Introduction
WorkSync Ops ("we", "us", or "our") operates https://www.worksyncops.com and related APIs. This Privacy Policy explains how we collect, use, share, retain, and delete personal data when you use our service, including data obtained from Google APIs when a Google Workspace administrator connects their organization.
Our use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
Information Collection and Use
We collect several types of information to provide and improve the service:
- Account data: email address, name, and authentication credentials for WorkSync Ops users.
- Usage data: browser type, IP address, pages visited, and timestamps needed for security and support.
- Google Workspace data (admin-authorized only):directory users and groups; Drive file metadata (name, owner, sharing/visibility, mime type, size, modified time); offboarding-related settings such as Drive/Calendar transfer status and Gmail forwarding configuration. We use this data to power inventory, DLP exposure scanning, automated offboarding, and compliance reporting for the customer's own tenant.
- Cookies: used for authentication and essential site functionality.
Use of Data
We use collected data to:
- Provide, maintain, and secure the WorkSync Ops service
- Display inventory, DLP violations, and compliance reports to authorized tenant users
- Run customer-initiated sync, scan, and offboarding workflows
- Provide customer support and notify you about service changes
- Detect, prevent, and address technical and security issues
We do not use Google user data for advertising, personalized ads, credit scoring, or selling data.
Sharing, transfer, and disclosure of Google user data
We do not sell Google user data. We do not share Google user data with third parties for advertising or unrelated marketing.
We may share or disclose Google user data only in these limited cases:
- Infrastructure processors: trusted service providers that host or process data solely to operate WorkSync Ops under contractual confidentiality and data processing terms (for example cloud hosting, database, and email delivery providers). They may process data only on our instructions and are not permitted to use Google user data for their own purposes.
- Within the customer's organization: authorized users of the same WorkSync Ops tenant can view inventory, DLP, and offboarding results that include Google Workspace data for their own domain.
- Legal requirements: when required by law, regulation, legal process, or governmental request, or to protect the rights, safety, and security of WorkSync Ops, our users, or the public.
- Business transfers: if we are involved in a merger, acquisition, or asset sale, Google user data may be transferred as part of that transaction, subject to continued protection consistent with this policy and applicable Google policies.
We do not transfer Google user data to independent third parties for their own use.
Retention and deletion of Google user data
Google Workspace data obtained via Google APIs is retained only while the customer organization keeps Google Workspace connected and continues using WorkSync Ops, and only as needed to provide inventory, DLP, offboarding, and compliance features.
- Disconnect: when a customer disconnects Google Workspace in Settings, we revoke OAuth tokens and stop new Google API access for that tenant.
- Deletion on request: the customer administrator (or an authorized contact) may request deletion of Google user data associated with their tenant by emailing privacy@worksyncops.com. We will delete or irreversibly anonymize that Google user data from active systems within 30 days, except where we must retain limited records for legal, security, or dispute-resolution purposes.
- Account closure: when a WorkSync Ops tenant account is closed, we delete or anonymize associated Google user data within 30 days on the same basis.
- Backups: residual copies in encrypted backups are purged on a rolling backup lifecycle and are not used for production features after deletion.
Security of Data
We use commercially reasonable administrative, technical, and organizational measures to protect personal data, including encryption in transit and access controls. No method of transmission or storage is 100% secure.
Changes to This Privacy Policy
We may update this Privacy Policy from time to time. We will post the updated policy on this page and revise the effective date above.