GFI Tracker
Official application information page for Google OAuth branding verification. Application name on this page: GFI Tracker.
1. What is GFI Tracker?
GFI Tracker is a private web application (back-office software) used by an insurance agency.
GFI Tracker is not a public consumer social app, not a marketing website, and not an advertising product.
2. Who uses GFI Tracker?
- Licensed insurance agents (invitation-only accounts)
- Managers assigned to those agents
- Administrators who create and manage accounts
Accounts are created by an administrator. Users cannot self-register.
3. What does GFI Tracker do?
GFI Tracker stores and displays business activity that agents and managers enter into the application. Specifically, GFI Tracker:
- Tracks insurance production records (policies, recruits, field trainings, pipeline stages)
- Tracks agent goals, vision items, and training checklist progress
- Stores agent office hours / availability schedules entered in GFI Tracker
- Optionally reads, creates, updates, and deletes Google Calendar events for an agent who connects Google Calendar
4. Purpose of this application (summary)
Purpose statement
The purpose of GFI Tracker is to operate a private insurance-agent back-office system that tracks production, training, goals, and office hours, and that can optionally sync an agent’s appointments by reading and writing Google Calendar events.
5. Why does GFI Tracker request Google Calendar access?
GFI Tracker requests Google Calendar access so an agent can manage the same appointments inside GFI Tracker that exist on that agent’s Google Calendar.
Without Google Calendar access, GFI Tracker still works for production tracking, training, goals, and office hours. Google Calendar is an optional add-on feature.
6. Is Google Calendar optional?
Yes. Google Calendar connection is optional.
- Only the agent can start the Google OAuth connection.
- Agents who never connect Google Calendar can use all non-Calendar features.
- An agent can disconnect Google Calendar at any time inside GFI Tracker.
7. What Google data is accessed?
When an agent connects Google Calendar, GFI Tracker requests this OAuth scope only:
https://www.googleapis.com/auth/calendar.events — read, create, update, and delete events on the agent’s Google calendars
GFI Tracker also receives the connected Google account email address associated with the primary calendar so the product can show which Google account is connected.
GFI Tracker does not request these scopes:
https://www.googleapis.com/auth/calendar (full calendar settings / ACL access)
https://www.googleapis.com/auth/calendar.readonly
https://www.googleapis.com/auth/calendar.events.readonly
- Gmail, Drive, Contacts, or other Google Workspace product scopes
OAuth is requested with access_type=offline so GFI Tracker can store a refresh token and continue syncing events after the popup closes. GFI Tracker does not use Google Sign-In (openid / email / profile) for app login; app login is separate (email/password via the agency account system).
8. How is that Google data used?
- Read Google Calendar events: GFI Tracker lists the agent’s events in an in-app Month / Week / Day calendar next to office hours.
- Create Google Calendar events: the agent can add a new event from GFI Tracker; GFI Tracker writes that event to Google Calendar.
- Update Google Calendar events: the agent can edit an existing event from GFI Tracker; GFI Tracker patches that event in Google Calendar.
- Delete Google Calendar events: the agent can delete an event from GFI Tracker; GFI Tracker deletes that event in Google Calendar.
- Manager / admin view: administrators and the agent’s assigned manager may view the agent’s events read-only inside GFI Tracker for coaching and scheduling. They cannot create, update, or delete the agent’s Google Calendar events.
GFI Tracker does not use Google Calendar data for advertising. GFI Tracker does not sell Google Calendar data.
9. How Google authorization is stored
- GFI Tracker stores the Google OAuth refresh token on the server.
- The refresh token is encrypted (AES-256-GCM) before storage.
- The refresh token is never exposed to the browser.
- Calendar event details are fetched on demand to render the current calendar view.
10. How users revoke Google access
11. Google API Services User Data Policy — Limited Use
Limited Use disclosure
GFI Tracker’s use and transfer to any other app of information received from Google APIs will adhere to the
Google API Services User Data Policy,
including the Limited Use requirements. GFI Tracker uses Google Calendar event data only to provide and improve the calendar features described on this page, does not transfer that data except as needed to provide those features or as required by law, and does not use that data for advertising or sell it.
12. Application name (exact match)
The official application name is:
GFI Tracker
This exact string is the application name on:
- this homepage (title, H1, and body text)
- the Google OAuth consent screen App name field
- the Privacy Policy and Terms pages
13. Privacy Policy and Terms
14. Contact / support
Application: GFI Tracker
Website: https://gfitracker.com
Support email: admin@gfitracker.com