Official documents
Partner Privacy (Gmail)
1. Who the controller is and who this document applies to
CONNECTBASE SRL, IDNO/tax code 1023600007753, registered office: MD-2089, Republic of Moldova, mun. Chișinău, s. Ciorescu, str. Ștefan cel Mare, nr. 9, operates the Autocare platform, including autocare.md and the partner interface.
This document applies to individuals who, on behalf of an Autocare partner company, connect a Gmail account to Autocare, as well as to the data of individuals appearing in the retrieved messages (for example, senders, customers or passengers). It supplements the Autocare General Privacy Policy, available in the Legal Information Center, which remains applicable to other processing activities.
Distinct roles. The partner company selects the mailbox, folder and senders whose messages are retrieved and uses the resulting bookings in its own transport business, acting as an independent controller for that activity. CONNECTBASE SRL operates the Autocare service, account and platform security, and the automatic retrieval of messages described in this document.
For questions and to exercise your rights: [email protected], telephone +373 60 003 377.
2. What access we request from Google
| Permission (scope) | What we use it for |
|---|---|
| openid | Authenticating the connection with the selected Google account. |
| Identifying the connected Gmail address so it can be displayed in the partner account and messages can be correctly associated. | |
| https://www.googleapis.com/auth/gmail.readonly | Reading messages and metadata from the selected folder for the features described below. This is a read-only permission: Autocare does not send, delete, move or modify messages in Gmail. |
The Gmail connection feature requests only the permissions listed in the table above and uses them only for the operations described in this document. The authorisation request allows Google to add to the same authorisation permissions that you previously granted to the same Autocare application (include_granted_scopes), so the authorisation may also include permissions granted in another context. The Gmail connection feature uses the authorisation only for the Gmail operations described here.
3. What data we read and when
3.1. During setup
To help you choose booking sources, Autocare reads the metadata (sender, subject, date, Message-ID) and the message body snippet generated by Gmail (“snippet”), which we store up to 500 characters, for up to 200 recent messages in the folder you select, from the last 30 days by default (the period can be extended up to 90 days). At this stage, messages are not filtered by sender, so the list may also include messages unrelated to bookings, and their snippets may contain personal data.
When you select a message for preview or testing, Autocare reads the full content of that message and sends it to the configured artificial intelligence provider (see section 5) to show you what data could be extracted. This happens for the message you select, even if its sender has not (yet) been configured as a source.
Samples collected during setup (metadata, snippets and the content of previewed or tested messages) are automatically deleted approximately 7 days after they are read, including if the connection has been activated in the meantime. If you cancel setup, the samples are deleted immediately, in the same operation as the cancellation (see section 6).
3.2. After activation
Once you activate the connection, Autocare retrieves all of each new message in its entirety that arrives in the selected folder, including messages from senders you have not configured. What happens next depends on the sender:
- messages from configured senders are automatically processed to identify and extract booking and passenger data;
- messages from unconfigured senders are not sent for automatic booking processing, but are stored by Autocare and are visible to the partner company’s operators in the interface. Their content is automatically deleted approximately 24 hours after receipt; after that, only metadata remains visible.
Message content is not retained indefinitely in Autocare. The time limits after which it is deleted and the data that remains are described in section 6.
3.3. Categories of data
Depending on the message, the data may include: the connected Gmail address; message headers (for example, sender, recipients, subject, date); the message body snippet generated by Gmail (“snippet”); the message body; text extracted from PDF attachments; and booking and passenger data extracted from them (for example, name, contact details, route, date, number of seats).
4. How we use the data
We use Gmail data only to provide and improve the user-facing feature for retrieving booking requests from email:
- displaying messages and sources in the partner interface for setup and control;
- previewing, during setup, the data that could be extracted from a message you select;
- automatically extracting booking data from messages from configured senders and creating or updating booking records in the partner account;
- diagnosing errors, securing the service and preventing abuse;
- complying with legal obligations.
Legal basis for processing, as applicable. Messages are retrieved and processed because the service is requested and activated by the partner company as part of its relationship with Autocare. Error diagnosis, security and abuse prevention are based on security obligations and proportionate legitimate interests, while disclosures to authorities are made only when required by law. The partner company must have the right to connect the selected mailbox and use the data of individuals who write to it for its bookings.
Transparency of automated processing
Data extraction from messages is performed automatically with the help of an artificial intelligence model and, after activation, an internal Autocare booking-processing service. The result may be incomplete or incorrect; the partner company’s operators can view the source messages in the interface while their content is retained (see section 6) and remain responsible for checking bookings before confirming them to passengers. When a message is awaiting manual review, Autocare displays an alert to the partner company’s administrators in the partner interface (the alert includes the message subject); the review is carried out by the partner’s operators, not Autocare staff. Autocare does not use this processing for advertising profiling.
5. Who we share data with
- The partner company’s operators who have access to the partner account in Autocare can view retrieved messages (including those from unconfigured senders) for as long as their content is retained under section 6, and thereafter only their metadata, as well as the resulting bookings.
- The artificial intelligence provider configured by Autocare receives the content of messages sent for extraction: after activation, messages from configured senders; during setup, messages you select for preview or testing, regardless of sender. The data sent may include the message body and headers, text from PDF attachments, data already extracted and the context of the relevant booking (including excerpts from previous messages related to the same booking). The default provider is currently OpenAI; the provider can be changed through Autocare configuration. You may request information about the provider in use at any given time by emailing [email protected].
- Autocare’s hosting, database and infrastructure providers, to the extent necessary for the service to operate.
- Competent authorities, only when disclosure is required by law.
Internal booking-processing service. After activation, extraction is coordinated by a processing service that is part of the Autocare platform and operated by CONNECTBASE SRL; it is not a third-party recipient. This service receives the message content and booking context from the Autocare application, processes them in memory for the duration of the request and sends them to the artificial intelligence provider. The service does not save message content in its database, on disk, in cache or in processing queues. Its technical logs may, however, contain fragments of data derived from messages (for example, extracted booking data or details from error messages); see section 6. Requests from this service to OpenAI are sent with the option requesting that responses not be stored by the provider (store: false); this option does not, by itself, determine how long the provider may retain the data received, for example for abuse prevention.
The automatic deletion described in section 6 applies to data stored in the Autocare application database. It does not extend to copies already sent to the artificial intelligence provider, whose retention period is set by the provider and which we are currently unable to specify, nor to the technical logs and backups described in section 6.
We do not sell Gmail data or share it with third parties for advertising.
Processing outside the Republic of Moldova. Content sent to the configured artificial intelligence provider (currently OpenAI) may be processed outside the Republic of Moldova. Information about the countries in which data may be processed and the safeguards applied to the transfer can be requested at [email protected]. The general rules on international transfers are described in section 7 of the General Privacy Policy.
6. Storage, security and retention
| Data | How we store it and for how long |
|---|---|
| OAuth tokens for the connected Google account | Stored encrypted at the application level and used only for the access described in section 2. They stop working when you revoke access from your Google account. They are removed from the Autocare database when you delete the connected mailbox from Autocare (see section 8); this deletion does not revoke access in your Google account. |
| Samples read during setup (metadata, “snippet” excerpts of up to 500 characters, and the content of previewed/tested messages) | Automatically deleted approximately 7 days after they are read, including if the connection has been activated in the meantime; the automatic cleanup process runs hourly, so deletion may take place up to approximately one hour after the 7 days have elapsed. If you cancel setup, the samples are deleted immediately, in the same operation as the cancellation, without waiting for the automatic process. |
| Content of new messages from unconfigured senders (the raw message source, text and HTML version) | Automatically deleted approximately 24 hours after the message is received. |
| Content of new messages from configured senders (the raw message source, text and HTML version) | Automatically deleted approximately 7 days after processing of the message is completed (if the completion time is not recorded, after the message is recorded in Autocare). The same period applies to messages whose processing has failed: a processing failure alone does not extend retention. Deletion is postponed, and the content remains stored beyond those 7 days, only while the message is still being processed or awaiting manual review, has an associated event (for example, relating to the booking or payment) that is still active or in progress, has a result that is not yet finalised, or has an open manual-review alert. Once these situations are resolved, the content is deleted by the automatic cleanup process; while any such case remains active, there is no maximum retention period. |
| Message metadata (the message record, Message-ID, sender, recipient, subject and date) and data for bookings created | Not deleted when the message content is deleted. They are retained to avoid retrieving the same messages more than once and for booking history, in accordance with the rules in the Autocare General Privacy Policy. You may request their deletion under section 9. |
| Backups and technical logs, including logs of the internal booking-processing service | May contain data from messages: backups may include content already deleted from the application database, while technical logs may contain fragments of data derived from messages (for example, extracted booking data or details from error messages). The periods above do not apply to these copies, and we are currently unable to specify a retention period for them. |
Automatic deletion is carried out by a process that runs hourly, so it may take place up to approximately one hour after the retention period has elapsed. An exception is cancellation of setup, when samples are deleted immediately.
We apply the access control, authentication and logging described in the General Privacy Policy. Unlike OAuth tokens, message content does not currently benefit from additional encryption at the application level.
7. Compliance with Google’s User Data Policy (Limited Use)
Autocare's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
In particular, Gmail data is used only to provide or improve the user-facing booking-import feature described in this policy; it is not used or transferred for serving advertisements, it is not sold, it is not used to determine creditworthiness or for lending purposes, and Autocare does not use or transfer it to develop, improve or train generalized or non-personalized AI and/or ML models.
In Romanian: Autocare’s use and transfer of information received through Google APIs complies with the Google API Services User Data Policy, including the Limited Use requirements. Gmail data is used only for the booking retrieval feature described here; it is not used for advertising, is not sold, and is not used or transferred by Autocare to develop, improve or train general artificial intelligence or machine learning models.
Autocare staff do not read the content of Gmail messages, except in circumstances permitted by this Google policy: with your explicit consent for specific messages (for example, in a support request), when necessary for security or investigating abuse, to comply with the law, or for internal operations using aggregated and anonymised data. Your partner company’s operators can view messages in the interface as part of the feature you have activated; the manual-review alerts described in section 4 are addressed to the partner company’s administrators and do not involve routine reading of messages by Autocare staff.
8. Your control and revoking access
- Sources: you choose the connected folder and the senders whose messages are processed for bookings.
- Revocation: you can revoke Autocare’s access at any time from your Google account at https://myaccount.google.com/permissions. After revocation, Autocare can no longer read new messages from Gmail.
- Data already retrieved: revoking access does not immediately delete messages already retrieved into Autocare. Their content is deleted according to the time limits in section 6, while message metadata and booking data remain. To request their deletion, write to [email protected].
- Deleting the mailbox from Autocare: you can delete a connected mailbox from the partner interface only after it no longer has booking sources linked to it. Deletion removes that mailbox’s OAuth tokens from the Autocare database, but does not revoke the access granted in your Google account; revocation must be done separately at https://myaccount.google.com/permissions. Deleting the mailbox also does not delete messages already retrieved: their content is deleted according to the time limits in section 6, while message metadata and booking data remain. To request their deletion, write to [email protected].
9. Individuals’ rights
You and the individuals whose data appears in messages have the rights described in the General Privacy Policy: access, rectification, erasure, restriction, objection, portability where applicable, withdrawal of consent and the right to lodge a complaint with the National Center for Personal Data Protection. Requests should be sent to [email protected]; we may request the information strictly necessary to verify identity and will respond without undue delay, normally within a maximum of one month.
The partner company decides which mailbox, folder and senders it connects and uses the resulting bookings in its own business as an independent controller (see section 1); individuals should also contact the partner regarding records retained by the partner outside Autocare.
10. Changes
We publish the version and effective date. Material changes, including changes to the retention periods described in section 6, will be reflected in a new version of this document. If a change expands access to Google data or its use, we will seek consent again where necessary.
CONNECTBASE SRL · IDNO/tax code 1023600007753
[email protected] · +373 60 003 377



