Google API Services disclosure

Last updated: 9 September 2026

BookAvi is booking software for appointment, service, hire and event businesses, operated by Clyde Side Events Scotland Ltd, trading as BookAvi, 41 John Street, Gourock, Scotland. This page explains exactly what BookAvi does with Google account data when a business owner chooses to connect Gmail or Google Workspace, and confirms our compliance with the Google API Services User Data Policy, including the Limited Use requirements.

What the connection is for

Connecting Google is optional. Businesses that connect it do so for one reason: so the emails BookAvi sends to their customers come from their own business address instead of a generic BookAvi address. If a business does not connect Google, BookAvi sends those emails from its own sending domain and nothing changes about how the app works.

Permissions requested, and why

Google permissions requested by BookAvi and the reason each one is needed
PermissionWhat it allowsWhy BookAvi needs it
https://www.googleapis.com/auth/gmail.sendSend email on your behalfSends the booking emails you ask BookAvi to send — quotes, contracts, invoices, payment reminders, event details and review requests — from your own business address, so your customers reply straight into your inbox.
https://www.googleapis.com/auth/userinfo.emailSee your primary email addressConfirms which mailbox you connected, so BookAvi can show it on the Email & Sending screen and set it as the sending and reply-to address.

These are the narrowest permissions that achieve the feature. BookAvi does not request permission to read, search, modify, label or delete messages, and it cannot do any of those things with the permissions above.

What BookAvi never does

  • It never reads, downloads, searches or indexes the contents of your mailbox.
  • It never deletes or modifies messages, drafts, labels or settings.
  • It never asks for or stores your Google password.
  • It never sends email from your account except the messages you trigger in BookAvi.
  • It never uses Google user data for advertising, profiling or credit assessment.
  • It never sells Google user data, and never transfers it to data brokers or information resellers.
  • It never uses Google user data to train generalised artificial intelligence or machine learning models.

Limited Use commitment

BookAvi's use and transfer of information received from Google APIs to any other app adheres to the Google API Services User Data Policy, including the Limited Use requirements. Specifically:

  • Google user data is used only to provide and improve the email sending feature described on this page.
  • Data is transferred to others only when necessary to provide that feature, for security reasons, to comply with applicable law, or as part of a merger or acquisition where users have been notified and consented.
  • No humans read your Google user data unless we have your explicit consent for a specific support request, it is necessary for security purposes such as investigating abuse, to comply with applicable law, or the data has been aggregated and anonymised.

How the connection is stored and secured

  • Authorisation uses Google's OAuth 2.0 flow with PKCE. You sign in on Google's own screens; BookAvi never sees your credentials.
  • The long-lived refresh token is encrypted before it is stored, is held only on the server, and is never sent to a browser.
  • Short-lived access tokens are requested only at the moment an email is sent and are not retained afterwards.
  • Data is held on infrastructure in EU/UK regions and all traffic is encrypted in transit.
  • Access to the connection is limited to the business that created it; BookAvi enforces per-business isolation at the database level.

How to disconnect

You can remove the connection at any time in BookAvi under Settings → Email & Sending → Google Workspace / Gmail → Disconnect. Disconnecting deletes the stored token immediately, and BookAvi reverts to sending from its own address. You can also revoke access directly at myaccount.google.com/connections. Deleting your BookAvi account deletes the stored token as part of that process.

Retention

The encrypted token, the connected email address and a log of send attempts (recipient address partly hidden, subject, status and timestamp) are kept while the connection is active. Tokens are deleted on disconnection. Send logs are kept for up to 12 months for delivery troubleshooting and then deleted. Message bodies are never stored in those logs.

Contact

Questions about this disclosure, or about data BookAvi holds: info@bookavi.com. See also our Privacy Notice, Terms and Conditions, Data Processing Agreement and list of subprocessors.