1. Scope and who we are
Choogha Inc. (“Choogha,” “we,” “us,” or “our”) is a Canadian software company based in Vancouver, British Columbia. We develop custom business software and operate products including Business Suite.
This Privacy Policy applies to choogha.com, Business Suite, and other Choogha services that link to it. A customer organization may control the business records placed in its workspace. In those circumstances, the customer determines why that information is processed and Choogha processes it to provide the contracted service. Questions about records controlled by your employer or organization may need to be directed to that organization first.
2. Information we handle
Information you or your organization provides
- Names, business email addresses, telephone numbers, titles, and profile details.
- Account credentials, membership, role, permission, and workspace information.
- Support requests and communications with Choogha.
- Business records entered into the service, such as customers, vendors, employees, projects, quotations, invoices, notes, files, and related operational information.
- Payment, subscription, and commercial information where applicable to a customer relationship.
Information generated through use of the services
- Authentication, security, access-control, and audit events.
- Device, browser, IP address, request, error, and diagnostic information.
- Feature usage, delivery status, and service-performance information.
- Records of outbound communications, which may include recipients, subject lines, message bodies, attachments, delivery results, and related business records.
Website information
If you contact us through the website or by email, we receive the information you choose to provide. Our hosting and network providers may also process ordinary technical logs needed to deliver and protect the website. We do not sell personal information or use Google user data for advertising.
3. Google Workspace and Google API data
Business Suite requests the narrow
https://www.googleapis.com/auth/gmail.send permission so an authorized
workspace account owner can connect the company sender and an authorized workspace
user can connect their own managed Google Workspace mailbox to send approved
business messages from it.
Google information we access or store
- The connected account’s verified email address, Google account identifier, and Google Workspace hosted domain.
- The OAuth permissions granted to Business Suite.
- Access and refresh credentials required to send authorized messages. Refresh credentials are encrypted at rest and are not shown to workspace users or Choogha personnel through the application.
- The recipients, subject, message content, and attachments that the customer directs Business Suite to send through the connected mailbox.
- Google delivery identifiers and success or failure information.
Google information we do not access
Business Suite does not use the Google connection to read inbox messages, list or search messages, access contacts, read drafts, inspect mailbox history, or change mailbox settings. We do not use Google user data for advertising, credit decisions, data brokerage, or training general-purpose artificial intelligence models.
Limited Use disclosure
Business Suite’s use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy , including the Limited Use requirements.
We use Google user data only to provide and protect the user-facing email features selected by the customer. We do not sell Google user data. We disclose it only to service providers acting for us where necessary to operate or secure the service, when directed or consented to by the customer, as required by law, or in connection with a corporate transaction subject to applicable notice and consent requirements.
4. How we use information
We use information where reasonably necessary to:
- Provide, configure, maintain, and improve the services.
- Authenticate users and enforce workspace, brand, role, and permission boundaries.
- Store, process, display, generate, and deliver customer-directed business records.
- Send invitations, password resets, quotations, invoices, and service notifications.
- Provide customer support and respond to inquiries.
- Monitor reliability, troubleshoot errors, prevent abuse, and protect security.
- Comply with legal obligations and enforce our agreements.
6. Retention and deletion
We retain information for as long as reasonably necessary to provide the services, satisfy the customer’s configured business and record-retention needs, maintain security and audit history, resolve disputes, and meet legal obligations.
A connected Google refresh credential is retained while the email connection remains active. Disconnecting the mailbox removes the active credential from Business Suite and initiates revocation with Google where supported. Outbound business messages and delivery records may remain in the customer workspace according to the customer’s service and legal retention requirements.
Deleted files may remain recoverable for a limited retention period before permanent deletion. Backups and security records may persist for a limited additional period before being overwritten or deleted through normal retention cycles.
7. Security
We use administrative, technical, and organizational safeguards designed to protect information, including encryption in transit, encryption of stored email credentials, tenant and brand isolation, role-based access controls, private object storage, audit logging, and restricted administrative access. No system can guarantee absolute security, and customers remain responsible for protecting their accounts and assigning appropriate user permissions.
8. Your choices and privacy rights
Depending on your location and relationship with Choogha, you may have rights to request access, correction, deletion, restriction, portability, or objection regarding your personal information. We may need to verify your identity and may direct a request to the customer organization that controls the relevant workspace records.
Workspace administrators can disconnect a Google Workspace mailbox in Business Suite. A Google account administrator can also review or revoke access from the account’s Google security permissions. To make a privacy request, contact us using the information below.
9. International processing
Choogha is based in Canada. We and our service providers may process information in Canada, the United States, and other jurisdictions where our providers operate. Those jurisdictions may have privacy laws that differ from the laws where you live. We use contractual and operational safeguards appropriate to the nature of the processing.
10. Children
Our business services are not directed to children and are intended for authorized personnel of customer organizations. We do not knowingly collect personal information from children through these services.
11. Changes to this policy
We may update this Privacy Policy as our services, practices, or legal requirements change. We will post the revised policy at this location and update the effective date. Where required, we will provide additional notice through the service or customer relationship.
12. Contact us
Questions, complaints, and privacy requests may be sent to:
Choogha Inc.
700–838 West Hastings Street
Vancouver, British Columbia V6C 0A6
Canada
support@choogha.com