InboxHub is an internal Gmail management tool built exclusively for
Pacific Safe Manufacturing employees. This policy explains how we
handle data accessed through Google's APIs.
Data we access
InboxHub accesses Gmail data through the following Google API scopes:
gmail.readonly (read emails),
gmail.send (send replies),
and gmail.modify (apply labels for status tracking).
This access is granted only for shared inbox Gmail accounts explicitly
authorized by a Pacific Safe administrator.
How we use data
Gmail data is used exclusively to power the InboxHub shared inbox
workflow — displaying emails to authorized team members, enabling
replies, and tracking assignment status via Gmail labels. We do not
use Gmail data for advertising, analytics, or any purpose outside
the core InboxHub functionality.
Data protection mechanisms
InboxHub implements the following technical and organizational
measures to protect sensitive user data obtained through Google APIs:
Encryption at rest: All OAuth tokens
(access tokens and refresh tokens) are encrypted using
AES-256-GCM encryption before being stored in our Azure
SQL database. Tokens are never stored in plain text.
Encryption in transit: All data transmitted
between the application and Google APIs is encrypted using
TLS 1.2 or higher. The admin panel and backend API are
exclusively served over HTTPS.
Access controls: Only explicitly authorized
employees added by a Pacific Safe administrator can access
InboxHub. Role-based access control ensures members only see
inboxes they have been granted permission to access.
Authentication: All users authenticate via
Google OAuth. JWT tokens are used for API session management
with configurable expiry and immediate revocation on
deactivation.
Secure hosting: The application is hosted
on Microsoft Azure with enterprise-grade security, including
network isolation and managed identity.
Minimal data access: InboxHub only requests
the minimum Gmail scopes necessary to provide shared inbox
functionality. Email content is fetched live on demand and
is not permanently stored in our database.
Data retention and deletion
InboxHub retains different types of data according to the
following policies:
OAuth tokens: Access tokens and refresh
tokens are retained only for as long as the shared inbox
account remains active in InboxHub. When a shared inbox
is removed or disabled by an administrator, all associated
OAuth tokens are permanently deleted from our database
within 30 days.
Email content: InboxHub does not permanently
store email content. Emails are fetched live from Gmail on
demand and are not cached or retained in our database.
Email metadata (such as message IDs used for assignment
tracking) may be retained for up to 90 days after the
associated shared inbox is removed.
Assignment and workflow data: Email
assignment records, status changes, internal notes, and
activity logs are retained for as long as the associated
shared inbox account is active. This data is deleted within
90 days of the shared inbox being permanently removed.
Employee accounts: Employee records are
soft-deleted (deactivated) when removed by an administrator.
All employee data can be permanently deleted upon written
request to admin@pacificsafemfg.com.
User deletion requests: Users may request
deletion of all their personal data by contacting
admin@pacificsafemfg.com. All personal data will be
permanently deleted within 30 days of a verified request.
Data storage
All data is stored in Microsoft Azure SQL Database hosted in
the United States. OAuth tokens are encrypted at rest using
AES-256-GCM encryption. Email content is never permanently stored.
Who has access
Only employees explicitly added by a Pacific Safe Manufacturing
administrator can access InboxHub. Access is revoked immediately
upon account deactivation. Administrators control which employees
can see which shared inboxes and at what permission level.
Data sharing
We do not sell, rent, or share any data with third parties.
Gmail data accessed through Google APIs is never transferred to
any external service outside of the core InboxHub workflow.
Google API Services User Data Policy
InboxHub's use and transfer of information received from Google APIs
adheres to the
Google API Services User Data Policy
,
including the Limited Use requirements. InboxHub does not use
Google user data to develop, improve, or train generalized
AI or ML models.