Privacy Policy
Effective Date: 2025/11/17
Last Updated: 2025/11/17
This Privacy Policy describes how Gorillasync (“we”, “us”, “our”) collects, uses, stores, and shares information when you use our service (the “Service”). By creating an account or using the Service, you consent to this Policy.
1. Information We Collect
- Account Information. We collect your email address, login credentials (passwords are hashed), and basic profile data when signing in with Google.
-
Trade Confirmation Emails. When you forward trade-confirmation emails to
your assigned forwarding address, we store:
- Full email body (stored indefinitely)
- Email metadata (sender, subject, timestamps)
- Parsed trade data
- Processing logs and audit information
- Google Integration. When connecting Google Sheets, we store OAuth tokens, your Google ID, spreadsheet references, and sync activity. Tokens are stored securely and used only to perform the sync operations you authorize.
- Payment Information. Stripe processes payments on our behalf. We do not store credit card numbers or billing details. We receive only limited Stripe metadata.
- Technical Data. We collect IP addresses, login events, device/browser information, error logs (via Sentry), and usage statistics.
2. How We Use Your Information
- Authenticate your account and manage your profile.
- Receive, store, and process the emails you forward.
- Parse submitted emails into structured transaction data.
- Write that data to your connected Google Sheets.
- Maintain logs for support, security, debugging, and analytics.
- Operate subscription billing via Stripe.
- Improve and monitor service performance, including limited-mode Google Analytics.
- Use anonymized or aggregated data for analytics or future commercial purposes (non-identifiable only).
3. Third-Party Services
- Mailgun (inbound email processing)
- Google (OAuth and Sheets API)
- Stripe (billing and subscriptions)
- Sentry (error monitoring)
- Cloudflare (security and threat filtering)
- Render (hosting infrastructure)
4. Data Storage and Retention
- Storage. Data is stored in our secure hosting environment, which provides industry-standard encryption in transit and at rest.
- Email Bodies. Email bodies and parsed data are stored indefinitely unless your account is deleted.
- OAuth Tokens. Stored securely and removed upon account deletion or token revocation.
- Logs. Operational and security logs are retained as necessary for troubleshooting and platform integrity.
5. Account Deletion
- You may request deletion by emailing support@gorillasync.com.
- Account data will be deleted within 7 days. During this period, you cannot reverse deletion or reactivate the account.
- OAuth tokens, email bodies, and parsed transaction data will be removed.
- Some anonymized trade data may continue to be kept for statistical or operational purposes.
6. Anonymized and Aggregated Data
- We may generate anonymized or aggregated datasets from your submitted emails and parsed transactions.
- These datasets contain no direct personal identifiers and cannot reasonably be re-identified.
- We may use or commercialize such anonymized datasets. You will not receive compensation for this.
- You may request to opt out of future inclusion by emailing support@gorillasync.com.
7. Geographic Restrictions
- The Service is intended for users in Canada and the United States.
- We do not target or accept users from the European Union or EEA. Accounts found to be from these regions may be restricted.
8. Children’s Privacy
- The Service is not intended for users under 18. We do not knowingly collect data from minors.
9. Changes to This Policy
- We may update this Privacy Policy from time to time.
- For material changes, we will provide notice through the website or by email.
- The “Last Updated” date at the top reflects the most recent revisions.
10. Contact
For questions about this Privacy Policy or your data, contact: