top of page

PRIVACY POLICY FOR TLA Project and Financial Mgmt

Privacy Policy

 

TLA Project and Financial Mgmt

 

Last updated: September 11, 2026

 

The Lannang Archives (TLA) operates this system to manage project proposals, fundraising records, funding requests, approvals, disbursements, receipts, financial reconciliation, and financial reports. This policy explains how TLA handles information through the system's Google Sheets, Google Forms, Google Drive files, Apps Script automation, and notification emails. It applies to this system, rather than every service offered on TLA's website.

 

For privacy questions or requests, contact lannangarchives@gmail.com.

 

1. Information we collect and access

 

Depending on your interaction with the system, we collect:

 

Identity and contact details: your name, verified Google account email address, position or committee, and coordinator, collaborator, donor, or payee contact details supplied in a form or financial record.

 

Project information: project titles and codes, proposals, team members, objectives, timelines, budgets, funding arrangements, partnership information, outcomes, and post-project documentation.

 

Financial information: requested and approved amounts, itemized expenses, earmarked funds, donations and pledges, payment destinations, payee names, bank or GCash account details, transaction references, refunds, and account balances recorded by TLA.

 

Supporting material: invoices, quotations, receipts, payment confirmations, photographs, partnership agreements, and other files you upload or link for review. These files may contain information about other people.

 

Workflow records: application and transaction IDs, form response IDs, submission times, revisions, reviewer identities and roles, approval or rejection decisions, feedback, confirmation records, notification delivery records, and processing errors.

 

TLA may also import existing project and financial records into the system. Please provide only information relevant to your request and remove unrelated personal details from supporting material where possible. TLA does not request Google passwords, bank passwords, GCash PINs, or one-time authentication codes.

 

2. How Google services are used

 

The TLA account authorizes the automation to operate the system. Applicants and reviewers submit signed-in Google Forms; their verified email addresses identify the person making each submission.

 

The automation uses Google Sheets to read and update the system workbook; Google Forms to create and manage the system's forms and process responses; and Google Drive to organize system files, access linked evidence, check file access and ownership, and save financial reports. It uses Apps Script triggers and Google API requests to process submissions and send notification emails from the TLA account. It also checks the installing account's email address.

 

Google's authorization screen may describe broad access to spreadsheets, forms, or Drive files accessible to the installing account. The system uses those permissions for its configured records, forms, reports, and supporting files. It does not read Gmail inbox messages. It does not connect directly to bank or GCash accounts; TLA personnel enter payment records and balance observations.

 

3. Why we use information

 

We use information to identify applicants and reviewers; assess project proposals and funding requests; check approval authority; track commitments and available funds; administer and document payments; match receipts and refunds to disbursements; prepare reports; communicate decisions and corrections; maintain an audit trail; and investigate errors or misuse affecting the system.

 

The automation checks authorization and financial rules. Authorized TLA personnel make project and funding decisions and review supporting evidence.

 

4. Who can access information

 

Relevant information is available to authorized TLA administrators, directors, finance personnel, proxy reviewers, and other personnel assigned to administer or review the records. People granted access to the master workbook may be able to see records relating to other applicants. Access is governed by the workbook and file sharing settings; it is not a private, applicant-only portal.

 

Application notifications are sent to the applicant's recorded email address. They may include application IDs, project codes, status information, and feedback. Copies delivered by email may remain in the recipient's mailbox.

 

Google processes information to provide the hosting, forms, storage, automation, and email services used by the system. Google's handling of information through its services is described in its Privacy Policy.

 

Where necessary to carry out a requested transaction or an expressly disclosed reporting requirement, TLA may provide relevant information to the payment provider, recipient, auditor, or funding partner, with the required authorization. Information may also be disclosed when necessary to comply with applicable law or investigate a security incident. We limit disclosures to information needed for the relevant purpose.

 

Submitting project photographs or documentation for internal review does not by itself authorize TLA to publish them publicly. Any separate publication must have an appropriate basis and any required permission.

 

5. Limits on the use of Google user data

 

TLA uses information obtained through Google APIs only to provide or improve the project and financial management functions described in this policy. TLA's use and transfer of information received from Google APIs will adhere to the Google API Services User Data Policy, including its Limited Use requirements.

 

TLA does not sell Google user data or use it for advertising, data brokerage, credit scoring, or lending decisions. The system does not send submissions or supporting files to an external AI service. Google Workspace API data is not used to develop, improve, or train generalized or non-personalized AI or machine-learning models.

 

Human review of information obtained through Google APIs is limited to the specific information submitted or otherwise affirmatively authorized for review, security investigations, legal requirements, and other uses permitted by Google's Limited Use requirements.

 

6. Storage and protection

 

System records and supporting material are stored in TLA-controlled Google files or in linked files made accessible to TLA. Reports and notification records can create additional copies. Linked evidence may remain under its original owner's control.

 

The system uses verified Google identities, checks against the authorized-person roster, protected workbook areas, restricted sharing, and validation of financial actions. Communication with the Google APIs uses HTTPS. These measures reduce unauthorized access and changes, but no system can guarantee absolute security.

 

Google may process information in locations outside your country. Its handling of information and service infrastructure is governed by the terms and policies applicable to the Google services TLA uses.

 

7. Retention and deletion

 

Project, application, accounting, evidence, and audit records are retained while needed for project administration, financial reconciliation, reporting, and applicable recordkeeping obligations. They are not automatically deleted when an application is approved, rejected, or closed. Removing an older confirmed item from the active approval view does not delete the underlying records.

 

You may request deletion by emailing lannangarchives@gmail.com, identifying the information concerned and, where available, the application or transaction ID. TLA will review the request and explain any records that must be retained and the reason. When information is no longer needed and deletion is appropriate, TLA will arrange its deletion or de-identification from records it controls. Copies in recipients' mailboxes or files controlled by other people may need to be addressed separately.

 

8. Your choices and requests

 

You may contact TLA to request access to, a copy of, correction of, or deletion of your personal information, or to raise a concern about its use. TLA may need to verify your identity before acting. Corrections to financial records may be recorded as amendments so that the audit history remains understandable.

 

You may choose not to submit information, although TLA may be unable to process a request without the details or evidence needed to assess it.

 

If you have granted the app access to a Google account, you can review or remove that access through your account's connected-app settings. Google explains how to manage app access here. Removing authorization stops the access it grants; it does not automatically erase records already submitted to TLA. Removing the installing TLA account's authorization can stop the automation.

 

9. Changes and contact

 

TLA will update this policy when the system's data practices change and revise the date above. Material changes will be communicated through the system or appropriate notices, with additional consent obtained when required before information is used for a new purpose.

 

The Lannang Archives

Privacy and system contact: lannangarchives@gmail.com

Website: The Lannang Archives

 

Owner notes — exclude this section from the published policy

 

This is a draft based on the supplied TLA automation code, version 1.0.1. Review it against TLA's actual practices before adopting it. It has not been published, and Google's acceptance has not been verified. Set the policy's update date to the date you finalize it.

 

In TLA's website editor, create a dedicated public page titled Privacy Policy — TLA Project and Financial Management. A suggested URL slug is tla-finance-privacy-policy; this is a proposed path, not an existing verified page.

 

Paste the policy above, ending at the TLA contact details, into the page as ordinary selectable text. Use Helvetica. Google requires policy text in the webpage body; embedding a PDF or document is insufficient.

 

Link the new policy from the page describing the app and from the website footer. The app homepage must also explain what the TLA system does. This short description can be added there: “TLA Project and Financial Management, also called TLA Project and Financial Mgmt, is The Lannang Archives' system for project proposals, fundraising records, funding requests, approvals, payment documentation, financial reconciliation, and reporting. It uses Google Sheets, Forms, Drive, and Apps Script. Contact lannangarchives@gmail.com for access or support.”

 

Publish the page and open its actual URL in a signed-out browser window. Confirm that the entire policy is visible without a password or login.

 

In Google Auth platform → Branding → Application privacy policy link, replace the current homepage address with the new page's actual URL. Save, then use the verification page's option to request another review after fixing the issue. If a review is already in progress, follow Google's displayed instructions for changing branding.

 

Confirm that lannangarchives.org is registered under Authorized domains and that domain ownership is verified as Google requires. Do not make the finance workbook or evidence files public.

 

Add the policy link to the system's Instructions tab and each form's description before collecting live submissions. Suggested notice: “TLA collects your verified Google email address and the information and files you submit to process project and financial requests. Authorized TLA personnel will review the specific application and evidence you submit. Read our Privacy Policy: [paste the published policy URL]. Contact lannangarchives@gmail.com with privacy questions.” Where an affirmative acknowledgment is required, obtain it before submission; this draft does not add one to the forms automatically.

 

Confirm the described sharing, human review, retention, deletion handling, and limits on secondary use in practice. No fixed retention period has been invented here; TLA should maintain the appropriate retention rules for its records.

 

Google's privacy-policy guidance requires a dedicated page that identifies the app and explains data access, use, sharing, protection, retention, and deletion. Its brand-verification guidance explains homepage links and domain verification. Completing the page addresses the reported content issue; Google may identify additional issues during review.

bottom of page