How we protect your data and use Google's APIs responsibly.
GBP Manager is operated by The Apps Galore and connects to Google Business Profile using standard OAuth 2.0 with the
business.manage scope. We only ever read or write the profiles a user is authorized to manage,
and never access any profile outside that authorization.
100% of Google data is obtained through Google's official Business Profile APIs. We do not scrape Google Search, Maps, or any other property.
Review and Q&A replies are written and sent manually by the user - there is no automated posting. We do not generate fake reviews, and we never gate, filter, or suppress reviews. Our review‑request features present the public Google review option to every customer equally.
We smooth API requests with a token‑bucket scheduler to stay well under Google's limits, respect the per‑profile edit cap, and apply exponential backoff with jitter on transient errors. We use Google Cloud Pub/Sub push notifications instead of aggressive polling.
OAuth refresh tokens are encrypted at rest. Passwords are hashed. We store only the data needed to provide the dashboard. Cached Google-provided review and Q&A text, reviewer photos, and legacy full location payloads are scrubbed after 30 days by default; narrow operational records and derived rollups are kept only while needed for the service. Payment card data is handled by Stripe - never stored on our servers.
You can disconnect a Google account at any time; doing so revokes the token and deletes the connection and its associated synced data. You can also request full account deletion. We honor data access, correction, and deletion requests.
Our use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including its Limited Use requirements. Google user data is used solely to provide the management features you request - never sold, never used for advertising, and never used to train generalized AI/ML models.
Administrative actions are recorded in an internal audit log, and access to support tooling is restricted to authorized staff.
See also our Privacy Policy and Terms of Service.