Local Business Manager

Security

How we protect the Business Profiles that owners and managers connect, stated plainly. We do not hold security certifications and do not claim any.

OAuth 2.0 only

Profiles are connected through Google's own sign-in screen using OAuth 2.0. Local Business Manager never asks for, sees or stores a Google password.

One scope, for one purpose

The app requests the business.manage scope, which is needed to read and update the Business Profiles a user owns or manages. It does not request access to Gmail, Drive, Calendar or any other Google service.

Tokens encrypted at rest

OAuth access and refresh tokens are encrypted at rest and in transit. Staff cannot view them, and they are deleted when a connection is removed.

Revocable at any time

Disconnect inside the app, or remove access at myaccount.google.com/permissions. Either action stops all further access immediately.

Where data is stored

Application data is hosted in the United States on DigitalOcean infrastructure, with encrypted backups that are purged within 90 days.

Staff access

Production access is limited to the people who operate the service, protected with individual accounts and two-factor authentication, and logged.

Scope and revocation

Requested scope: https://www.googleapis.com/auth/business.manage. Remove access at any time at myaccount.google.com/permissions or from the app settings. See Data deletion for what happens next.

Reporting a security issue

Email security@localbusinessmanager.xyz with a description and steps to reproduce. We acknowledge reports within two business days.