Legal

Privacy Policy

Effective Date: July 10, 2026  ·  Last Updated: July 10, 2026

1Introduction

This Privacy Policy describes how Form Handler & Email Connector ("the Service," "we," "us," or "our") collects, uses, and protects information when you use our application to connect your website forms to your Gmail account. This policy applies to all users of the Service and covers our use of data accessed through Google APIs.

By connecting your Google account to the Service, you agree to the practices described in this Privacy Policy. If you do not agree with these terms, please do not authorize the Service to access your Google account.

2Information Collection

When you connect your Gmail account, the Service uses Google OAuth 2.0 to request a limited, specific authorization: the ability to send email messages on your behalf (gmail.send scope). This grants us an access token and refresh token that permit the Service to compose and send outgoing emails from your Gmail account in response to form submissions.

We do NOT read, access, collect, or store the contents of your Gmail inbox, sent mail, drafts, contacts, or any unrelated account metadata. The Service has no capability to browse, search, or retrieve any existing email in your account — its access is strictly limited to sending new, outgoing messages that you configure.

In addition to the Gmail send permission, we may collect basic account identifiers (such as your email address and name) solely to associate your Google account with your Service configuration, and the form submission data your visitors enter, which is used only to generate the outgoing notification email.

3Information Usage

We use the authorized Google permissions and tokens strictly to run the service and send email notifications on your behalf:

  • Tokens are used exclusively to authenticate outgoing, send-only requests to the Gmail API.
  • Tokens are used only to transmit email notifications generated from your form submissions.
  • Tokens are never used to access, index, mine, or analyze any other part of your Google account.
  • We retain tokens only for as long as your account remains connected to the Service, and delete them upon disconnection or account deletion.

4Data Protection & Security

We implement robust administrative, technical, and physical security measures to safeguard your sensitive data against unauthorized access, disclosure, alteration, or destruction:

  • Encryption at Rest: All sensitive credentials, including Google OAuth access and refresh tokens, are encrypted at rest using industry-standard AES-256-GCM encryption before being written to our database. Plaintext tokens are never stored, logged, or exposed.
  • Encryption in Transit: All communications between your website forms, our server, and Google's API endpoints are encrypted in transit using secure transport layer security (HTTPS with TLS 1.2 or higher).
  • No Third-Party Access: We do not sell, rent, trade, or share any of your data. All form data and OAuth tokens remain strictly within our secured server environment for the sole purpose of sending email notifications on your behalf.
  • Access Controls: Access to our server and database environment is restricted to authorized systems only, secured by firewalls, and protected by key-based authentication.

5Data Sharing

We do not sell, rent, share, or transfer any data obtained through Google APIs to third-party tools, analytics platforms, advertising networks, or data brokers. Information accessed via your Google account is never used to build advertising profiles, for personalized or interest-based advertising, or for any purpose unrelated to the core function of sending your form notification emails.

Data may only be disclosed if required by law, regulation, legal process, or governmental request, or to protect the rights, property, or safety of the Service, its users, or the public.

6Google API Limited Use Disclosure

This application's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.

"Our application's use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements."

In practice, this means Google user data obtained through this integration is used only to provide and improve the user-facing features of the Service that you have directly requested, and is never used for serving advertisements or sold to any third party.

8Contact Information

If you have any questions, concerns, or requests regarding this Privacy Policy or how your information is handled, please contact us:

Privacy & Support
info@solithub.ca