Privacy Policy
Last updated: September 9, 2026
SmartDealMind LLC ("SmartDealMind", "we", "us") operates the website at smartdealmind.com and provides custom website-build and AI agent services to small businesses in LaGrange, Troup County, and the surrounding area. This policy explains what information we collect, how we use it, and the choices you have. It also covers Google-connected tools we operate for authorized account and channel owners, including mailbox tools and Channel Desk.
1. Information we collect
We only collect what we need to do business with you:
- Account information — when you create an account or sign in via Google, we receive your name, email, profile picture, and a unique account identifier from Google. We use this only to authenticate you and personalize the admin experience.
- Connected Google services — if you separately authorize a mailbox or YouTube tool, we receive the account, message, or channel data needed for the features you use. This additional access is explained in section 4 and on Google's consent screen; ordinary website sign-in does not itself connect your mailbox or YouTube channel.
- Estimate requests — when you submit our "Request a custom estimate" form, we collect your name, email, phone number (if provided), business name, and the message you wrote. This goes into our internal estimate inbox so we can reply.
- Quote interactions — when you view a quote we sent you (a "/q/<token>" link), we record that you viewed it and which line items you accepted, so we know what to build.
- Business prospect data — for outbound sales we maintain a public-information database of local businesses (name, phone, address, public category, public website if any). This data comes from publicly available sources such as the LaGrange-Troup County Chamber of Commerce directory and Google Maps. It is not sold or shared.
- Server logs — like every website, our servers automatically log request metadata (IP, user-agent, timestamp, URL) for security and debugging. Logs are retained for a limited time and never sold.
2. How we use information
- To respond to estimate requests, send custom quotes, and provide the service you asked for.
- To authenticate admin accounts and protect against fraud or abuse.
- To reach out about projects you've engaged with us on.
- To improve our own internal sales process and demos.
- To provide the mailbox review and channel-management features you authorize, as described below.
We do not sell your personal information. Google user data is subject to the additional purpose and sharing limits in section 4.
3. Cookies
We use a small number of essential cookies:
session— keeps you signed in to the admin console.
We do not use third-party advertising or behavioral-tracking cookies on this site.
4. Google sign-in and connected services
Website sign-in
When you choose to sign in with Google, Google asks for your permission to share your basic profile (name, email, profile picture) with SmartDealMind. We use this information and your Google account identifier to identify your account and create a session. This website sign-in requests basic profile permissions. Connecting a separate Google service requires additional authorization.
Gmail and mailbox tools
If you authorize a Gmail integration, the permissions shown by Google can allow us to access message and thread identifiers, sender and recipient addresses, subjects, dates, labels, read status, snippets, message text or HTML, and attachment information such as filenames. We use this data to display, search and help you review your mailbox and carry out the mailbox tasks you request. A read-only permission permits reading; sending, drafting or changing messages requires the corresponding granted permissions and a tool that supports the requested action. We do not obtain your Google password through OAuth.
YouTube and Channel Desk
Channel Desk uses YouTube API Services. When a channel owner connects YouTube, we access the authorized channel's identity and relevant video metadata, publication status, processing status, thumbnails and caption tracks. We use these to confirm the correct channel, check releases and carry out approved publishing tasks. These tasks can send your video, title, description, thumbnail, captions and publication schedule to YouTube. The owner selects the channel and approves the release package; connecting one channel does not authorize us to manage another.
Google's handling of information is described in the Google Privacy Policy.
Google data use and sharing limits
We use Google user data to provide the features you authorize. We do not use it for advertising, sell it to data brokers, or use it to develop, improve or train generalized or non-personalized AI or machine-learning models. If you direct a connected assistant to review or summarize content, the content supplied to that assistant is processed to perform that task; the service providers involved are described in section 5. We allow human access only with your affirmative agreement to view the specific data, or when necessary for security or compliance with applicable law.
SmartDealMind's use and transfer of information received from Google APIs will adhere to the Google API Services User Data Policy, including its Limited Use requirements.
You can revoke the permissions you granted at any time in your Google account permissions page. Revocation stops future authorized access; it does not automatically erase information already saved by a tool or remove content you published on YouTube. Section 7 sets out our removal process and the applicable YouTube-data deadlines.
5. Third-party services
We rely on a small number of well-known providers to run the service:
- Cloudflare — hosting, content delivery, DNS, and security.
- Resend — transactional email (replies to estimate requests, account emails).
- Google — optional website sign-in, separately authorized Gmail and YouTube integrations, and embedded Google Maps on demo pages.
- Assistant and messaging services you use — if you use an operator assistant such as Codex or Claude to work with connected-service data, the information passed to that assistant is processed by its provider (OpenAI or Anthropic, respectively). If you use a Telegram interface, the commands and replies sent through it are also processed by Telegram. These interfaces can retain conversation history under their own settings and policies. Using Google sign-in alone does not send your mailbox content to an assistant or to Telegram.
We share information with service providers only as needed for the service or interaction you request. Each operates under its own privacy policy. Google-data transfers remain subject to the limits in section 4.
6. How we protect Google user data
We use safeguards to protect Google user data, including sensitive data, against unauthorized access, disclosure and alteration. Our website and connections to Google APIs use HTTPS with TLS encryption in transit. Channel Desk applies the following additional safeguards on the operator's computer:
- Local access — the Channel Desk service listens only on the computer's loopback interface. Its browser interface and temporary OAuth callback use local HTTP on that computer; token exchanges and YouTube API requests go to Google over HTTPS.
- Restricted storage — OAuth connection credentials, including refresh tokens, are stored separately from public content and release packages. The connection flow requires a directory accessible only to its operating-system owner and credential files readable and writable only by that owner. It rejects unsafe ownership or permissions, and rejects credential files or the private credential directory when they are symbolic links. Publishing records also use a local database protected by owner-only filesystem permissions.
- Token handling — short-lived access tokens are held in process memory instead of being written to saved connection files. Account credentials are not included in public release packages or connection-status responses.
- Connection validation — the OAuth connection uses Proof Key for Code Exchange (PKCE), checks the callback state, host and path, and confirms the expected YouTube channel before saving its credentials. These checks help prevent an intercepted or mismatched authorization response from establishing a connection.
- Limited diagnostic output — Channel Desk disables request logging for its local interface and OAuth callback. Connection and YouTube-provider errors use sanitized messages instead of exposing raw Google error responses or authorization credentials.
These local files are protected by filesystem access controls; Channel Desk does not itself encrypt them. The security of the operator's device and operating-system account therefore also matters. The data-use and sharing limits in sections 4 and 5 continue to apply, and section 7 explains retention and deletion.
7. Data retention
We keep account and project information as long as your account is active or as long as needed to complete and support a project we're working on with you. Connected tools may retain authorization tokens to maintain the connection, and local records of requested work and its results. Channel Desk also retains owner-supplied release assets and publishing records. We distinguish your original files from information retrieved through Google APIs; revoking a connection does not automatically remove your original files.
For YouTube API data, our retention rule is to refresh or delete stored metadata within 30 calendar days and periodically reconfirm authorization. If you ask us to delete that data or revoke access through us, we remove the associated API data as soon as possible and within seven calendar days. If you revoke access through Google's settings, we remove the associated API data as soon as possible and within 30 calendar days. These rules concern copies held by our tools; they do not delete your videos from YouTube.
To disconnect a tool or request deletion of Google-derived information we hold, email support@smartdealmind.com and identify the account and connected tool. Do not send passwords or tokens. We will verify the request, remove the associated connection credentials and stored information within our control, and explain any records we must retain for legal or security reasons. Deleting our records does not delete your original Gmail messages or published YouTube videos. Copies you have sent to a separate assistant or messaging service must also be managed through that service's history and deletion controls.
8. Your choices
- Email support@smartdealmind.com to access, correct, or delete your data.
- Revoke Google sign-in or connected-service access via your Google permissions page.
- Stop receiving outreach about your business — email us and we'll mark you as opted out.
9. Children's privacy
SmartDealMind is not directed at children under 13. We do not knowingly collect data from them.
10. Changes to this policy
If we make material changes, we'll update the "Last updated" date at the top of this page. If a connected feature needs additional permissions or a new use of Google data, we will explain the change and request the required authorization before using the data for that purpose.
11. Contact
SmartDealMind LLC
LaGrange, GA
support@smartdealmind.com