1. What Google User Data We Access
Our application integrates with Google Gmail to enable secure email sending within your WinWeb ERP system. When you authorize Gmail access, we request the following permissions:
- Gmail Send Scope (https://www.googleapis.com/auth/gmail.send): This allows us to send emails on your behalf through your Gmail account. We access your email address and the ability to compose and send messages.
- Email Address & Profile Information: We receive your Google email address, name, and basic profile information to authenticate and associate your Gmail account with your WinWeb user profile.
We do not request access to read your existing emails, contacts, calendar, or any other Google services beyond what is necessary to send outbound messages.
2. How We Use Google User Data
We use the Google user data accessed through Gmail OAuth exclusively for the following purposes:
- Sending Accounting Documents: Emails containing invoices, purchase orders, credit notes, and other accounting documents are sent through your Gmail account via the Gmail API, ensuring messages appear to originate from your Gmail address.
- Authentication & Account Association: Your email address is used to authenticate your identity and link your Gmail account to your WinWeb user profile for future sessions.
- Compliance & Audit Trails: Email metadata (send date, recipient information) is stored in your WinWeb database to maintain audit trails for accounting and compliance purposes.
We do not use this data for:
- Marketing or promotional purposes
- Profiling or behavioral analysis
- Sharing with third parties for any reason
- Any purpose unrelated to secure email delivery
3. Data Sharing, Transfer & Disclosure
We maintain strict confidentiality of your Google user data:
- No Third-Party Sharing: Your Gmail credentials, access tokens, and email data are never shared with third parties, partners, vendors, or service providers.
- Internal Access Only: Only authorized WinWeb administrators and your assigned user account can access Gmail integration settings and send history.
- Multi-Tenant Isolation: In our multi-tenant SaaS environment, your Gmail data is completely isolated from other customers' data. No customer can access another customer's Gmail integration.
- API Credentials: OAuth refresh tokens and access tokens are stored securely in our database and never transmitted to any external service except Google's OAuth servers.
4. Data Protection Mechanisms for Sensitive Data
We employ industry-standard security practices to protect your Google user data:
- OAuth Token Security:
- Access tokens are short-lived (1 hour) and automatically refreshed
- Refresh tokens are encrypted and stored in our database
- Tokens are never logged, displayed, or transmitted insecurely
- Tokens are invalidated immediately upon user logout or account deletion
- Secure Communication:
- All communication with Google APIs uses HTTPS with SSL/TLS encryption
- OAuth redirects use secure state tokens to prevent CSRF attacks
- API requests include proper authentication headers
- Database Security:
- Email data is stored in encrypted database fields
- Access is restricted to authenticated, authorized users only
- Database backups are encrypted and stored securely
- No Public Exposure:
- OAuth credentials and tokens are never exposed in URLs, logs, or error messages
- Email addresses are sanitized before any logging or troubleshooting
- Session Management:
- User sessions are validated on every request
- Admin restrictions prevent unauthorized Gmail setup
- Credentials require re-authentication for changes
5. Data Retention & Deletion
- Google Credentials Retention:
- OAuth refresh tokens are retained as long as your account is active and Gmail integration is enabled
- You can revoke Gmail access at any time through your WinWeb settings or directly via your Google Account
- Upon revocation, tokens are immediately deleted from our system
- Email Metadata Retention:
- Send history and email metadata (recipient, subject, date) are retained for 7 years for accounting and audit compliance
- This data is retained in your company's database as part of your accounting records
- You may request deletion of email metadata for compliance purposes by contacting support
- User Account Deletion:
- When your WinWeb user account is deleted, all associated Gmail credentials and access tokens are immediately destroyed
- Historical email metadata is anonymized or deleted per your data retention policy
- No backup systems retain your Gmail tokens
- Data Portability:
- You may request a copy of all Gmail-related data we store about you
- We will provide this information in a machine-readable format within 30 days of request
6. Your Privacy Rights
- Revoke Access: You can revoke Gmail access at any time through WinWeb Settings → Email Accounts → [Your Gmail Account] → Disconnect
- Request Information: Contact us at [your support email] to request information about what data we store
- Request Deletion: Submit a data deletion request for non-compliance records (accounting audit data is retained per legal requirements)
- Google Controls: You can manage all connected apps in your Google Account at myaccount.google.com/permissions
7. Changes to This Privacy Policy
We may update this privacy policy from time to time. Material changes will be announced via email to your WinWeb account. Your continued use of Gmail integration constitutes acceptance of our privacy practices.
8. Contact Us
For questions about our Gmail OAuth integration or this privacy policy, contact:
Winweb, Inc.
customer.care@winweb.com
857 400 9617
www.winweb.com