Back to home

Privacy

Privacy Policy

This policy explains how Realable processes data when you manage a website, collect enquiries, connect integrations, use analytics and operate a user account.

Connecting your Google account and Gmail

1. Data we process

We process data needed to operate user accounts, manage real estate websites and handle enquiries submitted through contact forms.

This typically includes names, email addresses, phone numbers, messages, property information, technical visit data and information needed to manage domains or integrations.

2. Purposes of processing

We use data to create and manage accounts, deliver enquiries, communicate with users, operate websites, secure the service and provide basic analytics.

Website visitors’ contact details are primarily used to handle their enquiry or property valuation request.

4. Data sharing

Data may be processed by providers of hosting, email services, analytics, technical support or integrated real estate systems.

Providers receive access only as needed to operate the service, subject to appropriate contractual and security arrangements.

5. Retention

We retain data for the duration of the account, to handle enquiries, meet legal obligations or as necessary to protect legal claims.

Technical and analytics data are retained for a period appropriate to their purpose and the settings of the website concerned.

6. Your rights

You may request access, correction, erasure, restriction of processing or data portability, or object to processing.

Where processing is based on consent, you may withdraw it at any time. Withdrawal does not affect the lawfulness of earlier processing.

7. Security

The service uses technical and organisational measures to protect accounts, forms, data and the administration interface.

Users are responsible for correctly configuring their website, credentials, legal notices and connected services.

8. Connecting Google and Gmail: data access

Connecting your own Gmail is optional. We request openid and email to verify the account, and https://www.googleapis.com/auth/gmail.send to send messages on your behalf.

Google provides the primary email address, a unique account identifier, email verification and granted permission information, and access tokens. We store connection details and an encrypted refresh token so sending can work without requiring you to sign in repeatedly.

To send a message, we process the sender and recipient addresses, subject and notification content generated from an enquiry. Google returns a sent message identifier. This integration does not read incoming mail, browse your mailbox, or modify or delete your messages.

9. How we use Google data

Account data verifies and identifies the connected sender. We use Gmail to send new enquiry notifications to the verified recipients configured for your website. A test message is sent to the connected address when you connect and when you manually test the connection.

You manage the sender, recipients and fallback sending in notification settings. If you enable fallback, the same notification may be sent from a Realable address when your own sender fails. The manual reply link for an enquiry opens your email application; it does not read your mailbox through the Gmail API.

10. Sharing data when using Gmail

We send tokens and outgoing message content to Google for authorisation and sending. Configured recipients receive the message content. We use Vercel and Supabase to operate the application and database; connection and enquiry data are processed in this infrastructure. Vercel Cron triggers automatic email queue processing. We use GitHub Actions for manually triggered recovery processing of the queue and scheduled cleanup of Gmail integration data as described in section 12; server-side processes access only the data needed for the operation concerned.

We do not sell data obtained through Google APIs or use it for targeted advertising or training general-purpose AI models. Access is limited to providing the feature, necessary support, security and legal obligations.

11. Protecting the Gmail connection

The refresh token is encrypted on the server using AES-256-GCM. Stored tokens are not included in data returned to the browser. Only an authorised account administrator can manage the connection; access to data is separated between customer accounts.

Production communication with the application and Google uses HTTPS. The authorisation flow is protected by one-time state and PKCE. Operational delivery results use status information and error codes rather than copying enquiry content into those logs.

12. Retention and deletion of connection data

We retain the refresh token while the connection is stored. When you disconnect, we remove it from active storage and ask Google to revoke authorisation. Google being unavailable does not prevent local token deletion. You can also remove access directly in your Google account settings.

We remove personal metadata of a disconnected Gmail connection, including the sender address and name, after 30 days from disconnection. We remove details of completed notifications sent through a custom Gmail connection, including the recipient address and message identifier, after 90 days from sending or final failure. Scheduled cleanup runs daily; records still used by ongoing delivery are removed after processing finishes. Incomplete erasure is escalated to support.

Temporary authorisation sessions expire after 10 minutes and are removed during daily cleanup after expiry. We retain Gmail integration audit records without message content or credentials for 180 days after the event, and minimal erasure completion records for 180 days after completion.

The basic delivery outcome and time, internal identifiers and a one-way recipient key remain with the enquiry history to prevent duplicate sending. This is not full anonymisation. Enquiries have their own retention period under section 5. Disconnecting or deleting data in Realable does not delete messages already sent in Gmail or held by recipients.

To request deletion of connection data or closure of your account, contact podpora@realable.cz. After verifying your authority, we will arrange deletion of data for which we have no further legal reason for retention and explain any exceptions. Removal from active storage does not mean immediate removal of backup copies; their availability depends on the infrastructure’s backup retention arrangements.

Manage access in your Google account

13. Limited use of Google data

Realable’s use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. If the way we use data changes, we will update this policy and notify users of the change.

Google API Services User Data Policy