Security & Your Data

You keep your data. You grant the access. You take it back whenever you want.

Handing a stranger access to your email and files is a reasonable thing to be nervous about. Here is exactly how it works, in plain language, before you have to decide anything.

The short version

  • Your data stays in your accounts. Varinta does not host it, copy it, or keep a warehouse of it.
  • You will never be asked for a password. Not once, not for any reason.
  • Email access is granted by you, through Google’s own approval screen, and you can shut it off from your own account settings in about two clicks.
  • File access is you sharing one folder, exactly like sharing a folder with a coworker. You can unshare it the same way.
  • Access is always the narrowest access that makes the tool work, and nothing beyond it.

1. Your data stays where it already lives

Varinta does not run a platform that your information gets uploaded into. There is no Varinta server holding your sales history, no database with your customer list in it, and no account you would have to close to get your data back.

The tools read from the place your data already sits — your Google Drive, your OneDrive, or a computer in your office — do their work, and write the results back to that same place. The output is normally an Excel or CSV file in a folder you own.

Two practical consequences worth pointing out. If you and Varinta ever part ways, there is no data migration and nothing to request back; it never left. And if a tool stops running for any reason, every file it has already produced is still sitting in your folder and still opens in Excel.

During a build, Varinta works against copies of your real data, because a tool tested on fake data breaks on real data. Those working copies live only as long as the project and are deleted at handoff. If you would rather the work be done only on data with names and identifying details stripped out, say so in scoping — that is often possible and costs nothing extra.

2. No password sharing, ever

Varinta will never ask for your email password, your accounting login, or any other account password. If you are ever asked for one by someone claiming to be from Varinta, that is not Varinta.

This is not just a courtesy to you. Password sharing is bad for both sides, and it is worth understanding why so the rule sticks.

  • It is all-or-nothing. Your password does not open one folder. It opens everything the account can reach — every message, every file, every connected app.
  • It leaves no trail. Anything done with your password looks like it was done by you. Nobody can later tell the two apart, which protects neither side.
  • You cannot switch it off cleanly. Revoking a shared password means changing it and re-logging in everywhere. Revoking proper access is two clicks.
  • It usually violates your own agreements. Most business software terms prohibit sharing credentials, and it can void support or insurance coverage.

The methods below exist precisely so nobody ever needs your password.

3. Email access uses Google’s own approval screen

When a tool needs to read your email — for example, to pull vendor invoices out of attachments — access is granted through Google OAuth. That is Google’s standard approval system, the same one you have already used if you have ever connected a calendar app or a scheduling tool to your Google account. What actually happens:

  1. Varinta sends you a link. You click it while signed into your own Google account.
  2. Google — not Varinta — shows you a screen listing the exact permissions being requested. For an invoice tool, that is typically read-only access to your mail: the tool can read messages, and cannot send, delete, or change anything.
  3. You read the list and click Allow, or you close the window and nothing happens.

You are never typing a password into anything of Varinta’s. You type it into Google, if at all, and Google hands back a permission token that is limited to what that screen described.

Turning it off is yours to do, at any time. Go to your Google Account, open the Security section, find “Your connections to third-party apps & services,” select Varinta, and remove access. That is it — roughly two clicks once you are on the page.

You do not have to send an email first, wait for a reply, or explain why. The switch is in your account, not Varinta’s, and the moment you flip it the tool stops being able to read anything. That is the point: the control belongs to you, permanently, not to the vendor.

4. File access is one shared folder, like sharing with a coworker

For Drive and file access, Varinta uses a dedicated Google service account. Despite the name, you can think of it as an employee-style account that belongs to the software rather than to a person — it has its own email-style address and no password anyone logs in with. Setting it up is something you already know how to do:

  1. You create or pick one folder in your Drive — just the folder the tool needs.
  2. You click Share on that folder, exactly as you would to share it with a new hire.
  3. You paste in the Varinta service account address you are given, choose Viewer or Editor depending on whether the tool needs to write results back, and click Send.

What that buys you:

  • Scoped. Access reaches that folder and what is inside it. Nothing else in your Drive is visible, because nothing else was shared.
  • Visible. It shows up in your own sharing panel, next to every other person you have shared with. Nothing is hidden from the account owner.
  • Removable by you. Open the folder’s sharing settings, remove the service account, done. Same two clicks, no call required.
  • Auditable. Because the service account is its own identity, activity attributed to it is distinguishable from activity by you or your staff — which is exactly what password sharing destroys.

If you use OneDrive or SharePoint instead, the shape is the same: you share one folder with one identity you can see and remove. If the tool runs entirely on a computer in your office, there is no cloud access at all — it reads local files and writes local files.

5. Least privilege, as a working rule

Least privilege is a plain idea with a technical-sounding name: ask for the smallest amount of access that lets the job get done, and nothing more. Varinta treats it as a rule, not an aspiration. In practice that means read-only wherever reading is enough — a tool that only extracts invoice data has no business being able to delete email. One folder rather than your whole Drive, even when whole-Drive access would be more convenient to build against. One mailbox rather than your whole organization. And access that ends when the work does: if a build needed access that ongoing operation does not, that access comes off at handoff.

When a project is scoped, the access it requires is written down in that same one-page scope, before anything starts. If you look at the list and think it is more than the job needs, say so — that is a fair challenge and the answer should be a specific reason, not a shrug.

What Varinta will never ask you for

Keep this list. If any of it is ever requested, something is wrong — whether the request appears to come from Varinta or from anyone else.

  • Your password. Not for email, not for accounting, not for your point-of-sale, not “just temporarily.”
  • A two-factor code. The six-digit code from your phone, an authenticator app, or a text message. Those exist to stop exactly this request. No legitimate vendor needs one.
  • Full account access when a single folder will do. If the tool works on one folder, one folder is what gets shared.
  • Admin rights to your Google Workspace or Microsoft 365 tenant when a single mailbox or folder is sufficient.
  • Permission to send email as you unless sending is literally the deliverable, in which case it is written into the scope and you approve it knowingly.
  • Your customer list, employee records, or payment card data when the tool does not need them. If a project genuinely touches sensitive records, that gets discussed openly in scoping first.

A couple of things this page does not claim

Varinta is a small shop and would rather be straight with you than impressive. This page makes no claim to any formal certification, audit, or compliance program, because there is not one to claim. What is described above is how the access actually works, which you can verify yourself — the approval screen is Google’s, the sharing panel is yours, and both are visible without taking anybody’s word for it.

Ask any question about access before you sign anything. If your answer is “I would need my IT person to look at this first,” that is a good instinct, and Varinta is happy to talk to them directly.

Placeholder — to add when true
  • [PLACEHOLDER] Business insurance (general liability / errors & omissions) — add carrier and coverage summary once a policy is in place. Do not state this until it is.
  • [PLACEHOLDER] Standard mutual NDA and master services agreement, reviewed by a California attorney — link here once available.
  • [PLACEHOLDER] Named service account address used for folder sharing, e.g. tools@[project].iam.gserviceaccount.com, once the Google Cloud project is created.
  • [PLACEHOLDER] Written data handling summary that a client’s own IT person or compliance officer can review.
  • [PLACEHOLDER] If any client work ever touches regulated data (health, payment, or similar), state the specific handling arrangement here. Do not make a general compliance claim.

Ask a question about access →