This Privacy Policy explains how Rubin Financial ("we," "us," or "our"),
operator of Rubin Financial - Agent System Tracker at
backofficetracker.com (primary) and
rubin-financial.prophog2.com (legacy mirror) (the "Service"), collects,
uses, stores, and protects information — including information obtained through Google APIs when you connect
your Google Calendar.
This Service is a private business tool used by licensed insurance agents and their
managers. Access requires an account created by an administrator.
1. Information we collect
Account information
When an administrator creates your account we store your name, email address, role, and business-related
activity you enter into the tracker (such as pipeline, training, and production records).
Google account data (only if you connect Google Calendar)
Connecting your Google Calendar is optional and initiated by you. If you connect it, we access:
Your Google Calendar events (via the https://www.googleapis.com/auth/calendar.events scope) so you can view, create, edit, and delete events inside the tracker; and
Your primary calendar's email address, so we can show which account is connected.
2. How we use Google user data
To display your calendar inside the Service alongside your office hours.
To let you add, edit, and delete your own events from within the Service.
To let your organization's administrators and your assigned manager view your calendar (read-only)
to support scheduling and professional development. Managers and administrators cannot edit your events.
We do not use Google user data for advertising, and we do not sell it.
Limited Use disclosure. Rubin Financial - Agent System Tracker's use and transfer of
information received from Google APIs to any other app will adhere to the
Google API Services User Data Policy,
including the Limited Use requirements. We only use Google Calendar data to provide and improve the calendar
features described above, we do not transfer it except as necessary to provide those features or as required by
law, and we do not use it for advertising or sell it.
3. How Google data is stored and protected
Your Google authorization (refresh token) is encrypted (AES-256-GCM) before it is stored, and is
held only by our secure backend function — never exposed to your web browser.
Stored tokens are protected by row-level security so they are accessible only to our server process.
Calendar event details are retrieved on demand to display your schedule and are not retained beyond what
is needed to show your current view.
4. Sharing
We do not sell your information. Google user data is visible only to you and, in read-only form, to your
organization's administrators and your assigned manager within the Service. We use trusted infrastructure
providers (for hosting and database services) solely to operate the Service; they process data on our behalf
under their own security and privacy commitments.
5. Your choices & revoking access
Connecting Google Calendar is optional. You can disconnect at any time from within the tracker.
You can also revoke this app's access from your Google Account at
myaccount.google.com/permissions.
Revoking removes our ability to access your calendar.
To request deletion of your account data, contact us using the details below.
6. Data retention
We retain account and business records for as long as your account is active or as needed to provide the
Service. When you disconnect Google Calendar or revoke access, the stored Google authorization is deleted.
7. Children
The Service is intended for business use by adults and is not directed to children under 13 (or the minimum
age in your jurisdiction).
8. Changes to this policy
We may update this policy from time to time. Material changes will be reflected by the "Last updated" date
above.