
We implement appropriate technical and organisational measures to protect your personal information, including:
- Encryption in transit (TLS 1.2 minimum, TLS 1.3 preferred) and at rest (AES-256)
- Access controls and role-based permissions
- Regular security assessments and vulnerability scanning
- Automated PII detection and handling via our privacy engine
- Infrastructure hosted on SOC 2 Type II certified providers
- DDoS protection via Cloudflare
While we take reasonable steps to protect your information, no method of transmission over the internet or electronic storage is completely secure. We cannot guarantee absolute security.
11. Your privacy rights
11.1 Australian Privacy Principles (all users)
Under the Australian Privacy Act 1988, you have the right to:
- Access the personal information we hold about you (APP 12)
- Request correction of inaccurate, out-of-date, or incomplete information (APP 13)
- Make a complaint about our handling of your personal information
- Interact anonymously or pseudonymously where practicable (APP 2)
- Opt out of receiving direct marketing communications (APP 7)
If you are not satisfied with our response to a privacy complaint, you may contact the Office of the Australian Information Commissioner (OAIC).
11.2 GDPR rights (EU/EEA/UK residents)
If you are in the European Economic Area, United Kingdom, or Switzerland, you have additional rights under the GDPR:
- Right of access (Art. 15): obtain a copy of your personal data
- Right to rectification (Art. 16): correct inaccurate data
- Right to erasure (Art. 17): request deletion of your data ("right to be forgotten"). You can also delete your account directly from your account settings without contacting support
- Right to restriction (Art. 18): limit how we process your data
- Right to data portability (Art. 20): receive your data in a structured, machine-readable format
- Right to object (Art. 21): object to processing based on legitimate interests or direct marketing
- Right to withdraw consent (Art. 7): withdraw consent at any time without affecting prior processing
- Right regarding automated decisions (Art. 22): not be subject to decisions based solely on automated processing with legal or significant effects
To exercise these rights, contact us at privacy@nodenarrative.io. We will respond within 30 days (or one month under GDPR). You also have the right to lodge a complaint with your local data protection authority.
11.3 CCPA/CPRA rights (California residents)
If you are a California resident, you have the following rights under the CCPA as amended by the CPRA:
- Right to know: what personal information we collect, use, disclose, and sell
- Right to delete: request deletion of your personal information
- Right to correct: correct inaccurate personal information
- Right to opt-out: opt out of the sale or sharing of personal information
- Right to limit: limit the use and disclosure of sensitive personal information
- Right to non-discrimination: not be discriminated against for exercising your rights
We do not sell your personal information. The advertiser-directed conversion transmissions described in section 6.1 are performed at a business customer's direction under a service-provider contract, for that customer's own measurement, and are not "sharing" for cross-context behavioural advertising on our own behalf. The Google advertising features (Google Signals, remarketing) on our own Website only run with your consent, granted via the cookie banner: rejecting Marketing cookies, or never accepting them, means we do not "share" your personal information for cross-context behavioural advertising. The cookie banner's Reject Non-Essential option and Manage Preferences panel serve as your "Do Not Sell or Share My Personal Information" opt-out. We do not yet automatically detect Global Privacy Control signals; contact privacy@nodenarrative.io if you are relying on GPC and want this treated as an opt-out. We do not use sensitive personal information for purposes beyond what is necessary to provide our Services.
To exercise your CCPA rights, contact us at privacy@nodenarrative.io. We will verify your identity before processing your request and respond within 45 days.
11.4 Data deletion instructions
Platform account holders can delete their account directly from account settings, or email privacy@nodenarrative.io. Deletion requests trigger an orchestrated erasure workflow across our data stores (relational database, graph database, cache, and analytics warehouse). Erasure is processed asynchronously; individual store deletions are retried on failure and tracked in an audit log. Limited records are retained where the law requires it (for example payment records under Australian tax law, and proof-of-consent records under GDPR Article 7).
End customers of our business customers: NodeNarrative processes your data as a processor/service provider on behalf of the business you interacted with (the controller). Please direct deletion requests to that business; we honour and execute controller-initiated deletion instructions, including cascading erasure of journey and attribution data tied to your customer identifier. If you are unsure who the controller is, contact privacy@nodenarrative.io and we will assist in routing your request.
Advertising platform data: where conversion data was previously transmitted to an advertising platform (section 6.1), deletion from that platform is governed by the platform's own processes; we will direct you or the controller to the relevant mechanism.
12. Automated decision-making
Our Platform uses algorithmic processing to provide marketing attribution insights. This includes:
- Attribution modelling: automated analysis of marketing touchpoints to determine their contribution to conversions. This processing is performed on Customer Data provided by our business customers.
- PII detection: automated scanning of Customer Data to detect and flag potential personal information, using Microsoft Presidio.
These automated processes provide analytical insights to our business customers and do not make decisions that produce legal or similarly significant effects on individuals. The attribution models generate statistical weightings; they do not make automated decisions about individual end customers.
In accordance with the Privacy and Other Legislation Amendment Act 2024 (Cth), we will provide additional disclosures about automated decision-making involving personal information as required when the relevant provisions commence on 10 December 2026.
13. Children's privacy
Our Services are not directed at children under the age of 16 (or 13 in jurisdictions where that is the applicable age). We do not knowingly collect personal information from children. If we become aware that we have collected personal information from a child without appropriate parental consent, we will take steps to delete that information promptly.
If you believe we have collected information from a child, please contact us at privacy@nodenarrative.io.
14. Data breach notification
We comply with the Notifiable Data Breaches (NDB) scheme under Part IIIC of the Australian Privacy Act 1988. In the event of an eligible data breach that is likely to result in serious harm:
- We will notify the Office of the Australian Information Commissioner (OAIC) as soon as practicable
- We will notify affected individuals as soon as practicable, including a description of the breach, the kinds of information involved, and recommended steps
- We will complete our assessment within 30 days of becoming aware of a potential breach
Where GDPR applies, we will notify the relevant supervisory authority within 72 hours of becoming aware of a qualifying breach, and affected individuals without undue delay where there is a high risk to their rights and freedoms.
If you believe there has been a security incident involving your data, please contact us immediately at privacy@nodenarrative.io.
15. Changes to this policy
We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or other factors. When we make material changes:
- We will update the "Last updated" date at the top of this page
- For material changes affecting your rights, we will provide reasonable notice via email or a prominent notice on our Website at least 30 days before the changes take effect
- Where required by law, we will obtain your consent to material changes
We encourage you to review this policy periodically. Your continued use of our Services after changes become effective constitutes your acceptance of the revised policy.
16. Contact us
If you have questions about this Privacy Policy, wish to exercise your privacy rights, or have a privacy complaint, please contact us:
| privacy@nodenarrative.io | |
| General enquiries | hello@nodenarrative.io |
| Post | NodeNarrative, Brisbane, QLD, Australia |
We aim to respond to all privacy-related enquiries within 30 days. If you are not satisfied with our response:
- Australia: You may lodge a complaint with the Office of the Australian Information Commissioner (OAIC)
- EU/EEA/UK: You may lodge a complaint with your local data protection authority
- California: You may contact the California Privacy Protection Agency (CPPA)
Privacy is our architecture, not just our policy. See how it works →