Command Desk by WebVillage Marketing

Privacy Policy

Effective September 13, 2026

1. Overview

Command Desk is a business operations platform provided by WebVillage Marketing ("Command Desk," "we," "us," or "our"). This Privacy Policy explains what information we collect, how we use it, when we share it, and the choices available to users.

Command Desk is designed for business use. A customer organization may provide access to its owners, employees, contractors, or other authorized users. In those cases, the customer organization may control what business information is entered into Command Desk and who can access it.

2. Information we collect

Depending on the features you use, Command Desk may process:

  • Account and profile information, such as your name, email address, organization, Profile access, and role.
  • Business operations data, such as leads, follow-up reminders, notes, tasks, customer information, status updates, and other records you or your organization enter into the service.
  • Website inquiry data, such as a prospect's name, company, email, phone number, inquiry message, form source, and related follow-up information when a customer routes website leads into Command Desk.
  • Connected-service data from services you explicitly authorize, such as Gmail.
  • Usage and diagnostic information, such as feature usage, connection status, timestamps, error information, and security/audit events needed to operate and protect the service.
  • Support information that you provide when requesting help.
  • Mobile and messaging information, such as a mobile phone number, messaging preferences, opt-in/opt-out state, consent timestamps and source, consent program/version identity, delivery records, and related messaging activity when you use text messaging features.

3. Google and Gmail data

Command Desk only accesses Google data after a user explicitly connects a Google account through Google's OAuth consent flow. We request the minimum Gmail permissions needed for the features the user chooses to use.

For the current Gmail integration, Command Desk may request:

  • Gmail read-only access so Command Desk can support email-reading features. The product is designed to let the user select a Gmail label that defines the email stream intended for Command Desk. During beta, if no email-reading feature is enabled, this permission may be used only to verify the connection and display available user labels.
  • Gmail send access so Command Desk can send or reply from the connected Gmail account when the user enables the in-product permission allowing Command Desk to send on the user's behalf.
  • Google account email address so the product can identify the connected account.

Command Desk does not request permission to delete email, change Gmail settings, or modify mailbox contents as part of the initial Gmail integration.

When a Gmail-powered feature creates a user-facing Command Desk record, relevant message content or metadata may be stored in that record so the user can review, act on, or follow up on the item. We do not use Google user data for advertising, and we do not sell Google user data.

When a user connects Google Calendar, Command Desk accesses the connected account’s calendar list and calendar event data, including event titles, dates, times, time zones, availability or busy status, and calendar identifiers. Command Desk uses this data to display connected calendars, calculate booking availability, detect conflicts, and read back bookings. When the user enables a writable or default booking calendar, Command Desk may create, update, reschedule, and cancel events on that calendar at the user’s direction. Relevant calendar identifiers, event details, connection settings, encrypted OAuth tokens, and synchronization status may be stored as needed to provide and maintain the integration. Google Calendar data is not sold, used for advertising, or used to train generalized AI or machine-learning models, and is shared only with service providers as needed to operate and secure Command Desk, when required by law, or when directed by the user. Users may disconnect Google Calendar in Command Desk or revoke access in their Google Account settings.

Command Desk's use and transfer of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

4. How we use information

We use information to:

  • Provide the Command Desk features requested by the user or customer organization.
  • Route leads, reminders, messages, tasks, and other business information to the correct customer Profile.
  • Generate user-facing summaries, suggested actions, and other AI-assisted workflow features where enabled.
  • Send user-authorized communications and notifications.
  • Maintain SMS consent and suppression records, provide support and troubleshooting, prevent abuse, and satisfy legal, carrier, or provider compliance requirements.
  • Maintain security, troubleshoot errors, and support users.
  • Measure product usage and improve reliability and usability.

We do not use Google user data to train generalized advertising models or generalized AI/ML models. If an AI-assisted feature processes user data, that processing is limited to providing the user-facing Command Desk feature requested by the user or organization.

5. How we share information

We do not sell personal information or Google user data. We may share information with service providers that help us host, secure, operate, support, or deliver requested Command Desk features, subject to appropriate contractual and confidentiality obligations.

We may also disclose information when required by law, to protect rights or security, in connection with a business transfer, or when the user or customer organization directs or consents to the disclosure.

6. Mobile phone numbers and text messaging

Command Desk may process your mobile phone number, messaging preferences, opt-in and opt-out state, consent timestamps and source, consent program/version identity, delivery records, and related messaging activity to provide requested messaging services, operational notifications, consent and suppression records, support and troubleshooting, abuse prevention, and legal, carrier, or provider compliance.

No mobile information is shared with third parties or affiliates for their own marketing or promotional purposes.

SMS opt-in data and consent are not sold, rented, or shared with third parties or affiliates for their own marketing or promotional purposes.

Service providers and carriers may process mobile information only as necessary to provide, operate, secure, route, or support the requested messaging service, or where required by law.

  • Message frequency varies based on selected settings and business activity.
  • Message and data rates may apply.
  • Reply STOP to unsubscribe from the applicable SMS program.
  • Reply HELP for assistance or contact inquiry@webvillage.marketing.
  • Opting out of SMS does not necessarily stop permitted non-SMS communications.
  • Consent to one messaging program is not consent to another messaging program.

7. OAuth tokens and connected accounts

Google OAuth credentials and access tokens used for app-user connections are managed through the authorized connector infrastructure. Command Desk does not display OAuth access tokens to users or intentionally store raw Google passwords.

Users may disconnect Gmail from Command Desk at any time. Users may also revoke Google access from their Google Account security settings. Disconnecting stops future access through that connection. Command Desk records that were previously created from authorized data may remain until deleted under the applicable account or retention process.

8. Data retention

We retain business records for as long as reasonably necessary to provide the service, support the customer's workflow, meet contractual obligations, resolve disputes, maintain security/audit history, or comply with law. Retention periods may vary by record type and customer relationship.

Customers may request account-data deletion or export subject to contractual, legal, security, backup, and recordkeeping requirements.

9. Security and access controls

We use administrative, technical, and organizational safeguards intended to protect information, including Profile-based access controls and controlled integration permissions. No online service can guarantee absolute security, and users are responsible for protecting their account credentials and promptly reporting suspected unauthorized access.

10. Children's privacy

Command Desk is a business service and is not intended for children under 13. We do not knowingly solicit personal information from children under 13 through the service.

11. Changes to this policy

We may update this Privacy Policy as the service or legal requirements change. We will update the effective date on this page when material changes are made and may provide additional notice when appropriate.

12. Contact

Command Desk is provided by WebVillage Marketing. Privacy questions or requests may be submitted through your Command Desk administrator or at inquiry@webvillage.marketing.