Google API Data Policy

COMPLIANCE WITH THE GOOGLE API SERVICES USER DATA POLICY

Google API Services User Data Policy Compliance
REMBRR INC. – Port Charlotte, Florida, USA.
Privacy and Compliance Office – privacy@rembrr.com

  1. General Statement
    This policy describes how REMBRR INC. accesses, uses, stores, and protects Google user data through OAuth 2.0 integrations.

    The text published in https://rembrr.com/politica-de-datos-google-api/ it is exactly the same as the one shown on the OAuth consent screen and in Google brand verification.

    REMBRR fully complies with the Google API Services User Data Policy, the Google Workspace Developer Policy, and all steps of the OAuth Verification and Brand Verification process required for the Gmail, Drive, and Calendar APIs.

  2. Accessed Data
    With the user's explicit consent, REMBRR INC. may request the minimum OAuth 2.0 scopes necessary to provide synchronization and productivity features between the user's Google account and the REMBRR platform.
    The data categories accessed are strictly limited to:
    Basic profile: name, email, and profile picture, used solely for authentication.

    Google Drive: view, create, and update files and metadata exclusively within the REMBRR workspace chosen by the user to link.

    Google Calendar: read and create events for calendar synchronization.
    Gmail (metadata only): subject, sender, recipient, and time, used exclusively for notifications or user-requested automations. REMBRR never reads, stores, or analyzes message content.
    Google Tasks / Google Keep (metadata only): titles and timestamps of notes or tasks if the user voluntarily connects them.

    No other Google user data is accessed, stored, or analyzed, including message content, attachments, or contacts.

  3. Data Usage
    The data obtained from Google is used exclusively for:
    Authenticate the user and manage secure sessions.

    Synchronize Drive files, Calendar events, Tasks, and notes within the user's workspace.

    Provide the requested functions and maintain service reliability.
    Google API data is never used for advertising, behavioral profiling, or resale.

  4. Data Sharing
    REMBRR does not share Google user data with third parties, except:
    With infrastructure or authentication providers that support the secure operation of the system and are subject to strict confidentiality agreements.
    When required by law or a court order.
    All treatment is carried out in strict compliance with the Google API Services User Data Policy and the OAuth Limited Use Requirements.
  5. Storage and Protection
    Encryption in transit (TLS 1.3) and at rest (AES-256).
    Stored exclusively on secure servers located in the United States.

    Protected using multi-level controls: RBAC, MFA, audit logs, and account-level isolation.

    REMBRR does not export Google data to external analytics or advertising systems.

  6. Retention and Disposal
    Data from Google integrations is retained only as long as the user maintains an active connection.
    When the user disconnects or requests deletion:
    OAuth tokens and all associated information are revoked and permanently deleted within a maximum of 30 days.
    Backup copies with residual data are automatically deleted in the next maintenance cycle, no later than 45 days.
    The user can verify the deletion by writing to support@rembrr.com or via /delete-data-request.
  7. User Control
    The user can revoke REMBRR's access to their Google data at any time by visiting https://myaccount.google.com/permissions.
    You may also request access, portability, or deletion directly at info@rembrr.com or through /user-data-rights.
  8. Transparency in the Connection Flow
    During Google sign-in or when connecting Drive, Calendar, Gmail, Tasks, or Keep, the user sees the following notice:
    “By signing in with Google or connecting a Google service, you accept REMBRR's Privacy Policy and Terms of Use.”
    The message includes links to /politica-de-privacidad, /terminos, and /user-data-rights.
  9. Compliance Commitments
    REMBRR INC. certifies that:
    This policy is reviewed annually or whenever Google updates its API Services User Data Policy.
    Security controls follow the NIST SP 800-53 and ISO/IEC 27001 frameworks.
    Every engineer with access to OAuth data receives privacy training and signs confidentiality agreements.
    A Data Protection Impact Assessment (DPIA) is maintained for the Gmail, Drive, and Calendar scopes.
    Users are notified of any substantial changes at least 7 days before they take effect.
  10. Google Data Privacy Contact
    Privacy and Compliance Office – privacy@rembrr.com
    REMBRR INC.
    23087 Langdon Avenue, Port Charlotte, FL 33954, USA.
  11. Last updated October 14, 2025.
    This version supersedes all previous ones and is identical to the text submitted for OAuth verification in the Google Cloud Console.