Google Business
Profile Connection
This page documents how STACKS connects to Google Business Profile, what the connection does with that access, the single permission it requests, and why that permission is required. It is reference documentation for operators and reviewers.
Availability
This connection is in limited availability. STACKS has requested access to the Google Business Profile APIs, that request is under review by Google, and the connection is not enabled on general STACKS accounts. Nothing on this page should be read as a statement that the feature is open for signup.
What this connects to
STACKS is a platform used by phone stores, repair shops, pawn shops, and device resellers to run inventory, pricing, and customer-facing listings. Many of those businesses maintain a Google Business Profile for each storefront they operate.
This connection links a STACKS account to a Google account that already has owner or manager access to one or more Google Business Profile locations. It uses Google's Business Profile APIs. The connection is made by the business itself, through Google's own OAuth consent flow, and it is scoped to the locations that business selects.
One STACKS account can hold one Google connection at a time. The connection grants no access to any Google product other than Google Business Profile.
What the connection does
The connection exists to do two things for the business that authorized it:
Publish posts
An operator writes a post in STACKS, selects which of their connected locations it applies to, and publishes. STACKS sends that post to Google Business Profile for those locations and reports back whether Google accepted it. The content of every post originates with the business.
Sync location information
STACKS reads the location details already on the Business Profile, such as name, address, phone, hours, and categories, so that what a business holds in STACKS and what customers see on Google can be kept consistent rather than maintained twice by hand.
The permission requested, and why
STACKS requests exactly one Google OAuth scope for this feature:
https://www.googleapis.com/auth/business.manage
Why this scope is required. Creating a local post on a Google Business Profile, and reading the location details that post is attached to, are both operations that Google gates behind this scope. Google does not publish a narrower read-only or post-only alternative for Business Profile management, so this is the minimum scope that permits the functionality described in Section 2. If Google offered a narrower scope covering posts and location reads alone, STACKS would request that instead.
What STACKS does with the breadth the scope allows. The scope technically permits more than STACKS uses. STACKS confines itself to the reads and writes listed in Section 4, against the locations the business selected. This limit is a commitment in our Privacy Policy, Section 4, not only a description of current behavior.
No other Google scope is requested for this feature. STACKS does not request Gmail, Drive, Calendar, Ads, Analytics, or Search Console scopes as part of this connection.
What data is read and written
| Data | Direction | Purpose |
|---|---|---|
| Business Profile account and location identifiers | Read | To list the locations available to the connected account, and to address the correct location when posting. |
| Location details: business name, address or service area, phone, website, hours, categories, attributes | Read | To show the operator which location they are working with, and to keep details held in STACKS consistent with the profile. |
| Posts composed by the business in STACKS | Write | To publish the post to the Business Profile locations the business selected. |
| Post status and any error Google returns | Read | To tell the operator whether a post published, and to show the reason if it did not. |
| Email address and display name of the Google account that authorized the connection | Read | To label the connection in STACKS so the business can see which Google account is connected. |
STACKS never receives or stores the Google account password. Authorization is held as OAuth tokens, which are encrypted at rest and never exposed to the browser.
How the connection is authorized
Every connection is made by the business itself, through Google's own consent flow. STACKS cannot connect a profile on a customer's behalf, and cannot connect a profile the authorizing Google account does not already manage.
The business starts the connection in STACKS
An operator with administrator rights on the STACKS account opens the Google Business Profile connection and chooses to connect a Google account. Nothing is sent to Google until this step is taken.
STACKS redirects to Google
STACKS sends the operator to Google's own OAuth 2.0 authorization endpoint. The sign-in happens entirely on Google's domain. STACKS never sees or handles the Google account password, and never asks for it.
Google shows its consent screen
Google identifies STACKS as the requesting application and lists the permission being requested. The operator sees exactly what access is being asked for before anything is granted, and can decline. Declining ends the flow and no data is shared.
Google returns an authorization code to STACKS
On approval, Google redirects back to a STACKS callback URL registered for this application and includes a single-use authorization code. STACKS exchanges that code server-side for an access token and a refresh token.
The business selects which locations to connect
STACKS lists the Business Profile locations available to the authorized Google account. The business selects the locations it wants STACKS to manage. Locations that are not selected are not read from or written to.
STACKS publishes only what the business asks it to
From that point, STACKS can publish posts to the selected locations and read their location details. Every post is created by the business in STACKS. STACKS does not generate or publish anything on its own initiative.
What STACKS does not do with this data
- We do not use this data for advertising of any kind, including personalized, retargeted, or interest-based advertising.
- We do not sell, rent, or license this data, and we do not share it with data brokers or information resellers.
- We do not use it to develop, improve, or train generalized artificial intelligence or machine learning models.
- We do not let staff read it, except with the explicit consent of the business, for security purposes, to comply with law, or where it has been aggregated and anonymized.
- We do not touch Business Profile locations the business has not selected, and we do not access any other Google service or Google product data.
- We do not request any Google scope beyond the one listed above for this feature.
STACKS' use and transfer of information received from Google APIs to any other app adheres to the Google API Services User Data Policy, including the Limited Use requirements.
Disconnecting, and what gets deleted
A business can end STACKS' access at any time, by any of these routes:
- Disconnecting the Google account from the connection settings in STACKS
- Removing STACKS at myaccount.google.com/permissions, which works whether or not STACKS is open
- Emailing yes@stacks.tech to ask us to disconnect and delete
Revoking access stops STACKS calling Google on that account immediately. Stored tokens are deleted within 24 hours, cached Business Profile data within 30 days, and backup copies on a rotation that does not exceed 90 days. Posts already published stay on the Business Profile, because they are Google-hosted content belonging to the business, and can be edited or removed by the business in Google directly.
The full data handling terms, including storage, retention, and the limits on transfer and human access, are in Section 4 of the STACKS Privacy Policy.
Questions about this connection
Write to yes@stacks.tech. Related documents: