Solvit operates the Solvit Messaging Hub ("the Service"). This policy explains how we collect, use, protect, and retain information when organizations and their authorized users connect communication channels, including Gmail.
1. Information we collect
- Account information such as name, email address, company membership, role, and authentication records.
- Google account information and OAuth authorization details when a user connects Gmail.
- Email content required to provide the Service, including message bodies, recipients, senders, subjects, headers, labels, attachments, thread identifiers, and delivery metadata.
- Communication data from other connected channels, such as WhatsApp messages and contact details.
- Operational and security data, including timestamps, audit events, IP-derived security records, errors, and device or browser information.
2. How we use information
We use this information only to operate and secure the Service. This includes synchronizing shared inboxes, displaying conversations to authorized company users, sending and replying to messages at their direction, processing attachments, maintaining delivery status, providing support, preventing abuse, and complying with legal obligations.
We do not sell personal information, use Gmail data for advertising, or allow humans to read message content except when required to provide user-requested support, investigate security or abuse, comply with law, or when the user or organization explicitly authorizes access.
3. Google API data
Our use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
The use of raw or derived user data received from Workspace APIs will adhere to the Google User Data Policy, including the Limited Use requirements. Solvit Messaging Hub does not transfer Gmail data to third-party AI services to create, train, or improve foundational or generalized machine learning models, and does not use that data for advertising.
The Service requests Gmail read access to synchronize messages into the shared inbox, and Gmail send access to send or reply only when a user directs that action. It does not request Gmail modify access, so it cannot change Gmail labels or move messages to Trash.
4. Sharing and subprocessors
Information may be processed by infrastructure, database, storage, email, and security providers that help us operate the Service. These providers receive only the access needed to perform their services and are required to protect the information. We may also disclose information when required by law or to protect users, the public, or the Service.
5. Storage, security, and retention
OAuth refresh tokens and provider credentials are encrypted before storage. We use access controls, tenant separation, audit logging, HTTPS, and other technical and organizational safeguards. No online service can guarantee absolute security.
OAuth credentials are removed when a channel is disconnected. Synchronized messages and operational records may remain available to the customer organization until deletion is requested or the organization closes its account, subject to backup, fraud-prevention, and legal-retention requirements.
6. User choices and deletion
Users can revoke Google access from their Google Account permissions page or disconnect Gmail in the Service. Organization administrators may request export, correction, or deletion of account and synchronized communication data by contacting us. Revoking access stops future Gmail access but does not automatically delete data previously synchronized into an organization workspace.
7. Children
The Service is intended for businesses and authorized adult users. It is not directed to children under 13.
8. Changes
We may update this policy as the Service or legal requirements change. We will publish the revised effective date on this page.
9. Contact
For privacy questions or data requests, contact Solvit at solvitcompany@gmail.com.