Privacy Policy

Effective date: July 13, 2026

ORPA CLOUD provides business operations software for service businesses. This policy explains what information ORPA CLOUD accesses, why it is used, where it is shared, and how users can control it.

Information we process

We may process account and workspace details; customer, job, quote, invoice, and schedule records entered by authorized users; payment status and connected-account identifiers provided by Stripe; security and audit events; and information from Gmail when a workspace administrator explicitly connects an account.

Google and Gmail data

ORPA CLOUD requests Gmail read-only access. It may import the sender, subject, date, message snippet, and limited email body text needed to display recent business messages and prepare user-requested drafts. ORPA CLOUD does not use this permission to send email, delete messages, change labels, archive messages, mark messages as read, or download attachments.

Use of information received from Google Workspace APIs adheres to the Google API Services User Data Policy, including its Limited Use requirements.

AI-assisted features

When an authorized user requests an email review, limited email text may be sent to OpenAI to create a structured summary, category, recommended action, risk flags, and suggested reply. AI output is saved as a draft for human review and is never sent automatically. ORPA CLOUD instructs the provider not to store application state and does not use Gmail content to train ORPA CLOUD models.

How information is used

Information is used only to operate visible product features, secure accounts, provide customer support, prevent abuse, process authorized payments, and maintain service reliability. ORPA CLOUD does not sell Google user data, use it for advertising, transfer it to data brokers, determine creditworthiness, or permit unrelated surveillance.

Service providers

ORPA CLOUD relies on limited-purpose processors, including Vercel for application hosting, Supabase for authentication and database services, Google for authorized Gmail access, Stripe for connected payments, and OpenAI for user-requested AI drafts. Each provider receives only the information needed for its role.

Security

Controls include HTTPS, restrictive browser security headers, encrypted OAuth tokens, server-only credentials, workspace-level database access rules, request throttling, signed payment webhooks, audit records, and human approval for AI-generated actions. No online service can promise absolute security.

Retention and deletion

Workspace records are retained while an account is active or as needed to provide the service and meet legal or security obligations. Disconnecting Gmail revokes access and deletes ORPA CLOUD’s encrypted Gmail tokens. Users may request deletion of imported Gmail data or their complete workspace by following the Data Deletion instructions.

Your choices

Workspace administrators may disconnect Gmail and Stripe. Users may request access, correction, export, or deletion of their information, subject to identity, ownership, legal, and fraud-prevention checks.

Contact

Privacy questions and data requests may be sent to privacy@orpacloud.com.