HiPowerVSES

Privacy and Google account access

Privacy Policy

HiPowerVSES CRM Internal Backup

Last updated: 10 October 2026

This policy describes the optional Google Drive backup feature operated by HiPowerVSES for its internal CRM.

بهره‌بردار: شرکت ویرا صنعت الکترونیک سورین

Purpose and information processed

The feature backs up the company’s CRM database to the Google Drive account authorized by its administrator. It obtains the connected account’s email to verify that it matches the configured master account. Backup filenames, file IDs, sizes, application ownership tags, checksums and upload status are processed to upload, verify and manage backups.

A backup contains the complete SQL database. It may include customer and contact information, invoices, sales items, product identifiers, inventory, returns, repair history, users, audit records and stored settings. Stored information can include login password hashes and confidential settings kept in protected form.

Google permission and connection storage

The application requests drive.file to create and manage its backup files. Google authorization takes place on Google’s sign-in and consent screens. The Google account password is not entered into or stored by the CRM backup feature.

The client ID, connected email, schedule and backup status are stored in the CRM database. The OAuth client secret, refresh token and resumable upload information are protected on the CRM server. On Windows, the protection keys are secured using machine-specific Windows protection.

Transfer, backup package and notifications

The central CRM service uploads backups over HTTPS to the authorized account’s Google Drive. The ZIP package contains a SQL .bak file and restoration instructions. The ZIP itself is not encrypted. It does not contain the server’s protection keyring or private certificate files; restoring these files alone is not a complete server migration.

After a successful backup, configured notification recipients receive an email containing the completion time, filename, size, file ID and SHA256 checksum. The database is not attached to this notice. This feature does not automatically share the Drive file with those recipients.

Retention and deletion

A replacement backup is uploaded and verified before older backup files belonging to the same CRM installation are permanently deleted. This can include app-owned backup files individually placed in Drive trash. The feature does not empty the account’s general trash or delete unrelated Drive files.

If upload, verification or cleanup fails, more than one backup may remain until a later retry completes. Local SQL backups follow the CRM’s separate backup retention settings.

Disabling backups and revoking access

The CRM administrator can disable scheduling or disconnect Google Drive in the application. Disconnecting removes the locally stored refresh token and disables scheduled online backups. Existing Drive files and local backups remain.

To revoke Google authorization, the account holder can remove the application’s access from Google Account connections. Remaining backup files can be deleted directly in Google Drive.

Use of Google user data

Google account and file information is used for the backup operations described in this policy. It is not sold or used by this integration for advertising or AI model training. The feature’s use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including its Limited Use requirements.

Google’s handling of information on its services is described in the Google Privacy Policy.

Contact

For questions about privacy, Google account access or data-related requests, contact the company:

virasanatelectronicsorin@gmail.com

سیاست حریم خصوصی پشتیبان آنلاین HiPowerVSES CRM

آخرین به‌روزرسانی: ۱۰ اکتبر ۲۰۲۶

این سیاست مربوط به قابلیت اختیاری پشتیبان آنلاین نرم‌افزار داخلی CRM شرکت «ویرا صنعت الکترونیک سورین» است.

کاربرد و اطلاعات پردازش‌شده

این قابلیت برای پشتیبان‌گیری از پایگاه داده CRM در Google Drive حساب تأییدشده توسط مدیر استفاده می‌شود. ایمیل حساب متصل برای تطبیق با حساب مستر دریافت می‌شود. نام، شناسه، حجم، برچسب مالکیت برنامه، checksum و وضعیت بارگذاری فایل‌های پشتیبان برای ارسال، تأیید و مدیریت نسخه‌ها پردازش می‌شوند.

نسخه پشتیبان شامل پایگاه داده کامل SQL است و می‌تواند اطلاعات مشتریان و تماس، فاکتورها، اقلام فروش، شناسه محصولات، انبار، مرجوعی‌ها، سوابق تعمیرات، کاربران، سوابق فعالیت و تنظیمات ذخیره‌شده را در بر بگیرد. این اطلاعات ممکن است شامل هش رمزهای ورود و تنظیمات محرمانه‌ای باشد که به‌شکل حفاظت‌شده ذخیره شده‌اند.

مجوز گوگل و نگهداری اتصال

برنامه مجوز drive.file را برای ایجاد و مدیریت فایل‌های پشتیبان خود درخواست می‌کند. ورود و تأیید مجوز در صفحات گوگل انجام می‌شود. رمز ورود حساب گوگل در قابلیت پشتیبان CRM وارد یا ذخیره نمی‌شود.

شناسه برنامه اتصال، ایمیل متصل، زمان‌بندی و وضعیت پشتیبان در پایگاه داده CRM نگهداری می‌شوند. Client Secret، Refresh Token و اطلاعات ادامه بارگذاری روی سرور CRM حفاظت می‌شوند. در نصب ویندوز، کلیدهای این حفاظت با سازوکار حفاظتی وابسته به همان ماشین محافظت می‌شوند.

بارگذاری، محتوای بسته و اعلان‌ها

سرویس مرکزی نرم‌افزار، پشتیبان را از طریق HTTPS به Google Drive حساب تأییدشده ارسال می‌کند. بسته ZIP شامل فایل SQL با پسوند .bak و راهنمای بازیابی است. خود ZIP رمزگذاری نشده است. کلیدهای حفاظت سرور و فایل‌های گواهی خصوصی در این بسته قرار ندارند؛ بازیابی این بسته به‌تنهایی معادل انتقال کامل سرور نیست.

پس از موفقیت، گیرندگان اعلان تنظیم‌شده در CRM، ایمیلی شامل زمان، نام، حجم، شناسه و SHA256 فایل دریافت می‌کنند. پایگاه داده به این ایمیل پیوست نمی‌شود و این قابلیت فایل Drive را به‌صورت خودکار با گیرندگان به اشتراک نمی‌گذارد.

نگهداری و حذف نسخه‌ها

نسخه جدید ابتدا بارگذاری و تأیید می‌شود؛ سپس نسخه‌های قدیمی متعلق به همین نصب به‌صورت دائمی حذف می‌شوند. این حذف می‌تواند فایل‌های پشتیبان متعلق به برنامه را که جداگانه به سطل زباله منتقل شده‌اند نیز شامل شود. سایر فایل‌ها و سطل زباله عمومی حساب پاک نمی‌شوند.

اگر بارگذاری، تأیید یا پاک‌سازی موفق نباشد، ممکن است چند نسخه تا زمان تکمیل تلاش بعدی باقی بمانند. پشتیبان‌های محلی SQL طبق تنظیمات مستقل نگهداری پشتیبان نرم‌افزار مدیریت می‌شوند.

قطع اتصال و لغو دسترسی

مدیر می‌تواند زمان‌بندی را غیرفعال یا اتصال Google Drive را در نرم‌افزار قطع کند. قطع اتصال، Refresh Token ذخیره‌شده را حذف و پشتیبان آنلاین خودکار را غیرفعال می‌کند. فایل‌های موجود در Drive و نسخه‌های محلی باقی می‌مانند.

برای لغو مجوز گوگل، صاحب حساب می‌تواند دسترسی برنامه را از بخش اتصال‌های حساب گوگل حذف کند. فایل‌های پشتیبان باقی‌مانده را نیز می‌توان مستقیماً در Google Drive حذف کرد.

نحوه استفاده از اطلاعات گوگل

اطلاعات حساب و فایل‌های گوگل برای عملیات پشتیبان‌گیری توضیح‌داده‌شده در این سیاست استفاده می‌شوند. این قابلیت اطلاعات را نمی‌فروشد و برای تبلیغات یا آموزش مدل‌های هوش مصنوعی استفاده نمی‌کند. استفاده و انتقال اطلاعات دریافت‌شده از APIهای گوگل مطابق سیاست داده کاربران سرویس‌های API گوگل و الزامات Limited Use انجام می‌شود.

نحوه پردازش اطلاعات در سرویس‌های گوگل در سیاست حریم خصوصی گوگل توضیح داده شده است.

ارتباط

برای پرسش‌های حریم خصوصی، دسترسی حساب گوگل و درخواست‌های مربوط به اطلاعات، با شرکت ویرا صنعت الکترونیک سورین تماس بگیرید:

virasanatelectronicsorin@gmail.com

بازگشت به معرفی برنامه