Privacy Policy
Last updated: 16 August 2026
1. What Vigo does
Vigo is a platform that helps restaurant businesses set up and run their own digital ordering system. When you connect your Google account, Vigo uses your credentials to create and configure cloud resources in your own Google Cloud project — including a Google Spreadsheet (menu, orders, customers), a Google Apps Script backend, a Firebase project for push notifications, and a Google Drive folder for images and documents.
All created resources belong to your Google account. Vigo does not own or control them after provisioning is complete.
2. What Google account data we access
Vigo requests the following Google OAuth scopes:
- cloud-platform — create a Google Cloud project and enable required APIs on your behalf
- spreadsheets — create and populate a Google Spreadsheet with your menu and order data
- drive.file — create and manage only the Drive folders and files that Vigo itself creates (images, documents, APK); no access to your existing Drive files
- script.projects / script.deployments — deploy the Apps Script backend into your Spreadsheet
- firebase — register a Firebase project and configure push notification hosting
- service.management — enable Google Cloud APIs in your project
- openid / email — identify your account
3. How we use your data
We use your Google account access solely to set up and maintain your restaurant backend. Specifically:
- Creating and configuring cloud resources in your Google Cloud project
- Uploading menu images, your logo, and documents to your Drive
- Redeploying your backend when you request an update
- Removing provisioned resources if you delete your project
We do not sell, share, rent, or transfer your data or Google account access to third parties. We do not use your data for advertising.
4. Google API Services User Data Policy
Vigo's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. We access only the data necessary for the features described above, and we do not use it for any other purpose.
5. Data storage and security
We store an encrypted copy of your Google OAuth refresh token in our database to allow future provisioning actions (updates, cleanup) without requiring you to reconnect each time. The token is encrypted at rest using AES-256-GCM. We store your account email for identification purposes only.
You can revoke Vigo's access at any time from your Google Account permissions. After revoking, delete your project in the Vigo dashboard to remove all stored data.
6. Data retention
We retain your account data and encrypted token for as long as you have an active project in Vigo. When you delete a project, provisioned Google Cloud resources are removed and the associated token is deleted from our database.
7. Your rights
You have the right to access, correct, or delete your personal data stored by Vigo. To exercise these rights or with any questions, contact us at the address below.