Google API Services Disclosure
Last Updated: 14 August 2026
This disclosure describes how TravelCS accesses, uses, stores, shares and deletes information received from Google API Services (including Gmail and Google Workspace). It supplements the TravelCS Privacy Policy and applies specifically to data obtained through Google APIs after explicit user authorization.
1. Google API Services Disclosure
TravelCS's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
2. What Google Data We Access
TravelCS accesses Google Workspace data only after the authenticated user explicitly authorizes the connection through Google's OAuth consent screen. Only the minimum permissions required to deliver the requested functionality are requested.
The categories of Google Workspace data that may be accessed include:
- Gmail messages
- Email subjects
- Sender and recipient information
- Email metadata (thread IDs, message IDs, timestamps)
- Attachments where required for customer-support workflows
- The connected Google account's email address and profile name (for identification only)
3. Google Permissions Used
The application requests exactly two Gmail scopes, plus one identity scope:
https://www.googleapis.com/auth/gmail.readonly
Used to:
- read customer email conversations;
- retrieve message metadata;
- retrieve conversation threads;
- retrieve attachments required for customer support.
https://www.googleapis.com/auth/gmail.send
Used only when an operator explicitly sends or approves an outgoing email from TravelCS. TravelCS never sends emails automatically.
https://www.googleapis.com/auth/userinfo.email
Used only to identify which Google account was connected, so the connected mailbox address can be displayed in TravelCS settings.
Scopes TravelCS never requests
gmail.modifygmail.composegmail.insertgmail.labelsgmail.metadatagmail.settings.*https://mail.google.com/any Google Drive scopeany Google Calendar scope
TravelCS does not request gmail.modify, gmail.compose, gmail.insert, gmail.labels, gmail.metadata, any gmail.settings.* scope, the full-access https://mail.google.com/ scope, or any Google Drive or Google Calendar scope. TravelCS performs no Gmail writes other than sending an operator-approved email.
Sign-in with Google (when used to log in to TravelCS) additionally uses the standard openid, email and profile identity scopes to create or match your TravelCS account. These are identity scopes only and grant no access to Google Workspace data.
3.1 What TravelCS Does With These Permissions
- Displaying Gmail conversations inside the TravelCS unified Inbox.
- Synchronizing incoming customer emails with the operator's TravelCS workspace.
- Generating AI-assisted reply drafts inside TravelCS that the operator reviews before sending — no Gmail draft is ever created.
- Sending operator-approved replies from the operator's own Gmail account.
- Linking email conversations with the corresponding bookings or leads.
TravelCS performs no Gmail writes other than sending an operator-approved email. It does not change read/unread state or labels, does not create Gmail drafts, does not archive, delete or trash emails, does not manage folders or mailbox organization, and does not access Gmail settings.
Every permission supports functionality that the operator can see and control inside TravelCS.
3.2 Trust & Transparency — Principle of Least Privilege
TravelCS follows the Principle of Least Privilege. Gmail permissions are limited to what is strictly necessary for the Inbox feature, and they are reduced whenever functionality no longer requires broader access. When a scope stops being needed, it is removed from the consent request rather than kept "just in case". Connections that Google grants only partially are rejected at connect time instead of being silently downgraded.
4. Artificial Intelligence
- AI features are used only to assist the authenticated operator.
- Google Workspace data is processed only to generate personalized reply drafts inside TravelCS and workflow suggestions for that operator. These drafts live in TravelCS only — they are never written back to Gmail as Gmail drafts.
- Google Workspace data is never used to train generalized artificial intelligence models.
- Google Workspace data is never used to improve foundation models.
- The underlying model providers TravelCS uses are contractually bound not to train on API traffic sent through TravelCS.
5. What We Never Do
- We never sell Google user data.
- We never use Google Workspace data for advertising, ad personalization or ad targeting.
- We never use Google Workspace data for marketing profiling.
- We never allow third-party AI providers to train on Google Workspace data.
- We never access a Google account without the user's explicit OAuth authorization.
- We never send emails from an operator's Gmail account without an action initiated or authorized by that operator.
6. Limited Use Compliance
Google Workspace data obtained through Google APIs is used exclusively to provide user-facing functionality requested by the authenticated user. TravelCS complies with Google's Limited Use requirements: data is not sold, not shared with advertisers, and not transferred to third parties except to the sub-processors strictly required to operate the requested feature, or where required by law.
7. Data Sharing
Google Workspace data is processed only by the trusted infrastructure providers required to operate TravelCS — cloud hosting, authentication, secure database infrastructure and backups — each bound by a written data-processing agreement. The current list is published at /sub-processors. Google Workspace data is never sold and never shared with advertisers.
8. Data Retention
Google Workspace data is retained only while required to provide the requested services. Users may at any time:
- Disconnect Google from Settings → Channels inside TravelCS — TravelCS revokes and deletes the stored OAuth tokens and stops all further synchronization. Emails already imported into TravelCS remain in your conversation history unless you request deletion.
- Revoke TravelCS's access directly from their Google Account at https://myaccount.google.com/permissions.
- Request deletion of Google Workspace data already stored in TravelCS by submitting a request via our Data Subject Access Request form. Imported Gmail content is retained for the lifetime of the workspace — there is currently no automatic age-based purge — and verified deletion requests are processed within 30 days, subject to applicable legal retention requirements.
Revoking TravelCS's access, either inside TravelCS or from your Google Account, stops all further access to your Google Workspace data and removes the stored authorization credentials. It does not by itself delete Gmail content already imported into your TravelCS workspace; that content stays in your conversation history until the workspace is deleted or you request its deletion. When a workspace is deleted, its data is removed from our live systems and a recovery backup is retained for the documented restore window (see /retention) before being permanently purged, unless a longer period is legally required.
9. Security
- HTTPS / TLS encryption in transit.
- Encryption at rest for stored data and OAuth tokens.
- Secure authentication for all operator accounts.
- Role-based access controls scoped to each operator workspace.
- Least-privilege principles for internal and infrastructure access.
- Audit logging for security-relevant events.
- EEA-hosted infrastructure by default.
10. Contact
For privacy questions, Google API questions, or data deletion requests:
- Privacy and Google user data: info@travelcs.ai
- General: info@travelcs.ai
- Data deletion requests: submit via our Data Subject Access Request form
This disclosure supplements the TravelCS Privacy Policy and applies specifically to information received through Google API Services.