Privacy Policy
This policy explains how information is handled through ghassanashag.com and Ghassan Ashag CRM, including website inquiries, client-service workflows and optional integrations with Google services.
Scope of This Policy
This policy covers the public website at ghassanashag.com and the private Ghassan Ashag CRM used for real-estate, property-management and short-term-rental operations. Some client portals have their own authenticated access controls but use related business systems and service providers.
Information You Choose to Provide
Depending on the feature you use, you may provide your name, email address, phone number, property address, MLS® number, search criteria, showing preferences, property-management details, lease and tenant information, maintenance information, documents, course interest, and the contents of messages or forms. Please do not submit information that is not reasonably necessary for the service requested.
How Information Is Used
Information is used to respond to requests, provide requested real-estate or property-management services, organize CRM records, arrange appointments or showings, maintain transaction/property records, provide portal access, support requested listing alerts or education access, reconcile authorized rent-payment records, maintain reasonable business records, and protect the systems from misuse. Marketing communications are sent only where requested, permitted or separately consented to.
Google Account Connections
Google integrations are optional. Google user data is accessed only after an authorized user chooses to connect a Google Account and grants the requested OAuth permissions. Depending on the CRM feature being used, the application may request access to Google Calendar, Google Drive, Google Contacts, Gmail and Google Tasks.
- Calendar: event information may be read, created, updated and deleted to support calendar synchronization and CRM appointments.
- Drive: file/folder metadata and permitted file content may be accessed to organize CRM documents, upload or retrieve requested files, and perform user-requested document review workflows.
- Contacts: names, email addresses, phone numbers, addresses and related contact fields may be read or updated for user-initiated or enabled contact synchronization.
- Tasks: task information may be read or updated when the user invokes supported task synchronization.
- Gmail: the CRM may send an email when the user explicitly initiates a send action, and may read authorized Gmail data for user-facing workflows such as CRM lead processing and rent-payment reconciliation.
Gmail Rent-Payment Data
When an authorized self-managed property-management user connects Gmail for rent-payment automation, the application uses read-only Gmail access to search for payment-notification messages relevant to Interac/e-Transfer payments. The system may process message headers and body text to identify the sender/payer, payment amount, payment date and the likely lease or rent charge.
For this workflow, full email bodies are processed to perform the match but are not stored as full email bodies. Limited information may be retained for reconciliation and audit purposes, including Gmail message/thread identifiers, payment date and amount, payer name/email where available, a short subject preview, matching evidence/confidence and status. Message identifiers may also be retained to prevent duplicate processing.
Disconnecting Gmail revokes the Google connection and removes the stored refresh credential from the connection record. Previously created rent-payment or audit records may remain where needed for accounting, transaction history, security, legal or legitimate business-record purposes.
OAuth Credentials and Security
OAuth access and refresh credentials are used only to maintain the Google connection and call the approved Google APIs. Persistent credentials are handled server-side rather than published in website code. The dedicated rent-payment Gmail connection encrypts its stored refresh token before it is saved. Access to CRM records is protected by authentication and database access controls.
Limited Use of Google User Data
Google user data is used only to provide or improve user-facing features that are visible in Ghassan Ashag CRM or its related authorized portals. Google user data is not sold, is not used for advertising, and is not used by Ghassan Ashag CRM to train generalized AI or advertising models.
When a user explicitly requests an AI-assisted document-review feature, the selected document content may be processed by the configured AI service solely to provide that requested feature. Google user data is not transferred for unrelated advertising or generalized model-training purposes.
Human access to Google user data is not routine and is limited to circumstances permitted by Google policy, such as providing user-requested support with appropriate consent, investigating security or abuse, or complying with applicable law.
Use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
Sharing, Transfer and Disclosure of Google User Data
For Google user data used by the Gmail Rent Payment Automation feature, Ghassan Ashag CRM does not sell, rent, license, or share the data with advertisers, data brokers, or unrelated third parties. Google user data is disclosed or transferred only as described below and only to the extent necessary to operate the user-requested feature.
- Supabase: Supabase acts as a contracted backend infrastructure provider. The Rent Payment Automation Edge Function uses the Gmail API on the authorized user's behalf, processes candidate message content to identify and match rent-payment notifications, stores the encrypted OAuth refresh credential, and stores only the limited reconciliation/audit metadata described in this policy. Supabase processes this information only to provide backend, database, authentication and server-side function services for the application.
- Netlify: Netlify hosts ghassanashag.com and the public OAuth callback endpoint. Netlify may transiently process the Google OAuth authorization code and state needed to route the user's authorization result to the backend. This callback does not receive or store Gmail message bodies.
- Legal and security disclosures: Google user data may be disclosed when required by applicable law, valid legal process, or when reasonably necessary to protect users, the service, or the rights and security of others, consistent with applicable law and Google policy.
- User-directed disclosures: Google user data may be disclosed to another party only when the user explicitly directs or consents to that disclosure and the disclosure is necessary to provide the requested user-facing feature.
Service providers acting on our behalf are not permitted to use Google user data for advertising, data brokerage, unrelated profiling, or generalized AI/ML model training. Gmail message content used by Rent Payment Automation is not shared with real-estate advertisers, professional referral partners, or unrelated clients.
Gmail user data used by Rent Payment Automation is not sent to any AI/ML service and is not used to develop, improve, or train generalized or personalized AI/ML models.
Why Gmail Read-Only Access Is Required
Rent Payment Automation requests only https://www.googleapis.com/auth/gmail.readonly. The feature must search the user's existing Gmail messages for likely Interac/e-Transfer or rent-payment notifications and then read the message headers and body text because the payer identity, payment amount and payment date may appear in the message body rather than in metadata alone. The application does not request Gmail write, modify, delete, compose or send permissions for this feature.
A metadata-only Gmail permission is not sufficient for this workflow because the application must use Gmail search queries to locate candidate payment notifications and must read message content to extract the payment details needed for matching. The read-only scope is therefore the minimum Gmail permission used by this feature.
Website Analytics
The public website uses first-party analytics to understand page visits, referral source, device/browser type, approximate city/region when supplied by the hosting platform, engagement time, and interactions such as calls, email clicks, article shares, listing clicks, form starts/submissions, scroll depth and video plays. The analytics system uses random browser/session identifiers to group activity into visits and does not intentionally store form-field values or raw IP addresses in the analytics tables.
Website Form Processing
Website forms are submitted to Ghassan Ashag's CRM lead database for follow-up and may also be stored through Netlify Forms as a backup. If the direct CRM handoff is temporarily unavailable, a verified form event may retry the CRM delivery and temporarily retain a retry record until the handoff succeeds.
Service Providers and Disclosure
Personal information is not sold. Information may be processed by service providers used to operate the website and CRM, such as hosting, database/authentication, Google API and authorized AI-processing services, only as reasonably necessary to provide requested features, secure the systems or comply with law. Real-estate and property-management work may also require information to be handled through brokerage, board, legal, financing, inspection, maintenance, transaction or accounting systems appropriate to the client relationship.
Data Retention
Information is retained only as reasonably necessary for the purposes described in this policy, including service delivery, transaction/property history, accounting, security, dispute resolution and applicable legal or professional record-keeping requirements. Retention periods may therefore differ by record type.
Your Choices and Google Access
You may request access to, correction of, or deletion of information you previously submitted, subject to legal and legitimate record-retention requirements. Optional Google connections can be disconnected from the applicable CRM/portal feature. You can also review or revoke third-party access from your Google Account security settings.
Contact
Privacy questions or requests can be sent to ghassan.ashag@gmail.com or made by phone at 647-707-1961.
This policy describes the current data practices of the website and CRM and may be updated when features, providers or legal requirements change.