How we use Google user data
Last updated: 13 August 2026
Cookiebees asks for access to your Google account only when you connect a feature that needs it. Nothing is requested at sign-up. This page lists every permission we request, what it does, and what we will never do with it.
Google Calendar - see and edit events on your calendar
Requested when you connect a calendar for meeting booking. We write a meeting to your Google Calendar when a lead books one through Cookiebees, and update or cancel it if the booking changes. We read your existing events for one purpose only: to know which times you are already busy, so those slots are hidden from your public booking page. We do not read event contents, guests or attachments for any other purpose, and we do not store your calendar.
Gmail - send email on your behalf
Requested when you choose to send from your own Google address instead of ours. We send only the messages you have configured: booking confirmations, reminders, follow-up sequences and campaigns you create. This permission is send-only. We do not read, search, index or store the contents of your mailbox, and we cannot see messages you receive.
Google Ads - manage campaigns and upload conversions
Requested when you connect Google Ads as a conversion destination. We upload completed conversions - purchases and qualified leads - back to the ad account that earned the click, as enhanced conversions, and we read campaign performance so reports can show cost against revenue. We do not create campaigns, change bids, change budgets or spend money on your behalf.
What we never do
We never sell Google user data. We never transfer it to third parties except as needed to provide the features you enabled, to comply with applicable law, or as part of a merger or acquisition. We never use it for advertising, including retargeting or personalised advertising. We never allow humans to read it, except with your explicit permission for a support request you raised, for security purposes such as investigating abuse, to comply with applicable law, or where the data is aggregated and anonymised.
Limited Use
Cookiebees's use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. The policy is published at developers.google.com/terms/api-services-user-data-policy.
Retention and deletion
Access and refresh tokens are stored encrypted and are used only to perform the actions above. Disconnecting a Google integration in Settings deletes the stored tokens immediately and revokes our access. You can also revoke access at any time from your Google Account permissions page at myaccount.google.com/permissions. Deleting your workspace deletes all associated tokens and data.
Questions
Write to us through the contact page and we will answer. If you believe we are handling Google user data incorrectly, tell us and we will investigate.