Bazoom
Privacy Terms

Privacy Policy

Last Updated: August 1, 2026

Introduction

Bazoom ("we," "our," or "us") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, store, and safeguard Google user data when you use our Google OAuth authorization service. This policy complies with the Google API Services User Data Policy and Google APIs Terms of Service.

1. Data Accessed

When you authorize our application through Google OAuth, we request access to the following specific types of Google user data:

  • Google Drive Files (Limited Scope): We use the https://www.googleapis.com/auth/drive.file scope, which provides access only to files that our application creates. This scope allows us to:
    • Create new Google Sheets files in your Google Drive
    • Read and modify Google Sheets files that our application has created
    • Delete Google Sheets files that our application has created
    • Manage sharing settings for Google Sheets files that our application has created
    Important: This scope does NOT grant access to your existing Google Drive files, files created by other applications, or any other files in your Google Drive account.
  • Email Address: We use the https://www.googleapis.com/auth/userinfo.email scope to access your Google account email address. This is used solely for:
    • Identifying your account and associating it with your authorization tokens
    • Account management and token administration
    • Providing you with access to your stored tokens

What We Do NOT Access: Our application explicitly does NOT have access to:

  • Your existing Google Drive files, folders, or documents
  • Your Google Docs, Slides, or other Google Workspace files
  • Your Gmail messages or contacts
  • Your Google Calendar events
  • Your personal photos or media files
  • Any files created by other applications
  • Any other Google services or data beyond what is explicitly listed above

2. Data Usage

We use the Google user data we access exclusively for the following purposes:

  • OAuth Token Management: We store your OAuth access tokens and refresh tokens to maintain your authorization session. These tokens are used to authenticate API requests to Google services on your behalf.
  • Google Sheets Creation and Management: We use your authorization tokens to:
    • Create new Google Sheets documents in your Google Drive
    • Read data from Google Sheets that our application has created
    • Modify or update Google Sheets that our application has created
    • Manage sharing permissions for Google Sheets that our application has created
  • Account Identification: We use your email address to:
    • Associate your authorization tokens with your Google account
    • Provide you with access to view and manage your stored tokens
    • Enable account-specific token management features
  • Service Operation: We process your data to:
    • Maintain your authorization session
    • Refresh expired access tokens using refresh tokens
    • Log authorization activities for security and troubleshooting purposes

We will never use your Google user data for any other purpose, including but not limited to advertising, marketing, data mining, or any purpose unrelated to providing the core functionality of our service.

3. Data Sharing

We do not sell, trade, rent, or share your Google user data with any third parties.

Your Google user data (including OAuth tokens and email address) is used solely for the purposes described in this Privacy Policy and is never shared with:

  • Third-party service providers
  • Advertising networks or marketing companies
  • Data brokers or analytics services
  • Any other external parties

The only exception to this policy would be if we are required to disclose information by law, court order, or legal process, or if disclosure is necessary to protect our rights, property, or safety, or that of our users or others.

No Third-Party Access: We do not grant any third parties access to your Google user data for any purpose, including processing, analysis, or storage.

4. Data Storage & Protection

We implement comprehensive security measures to protect your Google user data:

  • Secure Storage: Your OAuth tokens are stored securely on our servers in encrypted format. Token files are stored in a protected directory with restricted file-level permissions (750) that prevent unauthorized access.
  • Encryption: All data transmission between your browser and our servers uses HTTPS/TLS encryption to protect data in transit.
  • Access Controls: Access to stored tokens is restricted to authorized personnel only, and all access is logged for security auditing purposes.
  • Server Security: Our servers are protected by:
    • Firewall rules and network security measures
    • Regular security updates and patches
    • Intrusion detection and monitoring systems
    • Secure file system permissions
  • Session Security: We implement secure session management with:
    • HttpOnly cookies to prevent JavaScript access
    • Secure flag to ensure cookies are only sent over HTTPS
    • CSRF (Cross-Site Request Forgery) protection tokens
    • Session timeout mechanisms
  • Input Validation: All user inputs are sanitized and validated to prevent injection attacks and other security vulnerabilities.
  • Error Handling: Error messages are logged securely and do not expose sensitive information to users.
  • Regular Audits: We perform regular security audits and reviews of our data storage and protection practices.

Despite these security measures, no method of transmission over the Internet or electronic storage is 100% secure. While we strive to use commercially acceptable means to protect your data, we cannot guarantee absolute security.

5. Data Retention & Deletion

Data Retention Policy: We retain your Google user data (OAuth tokens and email address) for as long as necessary to provide our services to you, or until you request deletion of your data, whichever comes first.

Specifically:

  • Active Accounts: If you continue to use our service, we retain your data to maintain your authorization and provide ongoing functionality.
  • Inactive Accounts: If you revoke access through Google but do not request deletion, we may retain your data for a reasonable period to allow you to re-authorize if desired.
  • Logs: Activity logs are retained for security and troubleshooting purposes for a period of up to 90 days, after which they are automatically deleted.

How to Request Data Deletion: You have the right to request deletion of your Google user data at any time. To request deletion, you can:

  1. Revoke Access via Google: Go to your Google Account Permissions page, find "Bazoom" in the list of connected apps, and click "Remove Access". This will immediately revoke our ability to access your Google account.
  2. Request Server-Side Deletion: Contact us at privacy@bazoom.net to request that we delete your stored tokens and associated data from our servers. Please include your email address in your request so we can identify your account.

Deletion Process: Upon receiving a valid deletion request:

  • We will delete your OAuth tokens from our servers within 30 days of your request
  • We will delete your email address and any associated account data
  • We will delete or anonymize any activity logs associated with your account
  • We will confirm deletion via email once the process is complete

Note: After deletion, you will need to re-authorize our application if you wish to use our services again in the future.

6. How to Revoke Access

You can revoke our access to your Google account at any time by:

  1. Going to your Google Account Permissions page
  2. Finding "Bazoom" in the list of connected apps
  3. Clicking "Remove Access"

Revoking access will immediately prevent our application from accessing your Google account. However, to ensure complete deletion of your data from our servers, please also contact us at privacy@bazoom.net to request server-side deletion.

Children's Privacy

Our service is not intended for children under 13 years of age. We do not knowingly collect personal information from children under 13.

Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of any changes by posting the new Privacy Policy on this page and updating the "Last Updated" date.

Contact Us

If you have questions about this Privacy Policy or your data, please contact us at:

Email: privacy@bazoom.net

Back to Home
Bazoom Bazoom Authorization Service
Privacy Policy Terms of Service
© 2026 Bazoom. All rights reserved.