Introduction
This Privacy Policy describes how Nexobiz Cloud ("Nexobiz Cloud", "Nexobiz", "we", "us") processes personal information when you visit https://nexobiz.cloud, register for a trial, subscribe, sign in, use tenant workspaces, or authorize optional third-party integrations.
This policy is written for Google OAuth App Verification and complies with Google API Services User Data Policy requirements. It applies to all users of the Nexobiz Cloud platform and connected Google integrations.
About Nexobiz Cloud
App name: Nexobiz Cloud. Organization: Nexobiz Cloud (Philippines). Website: https://nexobiz.cloud.
Nexobiz Cloud is a multi-tenant business SaaS platform for CRM, sales, projects, media library, email marketing, calendar, and business operations. Each customer organization receives an isolated workspace (tenant) with role-based access, module activation, and optional connected apps such as Google Drive and Google Calendar.
Information We Collect
We collect information in these categories:
- Account & profile data — name, email, phone, company name, role, avatar, and authentication identifiers (including SSO subject IDs from Google, Microsoft, or SAML).
- Billing data — plan selection, invoices, payment status, and transaction references processed by payment providers (we do not store full card numbers).
- Workspace content — records you create in CRM, sales, projects, HR, payroll, email marketing, and other modules, including files you upload or import.
- Connected-app authorization data — when an authorized user connects a third-party service, we store OAuth access tokens and refresh tokens (encrypted at rest), granted permission scopes, connected account identifiers, display names, and connection status per tenant.
- Third-party content metadata — file names, MIME types, sizes, thumbnails, external IDs, and import/sync timestamps needed to operate the Media Library and calendar sync features.
- Integration activity logs — connection events, token refresh outcomes, sync/import results, and error messages (we do not log raw secrets, client secrets, or full OAuth tokens in plain text).
- Usage & device data — IP address, browser type, session identifiers, feature usage, audit logs, and security events.
- Support & communications — messages you send through contact forms, email, or in-app support channels.
Google User Data We Access
When a tenant administrator or authorized user connects a Google integration, Nexobiz Cloud may access only the Google user data required for the selected feature. We collect the minimum data necessary and do not request broad Google permissions beyond what each live feature requires.
Depending on which integration you connect, Google user data may include:
- Google account name, Google email address, and Google profile information (openid, email, profile scopes) — used to identify the connected account in integration settings.
- Google Drive files you browse, select, or authorize for import — file names, file IDs, folders, thumbnails, MIME types, sizes, and document metadata needed for Media Library integration. We use drive.readonly to let authorized users search and import files into their tenant Media Library.
- Google Calendar events authorized by the user — event title, date, time, attendees, location, and meeting links when using Calendar integration for CRM form bookings, appointments, or read-only calendar aggregation in My Action Hub. We use calendar.events for create/sync/read workflows you enable.
- Gmail metadata or email content — only if and when a production Gmail integration is enabled by your workspace and you explicitly connect it. Gmail API scopes are not included in our current Google OAuth verification submission unless a live Gmail feature is enabled for your tenant.
How We Use Google User Data
Google user data is used only to provide Nexobiz Cloud features requested by the tenant or authorized user, such as:
- Connecting Google Drive to the tenant Media Library so authorized users can browse, search, import, or manage selected Drive files within their workspace.
- Syncing Google Calendar events with CRM form appointments, bookings, or read-only calendar views in My Action Hub when calendar sync is enabled.
- Creating or updating calendar events (including Google Meet links where configured) when a user submits a booking or triggers a calendar sync action.
- Displaying connected account information inside tenant integration settings and diagnostics.
- Refreshing OAuth tokens securely to maintain connections until you disconnect.
- Improving user-facing app functionality within the connected feature (for example import progress, sync status, and error recovery).
Prohibited Uses of Google User Data
Nexobiz Cloud does not use Google user data for advertising, retargeting, selling data, credit scoring, lending, data brokerage, or training AI models.
Google user data is not used to build advertising profiles, create unrelated marketing databases, or determine credit-worthiness. We do not sell Google user data to third parties.
Google user data is not sent to AI model providers unless a user explicitly triggers a user-facing AI feature and the data is required for that specific request (for example generating copy about an asset the user selected). Google user data is never used to train AI models.
We do not transfer Google user data to third parties for advertising or unrelated purposes.
How We Share Information
We do not sell Google user data or personal information.
Google user data may only be shared with trusted service providers when necessary to operate Nexobiz Cloud features, such as secure cloud hosting, database storage, authentication, logging, email delivery, and infrastructure. All subprocessors process data only to provide or improve app functionality under contractual safeguards.
When you use a connected app, Google may receive your authorization request, approved scopes, and API calls we make on your behalf. Third-party providers process data under their own privacy policies.
We may disclose information when required by law, to protect rights and safety, or in connection with a merger or acquisition with appropriate safeguards.
Data Security
We implement administrative, technical, and organizational measures to protect sensitive data, including:
- Encrypted HTTPS connections for all web and API traffic.
- Secure database storage with tenant data isolation — one tenant cannot access another tenant's Google files, calendar events, or OAuth tokens.
- Role-based permissions controlling who can connect, disconnect, browse, import, or manage integrations.
- OAuth access tokens and refresh tokens encrypted at rest using server-side encryption (Laravel Crypt / application key).
- Limited employee and developer access on a need-to-know basis.
- Audit logs for sensitive integration actions (connect, disconnect, token refresh, import, sync).
- Secure credential handling — client secrets and tokens are never exposed in browsers or plain-text application logs.
- Regular security review and monitoring of integration health and error patterns.
Data Retention and Deletion
Google user data is retained only as long as needed to provide the connected feature or comply with law.
When you disconnect a Google integration from tenant settings, Nexobiz Cloud revokes OAuth tokens with Google where possible and deletes stored tokens from our database. Connected account status changes to disconnected and future API access stops.
Content already imported into your Media Library or synced calendar records may remain in your workspace until you or your administrator deletes it, even after the external connection is removed.
Users and tenant administrators may request deletion of Google-related data by disconnecting integrations and deleting imported files or synced records within the workspace.
When the retention period expires or you request deletion, data is deleted or anonymized where legally permitted. Security logs and anonymized audit events may be retained longer according to operational requirements.
See our Disconnect / Revoke Access Guide at /help/disconnect-google-integrations for step-by-step instructions.
User Controls and Disconnecting Google Integrations
Authorized workspace users can disconnect Google integrations at any time:
- Google Drive — Media Library → Connected Apps → Google Drive → Disconnect. Confirms removal of OAuth access for the workspace.
- Google Calendar — CRM Forms studio → Calendar & meeting providers → Google Calendar → Disconnect, or My Action Hub → Calendar tab → manage connection.
- Google sign-in (SSO) — Account Settings → Connected accounts → revoke the linked Google account, or revoke Nexobiz Cloud in your Google Account security settings.
- You may also revoke access directly at https://myaccount.google.com/permissions under Third-party apps with account access.
Other Connected Apps & Third-Party Authorizations
Nexobiz Cloud also offers optional non-Google integrations (Canva, OneDrive, Dropbox, Box, Meta business tools, Microsoft sign-in, payment processors, and AI services). These are disabled until enabled by platform configuration and authorized by an authorized tenant user.
We use industry-standard OAuth 2.0 (including PKCE where required). Token exchange occurs server-side; client secrets never occur in your browser. Each tenant connection is isolated.
Cookies and Logs
We use session cookies and similar technologies to maintain login sessions, protect against CSRF, and remember preferences on our marketing site.
Server logs may record IP addresses, user agents, request paths, and error events for security and reliability. Integration logs record connection outcomes without storing raw OAuth tokens.
Your Rights & Contact Information
Subject to applicable law (including the Philippine Data Privacy Act of 2012), you may request access, correction, deletion, or restriction of personal information we control about you.
Workspace members should contact their organization's administrator for tenant-held data requests. Platform account holders may contact us at the email shown on this page.
For Meta-related data, see also our Facebook/Meta data deletion instructions at /privacy/facebook-data-deletion.
For privacy inquiries, data subject requests, integration questions, or security reports, contact us at the email shown below. We aim to respond within a reasonable timeframe.
Updates to This Privacy Policy
We may update this Privacy Policy from time to time, including when we add or change Google integrations or connected-app features. The effective date at the top of this page indicates the latest revision. Continued use after changes constitutes acceptance where permitted by law.