Privacy Policy
Octopus Dashboard (“the application”) is a private tool operated by two individuals, the owners of a small online shop (“we”). It is used only by the owners, for their own mailboxes and spreadsheets. This policy explains what Google user data the application accesses, why, where it is stored and how it can be removed.
1. Data the application accesses
When an owner signs in with Google and grants permission, the application can access:
- Gmail (scope
https://www.googleapis.com/auth/gmail.modify): the owner's own mailbox. The application reads emails sent by the shop's parcel forwarder, adds a label to mark an email as processed, and sends a reply in the same email thread only after the owner explicitly confirms it on screen. - Google Sheets (scope
https://www.googleapis.com/auth/spreadsheets): a spreadsheet of card balances that the owner designates. The application reads its cells and writes the amounts that the owner enters in the application. - The email address of the signed-in Google account, to identify which mailbox is connected.
2. How the data is used
The data is used only to provide the features the owner sees in the application: parcel cards with tracking numbers, statuses and deadlines taken from forwarder emails; reply drafts that the owner approves; and balance tracking. It is not used for advertising, profiling, selling, or building databases, and it is not used to train any artificial intelligence or machine learning model. The application does not send Gmail content to any AI model.
3. Where the data is stored
Parcel details extracted from emails, and sign-in credentials, are stored in a database on a private server controlled by the owners. Sign-in credentials (OAuth tokens) are stored encrypted. Documents the owner uploads (for example, customs documents) are stored in an encrypted vault protected by a password that only the owners know. Access to the application is restricted to the owners' email addresses by an access gate.
4. Sharing
We do not sell Google user data and do not share it with third parties. Humans do not read it, other than the two owners, who see their own data in the application. To run the application the owners choose to receive short status notices through Telegram (for example, “parcel delayed at customs, documents needed”) and optionally to post payment reports to their own Trello board. These messages contain parcel or payment status text only and go to services the owners themselves use.
5. Google API Services User Data Policy
The application's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
6. Retention and deletion
Data is kept while the owner uses the application. An owner can revoke the application's access at any time at myaccount.google.com/permissions. To have stored data deleted, write to the contact address below and it will be deleted.
7. Security
Access to the application is limited to two named email addresses through a sign-in gate; stored sign-in credentials and vault documents are encrypted; secrets are kept on the server and are never placed in the source code.
8. Changes and contact
If this policy changes, the date above is updated. Questions and deletion requests: ukrainianas@gmail.com.