Privacy Policy
Effective Date: September 6, 2026 | Last Updated: September 6, 2026
1. Overview & Quebec Law 25 Compliance
Imajery ("we", "us", "our") provides performance marketing and digital agency services. The Imajery Gateway (auth.imajery.app) facilitates direct integration between client websites and their respective cloud providers (Google Workspace, Google Drive, Microsoft 365, and OneDrive).
In strict compliance with Quebec Law 25 (Loi 25) and international privacy frameworks, the Gateway implements a zero agency PII custodianship architecture. Form submissions, user inquiries, and uploaded files are streamed in-memory directly into the client’s own cloud tenant.
2. Data We Access & How We Use It
- Google Drive API: We request the restricted scope
https://www.googleapis.com/auth/drive.filesolely to create and write to the dedicated folder titled📁 Website Form Uploadscreated by the app. We do not inspect, read, or modify any other files in your Google Drive. - Microsoft Graph API: We request
Files.ReadWrite.AppFolderandMail.Sendsolely to write files to your dedicated website form uploads directory and trigger internal notification emails within your tenant. - Encrypted Tokens: OAuth refresh tokens are encrypted at the edge using AES-GCM-256 and stored securely in Cloudflare KV.
3. Marketing Telemetry & Cryptographic Hashing
For marketing attribution and conversion tracking, customer identifiers (such as email address or phone number) are normalized and transformed via one-way cryptographic hashing (SHA-256) at the edge. No unencrypted, cleartext personal identifiers are ever stored in Imajery's analytics data warehouse.
4. Data Retention & Deletion
Clients may revoke access at any time via their Google Account Security Settings or Microsoft Entra ID Admin Center, or by contacting [email protected]. Revoking access will immediately disable further automated uploads.
5. Contact Us
For privacy inquiries or technical questions regarding data handling, please contact: