Security
How we protect the Business Profiles that owners and managers connect, stated plainly. We do not hold security certifications and do not claim any.
OAuth 2.0 only
Profiles are connected through Google's own sign-in screen using OAuth 2.0. Local Business Manager never asks for, sees or stores a Google password.
One scope, for one purpose
The app requests the business.manage scope, which is needed to read and update the Business Profiles a user owns or manages. It does not request access to Gmail, Drive, Calendar or any other Google service.
Tokens encrypted at rest
OAuth access and refresh tokens are encrypted at rest and in transit. Staff cannot view them, and they are deleted when a connection is removed.
Revocable at any time
Disconnect inside the app, or remove access at myaccount.google.com/permissions. Either action stops all further access immediately.
Where data is stored
Application data is hosted in the United States on DigitalOcean infrastructure, with encrypted backups that are purged within 90 days.
Staff access
Production access is limited to the people who operate the service, protected with individual accounts and two-factor authentication, and logged.
Scope and revocation
Requested scope: https://www.googleapis.com/auth/business.manage. Remove access at any time at myaccount.google.com/permissions or from the app settings. See Data deletion for what happens next.
Reporting a security issue
Email security@localbusinessmanager.xyz with a description and steps to reproduce. We acknowledge reports within two business days.