TouchTargets is a product of AGR Group, a proprietorship of Mukkara Rakesh Kumar Reddy, India.
GSTIN 37CPJPR8041G2ZH.
NO.28-5-711, LG 182, HOUSING BOARD COLONY, Anantapur Head Post Office, Hamali Colony, Ananthapuramu, Ananthapuramu, Andhra Pradesh, 515001
India
This policy explains how AGR Group, a proprietorship of Mukkara Rakesh Kumar Reddy, India ("TouchTargets", "we", "us") handles personal data and client data when you use touchtargets.com and app.touchtargets.com (together, the "Service").
Who we are (data controller):
AGR Group
NO.28-5-711, LG 182, HOUSING BOARD COLONY, Anantapur Head Post Office, Hamali Colony, Ananthapuramu, Ananthapuramu, Andhra Pradesh, 515001
India
Email: [email protected]
For personal data of people who appear in the data you connect (for example, names in reviews or on your site), you are usually the controller and we are your processor. See "Our role" below.
1. What we collect
1.1 Account data
- Name, email address, password (stored hashed), role in your workspace, and invitations you send or accept.
- Business and billing details: company name, billing country, currency, tax ID (such as GST number or VAT ID), and payment history.
- Support messages and notification preferences (email, WhatsApp).
1.2 Data from connected services
When you connect a site and verify that you own its domain, we read data from:
- Google Search Console: clicks, impressions, positions, queries and pages, and URL inspection results.
- Google Analytics 4 (GA4): traffic, landing pages and referral data, including visits from AI assistants.
- Bing Webmaster Tools: traffic and query data.
- Google PageSpeed Insights: performance results for your public pages. This needs nothing from you beyond the site URL.
Search Console, GA4 and Bing are read-only. You grant access by adding our service account or Bing account as a user on your property, and you can remove it at any time. We keep this data in our own database as daily figures (see section 6).
1.3 Crawl data
After you verify a domain, we crawl your public website to audit it. We store page URLs, status codes, titles, headings, meta tags, canonical and robots directives, headers, links between pages, page text needed for analysis, and the issues we find. We also probe about 35 well-known paths (for example .env, .git, backups) to check whether sensitive files are exposed. For those probes we inspect the response in memory only. We never store, log or show the contents, only the type, status, content type and size.
Our crawler identifies itself as TouchTargetsBot (details at https://touchtargets.com/bot), obeys robots.txt and Crawl-delay, and runs only while your domain verification stays in place.
1.4 Business profile content
What you enter about your business: company profile, offerings (with optional prices), audiences, competitors, goals, brand voice and proof points. We use it so the Service can word its findings and recommendations for your business and your goals.
1.5 Usage, technical and audit data
Log-in times, IP address, browser and device type, pages visited in the app, actions taken by you and by the Service (an audit log with before and after states), and records of each AI call (workspace, feature, tokens, cost).
1.6 What we do not collect
We do not collect the content of your Google account, email or files. We do not read payment card numbers (our payment provider does).
2. How we use your data
- To provide the Service: syncing your data, auditing your site, producing reports and recommendations, and applying changes you approve.
- To bill you and to meet tax and legal duties.
- To keep the Service secure, prevent abuse and fix faults.
- To contact you about your account, approvals, reports and service changes.
- To improve the Service using aggregated or de-identified usage data. We do not use your connected Google data for this.
We do not sell your personal data. We do not use your data for advertising.
3. How AI processes your data
Parts of the Service use AI models through the Anthropic API (Claude models) to help write explanations and summaries of findings. When this happens, the relevant parts of your data (for example, search performance, crawl findings and business profile content) are sent to Anthropic to generate the text.
- Anthropic processes this data to provide the API response. Anthropic’s Commercial Terms prohibit it from training its models on customer content, and our API inputs and outputs are not used to train Anthropic’s models.
- We do not use your data to train or fine-tune any AI or machine-learning model, ours or anyone else’s.
- All model calls go through one internal gateway that logs which workspace, feature, tokens and cost were involved.
- Text that comes from outside, such as web pages, reviews, emails and AI answers, is treated as data and never as instructions to the model.
- The software can only use the tools it has been given, and any change to something outside our app needs your approval first (see our Terms of Service).
- We do not use free-tier AI services for client data.
AI output can be wrong. You should review it before relying on it.
4. Google API Services User Data Policy
TouchTargets’ use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
In plain terms, for data we receive from Google APIs (Search Console, GA4, Google Drive and Google Ads, and any other Google API we use):
- Limited to a stated purpose. We use it only to provide and improve the user-facing features of the Service that you asked for: showing your performance data, auditing your site, and producing reports and recommendations for you.
- No transfer except as allowed. We do not transfer it to others unless it is needed to provide or improve those user-facing features (for example, to our sub-processors listed below), to comply with law, or as part of a merger or sale of assets with notice to you.
- No advertising. We do not use it to serve ads, including retargeting, personalised or interest-based advertising.
- No human reading, except where permitted. We do not allow humans to read it unless we have your consent for specific data, it is needed for security purposes (such as investigating abuse), it is needed to comply with law, or the data is aggregated and used for internal operations in line with applicable law.
- No AI model training. We do not use Google user data to develop, improve or train generalised AI or machine-learning models. It is sent to Anthropic only to generate the output you asked for, as described in section 3.
You can stop our access at any time by removing our service account from your Search Console or GA4 property (or by revoking access in your Google Account settings once Google sign-in is available). You can also disconnect the connector in the app. See section 6 for deletion.
5. Sub-processors and who we share data with
We share data only with providers that help us run the Service, under contracts that require them to protect it. The named providers are listed on our sub-processors page, https://touchtargets.com/subprocessors, which forms part of this policy. In short:
- Hosting: our production service is hosted on a dedicated server managed through Laravel Forge. Some non-production/staging environments may run on other providers (currently Oracle Cloud, India).
- AI: Anthropic (Claude API).
- Google and Microsoft (Bing): the sources of the search and analytics data you connect, and the PageSpeed API.
- Payments: our payment provider, which handles payment and tax. The current list is on our Sub-processors page.
- Messaging: Meta (WhatsApp Cloud API) and Postmark (transactional email).
We may also disclose data if the law requires it, or to protect our rights, or in a business transfer (with notice to you). We will update the sub-processors page before adding or replacing a provider that handles client data, and will tell clients by email at least 30 days ahead.
6. Retention and deletion
- Account and workspace data: kept while your account is active.
- Connected data: site-level daily totals are kept for as long as your workspace exists. Search query-and-page detail older than 16 months is rolled up into monthly summaries. Page-level Search Console data and Bing query detail are currently kept in full.
- Crawl data: we keep the pages and issues of the last 6 crawls per site (the last 3 for sites of 25,000 pages or more), link data for the last 2 crawls, and run summaries for as long as your workspace exists. Older detail is deleted automatically each day.
- Audit log: kept for as long as your workspace exists, so you can see what was changed and undo changes within 30 days.
- Billing records: kept as long as Indian tax and accounting law requires.
- Disconnecting or losing verification: stops all syncing and crawling. Data already synced is kept unless you ask us to delete it.
- Deleting your data: you can ask us at any time to delete your workspace or personal data (see section 11). We will delete or anonymise it within 30 days, except records we must keep by law. Backups roll off within 35 days of the deletion.
- After cancellation: your data stays available for export for 30 days, then we delete the workspace and its data (backups roll off within 35 days).
7. Data export
You can ask for a copy of your data at any time, and you can export it before cancelling. Until self-serve export is available in the app, export is on request: email [email protected] and we will send your data in a common machine-readable format (such as CSV or JSON) within 30 days.
8. International transfers
We are based in India. Our hosting, sub-processors and you may be in other countries, so your data may be transferred to and processed in India, the United States and other countries.
- For transfers of personal data from the EEA, UK or Switzerland, we rely on the EU Standard Contractual Clauses and, for the UK, the UK International Data Transfer Addendum. Our Data Processing Agreement covers this in full and is available on request at [email protected].
- Under India’s Digital Personal Data Protection Act, 2023 ("DPDP Act"), we transfer personal data outside India only to countries and under conditions not restricted by the Government of India.
EU/UK representative (Article 27 GDPR / UK GDPR): we have not appointed one, because we have no EU or UK client workspace at this time. If that changes, we will name the representative here.
9. Our role
- For your account data (your name, email, billing details), we are the controller (called "Data Fiduciary" under the DPDP Act).
- For personal data inside the data you connect or crawl (for example, customer names in reviews or on your website), you are the controller or Data Fiduciary and we are your processor. We process it only on your instructions and as this policy and our Terms of Service describe. You are responsible for having a lawful basis to give us that data.
10. Cookies
We use:
- Essential cookies to keep you signed in, protect forms from forgery and remember your session. The app cannot work without them.
- Analytics cookies on touchtargets.com (our public website) only: we use Google Analytics 4 to understand how the site is used. Where the law requires consent (for example in the EEA and UK), we ask first and you can refuse.
The app (app.touchtargets.com) uses essential cookies only.
We do not use advertising cookies. You can block or delete cookies in your browser, but the app may then not work.
11. Your rights and how to use them
Under the DPDP Act (India)
You have the right to: access information about the personal data we process; correct and update it; erase it; nominate another person to exercise your rights if you die or become incapacitated; and have your grievances redressed. You may withdraw consent at any time (this does not affect what we did before, and we may keep data we must keep by law).
Under the GDPR and UK GDPR (where they apply to you)
You have the right to access, correct, erase, restrict or object to processing, data portability, and to withdraw consent. You may also complain to your local data protection authority.
How to make a request
Email [email protected] from the address on your account. We may need to verify your identity. We will reply within 30 days, or sooner where the law requires it.
Grievance Officer (DPDP Act)
Name: Rakesh Reddy
Address: AGR Group, NO.28-5-711, LG 182, HOUSING BOARD COLONY, Anantapur Head Post Office, Hamali Colony, Ananthapuramu, Ananthapuramu, Andhra Pradesh, 515001
India
Email: [email protected]
If we do not resolve your grievance, you may complain to the Data Protection Board of India once it is established and open to complaints.
12. Security
We use encryption in transit, encrypted storage for credentials, separation between client workspaces, access controls, an audit log, and controls that keep our crawler and connectors to domains you have verified. No system is completely secure. If a breach affects your personal data, we will notify you and the authorities as the law requires.
13. Children
The Service is for businesses and is not for anyone under 18. We do not knowingly collect children’s data.
14. Changes to this policy
We may update this policy. If a change is material, we will tell you by email or in the app before it takes effect. The "Last updated" date shows the latest version.
15. Contact
AGR Group
NO.28-5-711, LG 182, HOUSING BOARD COLONY, Anantapur Head Post Office, Hamali Colony, Ananthapuramu, Ananthapuramu, Andhra Pradesh, 515001
India
[email protected]
Company details
AGR Group (Mukkara Rakesh Kumar Reddy, proprietor)
NO.28-5-711, LG 182, HOUSING BOARD COLONY, Anantapur Head Post Office, Hamali Colony, Ananthapuramu, Ananthapuramu, Andhra Pradesh, 515001
India
GSTIN 37CPJPR8041G2ZH
[email protected]
Approved by Mukkara Rakesh Kumar Reddy, Proprietor, AGR Group, 7 Oct 2026