This covers the Corp website at corpsystems.net and the Corp app. It is written so you can actually read it, and if any part of it is unclear you can ask us and get a straight answer from a person.
Corp is an independent software business, and every message sent to hello@corpsystems.net is read by a person rather than dropped into a ticket queue.
Files you upload. If you hand a tool on this site a file, like a card statement for the spend check, we read it, give you your result, and delete the file from the server within 24 hours. The result goes to your browser and the statement does not stick around anywhere.
Account data you connect. If you connect a Google account, we request only the scopes listed under Google user data below. If you connect a Microsoft account, the equivalent applies through Microsoft Graph.
Data your business already holds. When Corp runs on your own machine, your data never leaves it. Your reviews, your mailbox, your applicants and your spending are read where they already sit, and none of it gets uploaded to us.
Basic site data. Ordinary web server logs, so an IP address, a browser type, which page was asked for and when. We keep those 30 days to fix faults and spot abuse and then throw them away. There is no advertising tracker, no analytics pixel and no third party cookie anywhere on this site.
This section exists because Google requires it, and because it is the part most worth reading.
The scopes we request, and why each one:
.../auth/business.manage to read the reviews left on your Google Business Profile and to publish the reply you approved. This is the only way to reply to a review through Google's own interface rather than by driving a browser..../auth/gmail.modify to read incoming mail so a reply can be drafted, and to place that draft in your Drafts folder. We request gmail.modify rather than full mail access precisely because gmail.modify cannot permanently delete a message.What we do with it. We read a review so we can write you a reply to it, and we read your mail so we can work out whether it needs you and draft the answer. That is the whole of it.
What we never do with it. We do not sell it. We do not transfer it to anyone except a subprocessor listed below, and only as needed to run the feature you asked for. We do not use it for advertising. We do not use it to train, retrain, or fine tune any machine learning model. No human at Corp reads your mail or your reviews except where you have specifically asked for support on a problem, where the access is limited to what is needed to fix it, and where it is logged.
Limited Use. Corp's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
Sending. Corp does not send email on your behalf. Every reply it writes is placed in your Drafts folder and waits for you. The only content Corp publishes anywhere on its own is a reply to a Google review, and only where you have explicitly switched that on and set the rules for it.
This is the question everybody asks first, so here is the honest answer in order. Your account has its own key, generated at random rather than worked out from your name or your email, so nobody can guess their way into it from the outside.
Every single request for your information is filtered by who you are down at the database, not up in the page. That distinction matters more than it sounds: a boundary in the interface is a boundary somebody can walk around by editing a web address, and a boundary in the database is one they cannot. There is no account number in any request for anybody to change.
Anything of yours that we do store is locked with a key belonging to your account and nobody else's, so even sitting still your information is not readable next to another client's. We test that boundary by attacking it ourselves rather than assuming it holds.
Two people at Corp can open a client account to help with a problem. When that happens it is written down, with who looked, whose account and when, and the screen says whose account is being viewed the entire time. There is no way for us to sign in as you, and nothing we can do from there writes to your records.
We keep this list as short as the product allows:
That is the whole list, and if it ever grows this page gets updated before the new company touches anything.
All of that goes to hello@corpsystems.net.
If you give us your mobile number, we may text you about work in progress, something waiting for your approval, or a reply to a message you sent us. We do not send marketing texts to people who have not asked to hear from us.
We never sell or share your mobile number, and we never share text message consent with anyone else for their own marketing. Your number is used to reach you and nothing else.
Credentials live in configuration on the machine, never in the code and never in a message, and one that leaks gets killed and replaced rather than left alone. The full detail of how clients are kept apart is on the security page.
Corp is a tool for businesses. It is not directed at anyone under 18 and we do not knowingly collect data from them.
If we change this in a way that affects what happens to your data, you hear about it before it takes effect rather than after, and the date at the top is always the version you are reading.