1. Introduction
AMES Solutions Ltd ("AMES", "we", "us", or "our") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our activity management platform.
2. Information We Collect
We collect information that you provide directly to us, including:
- Account information (name, email, password)
- Organisation details (business name, address, contact information)
- Member information (names, dates of birth, medical information where necessary)
- Payment information (processed securely via Stripe)
- Communications with us
3. How We Use Your Information
We use the information we collect to:
- Provide, maintain, and improve our services
- Process transactions and send related information
- Send you technical notices and support messages
- Respond to your comments and questions
- Analyse usage patterns to improve user experience
4. Data Sharing
We do not sell your personal information. We may share your information with trusted third parties who assist us in operating our service (such as Stripe for payments), subject to strict data protection agreements.
5. Data Security
We implement appropriate technical and organisational measures to protect your personal data against unauthorised access, alteration, disclosure, or destruction. This includes encryption, access controls, and regular security audits.
6. Your Rights
Under GDPR, you have the right to:
- Access your personal data
- Rectify inaccurate data
- Request deletion of your data
- Object to processing of your data
- Request data portability
7. Google User Data & Gmail Integration
If you connect a Google account to the AMES mailbox, you can read, organise, and send email from within AMES, including AI-assisted drafting and labelling. We access your Google data only with your explicit consent through Google's permission screen, and only for the scopes below:
- Email address and basic profile — to identify the connected Google account and display its name in AMES.
- Send email (
gmail.send) — to send messages you compose in AMES. - Read and manage messages (
gmail.modify) — to display your inbox and manage messages, labels, and drafts on your behalf.
How we store it. OAuth tokens are encrypted at rest. We do not store full message bodies or attachments — only the limited metadata needed to display your mailbox (sender and recipients, subject, timestamps, and a short preview snippet). Full content and attachments are fetched live from Google when you open a message.
AI features and sub-processors. To generate suggested drafts and labels, message content is processed by our AI sub-processors — the Vercel AI Gateway, which routes to large language model providers (OpenAI, Anthropic, and Google). These providers process the content to return a result and, under their API terms, do not use it to train their models. A current list of sub-processors is available on request.
Limited Use.AMES's use and transfer of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements. We do not use Google user data for advertising; we do not sell or transfer it; we do not use it to develop, improve, or train generalised, non-personalised AI or ML models; and we do not allow humans to read it except where you give explicit consent, where required for security or to comply with the law, or on data that has been aggregated and anonymised.
Revoking access and deletion. You can disconnect Google at any time from the AMES mailbox settings, which revokes our access. You may also revoke access directly at myaccount.google.com/permissions. To request deletion of Google data we hold, email privacy@amessolutions.io.
8. Contact Us
For any privacy-related questions or to exercise your rights, please contact our Data Protection Officer at privacy@amessolutions.io.