Legal
Privacy Policy
Last updated: June 15, 2026
Business Health ("we," "us," "our") operates getbusinesshealthy.com and the associated web application (the "Service"). This Privacy Policy explains what information we collect, how we use it, how we share it, how long we retain it, and the choices you have. By using the Service, you agree to this policy.
1. Information we collect
- Account data: name, email address, and password hash (or OAuth identity) when you sign up.
- Business data: the businesses, locations, and Google Business Profiles you connect, plus the audit/health-check results we generate for them.
- Google user data (only if you connect a Google Business Profile — see Section 3).
- Billing data: processed by Stripe; we store subscription status and plan, not card numbers.
- Usage data: standard server logs (IP, user agent, timestamps) and product analytics events used to operate and improve the Service.
2. How we use information
- Operate the Service: run health checks, generate audits, display dashboards.
- Communicate with you: transactional emails, product updates you opt into, support replies.
- Improve the Service: aggregate, de-identified analysis of usage and audit outcomes.
- Comply with law and protect the Service against abuse.
We do not sell your personal information or your Google user data, and we do not use Google user data to serve advertising.
3. Google user data (Google Business Profile API)
When you choose to connect a business, we use Google OAuth to request access to your Google Business Profile. This section satisfies the disclosure requirements of the Google API Services User Data Policy, including the Limited Use requirements.
Scopes we request
openid,userinfo.email— to identify the Google account that authorized the connection.https://www.googleapis.com/auth/business.manage— to read your Business Profile metadata (categories, hours, attributes, photos), reviews, posts, and Q&A so we can audit and report on profile health.
How we use Google user data
- Read your Business Profile and reviews to compute audit scores and recommendations shown only inside your account.
- Refresh the data periodically while a connection is active so reports stay current.
- Show owner-reply status and recent post/Q&A activity in your dashboard.
How we do not use Google user data
- We do not transfer Google user data to third parties except as needed to provide the Service (e.g., our hosting and database provider acting under contract), for security, or as required by law.
- We do not use Google user data to train generalized AI/ML models. Where we apply AI to summarize or grade your profile, the processing happens per-request, scoped to your account, and outputs are visible only to you.
- We do not allow humans to read Google user data except (a) with your explicit consent for support, (b) for security investigations, (c) to comply with law, or (d) in aggregated, de-identified form.
- We do not use Google user data for advertising or resell it.
Storage and security
- OAuth refresh tokens are encrypted at rest with AES-256-GCM before being stored.
- Access tokens are short-lived and refreshed server-side.
- Data is stored on managed infrastructure (Supabase/Postgres) in encrypted-at-rest databases, protected by row-level security so members of one organization cannot read another's data.
Revoking access and deletion
You may disconnect a Google Business Profile at any time from App → Settings. Disconnecting:
- Immediately revokes our access tokens and deletes the encrypted refresh token from our database.
- Stops all future syncs for that business.
You may also revoke access directly at myaccount.google.com/permissions. To request deletion of cached Google user data (audit snapshots, fetched reviews), email bforstie@gmail.com and we will delete it within 30 days unless retention is required by law.
4. Sharing
We share information only with:
- Subprocessors acting under contract: Supabase (database/auth/storage), Cloudflare (hosting/CDN), Stripe (billing), Resend or equivalent (email), and AI providers (Google AI, OpenAI) for on-request inference.
- Other users in your organization who have been granted access by you.
- Authorities when required by valid legal process.
5. Retention
We keep account and business data while your account is active, and for up to 90 days after closure to allow recovery and meet legal obligations. Encrypted OAuth refresh tokens are deleted immediately on disconnect. You can request earlier deletion at any time.
6. Your rights
Depending on where you live (GDPR, CCPA, etc.), you may have rights to access, correct, export, restrict, or delete your personal information, and to object to certain processing. Email bforstie@gmail.com to exercise any of these rights. We do not knowingly collect data from children under 16.
7. International transfers
Our infrastructure is operated in the United States. By using the Service from outside the U.S., you consent to your information being processed there.
8. Changes to this policy
We will post material changes here and update the "Last updated" date. Continued use of the Service after changes take effect constitutes acceptance.
9. Contact
Questions or requests: bforstie@gmail.com.