MAIN SHOFIELD GROUP, INC.
Privacy Policy
Shofield AI websites and Shofield AI Platform
Last updated: September 15, 2026
Privacy Policy
Privacy policy updated September 15, 2026. This policy covers Shofield AI websites and the Shofield AI Platform, operated by Main Shofield Group, Inc., Delaware, United States. Read the dedicated Privacy Policy page.
Shofield respects the privacy of customers, users, prospects, website visitors, and other individuals whose personal information we process.
Information We May Collect
Account Information
Name, business name, job title, email address, telephone number, billing information, login information, and account settings.
Business Information
Company details, customer records, CRM data, leads, communications, workflows, documents, sales pipeline data, and other information submitted through the Services.
Usage Information
Features used, interactions with AI agents, prompts, autonomous actions, timestamps, usage volume, diagnostic information, device information, browser information, IP address, and approximate location derived from technical information.
Communications
Messages sent to Shofield, support conversations, sales communications, feedback, and other correspondence.
Payment Information
Payment transactions and billing details.
Full payment-card information is generally handled by our payment processors rather than stored directly by Shofield.
Connected Services
Where you connect third-party accounts, we may process information made available through the permissions you authorize.
Google account and Google Workspace data
This section applies to Google Sign-In and Google connections in the Shofield AI Platform, including CRM Inbox, Sales Manager and Calendar features at platform.shofield.ai and mvp.shofield.ai. It takes precedence over broader statements in this policy about marketing, analytics, AI training, sharing and business development when Google user data is involved.
Data accessed and purposes
- Google Sign-In: Google account identifier, verified email address and available name/profile information authenticate you, create or link your account and maintain your session. Signing in alone does not authorize mailbox access.
- Personal Gmail inbox: with your separate permission, Shofield reads message content and headers, sender and recipient addresses, subjects, dates, message/thread identifiers and attachment information. It imports email history, including sent and archived messages, for reading and searching in your private CRM Inbox. Attachment contents are retrieved when requested. Sending permission enables the emails, replies, forwards and attachments you choose to send through Gmail.
- Business email and Calendar connections: separately authorized Sales workflows may read and send messages, process replies and use message-management permissions. Calendar event access supports checking availability and booking or managing meetings, including event details, times and attendees. These connections are distinct from the private inbox and follow workspace permissions and configured workflow approvals.
- Connection records: we retain granted permissions, encrypted access/refresh credentials, connection identity, synchronization state and operational records needed to keep authorized features working. Shofield does not receive your Google password.
Storage, access and protection
Imported message content and metadata are stored in Shofield's hosted database; these are copies separate from Gmail. Attachments downloaded through the inbox pass through our server to your browser. Connection credentials are encrypted before database storage. HTTPS, authenticated sessions, workspace checks and mailbox-owner checks protect access. Other workspace users and administrators cannot read your personal inbox through the platform, including support-view mode. If you intentionally share content or connect a business workflow, the permissions of that feature apply.
Service providers and disclosure
Google processes authorized mailbox and Calendar requests; selected message recipients and meeting attendees receive the information you send or invite them to receive. Our hosting and database infrastructure processes data to operate these features. For an AI-assisted workflow that you explicitly enable, relevant content may be processed by the AI service provider used for that feature, subject to the restrictions below. Connecting a personal inbox alone does not submit its contents to an AI model.
Google-data transfers are limited to consented, visible features, necessary security investigations, legal requirements, or a business transfer with your prior explicit consent. Staff and contractors may read specific Google content only with your affirmative permission, when necessary for security or legal obligations, or in aggregated, anonymized form for internal operations as permitted by Google's policies. We do not grant routine human access to private mail for product development.
Limited Use and AI restrictions
Shofield's use and transfer of information received from Google APIs follows the Google API Services User Data Policy, including its Limited Use requirements, and the Google Workspace API user data policy.
We do not sell Google user data, disclose it to data brokers or information resellers, use it for advertising targeting or retargeting, or use it for creditworthiness or lending decisions. These restrictions also cover derived data. Google Workspace API data is not used to develop, improve or train generalized or non-personalized AI or machine-learning models. We do not permit AI providers to use that data for those purposes. Authorized AI processing is limited to the specific user-facing workflow; it is not permission for general model training.
Retention, disconnecting and deletion
Connection credentials are retained while needed for the authorized connection. Disconnecting a personal mailbox in CRM Inbox clears its stored credentials and stops future synchronization; a request already in progress may finish. Disconnecting does not automatically delete imported messages, previously created CRM records or send-status records. Imported copies remain available until deleted through a data-deletion request or applicable account data removal. Shofield deletion does not delete the original messages held by Google or recipients.
You can also withdraw Google access through your Google Account connections. Revocation stops authorized access but does not itself erase copies already held by Shofield. To request deletion of those copies, connection records or your account, email Legal@shofield.ai with the subject “Privacy Request”, your account email, the connected mailbox and the scope of your request. Do not send passwords or tokens. We verify identity and process the request subject to applicable legal obligations, explaining any necessary retention. Restricted backup and security records may persist through their retention cycles; we do not promise immediate deletion from every backup.
Changes to Google-data use
We update this policy and notify affected users before materially changing how Google data is used. We obtain renewed consent before accessing additional data or using it for a new purpose. Google authorization, verification and any required security assessment remain separate from this policy; publishing it does not mean Google has approved Shofield AI.
How We Use Personal Information
We may process personal information to:
- provide Shofield AI;
- create and maintain accounts;
- authenticate users;
- operate AI agents;
- execute customer instructions;
- process transactions;
- manage subscriptions and credits;
- provide customer support;
- communicate with customers;
- improve functionality and reliability;
- analyze product usage;
- detect fraud and abuse;
- protect our systems;
- enforce agreements;
- comply with legal obligations;
- develop our business; and
- send marketing communications where permitted.
Where applicable, our legal basis may include performance of a contract, legitimate interests, compliance with legal obligations, and consent.
Customer Data and Data Protection Roles
Where a business customer uploads or connects personal data concerning its own customers, prospects, employees, or other individuals, the customer will ordinarily determine why and how that data is processed.
In those situations, the customer generally acts as the data controller or business, and Shofield may act as a data processor or service provider on the customer’s behalf.
Customers are responsible for determining whether they have a lawful basis for collecting and processing personal information through Shofield AI.
Where required, additional data-processing terms may apply.
AI Providers and Subprocessors
Providing Shofield AI may require information to be processed by carefully selected infrastructure providers, AI model providers, cloud services, communications providers, payment processors, analytics services, database providers, and other subprocessors.
The specific providers used may change as technology develops.
Where appropriate, we implement contractual and technical measures designed to protect information handled through those providers.
Certain data may be processed outside the country where it was originally collected.
Where required by applicable law, Shofield uses appropriate mechanisms to support international transfers of personal information.
AI Training
Shofield may use operational information to improve the security, reliability, performance, and functionality of its platform.
For data other than Google user data, handling by third-party AI providers depends on the product, API and contractual arrangements. The Google-data restrictions above apply regardless of provider choice.
For business implementations involving sensitive or proprietary information, Shofield may use enterprise/API configurations designed to provide additional data protections where available.
Shofield does not grant third parties unrestricted ownership of Customer Data.
Data Retention
We retain personal information for only as long as reasonably necessary for the purpose for which it was collected, including to:
- operate accounts;
- provide Services;
- satisfy contractual commitments;
- maintain security;
- comply with legal obligations;
- resolve disputes; and
- enforce agreements.
Retention periods may vary by category of information and legal requirement.
Backups and security logs may remain for a limited period after deletion from active systems.
Privacy Rights
Depending on your jurisdiction, you may have rights relating to your personal information, including rights to:
- request access;
- request correction;
- request deletion;
- receive certain information in portable form;
- restrict certain processing;
- object to certain processing;
- withdraw consent where processing is based on consent; and
- complain to an appropriate data-protection authority.
Certain requests may be subject to legal exceptions.
We may need to verify your identity before processing a request. Email Legal@shofield.ai with the subject “Privacy Request” to exercise these rights.
European Economic Area, United Kingdom and Similar Jurisdictions
Where applicable data-protection law provides such rights, individuals may exercise their rights regarding access, correction, deletion, restriction, portability, objection, and withdrawal of consent.
Individuals may also have the right to lodge a complaint with their local data-protection supervisory authority.
Where Shofield processes personal data on behalf of a business customer, individuals should ordinarily direct requests to that business as the relevant controller.
California Privacy Rights
California residents may have additional privacy rights under applicable California privacy laws.
Depending on applicability, these may include rights to:
- know what personal information is collected;
- access personal information;
- correct inaccurate information;
- request deletion;
- obtain information regarding certain disclosures;
- opt out of certain sales or sharing;
- limit certain uses of sensitive personal information where applicable; and
- exercise privacy rights without unlawful discrimination.
Shofield does not sell personal information for monetary consideration.
Where disclosures for advertising or related purposes qualify as “sharing” under applicable California law, eligible individuals may exercise available opt-out rights.
We may request information reasonably necessary to verify a privacy request.
Authorized agents may submit requests where permitted by law and where appropriate authorization can be verified.
Cookies and Similar Technologies
Shofield websites and applications may use cookies, pixels, local storage, SDKs, and similar technologies.
These technologies may be used for:
- essential functionality;
- authentication;
- security;
- remembering preferences;
- analytics;
- performance measurement;
- product improvement;
- attribution; and
- advertising or marketing where permitted.
Where required by law, non-essential cookies will be used subject to applicable consent requirements.
Users may also control certain technologies through browser settings or available privacy controls.
Security
Shofield uses reasonable administrative, organizational, and technical safeguards designed to protect information.
These may include appropriate authentication, access controls, encryption, monitoring, backups, infrastructure security, and security testing.
However, no internet-connected service can guarantee absolute security.
Customers are responsible for securing their own credentials, devices, endpoints, connected applications, networks, and account permissions.
Privacy updates and contact
We publish revisions here and notify affected users of material changes where required. New Google-data purposes require renewed consent as described above. Contact Main Shofield Group, Inc., Delaware, United States, at Legal@shofield.ai about this policy or your privacy rights.