Privacy Policy

You are here:

Privacy Policy

Last updated: 1/4/2025

Carl’s Consulting Agency respects your privacy and is committed to protecting any information you provide while using our website and services, including our webmail interfaces and associated plugins.

Information We Collect

We prioritize simplicity and only collect information necessary to provide our services.

General Website Data:

  • Your name and email address (when voluntarily submitted).

  • Information submitted through contact forms or support tickets.

Google User Data (Google Drive Integration): If you choose to connect your Google Drive account to our webmail interface, we access specific data to facilitate this integration:

  • Authentication Tokens: We store secure access tokens to maintain your connection without requiring you to log in every time.

  • File Metadata: We access the names and types of files in your Google Drive to display them within the webmail interface.

  • File Content: We access file content only when you explicitly choose to attach a file to an email.

Dropbox User Data (Dropbox Integration): If you choose to connect your Dropbox account, we access specific data to facilitate file attachments:

  • Authentication Tokens: We store secure tokens to maintain the connection.

  • File Metadata & Content: We access your Dropbox file hierarchy and file content only when you actively browse for and select a file to attach to an email. We do not background sync or analyze your entire Dropbox library.

Billing & Payment Information: When you pay an invoice via our self-hosted client portal, we collect contact details necessary to process the transaction.

  • Data Sovereignty: Our billing system is hosted on our own secure infrastructure. We do not share your invoice history or client details with third-party SaaS billing providers.

  • Payment Data: We utilize trusted third-party payment processors (Stripe and PayPal) to handle financial transactions. We do not store full credit card numbers or bank account details on our local infrastructure. All sensitive financial data is tokenized and processed directly by the payment provider.

AI Writing Assistant (Groq Integration): If you use the optional AI writing features to draft or edit emails, we process specific dat

  • Input Data: The text prompts, draft content, or email context you voluntarily submit to the AI assistant is transmitted securely to our AI provider (Groq) for processing.

  • Zero Retention: We have configured our integration to minimize data retention. Your email content is processed transiently to generate the response and is not permanently stored or used to train the AI provider’s third-party models.

We do not collect sensitive personal information unrelated to the technical functionality of our services.

Hosting & Infrastructure Data

If you utilize our managed hosting, VoIP, or server infrastructure services, our systems automatically collect technical usage data to ensure security and stability:

  • Server Logs: Our web and email servers (Apache/Nginx, Postfix) automatically log IP addresses, browser types, timestamps, and request details. This is standard industry practice for diagnosing errors and blocking malicious traffic.

  • VoIP Logs: If we host your phone system, we process Call Detail Records (CDRs), including source/destination numbers and call duration, and troubleshooting purposes.

  • Stored Content: We host the files, databases, and emails you upload to our infrastructure. While this data resides on our servers, we do not access or analyze the contents of your hosted data unless required for technical support, server migration, or security incidents.

How We Use Information

Information collected is used solely to:

  • Respond to inquiries and provide technical support.

  • Authenticate your identity for secure access to services.

  • Google Drive Integration: To allow users to browse their Google Drive files within the webmail interface and attach selected files to outgoing emails.

  • Dropbox Integration: To allow users to browse their full Dropbox folder hierarchy and attach selected files to outgoing emails directly within the Roundcube interface.
  • Billing: To process payments, manage subscriptions, and send invoices via our billing platform (Invoice Ninja).
  • AI Writing Assistant: To generate text drafts, summarize content, or improve writing style upon your specific request. Input data is sent to the AI provider solely for the purpose of generating the immediate response.
  • Service Delivery: To create relevant content, blog posts, or marketing materials as per your subscription. We may process business-related information (such as your industry, company name, or service details) through third-party AI tools to generate these deliverables.
  • Infrastructure Security: To detect and block brute-force attacks, DDoS attempts, and unauthorized access using automated tools (such as Fail2Ban and firewalling).

Data Retention: Google Drive files are not permanently stored on our servers. They are accessed temporarily for the purpose of attachment transmission and are not retained after the email is processed.

Google API Services User Data Policy

Limited Use Disclosure

Carl’s Consulting Agency’s use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

We do not use Google Workspace data for:

  • Serving advertisements.

  • Retargeting or marketing purposes.

  • Developing, improving, or training generalized AI and/or ML models.

Third-Party Sharing

We do not sell, rent, or share your personal information with third parties for marketing purposes.

We may use trusted third-party infrastructure providers (such as data center hosting, SMTP relays, payment processors like Stripe and PayPal, and AI processing services) to operate our services. These providers are bound by strict confidentiality agreements and only have access to information necessary to perform their specific technical functions.

Cookies & Analytics

This website uses Google Analytics to understand how visitors engage with our site. Google Analytics uses cookies to track your interaction with the Site (such as page views, session duration, and browser type).

We collect this data anonymously to improve website performance and user experience. We do not combine this analytical data with your personally identifiable information.

  • Opt-Out: You can prevent your data from being used by Google Analytics by installing the Google Analytics Opt-out Browser Add-on.

  • Session Cookies: We also use basic session cookies to maintain your login state within our webmail interfaces. Disabling these cookies will prevent you from accessing secure services.

Third-Party Services

We may use trusted third-party services (such as hosting providers, analytics tools, or email services) to operate this website. These services only have access to information necessary to perform their functions and are required to protect it.

Data Security

We take practical, industry-standard measures to protect your data. This includes encryption of authentication tokens and securing data in transit (SSL/TLS). However, no method of transmission over the internet is 100% secure.

Changes to This Policy

This Privacy Policy may be updated to reflect changes in our services or regulatory requirements. Changes will be posted on this page with an updated effective date.

Contact

If you have questions about this policy or our data practices, please contact us:

Carl’s Consulting Agency

Carl’s Consulting Agency is a brand operated by Bledsoe Labs, LLC.