Skip to the policy
Inveshub App Factory
← Back to App Factory

INVESHUB APP FACTORY

Privacy policy

How Inveshub App Factory handles personal information, connected services, and your choices.

A policy for the platform

Covers your account, workspaces, business applications, and the services you choose to connect.

Access with a purpose

Connected data is used for the features you enable, within the permissions you grant.

You have choices

Manage connections, withdraw consent, or contact us to request access, correction, or deletion.

Who we are and what this covers

Inveshub Company Limited ("Inveshub", "we", or "us") provides App Factory, a platform for creating, operating, and managing business applications. This policy explains how we collect, use, disclose, and protect personal information through our website, web and mobile interfaces, workspaces, generated applications, and connected services.

For platform accounts, administration, billing, and security, Inveshub determines how the relevant information is processed. When an organization (a tenant) uses App Factory to handle its own customer, employee, or other business information, that organization generally determines the purposes and permissions, and we process it on the organization's behalf. Its own privacy notice may also apply.

Information we handle

The information involved depends on the features you use, the content you provide, and the services you authorize. These categories describe the platform broadly; they do not mean that every feature collects every category.

  • Account and organization information: names, email addresses, profile details, organization details, workspace membership, roles, authentication identifiers, and account preferences.
  • Business content: instructions, conversations, documents, files, images, generated content and source code, application records, transactions, and other information you or your organization submit or create.
  • Connected-service information: account identifiers, granted permissions, connection credentials, and the records needed for an enabled integration, such as calendar entries, communications, files, or transaction information.
  • Billing information: subscription and usage records, billing contacts, invoices, payment status, and payment-provider references. Payment-card collection is handled through the selected payment provider's payment flow.
  • Technical and operational information: device and browser details, network information such as IP addresses, session information, activity and error logs, usage measurements, and security events.
  • Support communications: information you provide when contacting us, reporting an issue, requesting assistance, or exercising your privacy rights.

Why we use information

We use information to provide and administer the platform; authenticate users; manage workspace access; create, run, and maintain applications; store and retrieve content; carry out authorized integrations and business operations; measure usage and bill for services; provide support and service notices; troubleshoot and improve reliability; prevent abuse; and meet applicable legal obligations.

Depending on the activity and applicable law, processing relies on providing a requested service or performing a contract, legal obligations, legitimate interests such as platform security and service administration, or your consent. Where consent is required, we request it for the relevant activity. Declining required information may prevent us from providing that feature.

Connected services and permissions

An integration operates when you or an authorized workspace administrator configure it and grant the required permissions. We use the connected information for the requested user-facing features and related operation of the service. Access within a workspace also depends on the roles and application permissions set by the organization.

Adding a new connector does not by itself authorize access to your external accounts. The connection flow and feature descriptions identify the permissions and purposes that apply. Where a new use is outside what we have disclosed, we will provide additional notice and obtain any required consent before that use.

Google account and Calendar information

Google sign-in uses identity information, such as your Google account identifier, name, and email address, to register, authenticate, and link your App Factory account. Signing in does not itself connect your Google Calendar.

If you enable Google Calendar and grant access, we can list calendars so you can select which to use, check availability, and read, create, update, or delete events for your enabled business features. This may involve calendar names and identifiers, event titles and descriptions, locations, dates and times, recurrence, and attendee details. Calendar access remains subject to your Google permissions and workspace configuration.

We store protected authorization tokens and connection settings to maintain the connection. Information returned by a requested operation may also be stored in your application records and relevant operational records. Authorized workspace users and applications may access those records according to their permissions.

Our use and transfer of Google API data follow the Google API Services User Data Policy, including its Limited Use requirements. We do not sell this data, use it for advertising, or use it to train general-purpose AI or machine-learning models. Human access is limited to your permission, security needs, legal obligations, or other access permitted by that policy.

You can disconnect an integration through its available connection controls or revoke access in your Google Account. Revoking access stops future authorized access; it does not automatically erase information already stored in your workspace. Contact us or your workspace administrator to request deletion of retained information.

AI-assisted features

When you use an AI-assisted feature, the instructions, content, and relevant context needed for that request may be processed by AI and workflow service providers to generate responses, applications, or other requested results. Review the information you submit and only include information you are authorized to use.

This policy does not grant unrestricted access to connected accounts for AI processing. Such processing must serve the feature you enable and remain within the permissions and purposes disclosed to you. The restrictions for Google data above also apply when an AI-assisted feature is involved.

Sharing and service providers

We may disclose information to authorized people and applications in your organization; to infrastructure, storage, AI, communication, authentication, payment, and other service providers needed to deliver the feature; when you direct us to share it; or when necessary to comply with law, protect rights, or investigate fraud or security incidents.

The information shared depends on the service and the operation. For example, a payment provider processes a payment, while a connected calendar provider processes a calendar request. A provider's own privacy terms apply to its direct relationship with you. Information may be processed in Thailand or other countries where the relevant providers operate, subject to applicable transfer requirements.

We do not sell personal information. Any disclosure of Google API data remains subject to the Google-specific restrictions above.

Storage, retention, and deletion

Information may be held in platform databases, file and object storage, application environments, logs, and backups. We retain it for as long as needed for the relevant service, the organization's instructions, security, dispute resolution, and applicable legal or accounting obligations. The appropriate period depends on the type of information and why it is held.

You can request account or information deletion by contacting us. We assess the request, verify identity where necessary, and coordinate with the workspace owner when the information belongs to an organization. Some records may need to be retained for legal obligations, security, or unresolved claims; restricted backup copies may remain until their retention cycle ends. We will explain relevant limitations when responding.

Deleting an App Factory account, disconnecting a service, and deleting records held by an external provider are separate actions. Please specify which information and services your request concerns.

How we protect information

We use technical and organizational measures appropriate to the information and service, including authenticated access, workspace and role permissions, protected connection credentials, encrypted connections, and operational monitoring. Access is restricted according to responsibilities and service needs.

You and your organization also help protect information by managing members and permissions, reviewing connected services, and safeguarding accounts. Contact us if you suspect unauthorized access or a privacy incident.

Cookies, browser storage, and preferences

The platform uses cookies or similar browser and device storage for sign-in, sessions, security, language settings, and other preferences, and may use usage-measurement technologies to understand and improve the service. Identity, payment, and connected-service providers may use their own technologies during their service flows.

You can manage browser storage and permissions in your browser or device settings. Blocking or clearing essential storage may sign you out or affect platform features. Where consent is required for a particular use, that consent is separate from simply signing in.

Your choices and privacy rights

Depending on applicable law, you may request access or a copy, correction, deletion, restriction, or portability of your personal information; object to certain processing; withdraw consent; or lodge a complaint with the relevant data protection authority. Rights may be subject to legal exceptions and the rights of others. Withdrawal does not affect processing lawfully carried out before withdrawal.

To make a request, contact us using the details below. We may ask for the information necessary to verify your identity and locate the relevant records. If your request concerns an organization's application, you may also contact its administrator or privacy contact. We will respond within the time required by applicable law.

Changes to this policy

This policy describes data categories and purposes across the platform rather than a fixed list of products or connectors. We may update it as our services or legal requirements change and will display the updated date on this page. For material changes, we will provide an appropriate notice and request additional consent where required. A new feature does not remove your existing permission controls.

Questions or a privacy request?

Contact us with your account email, the relevant workspace, and what you need. Please do not send passwords, access tokens, or payment-card details.

[email protected] ↗
Inveshub Company Limited · 5/1108 Prachachuen Village, Samakee Road, Soi 63, Bang Talat, Pak Kret, Nonthaburi 11120, Thailand
↑ Back to top