Data Use & Permissions Rationale

This page is intended to support OAuth verification and API quota review requests by explaining least-privilege access and data handling.

How AIRETRIX uses connected data

  • Unified engagement: present messages, reviews, and notifications in one place for business operations.
  • Routing + CRM mapping: route events into the customer’s configured CRM/ORM systems.
  • Approved templates + user-enabled replies: send responses only when enabled by the customer, using customer-approved templates and configurations, subject to platform policies and opt-outs.
  • Analytics: aggregate insights across connected platforms (reviews, post performance, response times) for business intelligence.

Least-privilege principles

  • Permissions are requested only when a user enables the matching feature.
  • Scopes are limited to the minimum required (read events where possible; write only when the user enables replying/publishing).
  • Users can revoke access at any time; the service must continue to function gracefully with reduced permissions.

Google user data policy alignment (summary)

  • We do not use Google user data for advertising.
  • We do not sell Google user data.
  • We use Google user data only to provide the user-requested features described here.

Typical permissions (examples)

Actual scopes vary by customer configuration and features enabled.

  • Google Business Profile: read/manage business content and respond when enabled by the user.
  • Google notifications: receive event notifications to trigger routing and alerts.
  • Gmail (optional): read access only when the user connects Gmail workflows.
  • Meta/Facebook: manage connected business integrations for messaging/workflows when enabled.
  • X (Twitter): manage connected accounts for messaging/workflows when enabled.

Data handling

  • No end-customer PII stored by default; data is encrypted in transit and at rest where stored.
  • We store the minimum operational data needed to provide the service securely and reliably (e.g., OAuth tokens and account identifiers).
  • Customers can request deletion assistance via info@airetrix.com.