1. Scope and contact
This policy covers Nessara Office, the private job-administration application used by Nessara Construction. The public construction website may collect project-request details separately when a visitor submits its contact form.
Questions, access requests, deletion requests, or requests to remove a Google connection can be sent to nessaraconstruction@gmail.com.
2. Google data the app accesses
Account and authorization data
When the Office owner approves Google access, the app receives OAuth credentials, the approved scope set, and the connected Gmail address. Google handles the password and consent process; Nessara Office does not receive the Google password.
Gmail sending
For an Office email, the app sends Google the sender address, recipient address, subject, message body, message identifier, and any attached document bytes and filenames. Owner-reviewed estimate and invoice emails include their PDF, and a document-share email includes the selected document. A photo-share email includes a link to the selected photos. Google returns provider message and thread identifiers used to record delivery; estimate and invoice thread identifiers also correlate a later reply.
Gmail reply metadata
The app establishes a forward-only Gmail history cursor and processes metadata for newly added messages. That metadata can include the mailbox profile and history identifier; message and thread identifiers; labels; and the From, To, Subject, Message-ID, In-Reply-To, and References headers.
The app does not request or store reply bodies or attachments. It retains an inbound reply record only when the Gmail thread exactly matches an estimate or invoice message sent by Office. That record contains the subject, Google message and thread identifiers, associated Office record, and detected time. Metadata for unmatched messages is not retained in the Office database.
Google Calendar events
Office reads events from the connected user’s owned primary calendar to display Google appointments alongside job assignments and keep schedule changes current. This includes appointments created outside Office, including personal appointments kept on that calendar. Imported details are visible to authorized Office users. The imported fields include the event title, description, location, start and end dates or times, time zone, all-day status, identifier, version, status, Google event link, recurrence information, and whether the connected user organizes the event.
Office also creates, updates, and removes assignment events. Assignment details can include the job and customer name, location, start and end, status, subcontractor name, arrival information, scope summary, and an optional subcontractor attendee email. An authorized Office user can create appointments and edit or delete eligible ordinary events organized by the connected account, including an individual recurring occurrence; recurring series and special Google event types are not edited in Office. Before a change or deletion, Office checks the event’s identity, ownership, and current version. Office assignment verification also checks its private Office markers and attendee data. Changes detected in Google can update the corresponding Office schedule.
3. How Google data is used
- Send project messages and configured follow-ups chosen by an authorized Office user.
- Confirm delivery receipts, prevent unsafe duplicate sends, and associate a customer reply with the correct Office estimate or invoice.
- Stop an applicable follow-up sequence when a matching reply is detected.
- Display imported primary-calendar appointments alongside Office work, reflect Google schedule changes in Office, and create, update, or remove eligible owner-organized appointments and Office assignments.
- Verify that the OAuth token belongs to the single Google account configured for the application and includes only the approved permissions.
Google user data is not used for advertising, audience profiling, sale of data, or training a general-purpose artificial-intelligence or machine-learning model.
4. Storage and security
OAuth credentials are stored in a server-side token file with operating-system permissions restricted to the application service. They are not stored in the visitor’s browser. Office operational records are stored in the application’s private database. Staff access requires an authorized Office sign-in. An owner may separately share selected job photos or a document through an expiring link; anyone who receives that link can open the selected files without an Office account until the link expires or is revoked. Share records retain the selection, a hash of the access token, expiry and revocation state, and email delivery details. Shared photos are re-encoded without camera or location metadata; the original files remain in private storage.
Stored operational data can include sent email subjects and bodies, recipients, Google message and thread identifiers, matched reply subjects and identifiers, Gmail history cursors, and the imported Calendar fields described above. Calendar records also include Office assignment identity markers, synchronization state and checkpoints, and attendee state for Office assignment invitations. Imported appointment records retain selected event fields, not the complete Google event response: attendee email lists, creator details, conference or meeting metadata, attachment metadata, reminders, and unrelated private event properties are excluded. Reply bodies and unmatched Gmail message metadata are not stored by Office.
No internet-connected service can eliminate every security risk. Nessara Construction limits the Google account, OAuth scope set, application access, and stored provider receipts to what the current workflow needs.
6. Retention and deletion
The local OAuth token is retained until the connection is replaced or the token is removed from the Office server. Google may invalidate the credential or the account owner may revoke access sooner; either action prevents the stored credential from authorizing new Google API access. Sent-message records, matched-reply metadata, imported Calendar details, Calendar receipts, and related Office records are retained while needed for project administration, delivery safety, and Nessara Construction’s business records.
The initial Calendar read and periodic full refresh include calendar history from 1970 onward and appointments through approximately two years after the refresh date. Incremental updates may include changed events outside that window. The import or display window is not a deletion schedule: canceled events and events no longer displayed can remain in local records. Nessara Office does not currently apply a fixed automatic deletion schedule to these operational records. A request to remove the local Google token or delete associated Google-derived records can be sent to the contact above. Nessara Construction will evaluate the request against operational, security, and recordkeeping needs and confirm what can be removed.
7. Choices and revocation
The authorized account owner can decline the Google connection or revoke it from the Google Account third-party connections page. Revocation stops new API access but does not by itself delete Office records already retained or an event or message already delivered through Google.
To request local token removal, deletion of eligible stored records, or an operator change that disables Calendar synchronization, email nessaraconstruction@gmail.com. A subcontractor is added as an event attendee only when the Office owner selects that option for the individual assignment.
8. Changes to this policy
This page will be updated if Nessara Office changes how it accesses, uses, stores, or shares Google user data. The date above identifies the current version. Material new uses of Google data will not be introduced without an updated disclosure and any consent required by Google or applicable law.