Privacy Policy
Last updated: June 3, 2026
MailProvision is operated by Retty Software LLC ("we", "us"). This policy explains what data we collect, why, and how long we keep it. For the specific technical scopes and subprocessors, see our Security page.
What we collect
- Account data: your email, hashed password, and name.
- Workspace OAuth tokens, stored encrypted at rest.
- Per provisioning: end-user name and recovery email submitted via your invite link.
- Billing data via Stripe (we do not store card numbers).
How we use it
Solely to operate MailProvision: authenticate you, connect to your Workspace, provision the users you ask us to, bill the subscription, and respond to support requests.
Who we share data with
We do not sell, rent, or trade your data. We do not share, transfer, or disclose Google Workspace data, or any data we obtain through Google APIs, to third parties except as needed to operate the service for you, where required by law, or in connection with a merger or acquisition. The only parties that ever receive your data are the subprocessors we rely on to run MailProvision:
- Laravel Cloud, our hosting provider, stores the application database (including encrypted OAuth tokens) and runs the application.
- Stripe processes subscription billing. It receives billing data, not Google user data.
- Resend sends transactional email (invites, provisioning notifications). It receives the recipient email addresses required to deliver those messages.
- Google, whose Workspace Admin SDK we call to create the users you ask us to provision.
MailProvision's use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. We do not use Google Workspace data for advertising, and we do not transfer it to others except to provide or improve MailProvision for you, to comply with applicable law, or as part of a merger or acquisition.
How we protect your data
We treat OAuth tokens, recovery emails, and credentials as sensitive data and protect them accordingly:
- Encryption in transit: all traffic is served over TLS (HTTPS), and our calls to Google APIs use TLS.
- Encryption at rest: Google Workspace OAuth access and refresh tokens are encrypted at rest using Laravel's encrypted casts (AES-256). Passwords are stored only as one-way hashes, never in plaintext.
- Access controls: recovery emails and other production data are accessible only to authorized personnel, and each workspace's data is isolated to that account.
- Minimization and deletion: we request the narrowest Google scopes needed to provision users, and OAuth tokens are deleted within 24 hours of disconnecting a Workspace.
Retention
Account and Workspace data: retained while your account is active and for 30 days after deletion. Provisioning records: retained for audit purposes for 13 months. OAuth tokens are deleted within 24 hours of disconnecting a Workspace.
Analytics & cookies
We use Datafast, a privacy-friendly analytics tool, to understand how visitors find and move through the site. By default we run in cookieless mode, no cookies, no cross-site identifiers, only aggregate page counts.
If you click "Accept" on the cookie banner, Datafast switches to its first-party cookied mode, which lets us count returning visits and attribute conversions. That's the only thing the cookie banner controls. You can change your decision any time by clearing mp_consent in your browser cookies for mailprovision.com.
We do not use Google Analytics, Facebook Pixel, or any third-party advertising trackers.
Your rights
Email [email protected] to request access, correction, or deletion of your data.
Contact
Retty Software LLC, [email protected].