Privacy Policy
Last updated September 29, 2026
This policy explains what information Ballet Rodeo HQ (“HQ”) collects, how it is used, and the choices you have. HQ is the private team workspace of Ballet Rodeo (“we”, “us”). It is used only by the owner and the people the owner invites.
Who this covers
- The owner, who manages HQ and may connect the company’s Google account.
- Team members, who sign in with their email address and may connect their own Gmail.
Information we collect
- Account details: your name, email address and role, used to let you sign in and to decide what you can see.
- Work you do in HQ: tasks, comments, requests, files you upload and activity notes such as who did what and when.
- Google connection details: if you connect a Google account, the account email address and an encrypted permission token that lets HQ act only within the access you approved.
Google user data
HQ asks Google for the smallest access it needs, and only after you choose to connect.
Team members’ own Gmail
- Access requested: read your email (Gmail read-only) and create and send email you write (Gmail compose). Nothing else. No Calendar and no Drive access.
- Why: so you can read work email threads and send work email from your own address without leaving HQ.
- What is stored: HQ does not store the text of your email. Messages are fetched from Google when you open them and are not saved in HQ. HQ keeps only your connected address, an encrypted token, and a short activity note when you send an email (who it went to and the subject, never the message).
- Who can see it: only you. The owner cannot read your email in HQ and can only see whether you are connected. HQ’s AI team cannot access your Gmail and your email is never sent to any AI service.
- Your control: you can disconnect at any time in HQ, or remove HQ’s access in your Google Account permissions. The owner can turn off your ability to send or disconnect you, and when your HQ access is removed your Google connection is revoked and deleted.
The company account (owner only)
- Access requested: read company email (Gmail read-only), create drafts and send email the owner approves (Gmail compose), read the calendar (Calendar read-only), and read and save company documents (Drive read-only, and files HQ creates).
- Why: to keep supplier and partner conversations, the company calendar and company documents in one place, and to prepare drafts for the owner.
- What is stored: calendar events and imported company documents are saved in HQ. When HQ sends an email for the company and someone replies, that reply is saved so the team can see it. Other email is read when needed and is not copied into HQ in bulk.
- AI processing: content from the company account may be sent to Anthropic, the provider of the AI models HQ uses, so the AI team can summarize threads and prepare drafts. Nothing is sent by email without the owner’s approval.
HQ’s use and transfer to any other app of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. We do not use Google user data for advertising, we do not sell it, we do not use it to train AI models, and no person at Ballet Rodeo reads a team member’s Gmail content through HQ.
How we use information
To run HQ: sign you in, show you the work you have access to, let the team collaborate, and keep a record of activity. We do not sell your information or use it for advertising.
Who we share it with
We use a small number of service providers to run HQ, and they process data only to provide their service:
- Vercel, which hosts the HQ website.
- Supabase, which provides the database, sign-in and file storage.
- Google, whose services you choose to connect.
- Anthropic, for AI features. Only company data the owner has chosen to use with the AI team, and never a team member’s Gmail.
We may also disclose information if the law requires it.
Security
Connection tokens are encrypted, sign-in uses one-time email links, each person can reach only the parts of HQ their role allows, and access can be removed at any time. No system is perfectly secure, but we take care to protect what you entrust to HQ.
Retention and deletion
Work in HQ is kept while it is useful to the business. When a team member’s access is removed, their Google connection is revoked and deleted straight away. You can ask us to delete your account information by emailing info@balletrodeo.com.
Your choices
- Disconnect your Gmail from HQ at any time.
- Review or remove HQ’s access at myaccount.google.com/permissions.
- Ask us what we hold about you, or to correct or delete it.
Changes and contact
If we change this policy we will update the date above. Questions: info@balletrodeo.com. See also our Terms of Service.