APPLICATION PRIVACY
Application privacy notice
This notice explains how Spearis Marketing, based in Miami, Florida, handles information in its business automation application at app.spearismarketing.com. It is separate from the public marketing website's privacy policy.
Information the application handles
- Business setup: business name, review link, timezone, message templates, scheduling choices, and workflow approvals.
- Google account information: account identifier and email address used to verify the authorized connection, granted permissions, and authorization tokens used to maintain that connection. Google handles Google sign-in; the application does not receive your Google password.
- Completed-job information: spreadsheet identifiers, tab names and headings, and row data read from configured source ranges. This can include job identifiers, customer names, email addresses, completion dates, status, language preference, and permission indicators. Include only data needed for the service in the configured tab; other cells in a fetched range may also be processed during mapping or preview.
- Operational records: permission evidence, opt-outs, source snapshots, schedules, email content and recipients, sending attempts, provider responses or identifiers, exceptions, and audit history.
- Access and technical records: operator and invited client account email addresses, business assignments, password hashes (not readable passwords), invitation and revocation records, setup confirmations, sign-in and session information, request and service logs, and technical information processed by hosting providers to operate and secure the service.
Google permissions and purpose
Google identity permissions identify the account giving consent. Gmail send-only permission lets the application send the configured initial post-completion email and an explicitly initiated owner-mailbox test. It does not grant permission to read, modify, or delete inbox messages. Spearis does not use this connection to read incoming replies.
A separate agency connection requests access to specific files selected through Google Picker (the drive.file permission). Google permits viewing and changing those selected files within the authorized account's existing rights; Spearis uses the connection only to read configured spreadsheet sources, not to create, edit or delete files. Client spreadsheets should be shared with the agency account as a Viewer. The application does not request access to all Drive files. A short-lived file-access token is provided to Google Picker in the signed-in operator's browser; refresh tokens and the OAuth client secret remain server-side.
Spearis uses this information to configure and deliver the agreed service, confirm account identity and permission, prevent duplicate or unwanted messages, apply pauses and opt-outs, resolve failures, and maintain operational and security records.
Limits on use and sharing
Spearis Marketing's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including its Limited Use requirements.
Google user data is not sold, used for advertising or unrelated marketing, or used to train generalized artificial intelligence or machine-learning models. The email service does not send Google user data to an AI model.
Authorized Spearis personnel access information only as needed to provide support with permission, operate the requested service within permitted access, investigate security or abuse, or meet applicable legal obligations. Google user data is not browsed for unrelated purposes.
Google processes account authorization, spreadsheet requests, and email delivery. Render hosts the application and its database. These providers process information needed to supply their services. Email recipients and their mail providers receive the content addressed to them. Spearis may disclose information where required by law or necessary for security, subject to the restrictions applicable to Google user data.
Social Content service
When a business uses Social Content, Spearis stores its content profile, uploaded media references, notes, permission confirmations, caption versions, approvals, schedules and publishing results. Photos and videos are stored privately in Cloudflare R2 under client-specific references. Short-lived links allow authorized viewers and the publishing provider to retrieve the selected media.
When a Spearis operator requests AI drafting, the supplied content profile and submission notes are sent to OpenAI to suggest captions. This feature does not read Gmail or use customer spreadsheet records. Media files are not sent to the caption model. Generated wording requires human review; it is not published automatically. Spearis requests that generated responses are not stored through the API response-storage option; provider security retention may still apply.
Buffer receives the approved captions and temporary media links to publish to the business's configured social channels. Published content is visible according to those channels' settings. Withdrawing permission or pausing Spearis stops future handoffs but cannot recall a post already handed to Buffer; removal may require action in Buffer or the social account.
Storage and security
The hosted application stores configuration, job, permission, activity and audit records in a database. Saved Google authorization tokens are encrypted, with the encryption key held separately in hosting configuration. HTTPS protects browser connections. Operators sign in to the internal dashboard; invited client accounts can access only their assigned business portal. Revoking a portal account does not itself disconnect Google or pause an automation; contact Spearis for those changes. No system can guarantee absolute security.
Retention, disconnection, and deletion
Information is retained as needed to provide the service and maintain permission, suppression, duplicate-prevention, audit, security, and legally required records. The application does not currently apply a universal automatic deletion period. Disconnecting Google does not automatically delete previously stored job or activity records.
You can revoke Google access using Google Account connections. You can also ask Spearis to pause the service, disconnect an account, correct information, or delete service data by emailing spearismarketing@gmail.com. We verify the requester's authority and review what can be removed, what must be retained and why, and any applicable backup retention. Revoking access stops further authorized Google API access; it does not recall email already sent.
Business and recipient requests
Businesses are responsible for supplying accurate job data and appropriate permission for the messages they request. Customers may contact the business that sent their message or Spearis with questions or opt-out requests. This service is intended for businesses and is not directed to children.
We may update this notice when the service or its practices change. Questions and requests can be directed to Spearis Marketing, Miami, Florida, at spearismarketing@gmail.com.