1 Introduction
Winsoft Solutions ("Winsoft", "we", "us", or "our") develops and provides desktop software applications for business and professional use, including:
- Winsoft BusinessBuddy — Comprehensive retail billing, inventory management, and POS desktop solution.
- Winsoft MediSmart — Specialized pharmacy billing, batch management, and drug stock control software.
- Winsoft MediSmart Plus — Wholesale pharma distributor ERP, bulk invoicing, and supply chain management software.
This Privacy Policy explains how information is handled when you use our applications and, in particular, when you use the optional email-sending functionality provided through the Google Gmail API.
We respect the privacy of our customers and aim to collect and process only the information necessary to provide our products and services.
2 Customer-Controlled Data
Our desktop applications are designed to allow customers to maintain their business and application data in databases located at their own premises or otherwise under their control.
Depending on the application and how it is configured, this information may include customer names, contact information, email addresses, invoices, medical or business records, transactions, reports, and other information entered or maintained by the customer.
The customer's data is primarily processed and stored by the desktop application and the database infrastructure controlled by the customer.
3 Google Gmail Integration
Our desktop applications may provide an optional facility that allows a user to send emails using the user's own Google Gmail or Google Workspace account.
This functionality is provided through the Google Gmail API.
When a user chooses to use this functionality, the relevant Winsoft application asks the user to authorize the application to send email on the user's behalf.
The authorization is performed through Google's authentication and authorization system. The user remains in control of whether or not to grant this permission.
4 Google Data We Access
For the email-sending functionality, Winsoft applications request only the Google permissions necessary to send email.
Where the application is configured only for sending email, it uses the following Gmail API permission:
This permission allows the application to send email on behalf of the authorized Google account.
The application does not need permission to read the user's Gmail inbox or read the user's existing email messages in order to provide the email-sending functionality.
We do not intentionally access Gmail data that is not necessary for sending an email requested by the user.
5 How We Use Google Data
Google account authorization and Gmail API access are used solely to provide the email-sending functionality requested by the user.
For example, a user may select a customer or recipient within a Winsoft application and select an option such as "Send Email". The application may generate an email using information maintained in the customer's local application database and submit that email to Google's Gmail service for delivery.
Google data obtained through the Gmail API is not used for:
- Advertising or targeted advertising
- User profiling
- Selling or renting information
- Determining creditworthiness
- Marketing unrelated products or services
- Any purpose unrelated to email delivery
6 Email Content and Recipient Information
The email content and recipient information used by the application may originate from information entered or stored by the customer in the customer's local database.
When the user requests an email to be sent, the relevant email information is transmitted directly from the customer's computer to Google through the Gmail API so that Google can process and deliver the email.
Winsoft does not require this email content or recipient information to be transmitted to Winsoft servers for the purpose of providing the Gmail sending functionality.
Winsoft does not intentionally store copies of these emails or their recipient information on Winsoft servers as part of this functionality.
Google may process email information in accordance with Google's own terms and privacy policies.
7 Google OAuth Credentials and Tokens
When a user authorizes a Winsoft application to use Gmail, Google provides authorization credentials, including OAuth access and, where applicable, refresh tokens, to the application.
These credentials are used by the desktop application to communicate with Google's services on behalf of the user.
The authorization credentials used by the desktop application are intended to be stored locally on the customer's computer and are not intentionally transmitted to Winsoft servers.
Winsoft does not use or store customers' Gmail OAuth credentials for its own purposes.
Users are responsible for maintaining the security of the computer on which the Winsoft application and its locally stored authorization information are installed.
8 Information We Do Not Collect Through the Gmail Integration
Through the Gmail integration, Winsoft does not intentionally:
- Read the user's Gmail inbox.
- Read the user's existing Gmail messages.
- Search the user's mailbox.
- Access Gmail contacts.
- Modify or delete Gmail messages.
- Use Gmail data for advertising.
- Sell Gmail data to third parties.
- Use Gmail data for user profiling.
- Store copies of Gmail messages on Winsoft servers.
- Store the user's Gmail OAuth credentials on Winsoft servers.
- Use Google user data for purposes unrelated to the Gmail functionality provided by the application.
The applications request only the Google permissions necessary for the functionality they provide.
9 Data Storage
Application and business data is primarily stored in databases controlled by the customer.
Information required by the desktop application to maintain an authorized Gmail connection, including OAuth credentials or tokens, may be stored locally on the customer's computer.
Winsoft does not intentionally transmit or store those Gmail authorization credentials on Winsoft servers.
The customer is responsible for implementing appropriate security measures for computers, databases, networks, and other infrastructure under the customer's control.
10 Data Sharing
Winsoft does not sell, rent, or trade personal information.
For the Gmail sending functionality, information necessary to send an email is transmitted to Google through the Gmail API when the user requests that an email be sent.
We do not share Google user data with third parties for advertising, marketing, or other unrelated purposes.
Information may be disclosed where required by applicable law, regulation, legal process, or where reasonably necessary to protect the rights, property, security, or safety of Winsoft, our customers, or others.
11 Google API Services User Data Policy
Limited Use Disclosure:
Winsoft's use and transfer of information received from Google APIs will comply with the Google API Services User Data Policy , including the Limited Use requirements where applicable.
We request only the permissions necessary to provide the functionality described in this Privacy Policy and do not use Google user data for purposes unrelated to the functionality requested by the user.
12 Security
We take reasonable technical and organizational measures to protect information handled by our applications.
The Gmail integration uses Google's OAuth 2.0 authorization mechanism rather than requiring users to provide their Google account password to Winsoft.
The desktop application communicates with Google using Google's supported authentication and API mechanisms.
Because the Gmail authorization credentials are maintained on the customer's computer, users and organizations are also responsible for protecting the computers on which the applications are installed.
No method of electronic storage or transmission can be guaranteed to be completely secure. We therefore cannot guarantee absolute security of information.
13 Revoking Google Access
A user can revoke the Gmail authorization granted to a Winsoft application through their Google Account Security Settings .
The user may also remove or disconnect the Gmail authorization from the Winsoft application where such functionality is provided.
After authorization has been revoked, the application will no longer be able to use the Gmail API on behalf of that Google account until the user provides authorization again.
14 Data Retention and Deletion
Winsoft does not intentionally retain Gmail email content or Gmail OAuth credentials on Winsoft servers as part of the Gmail sending functionality.
Business and application data maintained by the customer in the customer's own database is under the customer's control.
If a customer wishes to discontinue the Gmail integration, the Gmail authorization can be revoked through the user's Google Account settings and any locally stored application authorization information can be removed from the customer's computer.
Requests concerning information directly controlled by Winsoft may be submitted using the contact information provided below.
15 Children's Privacy
Our software products are intended for businesses and professional users and are not directed toward children.
We do not knowingly collect personal information from children through our websites or applications for purposes unrelated to providing our services.
16 Third-Party Services
Our applications may interact with third-party services, including Google services, when those services are explicitly enabled or used by the customer.
The use of third-party services is subject to the respective provider's terms and privacy policies.
For Google's services, users should also review Google's applicable privacy practices and policies.
17 Changes to This Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in our applications, services, legal requirements, or data-handling practices.
When we make changes, we will update the "Last Updated" date at the top of this page.
The updated Privacy Policy will be published at:
18 Contact Us
If you have questions about this Privacy Policy, our applications, or the way information is handled, please contact us: