TRA Cloud Reconciliation

Privacy Policy

Effective: October 1, 2026

TRA Cloud Reconciliation (“TRA”) is an internal operations and reconciliation system operated by Enrich Living. This policy explains how TRA accesses, uses, stores, and protects Google user data.

Google user data TRA accesses

When an authorized operator connects a Google account, TRA may request read-only access to Gmail. TRA may access message metadata and message content when necessary to identify and process operational notifications relevant to reconciliation workflows.

How Google user data is used

Google user data is used only to support internal operational reconciliation. This includes identifying relevant notifications, correlating them with internal records, determining transaction or fulfillment status, and maintaining an audit trail of reconciliation activity.

TRA does not use Google user data for advertising, behavioral profiling, marketing, or purposes unrelated to its internal reconciliation function.

Storage and retention

TRA may store limited derived operational information from relevant messages, such as identifiers, timestamps, transaction references, status information, and reconciliation results. Data is retained only for as long as reasonably necessary for operational continuity, reconciliation, audit, troubleshooting, and legal or accounting requirements.

OAuth credentials are treated as secrets and are stored in restricted infrastructure intended for application credentials. They are not displayed in the public interface.

Sharing of Google user data

Enrich Living does not sell Google user data. TRA does not transfer Google user data to advertising platforms, data brokers, or unrelated third parties. Data may be processed by infrastructure service providers solely as necessary to operate the application and subject to applicable security and confidentiality controls.

Google API Services User Data Policy

TRA's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.

Security

TRA uses access controls, restricted service identities, secret-management controls, and least-privilege application permissions designed to protect operational data and credentials.

Revoking access

An authorized Google account owner may revoke TRA's Google access at any time through the security and third-party access settings of their Google Account. Revoking access prevents future API access by that authorization.

Changes to this policy

This policy may be updated when TRA's functionality or data practices change. The effective date above will be updated when material changes are published.