1. Scope 适用范围
This Privacy Policy applies to the PayBoard payment operations platform and its authorized users. PayBoard helps organizations synchronize payment-notification emails, identify transaction signals, review records, and maintain operational and audit history. PayBoard is not Google, Gmail, Cash App, Chime, or any other payment or email provider.
本政策适用于 PayBoard 支付运营管理平台及其授权用户。PayBoard 用于同步付款通知邮件、识别交易信号、 核对记录并保存运营和审计历史。PayBoard 并非 Google、Gmail、Cash App、Chime 或其他支付及邮箱服务商。
2. Data we collect 我们收集的数据
Depending on the features an authorized user uses, PayBoard may process:
- Account and organization data: user names, login identifiers, roles, departments, account labels, and settings supplied to PayBoard.
- Payment operations data: transaction amounts, dates, counterparties, references, status, reconciliation decisions, and records imported or confirmed by authorized users.
- Google connection data: the connected Gmail address, OAuth tokens, granted scope, authorization status, Gmail message and history identifiers, watch status, and synchronization timestamps.
- Relevant Gmail message data: message identifiers, selected headers, sender and recipient information, subject, timestamp, and message text needed to determine whether an email is a payment, transaction, verification, or account-status notification.
- Derived and technical data: transaction signals extracted from messages, redacted summaries, message hashes used for duplicate detection, sync status, error information, security events, and audit logs.
根据授权用户启用的功能,PayBoard 可能处理账户与组织资料、支付运营记录、Gmail 连接和授权资料、 识别相关业务邮件所需的邮件标识与内容,以及由此生成的交易信号、脱敏摘要、去重哈希、同步状态和审计记录。
3. Google and Gmail data Google 与 Gmail 数据
If a user connects a Google or Gmail account, PayBoard uses Google user data only to provide the user-authorized email synchronization and transaction-recognition features described in this policy.
- PayBoard requests the
https://www.googleapis.com/auth/gmail.readonlyscope because it must read relevant messages to identify authorized payment and transaction notifications. - This permission does not allow PayBoard to send, edit, move, or delete Gmail messages. PayBoard does not ask for or store the user's Google password.
- PayBoard reads messages only within configured synchronization boundaries and applies mailbox, sender, and transaction-relevance checks for the requested feature.
- Attachments are not downloaded during normal Gmail ingestion. Full raw Gmail message bodies are not retained after normal processing; PayBoard stores selected metadata, derived records, and integrity or duplicate-detection hashes needed for the service.
当用户连接 Google/Gmail 账户时,PayBoard 仅使用 Google 数据完成用户授权的邮件同步和交易识别功能。 PayBoard 只申请业务所需的 Gmail 只读权限,不能发送、修改、移动或删除邮件,也不会索取或存储 Google 密码。 正常 Gmail 处理不会下载附件,完整原始邮件正文不会在正常处理完成后继续保存。
PayBoard's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including its Limited Use requirements.
4. How we use data 数据用途
PayBoard uses the data described above to:
- authenticate authorized users and administer access;
- connect and synchronize an authorized mailbox;
- identify payment, transaction, verification, and relevant account-status notifications;
- present records for user review, confirmation, reconciliation, reporting, and audit;
- prevent duplicate processing, investigate errors, protect the service, and maintain reliability; and
- respond to support, privacy, security, and legal requests.
PayBoard 使用上述数据提供身份验证、授权邮箱同步、交易与相关通知识别、人工核对与审计、去重与故障处理、 服务安全及支持。数据不会用于本政策未说明且未经用户授权的其他用途。
6. Storage and security 存储与安全
PayBoard uses administrative and technical safeguards appropriate to the nature of the data. These safeguards include HTTPS in transit, encrypted storage of Google OAuth access and refresh tokens, role- and account-based access controls, limited administrative permissions, audit logging, and controls designed to reduce unnecessary exposure of message content. No method of storage or transmission is completely secure, so PayBoard cannot guarantee absolute security.
PayBoard 采用与数据性质相适应的管理和技术措施,包括 HTTPS 传输、Google OAuth 访问与刷新令牌加密存储、 基于角色和账户的访问控制、受限管理权限、审计日志以及减少不必要邮件内容暴露的控制。任何系统都无法保证绝对安全。
7. Retention and deletion 保留与删除
- OAuth credentials: retained while the Gmail connection is active and deleted from PayBoard when an authorized user disconnects the mailbox. PayBoard also attempts to revoke the Google token.
- Temporary authorization data: short-lived OAuth state and verification data expire or are removed after use.
- Derived business records: selected message metadata, extracted transaction records, synchronization evidence, and audit records are retained for as long as reasonably necessary to provide recordkeeping, reconciliation, security, and legal functions.
- Backups: deleted data may remain temporarily in protected backups until those backups are rotated under normal backup procedures. Restored data remains subject to the deletion request.
Disconnecting Gmail stops future access and removes stored OAuth credentials, but it does not automatically delete transaction, synchronization-evidence, or audit records already created in PayBoard. A verified deletion request is required for those records, subject to legal, security, fraud-prevention, dispute, and recordkeeping obligations.
Gmail 连接有效期间保留 OAuth 凭据;授权用户断开邮箱时,PayBoard 删除本地凭据并尝试撤销 Google 令牌。 断开连接会停止后续访问,但不会自动删除已生成的交易、同步证据或审计记录。经验证的删除请求会在法律、安全、 反欺诈、争议处理和必要记录保存义务允许的范围内执行;备份中的残留数据会随正常备份轮换删除。
8. Your choices and Google revocation 选择与撤销 Google 授权
You can stop future Gmail access at any time by either method:
- In PayBoard, ask an authorized administrator to open the mailbox or synchronization settings and choose Disconnect.
- In your Google Account, open Third-party connections, select PayBoard, and remove its access.
Revocation prevents PayBoard from obtaining new Google data. It does not by itself delete data already processed by PayBoard; follow the data-request process below for deletion.
用户可随时在 PayBoard 邮箱/同步设置中选择“断开”,或在 Google 账户“第三方连接”中移除 PayBoard 的访问权限。 撤销后 PayBoard 无法再获取新的 Google 数据;如需删除已处理的数据,请按下述方式提交删除请求。
9. Data requests 数据请求
To request access, correction, export, or deletion of personal data or Google-derived data, email sarahariola5@gmail.com with the subject “PayBoard Privacy Request.” Include the PayBoard organization and connected Gmail address involved, but do not send a password, OAuth token, or full payment-card number. PayBoard may need to verify the requester's identity and authority before acting on the request.
如需访问、更正、导出或删除个人数据或 Google 来源数据,请发送邮件至 sarahariola5@gmail.com,主题注明“PayBoard Privacy Request”, 并提供相关 PayBoard 组织和已连接 Gmail 地址。请勿发送密码、OAuth 令牌或完整银行卡号。处理前可能需要验证身份和权限。
10. Contact and updates 联系与政策更新
Privacy and support questions may be sent to sarahariola5@gmail.com. PayBoard may update this policy when its data practices or legal obligations change. The updated date at the top of this page will identify the current version. If a material change affects the use of Google user data, PayBoard will provide appropriate notice and obtain consent where required before using the data for a new purpose.
隐私与支持问题可发送至 sarahariola5@gmail.com。 当数据处理方式或法律义务变化时,PayBoard 可能更新本政策,页面顶部日期用于标识当前版本;若 Google 用户数据用途发生重大变化, PayBoard 将按要求通知并在用于新目的前取得必要同意。