VelaFoldAuth is a centralized OAuth 2.0 integration service operated by VelaFold. It securely connects authorized VelaFold websites to Google Sign-In, Google Drive, and Google Calendar. Our contact address is info@velafold.com.
When you sign in through a VelaFold-connected website, VelaFoldAuth temporarily receives:
The OAuth scopes requested depend on the feature the user starts: email and profile for Google Sign-In, https://www.googleapis.com/auth/drive.file for Drive backup files, and https://www.googleapis.com/auth/calendar.events plus https://www.googleapis.com/auth/userinfo.email for Calendar event workflows.
For Google Drive authorization, the service receives a refresh token that allows the requesting VelaFold website to create, list, download, and delete website backup files in the user's Drive.
For Google Calendar authorization, the service receives a refresh token that allows the requesting VelaFold website to view, create, and update calendar events used by its configured workflows.
Google user data is used only to provide the feature the user explicitly authorizes: administrator sign-in, Drive backup storage, or Calendar event management. The broker issues a short-lived, single-use code to the requesting VelaFold website. It does not use Google user data for advertising, profiling, credit decisions, or unrelated purposes.
Broker codes, identity payloads, and refresh tokens are stored only until the requesting website exchanges the code, for a maximum of 5 minutes. Consumed records are deleted immediately and expired records are removed automatically. A connected VelaFold website stores its Google refresh token securely until an administrator disconnects the integration or Google revokes access.
User data is shared only with the registered VelaFold website that initiated the authorization request, through an authenticated server-to-server exchange. We do not sell, rent, or share Google user data with advertisers or unrelated third parties.
VelaFoldAuth uses a server-side session cookie solely to maintain state during the OAuth flow, such as preserving the registered return address. This cookie is session-scoped and expires when the browser session ends. We do not use tracking, analytics, or advertising cookies.
If you are located in the European Economic Area, you may request access, correction, deletion, or revocation of personal data processed by the service. You may also disconnect Drive or Calendar from the relevant VelaFold administration panel or revoke access from your Google Account. For inquiries, contact info@velafold.com.
All communication with VelaFoldAuth is encrypted via TLS. Authorization codes are generated using cryptographically secure random bytes, expire quickly, and are single-use. Registered websites must authenticate with a server-side secret before receiving data.
VelaFoldAuth's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including its Limited Use requirements.
We may update this Privacy Policy from time to time. The revision date above identifies the latest version.
For privacy-related questions, contact us at info@velafold.com.