Privacy Policy
1. Who we are
CodeCrafted (“we”, “us”, “our”) provides website development, mobile app development, cloud setup, automation, and managed IT support to small businesses. This Privacy Policy explains what information we collect, why we collect it, and how we handle it. It also sets out how we handle data we receive from Google APIs.
If you have questions, contact us at contact@codecrafted.in.
2. Information we collect
- Information you give us. When you contact us, book a consultation, or engage our services, we collect your name, email address, phone number, company name, and the details of your enquiry or project.
- Service data. When we build or operate systems for you, we may process the data those systems handle (for example configuration, logs, and records) strictly to deliver the service you asked for.
- Technical information. Our website may collect standard server logs such as IP address, browser type, and pages visited, used to keep the site secure and working.
3. Google user data
Certain features of our services (including internal automation and client tools) integrate with Google APIs. When you connect a Google Account to one of these features, we request only the access needed to provide that feature.
What we access. Where a feature is designed to manage email on your behalf, we request the Google scope https://www.googleapis.com/auth/gmail.modify. This allows the feature to read your Gmail messages and metadata, apply or remove labels, mark messages as read or unread, and move messages to and from the trash. We do not request the broader https://mail.google.com/ scope and therefore cannot permanently delete your email or alter your Gmail account settings.
How we use it. Google user data is used solely to provide and improve the feature you enabled — for example, categorising messages, extracting receipts or statements, surfacing reminders, or applying labels according to rules you configure. We do not use Google user data for advertising, profiling, or any purpose unrelated to the feature you requested.
How we store it. Authenticated access is granted through OAuth 2.0 tokens. We store the resulting refresh token and any data derived from your mailbox on infrastructure we control, protected by file permissions restricted to the operating user and encrypted in transit. We do not store your Google password and never have access to it.
How we share it. We do not sell Google user data and do not share it with third parties, except where necessary to operate the service (for example, cloud hosting we use to run the feature) or where required by law. Any such provider is bound to use the data only on our instructions.
How long we keep it. We retain Google user data only as long as needed for the feature to function, or until you disconnect the integration or ask us to delete it. When you revoke access, we stop accessing your data and delete the stored tokens; derived copies are removed on request.
Your control. You can revoke our access at any time from your Google Account at myaccount.google.com/permissions. You may also email us to request that we delete any stored Google user data.
Limited Use. Our use and transfer of information received from Google APIs to any other app adheres to the Google API Services User Data Policy, including the Limited Use requirements.
4. How we use information
- To respond to enquiries and provide the services you request.
- To operate, maintain, and secure the systems we build or manage.
- To communicate about your project, support, and service changes.
- To meet our legal and accounting obligations.
5. Sharing
We do not sell your personal information. We share it only with service providers who help us operate (such as hosting and email providers), with your direction, or where required by law.
6. Security
We use reasonable technical and organisational measures to protect information, including access controls, encryption in transit, and least-privilege access. No method of transmission or storage is completely secure, so we cannot guarantee absolute security.
7. Data retention
We keep personal information for as long as needed to provide services and meet legal obligations, then delete or anonymise it.
8. Your rights
Depending on where you live, you may have the right to access, correct, delete, or restrict the use of your personal information, and to object to certain processing. To exercise these rights, email contact@codecrafted.in.
9. Children
Our services are intended for businesses and are not directed to children. We do not knowingly collect information from children.
10. International transfers
We may process information in countries other than yours, including on cloud infrastructure. Where we do, we take steps to protect the information as described in this policy.
11. Changes
We may update this policy from time to time. Material changes will be reflected by the “Last updated” date above.
12. Contact
CodeCrafted — contact@codecrafted.in · codecrafted.in