Google API data use
Permissions the add-on requests and why
| Permission | What we use it for |
|---|---|
spreadsheets | Read and update the agency's CRM and Leads spreadsheets: last-update and milestone dates, statuses, checklist colors, and scan results. |
gmail.readonly | Read underwriting-related emails (for example carrier status updates and requirements) so they can be recorded in the agency's CRM sheet. Read-only: the add-on never sends, deletes or changes emails. Only enabled after the agency owner turns on scanning. |
drive | Read the agency's client folders and application documents, and move a client's folder to the matching stage folder when the case status changes. Only enabled after the agency owner turns on scanning. |
script.send_mail | Send milestone reminders and daily case summaries to the agency's own team members, from the agency's own Google account. Recipients are the agency's Owner, Front Office and Back Office members. |
script.external_request | Contact our backend to check the agency's subscription, download workflow settings, and send technical counters without client data. |
script.scriptapp | Create the add-on's triggers for this spreadsheet (on edit, on open, and the hourly scan). |
script.container.ui | Show the add-on menu and dialogs inside Google Sheets. |
userinfo.email | Identify the signed-in user so we can apply their agency role (for example, only the owner can enable scanning). |
During onboarding, our website separately asks for the drive.file permission, which only lets us create and
manage the spreadsheets and folders that our app creates for the agency.
Limited Use commitments
- Where Google data goes: email content, attachments and Drive files are processed by the add-on inside the agency's Google Workspace, and the results are written only to the agency's own spreadsheets and Drive. They are not transferred to our servers.
- Only for the user-facing features: we use Google user data only to provide and improve the features described above, which the agency can see in its own sheet.
- No transfer to others: we do not transfer Google user data to third parties, except as necessary to provide these features, to comply with law, or as part of a merger or acquisition with notice.
- No advertising: we do not use or transfer Google user data for advertising, retargeting or interest-based ads.
- No selling, no data brokers: we do not sell Google user data or use it to determine credit-worthiness or for lending.
- No AI training: we do not use Google user data to develop, improve or train generalized artificial intelligence or machine learning models.
- No human reading: our staff do not read Google user data, unless the agency gives us explicit permission for a specific support request, it is needed for security purposes, or it is required by law.
What our servers receive from the add-on
Only a fixed set of technical fields: add-on version, job type, start time, duration, success or failure, whole-number
counts (for example emails scanned, files scanned, records updated), a fixed error code (for example
GMAIL_AUTH_FAILED), which features are turned on, and the sheet structure version. Our backend rejects the
entire report if it contains anything else, such as an email address, a subject line, a file name, a URL or an error
message. Run history is deleted after 90 days.
Revoking access
The agency owner can turn scanning off from the add-on menu, and anyone can revoke the add-on's access at myaccount.google.com/permissions. The add-on checks its permissions before every scan and stops if they have been removed.
Contact
DT TEAM BUILDER LLC · dattran.iaa@gmail.com