Capstone Console

Privacy Policy

Effective October 8, 2026

This policy explains how Capstone Console handles information, including the data it receives from Google when a user connects a Google mailbox. Google user data is covered on its own, in section 4.

1. About this policy

Capstone Console (the “Console”) is the membership-sales workspace at console.capstone-hospitality.com. It is operated by Capstone Hospitality LLC, a Florida limited liability company that sells new memberships on behalf of private golf, country and yacht clubs (“Capstone”, “we”, “us”).

This policy covers the Console only. Capstone’s public marketing website, www.capstone-hospitality.com, has its own privacy policy.

2. Who uses the Console

The Console is a private business tool, not a consumer service. Capstone creates every account; nobody can sign up on their own. Accounts are issued to:

  • Capstone employees and contracted membership-sales representatives; and
  • staff of the clubs we represent whom Capstone has invited.

The Console also holds information about people who are interested in joining a club (“prospects”). Prospects do not have accounts.

3. Information the Console handles

This section describes information that does not come from Google.

  • Account information: your name, work email address, phone number if provided, role, the clubs you work with, your time zone, and sign-in records. Sign-in is handled by our authentication provider; the Console never stores your password in readable form.
  • Prospect and sales information: contact details and the sales history for people interested in club membership — inquiries, notes, tasks, tours, quotes, membership applications and survey responses. It comes from the clubs, from our representatives, from prospects themselves through club web forms, booking pages and text messages, and from lead sources a club uses, such as Facebook and Instagram lead ads.
  • Email engagement: an email sent from the Console carries a small tracking image and tracked links. When the recipient opens it or clicks a link, the Console records when it happened, which link was clicked, and a one-way hash of the recipient’s IP address (never the address itself), so the sender can see that the email was read.
  • Push notifications: if you turn on push notifications for a device, the Console stores that device’s push address (issued by your browser’s maker: Apple, Google, Mozilla or Microsoft), the keys that encrypt notifications for it and a short description of the browser, along with any quiet hours you set and kinds of notification you switch off. It uses them to send you your own Console notifications — the same ones shown in the bell, such as new leads and task reminders. Each notification is encrypted for your device, so the push service delivers it without being able to read it. Turning push off on a device, or signing out of the Console on it, deletes that device’s address, and so does the push service reporting that the device has unsubscribed. Nothing is pushed to a deactivated account, and deleting an account deletes its devices’ addresses. Push notifications go only to people with a Console account who turn them on — never to prospects, and never to a club’s client-portal login. They never include the subject line or text of an email from a connected mailbox: a notification about a new email inquiry, a bounced email or a problem with a mailbox is pushed with fixed wording, without the email’s subject, its sender’s name or the mailbox’s address.
  • Usage and technical information: records of changes made in the Console (an audit log) and the technical logs our hosting provider keeps to run the service.

Google user data — data the Console receives from Google when you connect a mailbox — is handled only as described in section 4.

Data the Console receives from Microsoft when you connect a Microsoft 365 or Outlook mailbox is handled only as described in section 4A.

4. Google user data

This section applies only to data the Console receives through Google APIs when a user connects a Google mailbox — either their own work mailbox, or a club’s membership-inquiry inbox they are authorized to hold. Connecting is optional, and the Console works without it. Where this section and the rest of the policy differ, this section governs Google user data.

4.1 What we access

When you connect, Google asks you to allow these permissions:

  • Your basic Google profile (openid, userinfo.email, userinfo.profile): your name and email address, used to confirm that the mailbox you connected is the one you intended, and to label the connection in your settings.
  • Read your email (gmail.readonly): to decide whether a message involves a prospect, the Console looks at its sender, recipients and reply-to address, its date, and the Gmail labels it carries (such as Spam or Promotions) — not its text. For a message that does involve a prospect, it then reads the subject line and text to save the excerpt described in 4.2. It does not change, label, move or delete any of your mail.
  • Send email as you (gmail.send): so an email you write in the Console is sent from your own address. This permission cannot read your mail.
  • Your calendars (calendar): your free/busy times and events, and the ability to add a booked tour to your calendar. The Console does not change your calendar settings or sharing.

4.2 How we use it

We use Google user data only to provide these features, which you can see in the Console:

  1. Prospect email on the timeline (any connected mailbox). When a message you send or receive involves someone who is already a contact in the Console for a club you work with, the Console saves the message’s subject line and a text excerpt of at most 2,000 characters to that contact’s timeline, with its date, whether it was sent or received, and technical identifiers for the message and its thread. Messages that involve no Console contact are discarded without being stored. The other recipients’ addresses are not saved. One kind is looked at first: when a mail server’s delivery-failure notice (from a “mailer-daemon” or “postmaster” address) arrives about an email sent from the Console, the Console reads its sender, its conversation thread and the reason it gives (for example “address not found” or “sending limit reached”), marks that sent email as not delivered with that reason, and tells the person who sent it. The notice itself is not stored; only the reason category is kept.
  2. New inquiries (a club’s inquiry inbox only). This is the one exception to the rule above. If you connect a club’s membership-inquiry inbox that the club has set up for the Console (for example a “join@” address), a message received after you connected, within the last seven days, that looks like a membership inquiry from someone not yet in the Console creates a new prospect record for that club: the sender’s name and email address, a note that the inquiry came by email to that inbox, the subject line and an excerpt of at most 2,000 characters on the timeline, and an in-app notification to the representative assigned to the prospect, which shows the subject line. Older mail in the inbox is never turned into prospects, and messages from the club’s own domain, from Capstone, or filed as spam or promotions are not captured.
  3. Sending email. When you write an email in the Console and press Send, the Console sends it through your mailbox so it comes from your address, and keeps a copy of what you sent (subject and body) on the contact’s timeline. The Console adds a small tracking image and tracked links to the email so you can see when it is opened (see section 3).
    Email sequences. A sequence is a short series of prepared emails. One starts only when a person at Capstone enrolls a prospect who is already in the Console. The Console then sends each email in that sequence when it falls due, through the mailbox of the representative who owns that prospect, so it comes from their address. It keeps a copy on the prospect’s timeline, with the same tracking image and tracked links. Each sequence email carries an unsubscribe link. A sequence stops when the prospect replies, unsubscribes, is marked as not qualified, or becomes a member. An email more than 14 days overdue is never sent, and sequence emails pause while a mailbox is at its daily sending limit (never more than Google’s own limit of 2,000 emails a day). A club’s inquiry inbox only ever emails that club’s prospects. The Console’s other automated emails, such as tour reminders, are switched off today, and we will update this policy before turning any of them on.
  4. Tour scheduling. When a prospect opens a club’s tour-booking page, the Console reads your free/busy times so it offers only times you are free; the prospect sees open time slots, never your events. When a tour is booked, the Console adds it to your calendar. Depending on Capstone’s email settings, the prospect may be added as a guest, in which case Google sends them the invitation.
  5. Your calendar in the Console. The Console can show your own calendar events beside your Console appointments. Only you can see them. They are fetched when you view the page and are not stored on our servers; the Console saves only your choice of which calendars to show.

We do not use Google user data for advertising, including retargeting or personalized or interest-based ads; we do not sell it; we do not transfer it to data brokers or information resellers; and we do not use it to determine creditworthiness or for lending. We do not use it for any purpose other than the features above.

4.3 Artificial intelligence

The Console has some AI-assisted features, such as suggested follow-ups for a prospect. No email message from a connected mailbox — its subject line, text or date — and none of your calendar data is ever sent to AI models or AI providers. Those features work from a prospect’s record in the Console (such as their name, their stage in the sales process and how they reached the club) and from calls, text messages, meetings and notes logged in the Console directly.

One part of that record can come from Google. When a prospect was created from a club’s inquiry inbox (4.2, item 2), their name is the one they used on their email, and the record notes which club inbox they wrote to. Those two items are sent to our AI provider, Anthropic, as part of the prospect’s record so it can, for example, address the prospect by name in a suggested email. Nothing else received from Google is sent.

We do not use Google user data, and do not allow it to be used, to develop, improve or train generalized or non-personalized artificial-intelligence or machine-learning models.

4.4 Who can see it

  • Timeline entries saved from your mailbox (4.2, items 1–3) become part of the club’s shared sales record for that prospect. They are visible to Capstone staff and representatives assigned to that club, and to Capstone’s administrators. Sharing the prospect’s history with the sales team is the purpose of the feature.
  • Your calendar is visible only to you.
  • Otherwise, no person at Capstone reads your Google user data, except: with your affirmative agreement for specific messages (for example, to help with a support request you raise); when it is necessary for security purposes, such as investigating abuse or a security incident; to comply with applicable law; or when the data has been aggregated and anonymized for internal operations.

4.5 Service providers and sharing

Google user data is processed on our behalf by these service providers, in the United States, only to run the features above:

  • Nylas, Inc. connects the Console to Google. When you connect, you sign in to Google through Nylas, and Nylas holds the resulting Google access and refresh tokens; the Console’s own database stores only a reference to your connection, never the tokens. Nylas delivers messages and calendar data to the Console and sends the email you send.
  • Supabase, Inc. hosts the Console’s database, where the timeline entries described in 4.2 are stored.
  • Vercel Inc. hosts and runs the Console application.
  • Anthropic, PBC provides the AI-assisted features. From Google user data it receives only the name and club-inbox note described in 4.3, never email content or calendar data, and it does not use what it receives to train its models.

We do not transfer Google user data to anyone else, except as necessary to comply with applicable law, to protect against security threats, or as part of a merger, acquisition or sale of assets, in which case we would notify you and the data would stay subject to this policy.

4.6 Limited Use

Capstone Console’s use and transfer of information received from Google APIs to any other app will adhere to Google API Services User Data Policy, including the Limited Use requirements.

The use of information received from Google Workspace scopes will adhere to the Google User Data Policy, including the Limited Use requirements (see the Google Workspace API User Data and Developer Policy). You can read Google’s policy at https://developers.google.com/terms/api-services-user-data-policy.

4.7 How long we keep it, and deleting it

The timeline entries in 4.2 are part of the club’s sales record, so they are kept while they are useful to the sales team, within the limits below. Calendar events are never stored on our servers, so there are none to keep or delete.

Email text is deleted after 24 months. The text the Console saved from a connected mailbox — the excerpt of each received message and the body of each email sent from the Console — is deleted automatically once the email is 24 months old.

When a mailbox is disconnected (Settings → My Mailbox → Disconnect) — your own mailbox or a club’s inquiry inbox — the Console revokes its access at Nylas, which ends the Console’s access to that Google account, and stops saving mail from it. What it already logged on prospect timelines stays, as part of the sales record Capstone keeps for the club, until the email text is deleted as described here: 24 months after the email, or sooner if you ask us to delete it. Connecting a different mailbox in place of one works the same way.

If your Console account is deactivated or deleted, the Console stops saving mail from your mailbox and revokes its access at Nylas (if Nylas cannot be reached at that moment, the Console retries daily until it can). The email text already saved on prospect timelines stays as part of the club’s sales record, until it is 24 months old or you ask us to delete it. Reactivating an account does not reconnect its mailbox.

If the Console’s access is revoked at Nylas (the connection is deleted there) by anything other than the Console itself — that is, not by a Disconnect, by connecting a different mailbox, or by an account being deactivated or deleted — and the mailbox is not connected again within 30 days, the Console deletes the email text it saved from that mailbox.

If you remove access from your Google Account instead of disconnecting in the Console, the Console stops receiving your data. As with a Disconnect, the email text already saved stays until it is 24 months old or you ask us to delete it.

What remains when email text is deleted: the record that an email took place — its subject line, date, direction and the prospect it belongs to — stays part of the club’s sales history. Prospect records created from a club’s inquiry inbox (name, email address and how they reached the club) belong to the club’s sales record and remain, as do in-app notifications about them. Our audit log, which is append-only so that records of changes cannot be altered, keeps the subject line of each email entry alongside other change records; audit records are kept for at least seven years because they also contain financial records. We also keep technical message identifiers (not message content) so the same message is never processed twice.

To ask us to disconnect a mailbox or delete data, including the email text kept after a mailbox was disconnected, subject lines or anything else received from your Google account, email kyle@capstone-hospitality.com. Use this too if you cannot disconnect in the Console yourself, for example because you can no longer sign in or your account is read-only. A club can ask the same for the email its inquiry inbox saved. We will verify the request and complete it within 45 days. Some records may need to be kept where the law requires it; we will tell you if so.

4.8 Your controls

4A. Microsoft user data

This section applies only to data the Console receives through Microsoft Graph when a user connects a Microsoft 365 or Outlook mailbox: either their own work mailbox, or a club’s membership-inquiry inbox they are authorized to hold. Connecting a Microsoft mailbox is available only once Capstone has switched it on, and connecting is optional.

What we access. When you connect, Microsoft asks you to allow these permissions:

  • Sign you in and read your profile (openid, email, profile, User.Read) and keep access (offline_access): your name and email address, used to confirm that the mailbox you connected is the one you intended and to label the connection in your settings, and so the connection keeps working without you signing in again.
  • Read and write your mail (Mail.ReadWrite): Microsoft requires this permission, together with the next one, for an app to send email from your mailbox. The Console uses it to decide whether a message involves a prospect, looking only at the sender, recipients, reply-to address, date and the folder it is in (such as Junk Email or Deleted Items), not the message’s text; for a club’s inquiry inbox it also reads the inbox’s list of folders, to tell which folder is which. For a message that does involve a prospect, it then reads the subject line and text to save the excerpt described in 4.2. Apart from sending the email you write, it does not create, change, flag, move or delete any of your mail.
  • Send email as you (Mail.Send): so an email you write in the Console is sent from your own address.
  • Your calendars (Calendars.ReadWrite): your free/busy times and events, and the ability to add a booked tour to your calendar. The Console does not change your calendar settings or sharing.

How we use, share and keep it. Sections 4.2 through 4.5, 4.7 and 4.8 apply to Microsoft user data exactly as they do to Google user data. That means the same features, the same 2,000-character excerpt and the same discarding of everything else. Delivery-failure notices are treated the same way; for Microsoft they can also come from a “MicrosoftExchange” system address of the mailbox’s own organization. No email message from a Microsoft mailbox and none of its calendar data is ever sent to an AI model; as 4.3 describes, only the name and club-inbox note of a prospect created from a club’s inquiry inbox can be. The same people and service providers (Nylas, Supabase, Vercel) handle it, with the same retention and deletion. We apply the limits in 4.6 to Microsoft user data too: we do not sell it, use it for advertising, or use it for any purpose other than the features above.

Your controls. Disconnect in the Console under Settings → My Mailbox, or ask us at kyle@capstone-hospitality.com. You can also remove the Console’s access from your Microsoft account: for a work or school account at https://myapps.microsoft.com (or ask your organization’s administrator), and for a personal account at https://account.live.com/consent/Manage.

4B. Text messages (SMS)

If you give a club or Capstone Hospitality your mobile number and tick the text-message consent box on a club’s web form, landing page, Facebook lead form, tour booking page or membership application, Capstone Hospitality may text you about your club membership inquiry: replies to your questions, tour confirmations and reminders, and follow-ups. Consent is optional and is not a condition of purchase or membership. Message frequency varies. Message and data rates may apply.

Opting out. Reply STOP to any text we send from our messaging number to stop all such texts; you will receive one confirmation and no further texts from that number. If a Capstone representative texts you from their own phone, reply STOP or tell them, and they will record your opt-out. Reply HELP for help, or email info@capstone-hospitality.com.

What we keep. Your mobile number, whether and when you agreed to texts, the exact consent wording you saw and where you saw it, and the texts sent to and received from you, which are kept with your inquiry record like emails and calls.

No sharing of mobile information. We do not share, sell, or provide your mobile phone number or messaging consent data to third parties or affiliates for marketing or promotional purposes. We do not sell or share your SMS opt-in data or personal information with third parties for marketing purposes. No mobile information will be shared with third parties or affiliates for marketing or promotional purposes. All the categories of sharing described in this policy exclude text-messaging originator opt-in data and consent; this information will not be shared with any third parties. Texts are delivered through our messaging provider, Twilio, which processes them only to deliver them (section 6).

5. How we protect information

  • Connections between your browser and the Console, and between the Console and Nylas, are encrypted in transit with TLS (HTTPS).
  • Our database provider and Nylas encrypt the data they store at rest.
  • Google access and refresh tokens are held by Nylas and are never stored in the Console’s database.
  • Access inside the Console is enforced by role and by club. Calendar events read from your Google account are shown only to you.
  • Changes to records are written to an append-only audit log, and email content is not written to the Console’s application logs.

No system is perfectly secure. If we learn of a security incident that affects your information, we will notify you and, where required, Google and the authorities.

6. How we use and share other information

This section covers information that is not Google user data.

  • Use. We use account and prospect information to run the Console for Capstone and the clubs we represent: managing inquiries and prospects, scheduling tours, preparing quotes, applications and invoices, reporting results to clubs, and paying our representatives.
  • Sharing. Prospect information is shared with the club the prospect is interested in, so the club can serve their membership inquiry. Mobile phone numbers and text-messaging consent are never shared with anyone, the club included, for marketing or promotional purposes (section 4B). We also use service providers that host the Console or provide its features — Supabase (database and sign-in), Vercel (hosting), Nylas (mailbox connections), Resend (delivery of the Console’s own system emails, such as notifications and quotes), Twilio (text messages with prospects; see section 4B), Slack (internal notifications to Capstone’s team, such as a new inquiry or a closed sale), HubSpot (importing existing prospect records) and Anthropic (the AI-assisted features, which never receive email content or calendar data from Google; see 4.3). Inquiries from Facebook and Instagram lead ads reach us from Meta. Browser push services (Apple, Google, Mozilla, Microsoft) deliver push notifications to the devices that turned them on, encrypted so that the service cannot read them (see section 3). We do not sell personal information and do not use it for advertising.
  • Retention. We keep this information while we represent the club concerned and afterwards for as long as we need it for accounting, legal and dispute-resolution purposes.

7. Your requests and choices

You can ask to see, correct or delete personal information we hold about you by emailing kyle@capstone-hospitality.com. Prospects who no longer want to hear from a club’s representative, or who want their record deleted, can contact us at the same address. We respond to requests within 45 days. Depending on where you live, you may have additional rights under local law, and we will honor them.

8. Children

The Console is for business users and is not directed to children. We do not knowingly collect personal information from children under 13, and Console accounts are issued only to adults working with Capstone or a club.

9. Changes to this policy

We will post any change on this page and update the effective date at the top. If a change affects how we use Google user data, we will tell you before the change takes effect and will not use your data in the new way without your consent; you can always disconnect your mailbox instead.

10. Contact us

Capstone Hospitality LLC
Email: kyle@capstone-hospitality.com

See also our Terms of Service.