Payroll, HR and hiring on one platform. Built for teams everywhere.Get pricing
Legal

Google API Services disclosure.

How Softra requests, uses, stores, and deletes data received from Google APIs.

Last updated: August 23, 2026

1. Where Google APIs are used

Softra offers optional "Continue with Google" sign-in for administrators, employees, and job applicants. Google sign-in is never required; email and password sign-in is always available.

2. Scopes requested and why

  • openid - to authenticate you and establish a Softra session.
  • https://www.googleapis.com/auth/userinfo.email - to identify your account and match it to your workspace membership or applicant record.
  • https://www.googleapis.com/auth/userinfo.profile - to display your name and profile picture in the product.

Softra requests no other Google scopes today. If a future feature needs one, it is requested only at the moment that feature is used, explained before consent, and is optional.

3. What we store

  • Google account identifier, email address, name, and profile picture URL, linked to your Softra user record.
  • Authentication events (time, IP address, result) in security logs.

Softra does not store your Google password and does not access Gmail, Drive, Calendar, or Contacts.

4. Limited Use commitment

Softra's use and transfer of information received from Google APIs to any other app adheres to the Google API Services User Data Policy, including the Limited Use requirements. Concretely, Google user data:

  • is used only to provide or improve the user-facing sign-in feature that requested it;
  • is not transferred to others except as needed to provide or improve that feature, to comply with applicable law, or as part of a merger or acquisition;
  • is not used for advertising of any kind;
  • is not sold and is not shared for cross-context behavioural advertising;
  • is not used to train generalized artificial intelligence or machine learning models;
  • is not read by humans, except with your explicit consent, for security purposes such as investigating abuse, to comply with applicable law, or where the data is aggregated and de-identified.

5. Revoking access

You can remove Softra's access at any time at myaccount.google.com/permissions. Revoking disables Google sign-in for your account; you can continue with email and password, or reset your password from the sign-in page.

6. Deleting Google data we hold

Email privacy@softraglobal.com from the address used with Google and ask us to delete data received from Google APIs. We verify the request and delete within 30 days, other than security log entries retained for up to 12 months and records we must keep by law. Deleting an entire Softra account also removes the linked Google profile data.

7. Security

Tokens are held server-side, encrypted at rest, never exposed to other tenants, and access is restricted to least-privilege internal roles. See Security for detail.

8. Related pages

Privacy Notice, Terms of Service, Data Processing Addendum, Sub-processors.