Privacy Policy
- 1. Introduction & Application Identity
- 2. Information We Collect
- 3. Google User Data & OAuth 2.0 Scopes
- 4. Google API Services User Data Policy (Limited Use Requirements)
- 5. How We Use Collected Information
- 6. Information Sharing & Prohibition on Data Reselling
- 7. Data Storage, Encryption & Security Standards
- 8. Data Retention & Account Deletion
- 9. How to Revoke Google Account Access
- 10. User Rights (GDPR, CCPA & Global Compliance)
- 11. Children's Privacy
- 12. Contact Information & Data Protection Officer
1. Introduction & Application Identity
Welcome to VIPMaal ("we," "our," "us," or "the Application"), accessible at https://vipmaal.com. VIPMaal is an email management and mailbox synchronization platform designed to assist users in organizing, managing, and reading authorized mailbox communications efficiently.
We are committed to maintaining the privacy, confidentiality, and security of all personal information entrusted to us. This Privacy Policy explains how we collect, use, process, disclose, and protect your information when you access or use VIPMaal, including when you integrate your Google account via Google OAuth 2.0.
By creating an account, accessing, or using VIPMaal, you acknowledge that you have read, understood, and agreed to the practices described in this Privacy Policy and our Terms of Service.
2. Information We Collect
We collect information in the following categories:
A. Account and Registration Information
- User Credentials: Your name, email address, and cryptographically hashed passwords (using industry-standard bcrypt) for account authentication.
- Profile Information: Assigned user roles (e.g., Administrator, Mailbox Owner/Seller, Authorized User/Buyer) and account preferences.
B. Operational and Usage Data
- Activity and Audit Logs: Timestamps, mailbox assignments, usage numbers, status changes, IP addresses, and User-Agent strings stored solely for security monitoring, fraud prevention, and audit compliance.
- Session Cookies: Secure, HTTP-only, SameSite session identifiers utilized strictly for maintaining authenticated session state.
3. Google User Data & OAuth 2.0 Scopes
VIPMaal offers integrations with Google services through official Google OAuth 2.0 APIs. When you choose to connect a Google account (such as Gmail), we request only the minimal permissions required to deliver our core synchronization and webmail reading services:
-
https://www.googleapis.com/auth/gmail.readonly: Grants read-only access to view email messages, message threads, message snippets, timestamps, sender/recipient addresses, labels, and message attachments. VIPMaal does NOT request or possess permissions to send emails on your behalf, compose drafts, delete messages, modify inbox labels, or alter your account security settings. -
https://www.googleapis.com/auth/userinfo.email: Allows VIPMaal to identify the connected Gmail address for mailbox association and account verification. -
https://www.googleapis.com/auth/userinfo.profile: Allows VIPMaal to retrieve your display name and basic account avatar to personalize your dashboard interface.
4. Google API Services User Data Policy (Limited Use Requirements)
Official Google Limited Use Disclosure:
VIPMaal's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
In accordance with the Google Limited Use requirements, VIPMaal explicitly adheres to the following restrictions regarding Google user data:
- Strict Purpose Limitation: Google user data is accessed, processed, and utilized exclusively to provide and improve the user-facing webmail and mailbox organization features of VIPMaal.
- Prohibition on Data Reselling: VIPMaal will never sell, license, rent, or monetize Google user data or personal data to any third party.
- Prohibition on Advertising Use: Google user data is NEVER used for serving advertisements, including personalized, contextual, re-targeted, or interest-based advertising.
- Prohibition on Credit or Lending Evaluation: Google user data is never used for determining creditworthiness, lending eligibility, or insurance underwriting.
- Prohibition on AI/ML Model Training: Google user data is not used to train generalized artificial intelligence or non-personalized machine learning models without your explicit opt-in consent.
-
Restricted Human Access: No VIPMaal personnel, employees, or contractors are permitted to read your email messages or Google user data, unless:
- You have provided explicit, affirmative consent for technical troubleshooting of a specific issue;
- It is strictly necessary for security investigations (such as detecting system abuse, malicious payloads, or security breaches);
- It is required to comply with applicable laws, court orders, or governmental regulations; or
- The data is aggregated and completely anonymized for internal system performance diagnostics.
5. How We Use Collected Information
We use the information we collect for the following specified purposes:
- Service Delivery: To authenticate your identity, synchronize mailbox folders, display incoming messages, and execute authorized mailbox operations within your VIPMaal dashboard.
- Dot-Alias Email Routing: To facilitate Gmail dot-alias assignment and tracking within the 25-usage lifecycle framework.
- Security & Authentication: To protect accounts against unauthorized access, brute-force attempts, session hijacking, and malicious activity.
- Customer Support: To investigate and resolve technical inquiries, bug reports, and account access questions submitted to
support@vipmaal.com.
7. Data Storage, Encryption & Security Standards
VIPMaal implements rigorous technical, administrative, and physical safeguards:
- Token Encryption at Rest: All OAuth 2.0 refresh tokens, access tokens, and sensitive authentication credentials are encrypted in our database using authenticated AES-256-GCM encryption. Encryption keys are stored separately from data tables.
- Data in Transit: All data transmitted between your browser, our servers, and Google APIs is strictly encrypted using Transport Layer Security (TLS 1.3 / HTTPS).
- Cookie Security: Session cookies are flagged with
HttpOnly,Secure(in production), andSameSite=Laxto prevent Cross-Site Scripting (XSS) and Cross-Site Request Forgery (CSRF). - Content Sanitization: Incoming email HTML bodies and attachments are parsed through server-side sanitization engines that strip executable scripts, dangerous SVG payloads, and tracking pixels prior to rendering.
8. Data Retention & Account Deletion
We retain your account information and encrypted credentials only for as long as your VIPMaal account remains active or as needed to provide you with the services.
- Disconnecting Mailboxes: When you disconnect a connected Gmail account from VIPMaal, all associated OAuth refresh tokens, access tokens, and cached message identifiers are permanently and immediately erased from our database.
- Account Deletion: You may request full deletion of your VIPMaal user account and all associated data at any time by emailing
support@vipmaal.com. Upon receipt, we will permanently purge all your user records within seven (7) business days.
9. How to Revoke Google Account Access
You maintain continuous control over VIPMaal’s access to your Google account. You may revoke access at any time through either of the following methods:
- Through VIPMaal Dashboard: Navigate to the Mailbox Management or Settings tab in your VIPMaal dashboard and click "Disconnect Mailbox".
-
Directly Through Google Security Settings: You can immediately and unconditionally revoke VIPMaal's permissions by visiting Google's official management page:
https://myaccount.google.com/permissions (Google Third-Party Apps with Account Access) .
Select VIPMaal and click "Remove Access". Upon revocation, VIPMaal will immediately lose all ability to access your Google account or refresh tokens.
10. User Rights (GDPR, CCPA & Global Compliance)
Depending on your geographic jurisdiction, you have the following rights regarding your personal information:
- Right of Access: The right to request copies of your personal information held by us.
- Right to Rectification: The right to request correction of any inaccurate or incomplete information.
- Right to Erasure ("Right to be Forgotten"): The right to request that we delete your personal data under certain conditions.
- Right to Restrict Processing: The right to request that we restrict the processing of your personal data.
- Right to Data Portability: The right to receive your personal data in a structured, commonly used, and machine-readable format.
To exercise any of these statutory rights, please submit a written request to support@vipmaal.com.
11. Children's Privacy
VIPMaal is not intended for use by individuals under the age of 18 (or the age of legal majority in your jurisdiction). We do not knowingly collect personal information from children. If we become aware that personal information from a minor has been collected, we will take immediate steps to delete such data.
12. Contact Information & Data Protection
If you have any questions, concerns, complaints, or inquiries regarding this Privacy Policy or our Google data handling practices, please contact our data protection team:
Application Name: VIPMaal
Website: https://vipmaal.com
Official Support Email: support@vipmaal.com
Physical Location: VIPMaal Operations