This Privacy Policy describes how Local Review Reply ("we", "us", or "our") collects, uses, and protects information when you use our service at localreviewreply.com and app.localreviewreply.com (the "Service").

1. Information we collect

Account information

When you sign in with Google, we receive your name, email address, and Google account ID via Google's OAuth 2.0 flow. We use this to create and identify your account.

Google Business Profile data

When you connect your Business Profile, we request access to manage your Business Profile data. We receive an OAuth refresh token (encrypted at rest using AES-256-GCM) that allows us to list managed locations, read reviews from connected locations, and post approved replies on your behalf. We also read location names and account identifiers to populate your dashboard.

Your Google OAuth token is encrypted before storage and decrypted only in memory at the time of an API call. We do not store your Google password or full account credentials.

Review and reply data

We store the review text, reviewer name, star rating, and review date for each review we detect on your connected locations. We store AI-generated draft replies and posted replies for your records and dashboard display.

Brand voice training data

If you provide example replies for brand voice training, we store those examples to include in AI prompts when generating replies for your account.

Billing information

Payments are processed by Stripe. We do not store credit card numbers. We store your Stripe customer ID, subscription plan, and billing status.

Usage data

We collect standard server logs including IP addresses, request timestamps, and HTTP response codes for security and debugging purposes. We also use first-party website analytics, and may use Google Analytics 4 on marketing pages, to understand page views, link clicks, demo usage, referrers, country-level location, device type, and anonymous visitor/session IDs. We do not use this analytics for advertising, remarketing, or selling data.

2. How we use your information

Local Review Reply's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.

3. Data sharing

We do not sell your data. We share data only with the following service providers, solely to operate the Service:

We do not use your review data or brand voice samples to train AI models, and we do not permit AI model training on your data through our providers.

4. Data retention

We retain your account data and review history for as long as your account is active. If you delete your account, we delete your personal data within 30 days, except where retention is required by law. Billing records are retained for 7 years for tax compliance.

5. Your rights

You may request access to, correction of, or deletion of your personal data at any time by emailing support@localreviewreply.com. You can disconnect Google Business Profile from the dashboard under Account settings. Disconnecting revokes the Google OAuth token where possible, deletes the stored token, removes connected locations, and deletes review/draft data tied to those locations. You may also revoke Google Business Profile access at any time from your Google account permissions, which will stop all polling and posting.

6. Security

We encrypt OAuth refresh tokens at rest (AES-256-GCM). Data is transmitted over HTTPS. We implement rate limiting and input validation on all API endpoints. Access to production systems is restricted to authorized personnel.

7. Cookies

We use a session cookie to maintain your login state. We may use first-party local storage or cookies to avoid counting internal traffic in website analytics. If Google Analytics 4 is enabled, Google may set analytics cookies on marketing pages. We do not use third-party advertising cookies or tracking pixels.

8. Children

The Service is not directed to children under 13. We do not knowingly collect personal information from children under 13.

9. Changes to this policy

We may update this policy from time to time. We will notify registered users of material changes by email. Continued use of the Service after changes constitutes acceptance of the updated policy.

10. Contact

For privacy questions, email support@localreviewreply.com.