Last updated: September 17, 2026
OrderRelay ("we", "our", "the app") relays purchase-confirmation emails from a connected Gmail mailbox into a merchant's own systems. This policy explains what data we access, why, and how it is handled.
When you connect a Gmail mailbox to OrderRelay, we request the
gmail.readonly OAuth scope, which lets our server read (but never
send, delete, or modify) messages in that mailbox.
OrderRelay only inspects messages sent from a specific, pre-configured purchase-notification address (e.g. a payments/checkout provider). All other mail in the mailbox is ignored and never read or stored. From a matching message we extract:
This information is stored in our database and forwarded, via webhook, to the merchant's own systems so they can fulfill and track the order. If a matching email cannot be parsed, we store its content temporarily so we can diagnose and fix the parsing failure.
We do not use Gmail data for advertising, do not sell or share it with third parties other than the merchant's own configured webhook endpoint, and do not use it to train generalized AI/ML models. No one at OrderRelay reads your email manually except as needed to investigate a reported bug, and only with the minimum access necessary.
Gmail OAuth refresh tokens are encrypted at rest and are never displayed or transmitted anywhere other than to Google's own token endpoint to obtain a short-lived access token. Purchase data is stored in an access-controlled database and is retained only as long as needed to support the merchant's order fulfillment and bookkeeping.
You can disconnect OrderRelay at any time from your Google Account's Security & third-party access settings. Once revoked, OrderRelay can no longer read the mailbox.
OrderRelay's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
Questions about this policy can be sent to amankumardx5@gmail.com.