Overview
Bostmap (“Bostmap,” “we,” “us,” or “our”) provides a WordPress plugin and related service that helps an authorized user verify ownership of a website through Google and submit an existing sitemap to Google Search Console. This Privacy Policy applies to bostmap.com, the Bostmap plugin, and related support services.
We use Google user data only to provide or improve the visible Bostmap features the user requests. We do not sell Google user data, use it for advertising, build advertising profiles, or use it to train general-purpose artificial intelligence models.
Information we collect
Information you provide
- Your email address and any message or diagnostic details you send to support.
- A website URL, domain, sitemap URL, or other configuration you enter.
- Feedback and communications relating to Bostmap.
Plugin and site information
- WordPress site URL, sitemap URL, sitemap type, verification method and status, Search Console property, and sitemap submission status.
- Basic compatibility details such as WordPress, PHP, plugin, and Bostmap versions when needed to provide the service or troubleshoot a problem.
- The plugin does not create custom reporting or crawl-history database tables. It may store minimal connection settings in existing WordPress options.
Technical information
- IP address, browser or device type, request time, referring page, error details, and security events generated when you use our website or service.
- Essential cookies or similar storage needed for security, login state, OAuth state validation, and basic preferences. We do not use Google user data for advertising cookies.
Google user data
Bostmap uses Google OAuth 2.0. You sign in and approve access on Google’s pages; Bostmap does not receive or store your Google password.
Data we may access
- Basic Google account identity needed to identify the connected account, such as email address and basic profile information, when included in the scopes you approve.
- Google OAuth access and refresh tokens used to make authorized API requests.
- Sites or properties associated with the authorized account, ownership-verification tokens and status, and sitemap submission status.
Permissions
We intend to request the narrowest permissions needed to verify a new site and submit its sitemap. These may include Google Site Verification verify-only access and Google Search Console read/write access. The final Google consent screen will show the exact permissions before you authorize them.
Google Limited Use disclosure
Bostmap’s use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
How we use information
- Authenticate the user and maintain the Google connection they requested.
- Request a supported site-verification token, place it through WordPress when technically possible, and ask Google to verify ownership.
- Discover or accept an existing valid XML sitemap and submit its URL to Google Search Console.
- Display connection, verification, and submission status to the user.
- Provide support, diagnose failures, prevent abuse, secure the service, and meet legal obligations.
- Improve the user-facing Bostmap workflow using aggregated or de-identified operational information.
We do not use Google user data for unrelated purposes. If our use changes materially, we will update this policy and request consent when required before using the data for the new purpose.
Retention and deletion
- OAuth tokens and active connection records are retained while your connection remains active and are deleted or rendered unusable after disconnection, account deletion, token revocation, or when no longer needed.
- We aim to delete active service data within 30 days after a verified deletion request, except where retention is legally required.
- Security and error logs may be retained for up to 90 days. Encrypted backups may persist for up to an additional 30 days before rotation.
- Support messages may be retained as needed to resolve the request and maintain an appropriate business record.
You may request deletion at any time by emailing [email protected]. You can also revoke Bostmap’s access through your Google Account permissions. Revocation stops future authorized API access.
Security
We use reasonable administrative, technical, and organizational safeguards. We use HTTPS to protect data in transit and encrypt stored OAuth tokens at rest. We restrict administrative access, keep the hosted Google application secret separate from customer WordPress sites, validate OAuth requests with state and PKCE protections, maintain security and error logs, apply dependency updates, and support token revocation. No system is perfectly secure, so we cannot guarantee absolute security.
Your choices and rights
Depending on your location, you may have rights to access, correct, delete, restrict, or receive a copy of personal information and to object to certain processing. You may disconnect Google access, uninstall the plugin, or ask us to delete your service data. We may need to verify your identity and authority over the connected site before completing a request.
Children
Bostmap is intended for website administrators and is not directed to children under 13 or the minimum digital-consent age in their country. We do not knowingly collect personal information from children.
International processing
Information may be processed in countries other than your own. Where required, we will use appropriate safeguards for international transfers.
Changes to this policy
We may update this policy as Bostmap develops. We will update the date above and provide additional notice when a material change affects how Google user data or personal information is used.
Contact us
Questions, privacy requests, and deletion requests can be sent to: