GM MetaIO

Privacy policy

Last updated: October 1, 2026

Who we are and what this policy covers

GM MetaIO is an internal tool operated by Gourmet Marketing. The team uses it to monitor and manage metasearch advertising for the hotels it works with. It is not a public service: only authorized members of the Gourmet Marketing team can sign in. Hotel clients and members of the public cannot.

This policy describes the personal information the tool handles about the people who sign in to it.

Questions about this policy or about your account: ops@gourmetmarketing.com

Information we collect

Team members sign in with their Google Workspace account. The tool asks Google for the openid, email and profile scopes and nothing else. It does not request or access Gmail, Google Drive, Google Calendar, contacts or any other Google data, and it does not keep the tokens Google issues during sign-in.

Received from Google when you sign in

  • Google account ID (the identifier Google assigns to your account): stored, so that only that Google account can use your access.
  • Name: stored, to show who is signed in and to label the list of users.
  • E-mail address: stored. It identifies your account in the tool.
  • Whether Google has verified the e-mail address, and the Google Workspace domain the account belongs to: checked at sign-in to confirm you are part of the team. Not stored.
  • Profile photo address: sent by Google as part of the basic profile. Not used and not stored.

Created by the tool

  • Account details: your role (viewer, editor or admin), whether your account is enabled, when it was created and when you last signed in.
  • Session cookie: keeps you signed in for up to 12 hours. It is encrypted and holds an internal account ID, a session number and the sign-in time. It does not hold your name, e-mail address or role.
  • Sign-in cookies: while you sign in, short-lived cookies protect the exchange with Google (a request-forgery token, a one-time verifier and the page to return to).
  • Theme cookie: remembers a light or dark theme if you choose one.
  • Audit log: sign-ins and sign-outs; sign-in attempts that were refused, with the e-mail address that was used, including addresses outside the team; accounts being created; role changes; accounts being disabled or enabled; resets of the link between an account and its Google account; and attempts to open something a role does not allow. Each entry holds the time, the account that acted and what was changed.

There are no advertising or analytics cookies.

How we use this information

  • Authentication: confirming that the Google account signing in is yours and belongs to the team.
  • Authorization: deciding what your role lets you see and do.
  • Security and accountability: keeping the audit log, so that changes can be traced to the account that made them.

The information is not used for advertising, for profiling or for analytics.

Sharing and disclosure

Google user data is not sold and is not transferred to third parties. It is processed only on the infrastructure that hosts the tool, which is Google Cloud.

The advertising data shown in the tool comes from the WIHP Meta I/O service. No information about the people who sign in is sent to it.

Google API Services User Data Policy

GM MetaIO’s use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

Google API Services User Data Policy

Storage, security and retention

  • Where: account records and the audit log are kept in a database in Gourmet Marketing’s Google Cloud project, in a United States region.
  • In transit: connections to the tool are encrypted (HTTPS).
  • Access: every page and action checks your current role on the server. Only admins can see the list of users, and the audit log is not shown in the tool. Lowering a role or disabling an account takes effect on that person’s next request.
  • Retention: the tool does not delete account records or audit entries on a schedule. They are kept until removal of the account or of the records is requested. An account that is no longer needed is disabled, which blocks sign-in.

Your choices

To have your access removed, or to ask for your information to be deleted, write to ops@gourmetmarketing.com.

You can also withdraw the tool’s access to your Google account at any time in your Google Account, under “Third-party apps & services”: myaccount.google.com/connections. Google will ask for your consent again the next time you sign in.

Changes to this policy

If this policy changes, the new version is published on this page and the date at the top is updated.

Back to sign-in