Skip to content

Privacy Policy

How Admin Shortstop handles your information, what we do with data you connect from Google, and the choices you have.

Last updated
9 August 2026
Effective
9 August 2026

Who we are

Admin Shortstop is an automation platform for service businesses. It connects to the systems a business already uses — email, phone, text messaging, and their CRM — so that customer requests are captured, routed, followed up, and resolved without repetitive manual work.

This policy is operated by Admin Shortstop LLC, 100 Lorenz St, Loretto, MN 55357, United States. If you have questions about anything here, write to privacy@adminshortstop.com.

Throughout this policy, “you” means the business that signs up and the people who use the product on its behalf. Where we act on behalf of that business — for example when we process the contents of a mailbox they connect — they are the data controller and we are the processor.

Google user data

This is the section Google's reviewers and our customers most need, so it comes first and is deliberately specific.

What we request, and why

Google OAuth scopes requested by Admin Shortstop
ScopeWhy we need it
gmail.readonlyRead messages in the mailbox you explicitly connect, so inbound customer email can be captured and turned into tracked work. Read-only: we can never send, modify, or delete your mail with this permission.
userinfo.emailRead the email address of the Google account being connected, so the connection is labelled correctly and cannot be attached to the wrong organization.
openidConfirm the identity of the Google account completing the connection.

We request nothing else. We do not ask for permission to send mail, to modify labels, or to access Drive, Calendar, Contacts, or any other Google service.

What we store from your mailbox

For each message in a connected mailbox we store: the Gmail message and thread identifiers; the sender's name and address; the To, Cc, Bcc and Reply-To addresses; the subject and preview snippet; the message body in plain text and HTML; the date sent and received; Gmail labels; and read and starred flags.

For attachments we store metadata only — filename, file type, and size. We do not download or retain the contents of attachments.

What we never store

  • Your Google password. We never see it — authentication happens entirely on Google's own sign-in page.
  • Access or refresh tokens in readable form. Refresh tokens are sealed with Google Cloud KMS envelope encryption; only the ciphertext and a wrapped data key are written to our database. Reading the database yields nothing without separate decryption permission held by one service account.
  • Our OAuth client secret anywhere near your browser. The authorization code exchange, token refresh, and revocation all happen server-side.
  • Attachment contents, as described above.

How we use it

  • Matching the sender of a message to a customer or lead record in your CRM.
  • Creating or updating a ticket in your CRM so the request is tracked to resolution.
  • Showing your team the message inside the Admin Shortstop dashboard.
  • Tracking follow-up state, so work is chased or closed on evidence rather than forgotten.

We do not use your Gmail data for advertising, and we do not sell it. We do not use it to train, retrain, or improve generalised artificial intelligence or machine learning models. Where an AI feature acts on a message, it does so only to produce that specific result for you — such as suggesting a reply drafted from your own approved knowledge base — and any AI provider we use is bound by the same restriction.

Limited Use disclosure

Admin Shortstop's use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

Human access

Our staff do not read your mail. The two exceptions are narrow: when you ask us to investigate a specific problem and grant access for that purpose, and where we are compelled by law. Access of either kind is recorded in an audit log that identifies who accessed what and when.

Other information we collect

  • Account information. Your name, work email address, organization name, and role. Used to sign you in and to decide what you are permitted to see.
  • Data from other systems you connect. Where you connect a phone system or a CRM, we process the records you direct us to — call metadata and summaries, text messages, customer and lead records, and tickets — for the same purpose of turning conversations into tracked work.
  • Operational logs. Records of what the automation did and when, including errors and retries, so failures are visible and traceable rather than silent.
  • Website usage. Standard server logs for our public website, including IP address and browser type, kept for security and diagnostics.

Where your data lives and how it is protected

Data is stored on Google Cloud Platform in the United States, and is encrypted in transit and at rest.

  • Every record belonging to a customer carries that organization's identifier, and the database enforces separation with row-level security. Our application connects with a database role that cannot bypass those rules, so a query that fails to specify an organization returns nothing rather than another customer's data.
  • Credentials for connected services are held in a managed secret store and encrypted with Cloud KMS. They are never written to our database in readable form and never sent to a browser.
  • Access to production systems is limited to the people who need it, and administrative actions are recorded in an audit log.

No system is perfectly secure, and we do not claim otherwise. If we become aware of a breach affecting your data we will notify you promptly and tell you what we know.

Who we share data with

We do not sell your data. We do not share it for advertising. We share it only with the service providers that make the product work:

Subprocessors
ProviderPurposeLocation
Google Cloud PlatformApplication hosting, database, encryption key management, and message queueing.United States
Google Workspace APIsSource of the mailbox data you explicitly connect. Data flows from Google to us, not the other way around.United States

We may also disclose data where we are legally required to, or to protect our rights or the safety of others. If our business is transferred, your data may transfer with it, and this policy will continue to apply until you are told otherwise.

How long we keep it

We keep the data in your account for as long as your organization has an active account with us, and for as long as it remains useful for the purpose it was collected — a ticket history is only valuable if it reaches back far enough to be worth consulting.

Disconnecting a mailbox does two things immediately: it revokes our access token with Google, so we can no longer read that mailbox, and it destroys the stored credential rather than merely orphaning it. Messages already imported before the disconnection are retained, and the dashboard tells you how many. To have those deleted as well, ask us — see below.

When an organization closes its account we delete its data within 90 days, except where we are required to retain records by law.

Your choices and rights

  1. 1.Disconnect at any time. Settings → Integrations → Manage → Disconnect. This revokes our access immediately.
  2. 2.Revoke directly with Google. You can remove our access from your Google account at myaccount.google.com/permissions without involving us at all.
  3. 3.Request a copy, correction, or deletion. Write to privacy@adminshortstop.com and we will respond within 30 days. If you are an employee of a customer of ours, we may direct your request to that customer, since the data is theirs.

Depending on where you live you may have additional rights — to object to processing, to restrict it, or to complain to a data protection authority. We honour those rights regardless of whether local law compels us to.

Children

Admin Shortstop is a tool for businesses and is not directed at children. We do not knowingly collect personal information from anyone under 16. If you believe we have, contact us and we will delete it.

Changes to this policy

When we change this policy we update the date at the top of this page. If a change materially affects how we handle your data — particularly data from Google — we will tell you directly rather than relying on you to notice.

Contact

Privacy questions: privacy@adminshortstop.com
Security reports: security@adminshortstop.com
Anything else: support@adminshortstop.com

Admin Shortstop LLC, 100 Lorenz St, Loretto, MN 55357, United States.