Sipes Studio

Sipes Studio Privacy Policy

Effective and last updated: September 28, 2026

A. About Sipes Studio

Sipes Studio is a private, internal application used by Sipes Studio to manage apparel production-art jobs and the business email connected to that work. It is not a consumer product and has no public sign-up; accounts are issued by Sipes Studio to its own staff, to production contractors, and to customers who are given limited portal access.

This policy explains what the application accesses, how it uses that information, and what it stores.

B. Google and Gmail data accessed

When an authorized staff user connects a Gmail account, the application requests exactly two permissions:

  • https://www.googleapis.com/auth/gmail.readonly — read-only access to the connected mailbox.
  • https://www.googleapis.com/auth/gmail.send — the ability to send a message from the connected account.

Under the read permission, the application may access information such as:

  • email messages and Gmail conversation threads
  • sender and recipient information
  • subject lines
  • message bodies, in plain text and HTML
  • timestamps
  • Gmail message and thread identifiers
  • attachment metadata, and attachment contents when an attachment is specifically requested
  • mailbox search results

The send permission is used only when an authorized staff user intentionally performs a send action in the application. The application does not send mail on its own schedule, and does not send in response to an incoming message.

The application does not request permission to modify the mailbox. It cannot mark messages read or unread, archive, star, label, delete, or otherwise change the state of the connected mailbox.

C. How Google user data is used

Information obtained from Google is used only to provide visible functionality inside the application:

  • displaying business email inside Sipes Studio
  • displaying full conversations
  • Gmail-backed mailbox search
  • showing attachments, and retrieving an attachment when a user opens it
  • customer communication sent by an authorized staff user
  • associating an email conversation with the Sipes Studio job or workflow record it relates to
  • allowing authorized staff to intentionally move a relevant email into a production workflow

Inbound email does not automatically create a production job.

Moving an email into production requires an explicit action by an authorized staff user. Where the application categorises a message or suggests that it may be production-related, that logic is advisory only — it is not production authority and cannot create or change a job by itself.

Google user data is not used to train generalised or third-party artificial-intelligence or machine-learning models.

D. Data stored by Sipes Studio

The application stores operational records needed for workflow, provenance, audit and job linkage. It does keep copies of email-derived information — it would not be able to show a work history otherwise. Stored items may include:

  • Gmail message identifiers and Gmail thread identifiers
  • sender name and email address, and matched customer/contact records
  • subject lines
  • message snippets, and message content where a workflow feature requires it
  • timestamps such as when a message was received
  • attachment metadata: file name, media type and size
  • relationships between an email and a customer, job or work order
  • workflow status, such as whether a message has been reviewed or converted
  • audit information about messages the application has sent, including recipient, subject, body, send status and provider message identifiers

Attachments remain stored in Gmail until they are needed. Viewing a conversation does not copy attachments into Sipes Studio. An attachment is copied into Sipes Studio job storage only when an authorized staff user intentionally incorporates it into a production workflow, at which point it becomes a production file for that job.

E. Google credentials

OAuth access and refresh credentials for the connected Google account are held server-side and are used only by the application server to call Google APIs on behalf of the connected account. They are not intentionally exposed to browsers, to customer portal users, or to contractor users.

F. Sharing

Google user data is not sold, rented, or used for advertising, and is not shared for any purpose unrelated to operating Sipes Studio.

Operating the application does require infrastructure providers, and information is processed by them as part of normal hosting and storage. These currently include Vercel (application hosting) and Supabase (database, file storage and authentication), together with Google itself for the Gmail integration.

G. Limited Use

Sipes Studio's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

H. Data security

The application uses reasonable safeguards appropriate to a small internal business system, including:

  • authenticated access — every non-public page requires signing in
  • role-based authorization, checked on the server, so staff, contractor and customer accounts each reach only what their role permits
  • server-side handling of Google credentials
  • database-level access rules restricting which records an account can read
  • controlled access to stored production files rather than public file URLs

No system can be guaranteed completely secure, and this policy does not claim otherwise. Security issues can be reported to the contact address below.

I. Data retention and deletion

Operational records may be retained as necessary for business workflow, recordkeeping, security and audit purposes. The application does not currently perform automated deletion of stored records on a schedule.

Users may contact Sipes Studio to request review or deletion of applicable stored data, including data derived from Google APIs, at sipesdesigns@gmail.com.

J. Disconnecting Google access

Gmail authorization can be revoked at any time from the connected Google Account's third-party access settings at myaccount.google.com/permissions. An authorized staff user can also disconnect the Gmail connection from within the application. Once disconnected, the application can no longer read the mailbox or send from that account.

Disconnecting stops further access. It does not by itself erase records already stored in Sipes Studio; use the contact address above to request deletion of stored data.

K. Contact