Privacy Policy

Effective Date: Jan. 6th 2025

BrokerageBox ("we," "us," or "our") operates the website https://brokeragebox.com(the "Site"). This Privacy Policy informs you of our policies regarding the collection, use, and disclosure of personal data when you use our Site and the choices you have associated with that data.

1. Information Collection and Use

We collect several different types of information for various purposes to provide and improve our service to you.

Types of Data Collected:

Personal Data: While using our Site, we may ask you to provide us with certain personally identifiable information that can be used to contact or identify you ("Personal Data"). Personally identifiable information may include, but is not limited to:

  • Email address
  • First name and last name
  • Phone number
  • Address, State, Province, ZIP/Postal code, City
  • Cookies and Usage Data

Usage Data: We may also collect information on how the Site is accessed and used ("Usage Data"). This Usage Data may include information such as your computer's Internet Protocol (IP) address, browser type, browser version, the pages of our Site that you visit, the time and date of your visit, the time spent on those pages, unique device identifiers, and other diagnostic data.

2. Use of Data

BrokerageBox uses the collected data for various purposes:

  • To provide and maintain the Site
  • To notify you about changes to our Site
  • To allow you to participate in interactive features of our Site when you choose to do so
  • To provide customer support
  • To gather analysis or valuable information so that we can improve our Site
  • To monitor the usage of the Site
  • To detect, prevent, and address technical issues

3. Transfer of Data

Your information, including Personal Data, may be transferred to—and maintained on—computers located outside of your state, province, country, or other governmental jurisdiction where the data protection laws may differ from those of your jurisdiction.

4. Disclosure of Data

BrokerageBox may disclose your Personal Data in the good faith belief that such action is necessary to:

  • Comply with a legal obligation
  • Protect and defend the rights or property of BrokerageBox
  • Prevent or investigate possible wrongdoing in connection with the Site
  • Protect the personal safety of users of the Site or the public
  • Protect against legal liability

5. Security of Data

The security of your data is important to us, but remember that no method of transmission over the Internet or method of electronic storage is 100% secure. While we strive to use commercially acceptable means to protect your Personal Data, we cannot guarantee its absolute security.

5.1 Google Data

5.1.1 Use of Google User Data

We access Google user data only for the purpose of providing core CRM functionality. When a user connects their Gmail account, we retrieve email metadata and message content solely to support features such as email parsing, contact management, communication tracking, and sending emails on behalf of the user. We do not use Gmail data for advertising, marketing, or any unrelated purposes.

5.1.2 Gmail API Scopes and Purpose

Our application uses Gmail API scopes exclusively to:

  • Read email messages for CRM parsing and workflow automation
  • Send emails from the user’s connected Gmail account
  • Maintain synchronization between the CRM and the user’s inbox.

We request only the minimum scopes required to perform these functions.

5.1.3 No Selling or Sharing of Data

We do not sell, rent, or share Gmail data with third‑party companies. Gmail data is never used for marketing, lead generation, advertising, or outreach. All data remains strictly within the CRM environment and is used only to provide services the user has explicitly requested.

5.1.4 Limited Internal Access

Access to Gmail data within our organization is strictly limited. Only authorized personnel who require access to maintain or improve the service may view user data, and all such access is logged and monitored. We enforce strict internal policies to prevent unauthorized access or misuse.

5.1.5 Data Storage and Security

Email data retrieved through the Gmail API is stored securely using industry‑standard encryption both in transit and at rest. We implement technical and organizational measures to protect user data from unauthorized access, disclosure, alteration, or destruction.

5.1.6 User Control and Revocation

Users may disconnect their Gmail account at any time. Upon revocation, we immediately stop accessing Gmail data and delete any stored tokens. Users may also request deletion of synced email data from our system, and we will comply promptly.

5.1.7 Compliance with Google API Services User Data Policy

We comply fully with the Google API Services User Data Policy, including the Limited Use requirements. Gmail data is used only to provide or improve user‑facing features within the CRM and is never transferred to external systems except as necessary to operate the service.

5.2 Microsoft Data

5.2.1 Use of Microsoft User Data

We access Microsoft user data only to provide core CRM functionality. When a user connects their Outlook or Microsoft 365 mailbox, we retrieve email metadata and message content solely to support features such as email parsing, communication tracking, workflow automation, and sending emails on behalf of the user. We do not use Outlook data for advertising, marketing, or any unrelated purposes.

5.2.2 Microsoft Graph API Permissions and Purpose

Our application uses Microsoft Graph API permissions exclusively to:

  • Read email messages for CRM parsing and workflow automation
  • Send emails from the user’s connected Outlook or Microsoft 365 account
  • Maintain synchronization between the CRM and the user’s mailbox

We request only the minimum permissions required to perform these functions.

5.2.3 No Selling or Sharing of Data

We do not sell, rent, or share Outlook or Microsoft 365 email data with third‑party companies. Email data is never used for marketing, outreach, lead generation, or advertising. All data remains strictly within the CRM environment and is used only to provide services the user has explicitly requested.

5.2.4 Limited Internal Access

Access to Microsoft user data within our organization is strictly limited. Only authorized personnel who require access to maintain or improve the service may view user data, and all such access is logged and monitored. We enforce strict internal policies to prevent unauthorized access or misuse.

5.2.5 Data Storage and Security

Email data retrieved through the Microsoft Graph API is stored securely using industry‑standard encryption both in transit and at rest. We implement technical and organizational measures to protect user data from unauthorized access, disclosure, alteration, or destruction.

5.2.6 User Control and Revocation

Users may disconnect their Outlook or Microsoft 365 account at any time. Upon revocation, we immediately stop accessing mailbox data and delete any stored tokens. Users may also request deletion of synced email data from our system, and we will comply promptly.

5.2.7 Compliance with Microsoft API Terms and Data Handling Requirements

We comply fully with Microsoft’s API Terms of Use and data‑handling requirements. Outlook and Microsoft 365 data is used only to provide or improve user‑facing features within the CRM and is never transferred to external systems except as necessary to operate the service.

6. Service Providers

We may employ third-party companies and individuals to facilitate our Site ("Service Providers"), to provide the Site on our behalf, to perform Site-related services, or to assist us in analyzing how our Site is used.

These third parties have access to your Personal Data only to perform these tasks on our behalf and are obligated not to disclose or use it for any other purpose.

7. Links to Other Sites

Our Site may contain links to other sites that are not operated by us. If you click on a third-party link, you will be directed to that third party's site. We strongly advise you to review the Privacy Policy of every site you visit.

We have no control over and assume no responsibility for the content, privacy policies, or practices of any third-party sites or services.

8. Children's Privacy

Our Site does not address anyone under the age of 18 ("Children"). We do not knowingly collect personally identifiable information from anyone under the age of 18. If you are a parent or guardian and you are aware that your Child has provided us with Personal Data, please contact us. If we become aware that we have collected Personal Data from children without verification of parental consent, we take steps to remove that information from our servers.

9. Changes to This Privacy Policy

We may update our Privacy Policy from time to time. We will notify you of any changes by posting the new Privacy Policy on this page.

You are advised to review this Privacy Policy periodically for any changes. Changes to this Privacy Policy are effective when they are posted on this page.

10. Contact Us

If you have any questions about this Privacy Policy, please contact us:

By email:

Scroll to Top