R&L Automations

Legal and trust

Privacy Policy

Effective and last updated: August 3, 2026

R&L Automations is operated by Lund Services LLC (North Dakota owned and operated). This policy explains how we handle information when you visit our website, request a call, communicate with us, use a managed service under a written agreement, or authorize integrations with third-party service providers (such as Google API services via Nylas). It is provided for general information and is pending final legal review.

Information we collect

  • Business and contact information: information you provide directly, including your name, business name, email address, phone number, contact details, service area, and operational needs.
  • Contracted service data: information needed to deliver a contracted service, including authorized system identifiers, configuration settings, consent and suppression records, message status, and limited operational event data.
  • Google API user data: when you authorize our service to connect to your Google Account (via Nylas or direct OAuth), we access specific user data strictly necessary to provide agreed-upon features. This includes:
    • Gmail data: email addresses, message metadata, and message content required for reading, composing, and sending authorized emails on your behalf.
    • Google Calendar data: calendar events, availability, titles, descriptions, and participant details required for appointment scheduling and calendar management.
    • Google Contacts (People API) data: contact names, email addresses, and phone numbers required for sync and client communication features.
    • Admin SDK data: directory user information (read-only) strictly as requested by Workspace administrators to set up managed connections.
  • Technical and operational data: technical information such as request timestamps, IP addresses, and security events. Service logs are designed to exclude message content, credentials, and unnecessary personal information.

How we use information

We use information to respond to requests, provide and support contracted services, protect accounts, reconcile authorized communications, investigate incidents, meet legal obligations, improve platform reliability, and execute user-authorized operations (such as sending scheduled emails or syncing calendar events). We do not sell personal information.

Google API Services User Data Policy compliance and Limited Use

Our application's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

Specific Google data handling practices:

  1. No data selling. Google Workspace user data (including Gmail messages, Calendar entries, and Contacts) is never sold, rented, or traded to any third party.
  2. No advertising usage. Google user data is strictly used to provide core productivity, communication, and scheduling features. It is never used or transferred for serving advertisements, including retargeting, personalized, or interest-based advertising.
  3. No generalized AI/ML training. Information received from Google APIs is never used to build, train, or improve generalized artificial intelligence or machine learning models without explicit prior user consent.
  4. Human reading limitations. Human employees or contractors are strictly prohibited from reading user email content, calendar details, or contact data obtained via Google APIs, except in the following limited circumstances:
    • We have obtained your explicit consent for specific technical support troubleshooting.
    • It is necessary for security purposes (such as investigating system abuse or severe bugs).
    • It is required to comply with applicable laws, regulations, or legal processes.
    • The data has been aggregated and anonymized for internal system diagnostics.

Client data and consent

For managed client services, the client decides why its customer or end-user information is used and is responsible for required notices, permissions, and lawful consent. We use that information only to provide the contracted service and documented support. R&L operates its own managed systems and CRM; we do not use client customer records to train shared models or market to those customers, and we do not integrate with external CRM or field-service platforms.

Retention and deletion

Operational event data and cached API data are retained only as long as needed to provide the contracted service and are deleted or purged on a regular schedule. Suppression, consent, security, billing, and audit records may be retained longer when needed to honor opt-outs, prove authorization, investigate an incident, or meet a legal obligation. Exact retention and deletion periods will be defined in the service agreement and are pending final legal review.

You may revoke our access to your Google Account at any time via your Google Account security settings. Revoking access halts all future data fetching, and associated token data will be removed in accordance with our system retention schedules.

Sharing and subprocessors

We share information with service providers (subprocessors) only as necessary to operate the service, follow client instructions, protect the platform, or comply with the law. When handling Google API data, data is only transmitted to authorized infrastructure and communication facilitators (such as Nylas) strictly required to execute the connection. See our Subprocessors page.

Security and incidents

We use strict security measures to protect user data, including access controls, tenant separation, encryption in transit (TLS 1.2/1.3) and at rest, managed secret storage, least-privilege roles, suppression controls, active monitoring, and tested rollback procedures. No security program eliminates all risk, but we continually maintain safeguards designed to protect sensitive API tokens and personal information. See Security and Incident Response.

Your choices and account deletion

You may ask to access, correct, or delete information you provided, or request full deletion of account data, subject to contractual, security, and legal limits. Marketing email includes an unsubscribe path. To request account or data deletion, contact us using the information below. See the SMS Privacy section below for how to opt out of text messages.

SMS Privacy

R&L Automations uses mobile phone numbers only to provide requested Front Office account notifications. Message frequency varies based on account activity. Message and data rates may apply. Reply STOP to unsubscribe or HELP for help.

Those notifications are recurring automated operational messages about your Front Office account: inbound caller alerts, caller-designated messages, appointment or service-request notifications, and call-transfer status. They are account notifications, not marketing. SMS consent is optional and is not a condition of purchase.

We do not share, sell, or provide mobile phone numbers or messaging consent data to third parties or affiliates for marketing or promotional purposes. We share a mobile number only with the service providers that carry the messages for us, such as our messaging platform, under contract and solely to deliver the notifications you asked for. See our Subprocessors page.

You give consent through our public SMS consent form, which is optional and is not a condition of purchase. We record the consent wording shown to you, the date and time, and the mobile number provided. Because a web form shows that a number was entered but not that the person controls it, we send one confirmation message and enroll the number only after it is confirmed. After you reply STOP, we send one confirmation and then stop sending text messages to that number, and we keep a suppression record so the opt-out continues to be honored.

Contact

Send privacy questions, data deletion requests, or Google API inquiries to support@rlbusinessautomations.com. We may verify the requester before acting.