Introduction
This page explains how Engrana uses third-party applications and services to provide you with the messaging automation service.
We are 100% transparent about which applications we use, what data we access, and why.
If you have questions, email us at info@engrana.es
What is Engrana
Engrana is a messaging automation platform for freelancers and small businesses that work with appointments.
Main application purpose:
Automate client communication (responses on WhatsApp, Instagram, Facebook) and appointment management (confirmations, reminders, no-show control) so business owners recover time and reduce losses from unconfirmed appointments.
Operator:
AUVE MEDIA GROUP SL
Tax ID: B19373067
Carrer Antoni Maura 13, 08225 Terrassa, Barcelona
Spain
Email: info@engrana.es
Third-party applications we use
Engrana integrates with the following third-party applications to function:
- Google Calendar API - Calendar and appointment management
- Google Sheets API - Data and spreadsheet management
- WhatsApp Business API (Meta) - Automatic messaging
- Instagram API (Meta) - Direct Messages messaging
- Facebook Messenger API (Meta) - Messenger messaging
- Stripe API - Payment processing
Below, we detail how we use each one:
Limited Use of Google user data
Engrana's use and transfer of information received from Google APIs to any other app adheres to the Google API Services User Data Policy, including the Limited Use requirements.
Engrana's use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
The use and transfer of raw or derived user data received from Google Workspace APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
In practice, the data we obtain from Google Calendar and Google Sheets:
- are used only to provide and improve the user-facing features of Engrana (calendar, availability, appointment reminders and confirmations);
- are not transferred to third parties except as necessary to provide those features, for security purposes, to comply with applicable law, or as part of a merger or acquisition with the user's consent;
- are never used for advertising purposes, our own or anyone else's, and are never sold;
- are not read by humans, except with the user's explicit consent, for security purposes, to comply with applicable law, or when the data is aggregated and anonymised.
Users can revoke Engrana’s access to their Google account at any time from myaccount.google.com/permissions. When they do, we stop syncing and delete the associated tokens.
1. GOOGLE CALENDAR API
Purpose of use
Engrana uses Google Calendar API to:
- Read calendar events from the user (scheduled appointments)
- Create new events when a client books an appointment
- Update existing events when an appointment is modified or canceled
- Sync in real-time to detect changes and send reminders
What data we access
Calendar data we read:
When we query the calendar we request these fields from Google, and no others:
- The event's internal identifier
- Start and end date and time, from which the duration is derived
- Event status (active or cancelled)
- Whether the event marks the calendar as busy or free
- The event title, which is shown to the account owner in their own calendar inside Engrana and is not used for anything else
Data we DON'T read:
- The event description or notes
- Attendees and guests: neither their names nor their email addresses
- Location, attachments and video call links
- Calendars the user doesn't explicitly authorize
- Any other Google product: Gmail, Drive or Contacts
When a client books, Engrana creates the event with the title, description and guest for that booking. Engrana writes that content; it does not come from reading the user's calendar.
How we use this data
For automatic appointment confirmation:
- Engrana reads calendar events
- 24 hours before the event, sends automatic message to client: "Hi [name], tomorrow you have an appointment at [time] for [service]. Do you confirm?"
- 3 hours before, sends final reminder
- If client cancels, we update the event in Google Calendar
For availability detection:
- When a client asks "Do you have availability tomorrow?", Engrana checks the calendar
- Detects free slots between events
- Responds automatically with available times
For appointment creation:
- When a client books (via web, WhatsApp, Instagram), Engrana creates the event in Google Calendar
- Includes all details: name, service, time, duration
- User sees the appointment automatically reflected in their calendar
For change management:
- If client changes time, Engrana updates the event in Google Calendar
- If client cancels, Engrana marks the event as canceled
Permission scopes requested
Engrana requests the following Google Calendar API scopes (permissions):
https://www.googleapis.com/auth/calendar.readonly
https://www.googleapis.com/auth/calendar.events
What they allow:
calendar.readonly: Read calendar events (to detect appointments and availability)calendar.events: Create, update, and delete events (to manage appointments)
What they DON'T allow:
- Access to other Google services (Gmail, Drive, etc.)
- Modify calendar settings
- Share calendars with third parties
How data is stored
Temporary storage:
- Calendar data is queried in real-time when needed
- We don't store a complete copy of your calendar on our servers
- We only store data from events that require action (pending reminders, confirmations)
Retention period:
- While using Engrana: Active data from upcoming appointments
- After canceling the service: 30 days → Complete deletion
- Backups: 90 days maximum → Permanent deletion
Security:
- Encrypted access tokens
- HTTPS/TLS connection
- Access restricted to authorized personnel only
- Hosting in European Union (GDPR compliant)
Security and privacy
Credential protection:
- Your Google credentials are handled via OAuth 2.0 (security standard)
- We never see or store your Google password
- Access tokens are encrypted in our database
GDPR compliance:
- All data is processed in the European Union
- We comply with the General Data Protection Regulation
- You can revoke access anytime from your Google account
Audit:
- We log all actions Engrana performs on your calendar
- You can see the action history in your Engrana panel
- In case of incident, we can trace what happened
Revoking access
You can revoke Engrana's access to your Google Calendar at any time:
Option 1: From your Google account
- Go to https://myaccount.google.com/permissions
- Search for "Engrana" or "AUVE MEDIA GROUP"
- Click "Remove access"
Option 2: From your Engrana panel
- Access Settings → Integrations
- Click "Disconnect Google Calendar"
- Confirm the action
What happens when you revoke:
- Engrana can no longer read or modify your calendar immediately
- Automatic appointment confirmation features stop working
- Already created events are not deleted (they remain in your calendar)
- Your data in Engrana is retained per our Privacy Policy
Why we need this access
Without Google Calendar access, Engrana CANNOT:
- Know when you have scheduled appointments
- Send automatic reminders 24h and 3h before
- Detect real availability to answer "Do you have availability tomorrow?"
- Create appointments when a client books via WhatsApp/Instagram
- Update the calendar when a client cancels or changes time
Alternative if you don't want to give access:
Engrana can work with other calendars (Apple Calendar, Outlook, Calendly). However, the integration process is less smooth.
Contact and support
Google Calendar questions:
Report security issue:
info@engrana.es (subject: "URGENT - Google Calendar Security")
More information:
2. GOOGLE SHEETS API
Purpose of use
Engrana uses Google Sheets API to:
- Read spreadsheet data (client lists, services, pricing)
- Write data (log appointments, confirmations, history)
- Synchronize information between your spreadsheet and the automation system
- Export reports of activity and metrics
What data we access
Data we read:
- Cell content (names, phone numbers, services, dates)
- Sheet structure (rows, columns, tabs)
- Names of authorized spreadsheets
Data we DON'T access:
- Spreadsheets you don't explicitly authorize
- Other files in your Google Drive
- Personal information unrelated to the service
How we use this data
For client management:
- Engrana reads your client list from the sheet
- Syncs names, phone numbers, and preferences
- Updates automatically when changes occur
For activity logging:
- Records confirmed, canceled, and completed appointments
- Saves message sending history
- Generates no-show and confirmation metrics
For customization:
- Reads services and pricing from your sheet
- Enables personalized messages based on client data
- Adapts automatic responses per configuration
Permission scopes requested
Engrana requests the following Google Sheets API scopes (permissions):
https://www.googleapis.com/auth/spreadsheets
What it allows:
spreadsheets: Read and write to authorized spreadsheets
What it DON'T allow:
- Access to other Google services (Gmail, general Drive, etc.)
- Delete entire spreadsheets
- Share sheets with third parties
How data is stored
Storage:
- Data is queried in real-time when needed
- We only store minimal data for operation (sheet IDs, configuration)
- Main data remains in your Google Sheets
Security:
- Encrypted access tokens
- HTTPS/TLS connection
- Access restricted to authorized personnel only
- Hosting in European Union (GDPR compliant)
Revoking access
You can revoke Engrana's access to your spreadsheets at any time:
Option 1: From your Google account
- Go to https://myaccount.google.com/permissions
- Search for "Engrana" or "AUVE MEDIA GROUP"
- Click "Remove access"
Option 2: From your Engrana panel
- Access Settings → Integrations
- Click "Disconnect Google Sheets"
- Confirm the action
What happens when you revoke:
- Engrana can no longer read or write to your sheets immediately
- Features depending on the sheet stop working
- Your spreadsheets are not modified or deleted
- Your data in Engrana is retained per our Privacy Policy
Why we need this access
Without Google Sheets access, Engrana CANNOT:
- Sync your client list automatically
- Log appointment and message activity
- Personalize messages with data from your sheet
- Generate exportable reports
Alternative if you don't want to give access:
Engrana can work without Google Sheets using its internal database, though you'll lose the flexibility of managing data directly from spreadsheets.
Contact and support
Google Sheets questions:
Report security issue:
info@engrana.es (subject: "URGENT - Google Sheets Security")
3. WHATSAPP BUSINESS API (Meta Platforms)
Purpose of use
Engrana uses WhatsApp Business API to:
- Automatically respond to client messages
- Send appointment confirmations
- Send scheduled reminders
- Request reviews after completed services
What data we access
- Incoming messages from your clients
- Contact name
- Phone number
- Multimedia (photos/videos clients send)
How we use this data
- To respond automatically per customized configuration
- To save conversation history (context)
- We DON'T sell or share messages with third parties
More details: See WhatsApp Usage Policy
4. INSTAGRAM API & FACEBOOK MESSENGER API (Meta Platforms)
Purpose of use
Engrana uses these APIs to:
- Automatically respond to Instagram direct messages
- Respond to Facebook Messenger messages
- Unify multichannel communication
What data we access
- Incoming direct messages
- Username
- Public profile information
Permission scopes
pages_messaging
instagram_basic
instagram_manage_messages
More details: See WhatsApp Usage Policy (also applies to Instagram/Facebook)
5. STRIPE API
Purpose of use
Engrana uses Stripe to:
- Process monthly subscription payments (€89/month)
- Process initial setup payment
- Manage automatic billing
What data we access
Stripe processes:
- Credit/debit card data (Engrana does NOT see the full number)
- Billing email
- Cardholder name
Engrana receives from Stripe:
- Successful payment confirmation
- Transaction ID (for your invoice)
- Last 4 digits of card (for reference)
Security
- Stripe is PCI-DSS Level 1 compliant (highest security level)
- Engrana NEVER sees your complete card number
- Encrypted payment tokens
More info: https://stripe.com/privacy
General third-party API usage policy
Principles we follow
1. Minimum necessary access
We only request permissions strictly necessary to provide the service.
2. Total transparency
This page documents exactly what we do with each API.
3. No data selling
We never sell or share your data with third parties for advertising.
4. Security first
Encryption, OAuth 2.0, EU hosting, regular audits.
5. User control
You can revoke access at any time.
Legal compliance
GDPR (General Data Protection Regulation):
- All data is processed in the European Union
- We comply with explicit consent requirements
- Access, rectification, erasure rights guaranteed
Provider policies:
- We comply with Google, Meta, Stripe Terms of Service
- Periodic compliance audits
- Up-to-date security certifications
Changes to this page
If we add new integrations or change how we use existing ones:
- We update this page with date
- We notify you by email
- You can revoke access if you disagree
Contact
Questions about third-party APIs:
Report security issue:
info@engrana.es (subject: "URGENT - Security")
Data controller details:
AUVE MEDIA GROUP SL
Tax ID: B19373067
Carrer Antoni Maura 13, 08225 Terrassa, Barcelona
Spain
Additional resources:
We are 100% transparent about how we use third-party services.
If anything is unclear, reach out.
