Legal
Privacy Policy
Last Updated: July 18, 2026
This Privacy Policy describes how Master CaseSync, LLC (“Master CaseSync”, “we”, “us”, or “our”), a Florida limited liability company, collects, uses, stores, and protects information when organizations and their authorized users use our multi-tenant SaaS platform for business operations and communications (including email, SMS, and WhatsApp).
Master CaseSync may integrate third-party services, including Google (Sign-In with Google and Gmail for sending email), the Meta WhatsApp Cloud API, Twilio, payment processors, and other email delivery providers, to allow authorized businesses to authenticate and communicate through the platform. Master CaseSync is not affiliated with, endorsed by, or owned by Google LLC, Meta Platforms, Inc., or WhatsApp. Use of the Service is also subject to our Terms of Service.
1. Information We Collect
Depending on how the platform is used, we may collect or process:
- Account information, such as login credentials, Google account identifiers (when Sign-In with Google is used), user roles, and account settings.
- Name and contact information for users and contacts managed in the platform (including email addresses and phone numbers).
- Business or organization information, including company profile details entered by customers.
- Information voluntarily entered into the platform, such as directory records, notes, event details, forms, documents, and related operational data.
- Billing and payment-related information processed through payment providers (we typically do not store full card numbers on our servers).
- Technical and security information, such as IP address, browser information, device/browser characteristics, and system logs used for security, diagnostics, and reliability.
- Google OAuth and Gmail connection data (described below), when you choose to sign in with Google or connect Gmail to send email.
- Email communications data (described below).
- WhatsApp messaging data processed through the Meta WhatsApp Cloud API when an organization enables that integration.
- SMS messaging data, including telephone numbers, message content, consent records, delivery status, and opt-out requests processed through Twilio when an organization enables SMS.
2. Google Sign-In and Gmail
Master CaseSync uses Google OAuth 2.0 for two limited, user-initiated purposes:
-
Sign-In with Google (login).
When you choose “Sign in with Google,” we request basic identity scopes
(
openid,email, andprofile). We receive your Google user ID, email address, and basic profile information needed to authenticate you and link or match your Master CaseSync account. We use this information only to sign you in, keep your account linked to Google, and maintain account security. - Gmail for sending email. Separately, an authorized user may connect a Google account in Settings so that Master CaseSync can send email on that user’s behalf through the Gmail API (for example form invitations, reminders, CHRA/PCP mailings, and other platform-initiated messages). That connection requests Gmail-related OAuth scopes necessary to send mail via Gmail. We store OAuth access and refresh tokens (and related expiry metadata) so the Service can send those messages without asking you to re-authorize every time.
How we use Google user data. We use Google account and Gmail data only to:
- Authenticate users who choose Sign-In with Google.
- Send emails that you or your organization explicitly request through the platform, using the connected Gmail account as the sending mailbox.
- Refresh OAuth tokens, troubleshoot send failures, and maintain the security of the connection.
What we do not do with Google user data. We do not sell Google user data. We do not use Google user data for advertising or marketing to third parties. We do not use Gmail content to train generalized AI/ML models. We do not transfer Google user data to third parties except as needed to operate the Service (for example hosting infrastructure under our control) or as required by law. Connecting Gmail is optional; Sign-In with Google is an optional authentication method where offered.
Limited Use. Master CaseSync’s use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
You may disconnect Google / Gmail from your account in Settings (or by contacting us). Disconnecting revokes our stored tokens for that connection, subject to Google’s own account controls (you can also revoke access in your Google Account security settings). Revoking access may stop Sign-In with Google and/or outbound Gmail sending until you reconnect.
3. Email Data and Communications
Master CaseSync sends and may facilitate email in several ways:
- Transactional / service emails we send — for example password resets, security alerts, invitations, form notifications, billing receipts, and account notices. These emails are necessary to operate the Service.
- Emails your organization sends via Gmail — when a user has connected Google/Gmail, messages (invitations, reminders, form links, mailings, and similar) may be sent through that user’s Gmail account using the Gmail API. Your organization determines the recipients and content.
- Emails sent through other delivery providers — where configured, some system or transactional mail may be sent via SMTP or an email API provider rather than Gmail.
- Administrative or product emails — occasional notices about service changes, security, or important product information.
Email-related data we may process includes:
- Sender and recipient email addresses (including the connected Gmail address used as the From mailbox).
- Subject lines and message content you or we compose for delivery.
- Delivery metadata (timestamps, delivery/bounce status where available).
- Gmail OAuth tokens needed to send on your behalf (when Gmail is connected).
- Unsubscribe or preference signals when provided.
We use email addresses and related metadata to deliver messages, prevent abuse, improve deliverability, troubleshoot failures, and comply with legal obligations. We do not sell email lists.
Marketing vs. transactional. Service emails required to operate your account may be sent even if you have opted out of optional promotional messages. Where we send optional marketing email, you may unsubscribe using the link in the message or by contacting us.
Organizations that send email through the platform (including via a connected Gmail account) are responsible for having a lawful basis to contact recipients, providing required disclosures, and honoring opt-outs under applicable law (including CAN-SPAM and similar rules).
4. WhatsApp Data
When an organization connects its WhatsApp Business account to Master CaseSync, we may process messaging-related data necessary to operate the requested messaging features. This may include:
- WhatsApp phone numbers.
- Contact names when available.
- Message content.
- Message metadata.
- Message timestamps.
- Message delivery and read statuses.
- Media or documents voluntarily exchanged through WhatsApp.
This information is processed only to provide the messaging functionality requested by the business using Master CaseSync (for example, receiving inbound messages, sending replies or templates, displaying conversation history, and updating delivery status).
Master CaseSync does not sell WhatsApp message data.
Master CaseSync does not use WhatsApp message content for advertising.
5. SMS and Phone Messaging Data
When SMS is enabled, we may process telephone numbers, message bodies, template content, consent and opt-out records, delivery receipts, and related logs through Twilio or similar providers.
Mobile information, SMS opt-in data, and messaging consent will not be shared with third parties or affiliates for their own marketing or promotional purposes. Text messaging originator opt-in data and consent are used only to provide the requested messaging service and honor applicable opt-out requirements (including STOP/HELP workflows).
6. How We Use Information
We may use information to:
- Provide and operate the Master CaseSync platform.
- Authenticate users (including via Sign-In with Google) and manage accounts, roles, and permissions.
- Provide customer and contact management functionality.
- Send transactional and service emails.
- Send customer-initiated emails through a connected Gmail account when the user has authorized that connection.
- Enable WhatsApp, SMS, and other messaging features at the customer’s instruction.
- Deliver messages and process status updates, bounces, and opt-outs.
- Process payments, subscriptions, and wallet transactions.
- Maintain security and help prevent abuse, fraud, and spam.
- Diagnose technical problems and improve reliability and performance.
- Comply with applicable legal obligations and enforce our Terms.
8. Multi-Tenant Data Isolation
Master CaseSync is a multi-tenant SaaS platform. Each organization has its own logically isolated workspace.
Users from one organization are not authorized to access the contacts, messages, emails, or business information belonging to another organization. Access controls and application logic are designed to enforce this tenant isolation.
9. Data Sharing and Third-Party Services
Information may be processed by infrastructure and integration providers necessary to operate the service, including hosting, Google (Sign-In and Gmail API), email delivery, authenticated messaging APIs, and payment processors.
When you use Sign-In with Google or connect Gmail, authentication and mail-sending requests are processed by Google under Google’s terms and privacy policy. We receive only the OAuth tokens and profile/email information needed for login and sending, as described in Section 2.
When the WhatsApp integration is enabled, messaging data is processed in connection with Meta Platforms / WhatsApp through the WhatsApp Cloud API. WhatsApp services are also subject to Meta’s and WhatsApp’s own terms and privacy policies.
When SMS is enabled, messaging data is processed in connection with Twilio (and carriers). Email may also be processed by SMTP or email API providers used to deliver system mail.
We do not sell personal information. We share information only as needed to operate the service, fulfill customer instructions, protect the platform, or comply with law (including lawful requests from authorities).
10. Sensitive and Healthcare Information
Customers may enter business or healthcare-related operational data into the platform. Organizations remain responsible for determining whether data they store is regulated (for example protected health information under HIPAA) and for using the Service only in ways permitted by law and their own policies.
Unless a separate written Business Associate Agreement (BAA) or equivalent contract applies, customers should not assume that every feature or third-party integration is configured as a HIPAA-covered environment. Contact us if you require a BAA or additional contractual safeguards.
11. Data Retention
Data is retained only for as long as necessary to provide the service, meet contractual requirements, maintain security, resolve disputes, and comply with applicable law.
Message logs, email delivery records, and audit trails may be retained for operational, security, and compliance purposes for a period that depends on the feature and legal requirements.
Organizations may request deletion of their data, subject to legal or contractual retention requirements that may prevent immediate or complete deletion in certain cases (for example billing records or security logs).
12. Data Security
Master CaseSync uses reasonable administrative, technical, and organizational safeguards designed to protect information. These measures may include:
- HTTPS encryption in transit.
- Access controls and role-based permissions.
- Authentication for authorized users (password and/or Sign-In with Google).
- Tenant isolation controls.
- Server-side handling of integration credentials, including Google OAuth tokens (credentials are not exposed to client-side JavaScript).
- Security monitoring and logging where applicable.
No method of transmission or storage is completely secure. We work to protect information but cannot guarantee absolute security.
Users and organizations are responsible for selecting strong passwords, protecting login credentials, and securing devices used to access the Service. Master CaseSync, LLC is not responsible for unauthorized access, account compromise, or related data loss or disclosure that results from weak, reused, shared, stolen, or otherwise insecure passwords or credentials created or managed by users, to the maximum extent permitted by law.
13. User and Business Responsibilities
Organizations using Master CaseSync are responsible for:
- Having the appropriate authority to contact individuals by email, SMS, WhatsApp, or other channels.
- Obtaining required consent when applicable and documenting it.
- Honoring unsubscribe, STOP, and other opt-out requests.
- Complying with WhatsApp Business Messaging policies, Twilio/A2P rules, Google / Gmail acceptable-use rules, and email anti-spam laws.
- Complying with applicable privacy and communication laws (including healthcare privacy rules where they apply).
- Properly managing their users, Google/Gmail connections, account access, and data retention within their tenant.
- Creating and maintaining strong, unique passwords (when not using Sign-In with Google); not sharing credentials; and promptly reporting suspected unauthorized access.
- Providing their own privacy notices to end users/patients/clients when required.
14. User Rights and Data Requests
Depending on your location and role, you or an authorized organization may request:
- Access to applicable personal data.
- Correction of inaccurate information.
- Deletion of applicable data.
- Information regarding data processing.
- Restriction of certain processing, or objection, where provided by law.
- Where applicable under U.S. state privacy laws, the right to know, delete, or opt out of sale/sharing of personal information (we do not sell personal information).
If you are an end user (for example a patient or client) whose data was entered by a business customer, please contact that organization first; we may redirect requests to the relevant customer as the controller of that data.
Requests are subject to identity and authority verification. We may decline or limit requests where permitted by law (for example, where another party’s rights or legal retention obligations apply).
15. International Transfers
Master CaseSync, LLC is organized under the laws of the State of Florida, United States. The Service may be hosted and processed in the United States or other countries where we or our providers operate. If you access the Service from outside those locations, you understand that information may be transferred to and processed in those countries, which may have different data-protection laws than your country of residence.
16. Children’s Privacy
Master CaseSync is not intended for direct use by children under 13 and does not knowingly collect personal information directly from children under 13 through public account registration. Authorized business customers remain responsible for the lawfulness of any information they enter into the platform about individuals they serve.
17. Changes to This Privacy Policy
We may update this Privacy Policy from time to time. When we do, we will revise the “Last Updated” date at the top of this page. Continued use of the platform after an update constitutes notice of the revised policy for platform users, except where additional notice is required by law.
18. Contact Information
For privacy-related questions or data requests, contact:
Master CaseSync, LLC — Privacy Contact
Email: no-reply@mastercasesync.com