Security
Last updated: July 1, 2026
Connecting your Gmail inbox is a significant ask. This page explains exactly how we protect that trust.
Read-only, minimum scope
HawkReturn requests the narrowest Gmail permission available - read-only access limited to identifying order and shipping emails. We cannot send email on your behalf, delete messages, or modify anything in your inbox. We do not request access to Google Drive, Calendar, or any other Google service.
What we access vs. what we store
We access order confirmation and shipping emails to extract return-relevant data. We store only: retailer name, detected delivery date, calculated return deadline, and your email address. We do not store email bodies, subject lines, sender addresses, or any other email content.
Encryption
All data transmitted between your browser and HawkReturn is encrypted using TLS (HTTPS). Data stored in our database is encrypted at rest. Your Google OAuth tokens are stored encrypted and are never exposed to the client browser.
Access controls
Access to production systems and user data is restricted to authorized personnel only. We follow the principle of least privilege - no person or system has access beyond what is strictly required.
Google OAuth verification
HawkReturn has undergone Google's OAuth verification process. We request only verified, approved scopes and comply fully with the Google API Services User Data Policy and its Limited Use requirements.
Revoking access
You can disconnect HawkReturn from your Google account at any time via Google Account → Security → Third-party access. Revoking access immediately stops all future inbox scanning. You can also delete your account and all associated data by emailing us.
Incident response
In the event of a data breach that affects your personal information, we will notify affected users within 72 hours of becoming aware of it, as required by applicable law.
Reporting a vulnerability
If you discover a security vulnerability in HawkReturn, please report it responsibly to hello@hawkreturn.com. Do not disclose it publicly until we have had a reasonable opportunity to address it. We take all reports seriously and will respond within 48 hours.