Your information
Privacy Policy
Last updated: September 13, 2026
What GetBack accesses
When you choose to connect Gmail, GetBack asks Google for your basic account identity and read-only Gmail access using the gmail.readonly scope. We use that access to find and process emails relevant to purchases, deliveries, returns, refunds, and related commerce events so that GetBack can organize those events and surface useful deadlines and follow-ups.
Read-only access does not let GetBack send email from Gmail, edit, archive, label, or delete Gmail messages, or change your Gmail account.
Google user data
GetBack does not store full copies of your Gmail messages or their MIME payloads as part of its persistent product data. Relevant message headers, snippets, and bodies are processed to identify commerce messages and extract the information needed to provide the service. GetBack stores structured or derived purchase information and limited metadata, which can include Gmail message and thread identifiers, sync state, and extraction diagnostics when needed to operate or troubleshoot the product.
GetBack's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including its Limited Use requirements.
Information GetBack stores
Depending on how you use GetBack, stored information can include:
- Your account email and Google account identity.
- Gmail connection and authorization data, along with synchronization state.
- Retailer, order, purchased-item, amount, delivery, return, refund, tracking, eligibility, and deadline information extracted from relevant messages or supplied through product controls.
- Purchase, return, and refund lifecycle events.
- Notification scheduling, delivery state, and delivery history.
- Limited technical and extraction diagnostic metadata needed to operate, recover, and troubleshoot GetBack.
- Feedback or support information you choose to submit.
How GetBack uses information
We use this information only to identify and organize purchases; estimate return opportunities and deadlines; track deliveries, returns, and refunds; calculate money at risk or recovered; synchronize Gmail; send GetBack transactional notifications; maintain and recover the service; diagnose extraction or operational failures; respond to feedback or support where applicable; diagnose reported bugs; and improve GetBack during beta. GetBack does not sell personal information.
Service providers
GetBack uses service providers only where needed to run the current service: Google supplies Gmail and account authorization; Vercel hosts the application and scheduled jobs; Neon provides the hosted PostgreSQL database; and Resend delivers transactional GetBack notification emails. These providers may process the information needed to perform their respective services. Retailers mentioned in extracted purchase information do not operate or sponsor GetBack.
Access and advertising
GetBack does not use Google user data for advertising. GetBack does not allow humans to read Gmail message content except when the user has given specific permission for support, when necessary for security or abuse investigation, to comply with applicable law, or when the data has been aggregated and anonymized for internal operations. GetBack does not sell Google user data or transfer it for unrelated purposes.
Retention and deletion
Structured GetBack information is retained while your account exists. Disconnecting Gmail stops future Gmail access and removes the saved authorization tokens, while preserving your saved GetBack purchase, return, and refund history.
Deleting your account permanently removes your GetBack account and GetBack-held user data through the product's deletion flow, including saved history, connection data, diagnostics, and notification records. GetBack attempts to revoke Google authorization when you disconnect Gmail or delete an account. Revocation can fail outside GetBack's control, but locally stored authorization tokens are removed as part of those flows.
Disconnecting Gmail or deleting GetBack does not delete your original Gmail emails. Those messages remain in Gmail and are controlled through your Google account.
Your controls
These controls are available inside Account & Sync:
- Disconnect Gmail stops GetBack's future Gmail access; your saved GetBack history remains.
- Delete my account & data deletes your GetBack account and saved GetBack data and removes the Gmail connection; your original Gmail emails remain in Gmail.
Security
Saved Google authorization tokens are encrypted before database storage. GetBack uses reasonable technical measures intended to protect information and limits Gmail permissions to what the product needs. No method of storing or transmitting information is completely secure.
Children
GetBack is not designed for children.
Changes to this policy
We may update this policy as GetBack changes. When we do, we will change the Last updated date on this page.
Contact
For privacy or support questions, signed-in users can use the feedback and support control on the GetBack dashboard. Our public support page explains connection recovery and how to use the support address displayed on Google's OAuth consent screen if you cannot sign in.