Privacy Policy
Last Updated: May 27, 2026
1. Introduction
At Eagna-Smart Solutions, Inc., owner and operator of the "Transit Ledger" application and services (collectively, "Transit Ledger"), we are committed to protecting your privacy and securing your business data. This Privacy Policy describes how the Transit Ledger Gmail & Drive Workspace Add-on and its associated platform collect, process, and protect your information.
2. Google User Data - Access, Use, Storage, and Sharing
In compliance with the Google API Services User Data Policy, Transit Ledger provides full transparency into how we handle Google user data accessed via our integrations:
-
How We Access Your Google Data: We request access via secure Google OAuth 2.0 consent screens.
Sensitive Data Scopes:gmail.addons.current.message.readonly: Access is restricted contextually to the specific email thread you actively open and process via the Workspace Add-on. We do not scan, search, or read other emails in your inbox.script.external_request: Required contextually by the Google Workspace Add-on (Apps Script) to securely communicate with our AWS API Gateway backend to fetch your profile configuration and transmit raw invoice files for AI parsing.drive.addons.metadata.readonly: Access is used solely to read file metadata (such as file names and extensions) of files you select in Google Drive, verifying format compatibility before launching the processing panel.
Non-Sensitive Scopes:drive.file: Access is used solely to create dedicated folders, upload processed receipt and invoice files, and append extracted transaction metadata (such as vendor name, dates, totals, and tax classifications) into the specific Google Sheet you designate as your ledger. We cannot access, view, or modify any other files or folders in your Google Drive.userinfo.email&userinfo.profile: Used to securely verify your email address and profile identity to map your Google session to your Transit Ledger billing account and tier preferences.gmail.addons.execute&script.locale: Standard technical permissions required to execute the Add-on inside your Gmail client and localize formats (dates, currencies) to your regional language and timezone.
- How We Use Your Google Data: Your data is used exclusively to provide the core service features of Transit Ledger: extracting receipt/invoice files from Gmail or Drive, analyzing document contents (using optical character recognition or multimodal AI models) to extract transaction information, categorizing that information via AI, and writing the structured details into your Google Sheets ledger.
-
How We Store Your Google Data: Our architecture uses secure, transient data processing.
- No Permanent Storage of Files: We do not store copies of your Google files on our servers. All transient files (including uploaded documents and incoming email streams) are temporarily held in encrypted, temporary cloud storage with an automatic 24-hour expiration policy.
- Credential Storage: Your Google OAuth refresh tokens are encrypted at rest using industry-standard AES-256 cryptographic keys managed by secure cloud key management systems. Transit Ledger never receives, collects, or has access to your Google account password; all authentication is handled securely and directly on Google's own domains via standard OAuth 2.0.
-
How We Share Your Google Data:
We do not share, sell, rent, or lease your Google user data with any third parties.
- No Advertising: Your Google user data is never used for targeting advertisements, building user profiles, or any other commercial monetization.
- Transient Enterprise AI Boundaries: Extracted document text is processed transiently through enterprise Cloud AI services (Amazon Textract / Google Cloud AI). Under strict enterprise data protection boundaries, user data received from Google APIs (including email contents, files, and processing prompts) is kept isolated, is never stored beyond transient processing, and is never used to develop, improve, or train public, proprietary, or non-personalized artificial intelligence (AI) and/or machine learning (ML) models.
- Compliance with Limited Use: Transit Ledger's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
3. How Your Data is Used & Transmitted
All file processing is strictly secure and transient:
- When you submit an invoice or receipt, it is transmitted securely via HTTPS to our AWS API Gateway.
- The file is temporarily held in secure, transient cloud storage with an automatic 24-hour expiration policy.
- Optical Character Recognition (OCR): Document text extraction is processed securely using Amazon Textract or Google Cloud AI services entirely transiently.
- AI Categorization: Tabular financial data is structured and categorized transiently utilizing Google Cloud AI services.
- Data Protection Commitment: All cloud data processing is performed strictly within enterprise-grade, paid service boundaries. In compliance with AWS and Google Cloud enterprise privacy agreements, your business documents, financial records, and processing prompts are kept strictly confidential, are processed in complete isolation, are never stored beyond the transient execution window, and are never utilized to train public or proprietary machine learning models.
- Strict Data Retention Boundaries: Extracted tabular financial data is written directly into your designated Google Sheet. Transit Ledger does not maintain a permanent database of your processed transaction records. All transient files (including raw incoming email streams and uploaded receipt/invoice documents) are managed under strict, automated lifecycle expiration rules and are permanently deleted after 24 hours. We do not sell, rent, or monetize your business data under any circumstances.
- System Operational and Telemetry Logs: To ensure platform stability, troubleshoot errors, and audit billing usage, we temporarily retain logs in AWS CloudWatch. Operational logs (containing high-level metadata such as transaction counts, user emails, and filenames, but never the text contents or extracted totals of your documents) are retained for a maximum of 60 days. De-identified billing and usage telemetry logs (which strictly redact all personally identifiable information, including email addresses, and use anonymous user identifiers) are retained for 365 days, after which they are automatically and permanently purged.
4. Payment Processing (Stripe)
We utilize Stripe, Inc. ("Stripe") as our third-party payment processor for subscription billing and portal services:
- No Card Storage: Transit Ledger never collects, processes, stores, or has access to your raw credit card numbers or payment details. All transaction info is entered securely and handled directly by Stripe.
- Stripe Privacy Policy: Payment processing is governed by Stripe's terms and privacy policies. You can view how Stripe manages your data at Stripe's Privacy Policy.
- Fraud Prevention: Stripe utilizes telemetry and identifiers for fraud detection and prevention. These identifiers are strictly used to protect payment security and do not track your user behavior for advertising.
5. Security Measures
Transit Ledger utilizes enterprise-grade cloud security mechanisms:
- All network requests are encrypted in transit via standard TLS 1.3.
- Identity Federation & Authentication (AWS Cognito): We utilize Amazon Web Services (AWS) Cognito as our secure identity federation and access management service. Transit Ledger never sees, stores, or handles your password. User sessions are verified securely via cryptographic JSON Web Tokens (JWT) issued by Cognito.
- Sensitive credentials, such as Google Refresh Tokens, are encrypted at rest using industry-standard AES-256 cryptographic keys managed through secure, hardware-isolated cloud security modules.
- Multi-tenant access is validated securely on every single API request using custom federated identity and token verification services.
6. Cookies and Tracking
Transit Ledger values your privacy and keeps your browsing clean:
- Our platform and dashboard do not utilize any third-party tracking cookies, advertising trackers, or user behavioral analytics (with the sole exception of secure, fraud-detection cookies and telemetry managed directly by Stripe).
- We only use essential, first-party session tokens required strictly to maintain your secure authenticated state.
7. Contact & Support
If you have questions regarding this Privacy Policy or wish to request data erasure (which you can also execute instantly via the Dashboard Delete Account button), please visit our Support Page or contact us directly at support@transit-ledger.com.