Purpose and information processed
The feature backs up the company’s CRM database to the Google Drive account authorized by its administrator. It obtains the connected account’s email to verify that it matches the configured master account. Backup filenames, file IDs, sizes, application ownership tags, checksums and upload status are processed to upload, verify and manage backups.
A backup contains the complete SQL database. It may include customer and contact information, invoices, sales items, product identifiers, inventory, returns, repair history, users, audit records and stored settings. Stored information can include login password hashes and confidential settings kept in protected form.
Google permission and connection storage
The application requests drive.file to create and manage its backup files. Google authorization takes place on Google’s sign-in and consent screens. The Google account password is not entered into or stored by the CRM backup feature.
The client ID, connected email, schedule and backup status are stored in the CRM database. The OAuth client secret, refresh token and resumable upload information are protected on the CRM server. On Windows, the protection keys are secured using machine-specific Windows protection.
Transfer, backup package and notifications
The central CRM service uploads backups over HTTPS to the authorized account’s Google Drive. The ZIP package contains a SQL .bak file and restoration instructions. The ZIP itself is not encrypted. It does not contain the server’s protection keyring or private certificate files; restoring these files alone is not a complete server migration.
After a successful backup, configured notification recipients receive an email containing the completion time, filename, size, file ID and SHA256 checksum. The database is not attached to this notice. This feature does not automatically share the Drive file with those recipients.
Retention and deletion
A replacement backup is uploaded and verified before older backup files belonging to the same CRM installation are permanently deleted. This can include app-owned backup files individually placed in Drive trash. The feature does not empty the account’s general trash or delete unrelated Drive files.
If upload, verification or cleanup fails, more than one backup may remain until a later retry completes. Local SQL backups follow the CRM’s separate backup retention settings.
Disabling backups and revoking access
The CRM administrator can disable scheduling or disconnect Google Drive in the application. Disconnecting removes the locally stored refresh token and disables scheduled online backups. Existing Drive files and local backups remain.
To revoke Google authorization, the account holder can remove the application’s access from Google Account connections. Remaining backup files can be deleted directly in Google Drive.
Use of Google user data
Google account and file information is used for the backup operations described in this policy. It is not sold or used by this integration for advertising or AI model training. The feature’s use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including its Limited Use requirements.
Google’s handling of information on its services is described in the Google Privacy Policy.
Contact
For questions about privacy, Google account access or data-related requests, contact the company: