Search for engine

SPIP Gmail integration privacy policy

Effective date: 9 October 2026

This policy describes the SPIP Drop-Ship Tracking application operated by Ozecomify Pty Ltd, trading as Spool Imports. SPIP is an internal business application that connects Spool Imports’ authorised Gmail mailbox to its supplier shipment tracking workflow.

Information we access

With the mailbox owner’s permission, SPIP uses the Gmail API’s read-only scope. It checks mailbox changes and message identifiers across the mailbox, including archived messages, so supplier shipment emails can be found after filing. It reads message headers, sender, subject and received time. It retrieves the text of relevant supplier order confirmations and shipment emails, which may contain customer names, delivery addresses, purchase and order references, product descriptions, quantities, carrier names and tracking numbers. Relevant emails may contain other information included by the supplier.

The integration does not send mail through Gmail, mark messages read, move, archive or delete messages. Supplier invoice processing remains manual; invoice subjects are excluded from shipment processing.

How we use the information

We use this information to associate supplier shipments with verified Spool Imports purchase orders and customer orders, provide customers with dispatch and tracking information, prevent duplicate notifications, recover failed processing and investigate operational exceptions. Customer contact and order details are checked against Cin7 Core and Magento before a notification is queued. Uncertain matches are held for review.

Storage and retention

SPIP stores captured message identifiers and headers, relevant supplier email text, extracted shipment details, matching evidence and processing audit records in its Cloudflare-hosted database. Google authorisation credentials are stored separately as encrypted service secrets. Stored integration records are retained for shipment support, duplicate prevention and operational audit. No automatic deletion period is currently configured. You can request deletion of stored integration data using the contact below; we will explain any records that must be retained for legal or operational reasons.

Service providers and sharing

Google provides Gmail access and mailbox-change notifications. Cloudflare hosts and processes SPIP’s application and records. Cin7 Core and Magento provide order information used for verification. Klaviyo receives the verified customer identity and the order, product, carrier and tracking details needed to send the operational shipment notification. The customer receives the details of their own shipment. These providers may process information outside Australia.

Google user data is used and shared only to provide this shipment tracking feature, address security issues, comply with law or as otherwise permitted by Google’s Limited Use requirements. We do not sell Google user data or use it for advertising, marketing audience creation, credit decisions or training general-purpose AI models. The current shipment parser uses deterministic rules rather than sending email bodies to an AI model.

Access and security

Connections use encrypted transport. The operational dashboard requires authenticated access, and service credentials remain on the server. Authorised staff or support providers may inspect specific records when the mailbox owner authorises this, when needed for security investigation or when legally required. Access is limited to the shipment tracking purpose.

Your controls and requests

The mailbox owner can revoke SPIP’s Google access through their Google Account’s third-party connections settings. Revocation stops future Gmail access but does not automatically erase records already stored by SPIP. Contact us to request access, correction or deletion of integration records, disconnect the integration or raise a privacy concern.

Google API Limited Use

SPIP’s use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including its Limited Use requirements.

Contact and changes

Contact Spool Imports at [email protected]. Changes to this policy will be dated on this page. If we propose a new use of Google user data or additional access, we will disclose it and obtain any required consent before making that change.