Privacy
Privacy Policy
This Privacy Policy explains how Polytrace Inc ("Polytrace", "we", "us", or "our") collects, uses, stores, discloses, and protects personal information through the Polytrace website, product, support channels, and connected-source integrations.
Polytrace is a B2B service for capturing operational communications and files, extracting structured data, monitoring changes, and sharing controlled outputs. Because the product can process emails, files, attachments, calendar data, websites, storage objects, and provider metadata selected by customers, this policy includes specific disclosures for Google, Microsoft, and other connected-source data.
This policy does not replace a signed order form, data processing agreement, business associate agreement, or other written agreement between Polytrace and a customer. If a written agreement applies to a customer workspace, that agreement controls where it conflicts with this public policy.
1. Roles and scope
For public website visits, demo requests, sales communications, account administration, billing administration, and direct support requests, Polytrace generally acts as the controller or business responsible for the personal information it collects.
For customer content processed inside a Polytrace workspace, including connected-source records and derived outputs, Polytrace generally acts as a processor, service provider, or contractor acting on the customer's documented instructions. The customer is responsible for deciding what sources to connect, what data to ingest, which users may access the workspace, what outputs to publish, and how long records should be retained, subject to the applicable agreement.
2. Information we collect
The categories of personal information Polytrace may collect depend on how a person or organization uses the site or service.
- Contact and commercial information. Name, work email address, company, job title, phone number, demo requests, sales communications, support messages, contract details, billing contacts, and similar business information.
- Account and identity information. Login identifiers, profile details, organization membership, role assignments, authentication events, MFA status, SSO identifiers, access grants, and account-security settings.
- Website and device information. IP address, browser and device information, pages visited, referring URLs, approximate location derived from network data, form-submission metadata, and analytics events.
- Operational and security logs. Audit events, access logs, security events, configuration changes, source setup events, delivery events, error logs, and records needed to detect abuse, maintain reliability, and support customer audits.
- Connected-source content and metadata. Email messages, headers, sender and recipient details, mailbox labels or folders, attachments, files, file names, folder paths, document metadata, calendar feed content, website pages, storage object metadata, storage object content, and other source data selected by the customer or authorized user.
- Credentials and tokens. OAuth tokens, API keys, service account credentials, storage credentials, IMAP credentials, and other secrets needed to connect customer-authorized sources. These are stored encrypted or otherwise protected according to the security controls for the service.
- Derived product data. Extracted fields, normalized values, search indexes, previews, alerts, workflow suggestions, audit references, publications, exports, and other outputs generated from customer-authorized records.
3. Sources of information
Polytrace may collect information directly from visitors, prospects, customers, authorized users, customer administrators, connected source providers, payment or billing systems, security tooling, analytics tools, subprocessors, and customer-authorized systems. Product data may also be generated by Polytrace from the customer content that the customer or authorized user chooses to process.
4. How we use information
Polytrace uses personal information and customer content only for legitimate business and service purposes, including:
- providing, operating, securing, monitoring, and improving the website and service;
- creating and administering customer accounts, organizations, workspaces, access controls, billing records, and support relationships;
- connecting customer-authorized sources and syncing records according to the customer's configuration;
- extracting structured data, indexing content, monitoring changes, generating alerts, producing governed outputs, and supporting controlled sharing workflows;
- responding to demo requests, contact requests, support requests, security questions, and legal or compliance requests;
- detecting, preventing, and investigating fraud, abuse, security incidents, policy violations, and service reliability problems;
- maintaining audit logs, provenance records, operational evidence, and legally required records;
- communicating about service changes, administrative matters, product updates, security notices, and commercial follow-up where permitted;
- complying with applicable law, contracts, court orders, government requests, and dispute-resolution obligations.
5. Legal bases for processing
Where privacy law requires a legal basis for processing, Polytrace relies on one or more of the following: performance of a contract, steps requested before entering into a contract, legitimate interests that are not overridden by individual rights, consent, compliance with legal obligations, protection of rights and security, and the customer's documented instructions when Polytrace acts as a processor or service provider.
Customers are responsible for having a lawful basis, notice, authorization, or other required permission for the source data and users they place into the service.
6. Connected-source data and OAuth providers
Polytrace can connect to third-party services only when a customer or authorized user configures the source and grants the required permission. Polytrace does not use provider access to change ingestion policies or connections without customer approval. Provider permissions should be limited to the access needed to provide the configured source feature.
- Google sources. Polytrace may request read-only Gmail and Google Drive permissions, including
https://www.googleapis.com/auth/gmail.readonlyandhttps://www.googleapis.com/auth/drive.readonly, when a customer connects Gmail or Google Drive. - Microsoft sources. Polytrace may request Microsoft Graph permissions such as
Mail.Read,Files.Read.All, andSites.Read.All, along with authentication scopes such asopenid,profile,email, andoffline_access, when a customer connects Outlook, SharePoint, or OneDrive for Business. - Other sources. Polytrace may process data from IMAP mailboxes, hosted inboxes, uploaded inbox archives, calendar feeds, websites, Amazon S3, S3-compatible storage, Google Cloud Storage, Azure Blob Storage, and other customer-authorized source systems supported by the product.
7. Google API Services disclosure
Polytrace's use of raw or derived user data received from Google Workspace APIs adheres to the Google API Services User Data Policy and the Google Workspace API User Data and Developer Policy, including the Limited Use requirements. This section is intended to clearly disclose how Polytrace accesses, uses, stores, protects, shares, retains, and deletes Google user data.
Google data accessed
When a customer connects Gmail, Polytrace may access raw mailbox identity information, message metadata, labels or folders, headers, message bodies, attachments, and related settings or synchronization data available under the read-only Gmail scope. When a customer connects Google Drive, Polytrace may access raw Drive account identity information, file metadata, folder metadata, file content, file hierarchy, and synchronization data available under the read-only Drive scope. Polytrace accesses only the Google accounts, mailboxes, folders, files, labels, queries, and source configurations selected or authorized for the customer workspace. Polytrace does not request a separate category of aggregated or anonymized user data from Google, but it may create derived values, aggregates, or de-identified information from the authorized raw data as part of the permitted product processing described below.
Google data use
Polytrace uses raw Google user data and any derived, aggregated, de-identified, or anonymized data only to provide or improve user-facing Polytrace features that are visible in the product, including source sync, record capture, attachment and file processing, search, filtering, extraction, review, monitoring, alerts, audit trails, controlled sharing, exports, and customer support for those features, or for security, legal, and operational exceptions permitted by the Google API Services User Data Policy. Polytrace does not use Google user data for advertising, retargeting, personalized advertising, sale to data brokers, credit-worthiness decisions, lending decisions, or surveillance.
Google data storage and retention
Google user data may be stored in the customer's Polytrace workspace as raw records, record versions, files, attachments, metadata, search indexes, extracted values, audit references, and generated outputs. Google user data remains in the workspace until it is deleted by an authorized user or administrator, removed under a configured retention policy, deleted following contract termination or a valid deletion request, or otherwise handled under the customer's agreement. Limited copies may remain temporarily in backups or where retention is required for security, audit, dispute-resolution, or legal purposes, and are removed or de-identified according to the applicable backup lifecycle and retention obligations.
Google data protection
Polytrace protects Google user data using encryption in transit and at rest, role-based access controls, least-privilege service access, audit logging, security monitoring, vulnerability management, backup controls, and incident-response processes. OAuth access tokens, refresh tokens, and other credentials are encrypted at rest, and key material is managed separately from the encrypted credentials.
Google data sharing and human access
Polytrace may disclose raw Google user data and derived, aggregated, de-identified, or anonymized Google user data to authorized customer users, customer-approved shared recipients, and subprocessors or security and infrastructure providers that help provide customer-enabled, visible product features. Polytrace may also disclose Google user data when necessary for security or abuse investigation, to professional advisers where necessary to comply with applicable law and subject to confidentiality obligations, to authorities where legally required, or to a successor entity in a permitted transaction only after explicit prior user consent. Polytrace does not sell Google user data or transfer it to data brokers, advertisers, or other third parties for unrelated purposes.
Polytrace personnel do not read Google message, file, or attachment content unless the customer provides documented, explicit consent for personnel to read specific data for support or troubleshooting, access is necessary for security or abuse investigation, access is required by law, or the data has been aggregated and de-identified for permitted internal operations in accordance with applicable law.
Google data deletion and revocation
A customer administrator or authorized user may revoke Polytrace's Google OAuth access through the Google account security settings, delete a source or its records where the product supports that action, or request deletion through the account, support, or contracting process. Revoking OAuth access or scheduling source deletion stops new collection. Revoking OAuth access does not by itself delete Google data already stored in the Polytrace workspace. Source deletion schedules cleanup of records from that source, processing state, search data, and generated results tied to the source. When another authorized deletion action or valid deletion request applies, Polytrace deletes or de-identifies the covered data according to the applicable agreement, subject to limited retention required for security, audit, dispute-resolution, legal obligations, and the ordinary backup lifecycle.
AI and automated processing
Polytrace may use automated processing, extraction engines, classification, normalization, and customer-enabled AI-assisted inference to provide visible product features. When Google user data is processed by a subprocessor for one of these features, Polytrace limits the transfer to what is needed to provide the customer-enabled feature and uses subprocessors under contract.
Polytrace does not use raw, derived, aggregated, or anonymized Google Workspace user data to create, train, retrain, fine-tune, or improve generalized, shared, or personalized machine-learning or artificial-intelligence models. Polytrace does not transfer Google Workspace user data to a third party that uses it for those purposes. Polytrace also does not use Google Workspace user data for advertising or unrelated profiling.
8. Microsoft and other provider data
For Microsoft and other connected providers, Polytrace uses provider data only to provide the source, extraction, review, monitoring, audit, and governed-sharing features selected by the customer. Polytrace stores source content, metadata, credentials, and derived outputs according to the customer's configuration and agreement. Polytrace does not sell provider data, use it for cross-context behavioral advertising, or use it for credit or lending decisions.
Provider access can usually be revoked through the provider's own account, tenant, app-consent, or security settings. Revoking provider access or deleting a source in Polytrace stops new collection from that source, subject to ordinary processing delays and the retention rules that apply to data already collected.
9. Sharing and subprocessors
Google user data is shared only as described in Section 7, and the general disclosures in this section do not expand the permitted uses or transfers of Google user data.
Polytrace may share personal information with vendors, subprocessors, affiliates, contractors, and professional advisers that support hosting, infrastructure, storage, security, logging, email delivery, analytics, billing, customer support, product operations, extraction, and legal compliance. These recipients are permitted to process information only for the purposes authorized by Polytrace or the applicable customer agreement.
Polytrace may also disclose information when required by law, to protect rights and security, to investigate abuse, to enforce agreements, in connection with corporate transactions, or with the customer's or individual's direction or consent.
10. Cookies and analytics
The public marketing website uses Google Analytics and may use cookies or similar technologies for essential site operation, security, analytics, performance measurement, and attribution. The product may also use cookies and similar technologies for login sessions, security, preferences, and product operation. More detail is available in the Cookie Policy.
11. Security
Polytrace uses administrative, technical, and organizational safeguards designed to protect information against unauthorized access, loss, misuse, alteration, and disclosure. These safeguards may include encryption in transit, encryption or protected storage for credentials, access controls, audit logging, least-privilege practices, network controls, monitoring, vulnerability management, backup controls, and incident-response procedures.
No security program can guarantee absolute security. Customers are responsible for configuring appropriate access controls, source scopes, user permissions, retention settings, and sharing settings for their own workspace.
12. International transfers
Polytrace and its subprocessors may process information in countries other than the country where the information was collected. Where required, Polytrace uses contractual, organizational, and technical safeguards intended to support lawful cross-border transfers, such as data processing terms, standard contractual clauses, equivalent transfer terms, or other recognized transfer mechanisms.
13. Retention
Polytrace retains information only as long as reasonably necessary for the purposes described in this policy, the applicable customer agreement, product configuration, legal requirements, security needs, backup lifecycle, dispute resolution, and audit obligations. Customer content retention may be controlled by workspace settings, source settings, deletion workflows, contractual retention terms, and operational backup schedules.
14. Privacy rights and choices
Depending on location and role, individuals may have rights to request access, correction, deletion, portability, restriction, objection, withdrawal of consent, appeal, or information about how personal information is processed. California residents may also have rights to know, delete, correct, opt out of sale or sharing, limit certain uses of sensitive personal information, and receive non-discriminatory treatment for exercising rights.
Polytrace does not sell personal information and does not share personal information for cross-context behavioral advertising as those terms are used in California privacy law. Polytrace uses sensitive personal information only for permitted service, security, compliance, and customer-instructed purposes.
If Polytrace processes customer content as a processor or service provider, privacy requests about that content may need to be directed to the customer that controls the workspace. Polytrace will assist customers with applicable requests as required by the relevant agreement and law.
15. Children
Polytrace is a business service and is not directed to children. Polytrace does not knowingly collect personal information from children under 16 through the public website or service. If you believe a child has provided personal information to Polytrace, contact us so we can review and take appropriate action.
16. Changes to this policy
Polytrace may update this Privacy Policy from time to time. The updated version will be posted on this page with a new last-updated date. If a change materially affects how Polytrace uses personal information or connected-source data, Polytrace will provide notice or seek consent where required by law, provider policy, or contract.
17. Contact
Questions or requests about this Privacy Policy can be sent through the Contact page or to support@polytrace.com. Provider-consent and OAuth verification questions may also be sent to info@polytrace.com.