Orchestiva
PrivacyTermsSign in

Legal information

Privacy Policy

How Orchestiva collects, uses, stores, protects, shares, retains, and deletes account, workspace, Google, billing, and AI-assisted feature information.

Last updatedSeptember 8, 2026

1. Who we are

Orchestiva is a digital business-workspace service operated by Orchestiva. Our website is www.orchestiva.com. For privacy questions or requests, email orchestiva@gmail.com.

When a business uses Orchestiva to manage information about its customers, employees, or other contacts, that business determines why it uses those records. Orchestiva processes the workspace information to provide the service. Requests about a business's records should normally be directed to that business first.

2. Information we handle

  • Accounts and workspaces: names, email addresses, authentication records, business profiles, memberships, roles, and invitations.
  • Business records: customer and lead details, communications, requests, appointments, estimates, jobs, projects, inventory, invoices, expenses, receipts, and supporting files.
  • Connected services: authorized account identifiers, provider record identifiers, synchronization metadata, granted permissions, and protected connection tokens.
  • AI inputs and outputs: selected content, relevant workspace context, generated drafts, suggestions, and extracted fields when an authorized user requests an AI-assisted feature.
  • Billing: plan, trial, subscription state, billing contacts, and payment-provider identifiers. Stripe-hosted checkout handles card details; Orchestiva does not receive the full card number or security code.
  • Security, operations, and support: request metadata, timestamps, errors, usage and audit events, and information included in support requests.

Not every connector is configured for every workspace. Listing a feature does not mean Orchestiva accesses a provider account without authorization.

3. Google account data

What Orchestiva accesses and why

  • Gmail: with permission, Orchestiva reads the connected mailbox address, message and thread identifiers, sender and recipient information, subject, date, snippet, and readable message body so authorized workspace users can view and synchronize a shared inbox. The separately requested Gmail send permission is used only to send a message that an authorized user has chosen to send.
  • Google Calendar: Orchestiva reads the connected Google identity, primary-calendar identifier and name, and owned event details such as title, status, date and time, time zone, location, meeting link, description, and provider update metadata. This imports and synchronizes appointments. The current connector does not create, edit, or delete Google Calendar events.
  • Google Business Profile: when this optional connector is available and authorized, Orchestiva reads account and location identifiers and names, reviewer name, rating, review text, and review dates to synchronize reviews. It can publish a review reply only after an authorized user approves that action.

OAuth access and refresh tokens, granted scopes, connection status, and synchronization metadata are stored so the requested connector can continue operating. Tokens are encrypted before storage. Imported Gmail messages, Calendar appointments, Business Profile reviews, and related workflow records are stored in the applicable tenant-scoped workspace.

How Google data is used and shared

Orchestiva uses Google user data only to provide and improve the user-facing features described above, maintain security, troubleshoot those features, and comply with law. Orchestiva does not sell Google user data, use it for advertising, use it to determine creditworthiness, or use it to train generalized AI models.

Google user data is shared only as needed with service providers acting for Orchestiva to deliver or secure the requested feature, with the user's consent, when legally required, or as otherwise permitted by the Google API Services User Data Policy. When a user requests an AI email draft, the selected Gmail message and limited relevant business context are sent to OpenAI to create that draft. Generating a draft does not send an email.

Orchestiva personnel do not read Google user data unless the user has affirmatively authorized support for specific data, access is required for security or legal compliance, or the data has been aggregated and anonymized for internal operations, as permitted by Google's policy.

Orchestiva's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

Controls, revocation, retention, and deletion

Users can disconnect a Google connector in Orchestiva. The disconnect process revokes the stored Google authorization and removes local connector credentials. Users can also revoke Orchestiva's access from Google Account permissions. Revocation stops future authorized access but does not automatically erase records already imported into a business workspace.

An authorized workspace administrator can manage imported business records under the platform's available controls. A user may also request deletion of imported Google data by emailing orchestiva@gmail.com. Workspace and account deletion requests follow the reviewed process in section 7, including identity and authority verification and any legal recordkeeping limits.

4. AI-assisted features

OpenAI processes selected inputs for configured AI-assisted features such as drafting replies, suggesting workflow information, or extracting receipt fields. Inputs depend on the feature and can include personal information and relevant business context. Credentials and unrelated mailbox messages are not part of the designed drafting payload.

Reviewed Orchestiva requests use OpenAI's Responses API with store: false, so Orchestiva does not ask OpenAI to retain Responses application state. OpenAI states that API data is not used to train or improve its models unless the customer explicitly opts in. OpenAI also states that default abuse-monitoring logs may contain prompts and responses and may be retained for up to 30 days, subject to stated legal and safety exceptions. See OpenAI's data-controls documentation.

AI output can be incomplete or inaccurate. An authorized user must review it before relying on it or taking an action.

5. Why we use information and who receives it

We use information to deliver authorized workflows, maintain accounts and access controls, communicate about the service, administer subscriptions, investigate problems, prevent abuse, and meet legal obligations. Hosting records does not transfer their ownership to Orchestiva.

Current service providers include Vercel for application hosting, Supabase for database, authentication, and storage services, Resend for authentication and invitation email, Stripe for subscription payments, and OpenAI for requested AI processing. Connected providers receive the data needed for authorized actions.

We may disclose non-Google information when legally required, to protect security or legal rights, or in a business transaction subject to applicable restrictions. Google data remains subject to the narrower limits in section 3.

6. Location, safeguards, and access

Service providers may process information outside a user's province or country, where different laws and lawful-access requirements may apply. Orchestiva does not promise Canada-only processing.

The application uses HTTPS, authenticated access, tenant-scoped permissions, protected storage, and encrypted connector tokens. These measures reduce risk but cannot guarantee absolute security. Platform administration is separate from ordinary workspace membership, and support access must follow its authorization process.

7. Retention and deletion

We retain information for authorized business recordkeeping, service operation, security, and applicable legal obligations. Removing a workspace member does not delete that person's global account or authored records. Disconnecting a provider does not delete imported records, and cancelling billing does not delete a workspace.

The current account and workspace deletion process disables access and schedules review with a minimum 30-day hold. The scheduler reviews requests; it does not automatically purge data when 30 days elapse. An operator reviews linked records and applicable legal and security obligations before any deletion action.

8. Choices and requests

Users can manage available account settings, ask a workspace administrator about access or correction, disconnect optional services, or contact orchestiva@gmail.com to request access, correction, withdrawal of consent, or deletion where applicable. We may verify identity and authority. Legal obligations and the rights of the relevant business workspace can limit a request.

Where Canadian privacy law applies, a person may also ask how personal information is handled or challenge compliance. We will respond according to the law that applies to the request.

9. Cookies, audience, and changes

Orchestiva uses cookies or similar storage for authentication and essential service operation. The reviewed application does not load client-side advertising or analytics code. Hosting and service providers still create operational request, security, and error metadata.

The service is intended for business users aged 18 or older and is not directed to children. We will date policy changes and provide appropriate notice of material changes. Where required, we will obtain consent before using information for a new purpose.

© 2026 OrchestivaDigital service · orchestiva@gmail.com