Privacy Policy
Last updated: September 7, 2026
TruckCrave ("TruckCrave," "we," "us," or "our") provides a shared inbox application that lets a team manage, reply to, and collaborate on email from a shared or personal mailbox. This Privacy Policy explains what information we collect, how we use it, and the choices you have, for anyone who uses the application (each, a "user" or "you").
Information we collect
Account information. When your organization creates an account for you, we store your name, email address, and role. If you set a password, we store only a securely hashed version of it — we never store or have access to your actual password. If you sign in with Google, we instead receive the basic profile information (name, email address) Google provides, and no password is stored for that account at all.
Email content. When a mailbox is connected — either a shared team mailbox or your own personal inbox — we access, store, and process the email messages, attachments, and metadata (sender, recipient, subject, timestamps) in that mailbox so the application can display, search, and let your team reply to that mail. Attachments are stored in encrypted cloud storage on your organization's behalf.
Content you create. This includes replies and forwarded messages you send, internal notes, signatures, message templates, and tags you add within the application.
Usage and log data. We collect standard technical data needed to operate and secure the service — such as sign-in timestamps, IP address, browser type, and application error logs.
How we use information
We use the information described above only to:
- Operate the shared inbox — syncing, displaying, searching, and organizing connected mailboxes;
- Let your team send, reply to, forward, and internally discuss email through the application;
- Authenticate users and enforce the access permissions your organization has configured;
- Notify you of activity relevant to you (new mail, mentions, assignments);
- Maintain, secure, debug, and improve the reliability of the application; and
- Comply with legal obligations.
We do not sell personal information or email content, and we do not use it for advertising.
How we access and use your Google Account data
When you connect a Gmail mailbox — whether a shared team mailbox or your own personal inbox — TruckCrave requests the following Google OAuth permissions ("scopes"), each tied to a specific, visible feature of the application:
| Permission | What it's used for |
|---|---|
| gmail.modify | Syncing incoming and outgoing mail into your shared inbox, and reflecting star, archive, trash, and spam actions you take in the app back to the real Gmail account. |
| gmail.send | Sending replies, forwards, and new messages you compose, through your own connected Gmail account. |
| gmail.compose | Creating, editing, and deleting drafts, and sending a message directly from a saved draft. |
| openid, email, profile | Identifying which Google account you connected. |
Through these permissions we access, store, and process: email message content (subject, body, sender/ recipient addresses), attachments, and draft messages belonging to the connected Gmail account, as described in "Information we collect" above. TruckCrave's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements — we do not use Gmail data for advertising, we do not sell it, and we do not allow anyone to read it except where necessary to provide the features above, with your explicit consent for a specific support request, for security/legal reasons, or where it has been aggregated and anonymized.
How we share information
We do not share email content or personal information with third parties except with the service providers that host and operate the application on our behalf (for example, cloud hosting and storage providers, and the Google APIs used to connect a Gmail mailbox), each bound to only use that information to provide those services to us — or as required by law.
Data retention and deletion
We retain email content and account data for as long as your organization's account remains active and a mailbox stays connected, so the application keeps working as expected. When a mailbox is disconnected (Settings → Channels, or your own personal inbox's connection settings), we immediately revoke our stored Google access token and delete the associated stored messages, notes, and attachment files, except where retention is required by law or for legitimate backup/security purposes.
Deactivating your account. You can request deactivation of your own account at any time from Settings → Teammates (an organization owner or manager can do the same for a teammate). This blocks sign-in immediately. For 7 days afterward, the request can be reversed by reactivating the account — after that 7-day retention period, it is automatically and permanently anonymized (your name, email, and any personal mailbox and its stored content are deleted), while conversation history other teammates still need is preserved without any personally identifying information attached to it.
Closing your organization's account. An account owner can request to close the entire company account from the same Settings → Teammates page. This immediately signs out every teammate. For 7 days afterward, the closure can be canceled by any owner — after that retention period, the company account and all of its data (every mailbox, conversation, message, and attachment) is automatically and permanently deleted.
Data security
We use industry-standard safeguards to protect information — including encryption in transit, encrypted storage of attachments, and access controls that restrict data to the teammates your organization has authorized. No method of transmission or storage is completely secure, and we cannot guarantee absolute security.
Your choices and rights
You can disconnect any Gmail mailbox yourself at any time directly within the application (Settings → Channels, or your personal inbox's own connection settings), which revokes our access and deletes the associated stored content as described above. You can also revoke access at any time from your Google Account's third-party access settings.
You can deactivate your own account, and an account owner can close the entire organization's account, directly within the application (Settings → Teammates) — see "Data retention and deletion" above for exactly what that does and the 7-day window to reverse it. For anything else — reviewing or correcting your account information — contact us at the address below. Depending on your location, you may have additional rights over your personal information under applicable law.
Children's privacy
This application is intended for business use by adults and is not directed at children. We do not knowingly collect information from children.
Changes to this policy
We may update this Privacy Policy from time to time. If we make material changes, we will update the "Last updated" date above.
Contact us
If you have questions about this Privacy Policy or how your information is handled, contact us at support@truckcrave.com.