Privacy Policy
Last updated: August 2026
Looking for how STACKS handles Google user data, including the Google API Services User Data Policy and its Limited Use requirements? See Section 4, Google User Data.
1. Information We Collect
We collect information you provide directly, including:
- Account information (name, email, company)
- Billing information (processed securely through Stripe)
- Device data you submit for pricing or checks
- Communications with our team
- Data from third-party accounts you choose to connect, described in Section 4 and Section 5
We automatically collect usage data, device information, and cookies when you use the Service.
2. How We Use Your Information
We use collected information to:
- Provide and improve the Service
- Process payments and manage subscriptions
- Send service notifications and updates
- Analyze usage to improve our products
- Respond to your requests and support inquiries
Data obtained through Google APIs is used only for the purposes described in Section 4 and is not used for the general product analytics described above.
3. Data Sharing
We do not sell your personal information. We may share data with:
- Service providers (payment processing, hosting, analytics)
- Legal authorities when required by law
- Business partners with your explicit consent
Data obtained through Google APIs is subject to the narrower sharing limits in Section 4, which override this section for that data.
4. Google User Data
STACKS offers an optional connection to Google Business Profile. This section describes how STACKS accesses, uses, stores, and deletes data obtained through Google APIs. It applies in addition to the rest of this policy, and where it is narrower than another section, this section controls.
STACKS' use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
4.1 What Google user data we access
When a business connects its Google account, STACKS requests a single scope:
https://www.googleapis.com/auth/business.manage
Through that scope STACKS accesses:
- Google Business Profile account and location identifiers for the profiles the business selects
- Location information on those profiles, such as business name, address or service area, phone number, website, hours, categories, and attributes
- Posts created through STACKS and the status Google returns for them
- The email address and display name of the Google account that granted access, used only to label the connection and to tell the business which account is connected
STACKS never receives or stores your Google account password, and never accesses profiles you have not selected.
4.2 Why we access it
- To publish posts to the Google Business Profile locations the business has selected, on behalf of that business
- To read location information so that details held in STACKS and details shown on the Business Profile can be kept consistent
- To report back to the business whether a post succeeded or failed, so errors can be corrected
We use this data for no other purpose. It is used only for the business that granted consent, and only for the locations that business selects.
4.3 We do not transfer it to third parties
We do not sell, rent, or license Google user data, and we do not share it with data brokers or information resellers. We transfer it only where one of the following applies:
- As necessary to provide or improve the Google Business Profile feature itself, which means to the infrastructure providers that host and transmit the data on our behalf under contract, and only for that purpose
- For security purposes, such as investigating abuse or a suspected security incident
- To comply with applicable law
- As part of a merger, acquisition, or sale of assets, and then only after obtaining the explicit prior consent of the business
4.4 We do not use it for advertising
Google user data is never used for advertising of any kind. That includes personalized advertising, retargeting, interest-based advertising, audience building, lookalike audiences, and advertising measurement. It is never passed to any advertising platform or tag, and it is never combined with the marketing and analytics data described in Section 7.
4.5 We do not allow humans to read it
Google user data is processed by automated systems. No STACKS employee or contractor reads it, except in these limited cases:
- With the explicit consent of the business, for example when it asks us to investigate a specific problem with its connection
- For security purposes, such as investigating abuse or a suspected security incident
- To comply with applicable law
- Where the data has been aggregated and anonymized, and is used for internal operations such as capacity planning
We do not use Google user data to develop, improve, or train generalized artificial intelligence or machine learning models.
4.6 How we store and protect it
OAuth access and refresh tokens are encrypted at rest, held separately from application data, never written to logs, and never exposed to the browser or to any client-side code. Access to the systems holding them is restricted to the small number of personnel who need it to operate the feature. Location data is cached only to the extent needed to show the connection and its post history.
4.7 How to revoke access, and what we delete
A business can revoke STACKS' access to its Google account at any time, by any of these routes:
- Disconnecting the Google account from the connection settings in STACKS
- Removing STACKS at myaccount.google.com/permissions, which works whether or not STACKS is open
- Emailing yes@stacks.tech and asking us to disconnect the account and delete the data
On revocation, by any route:
- Stored access and refresh tokens are deleted within 24 hours, and STACKS stops making any call to Google on that account immediately
- Cached Google Business Profile data is deleted within 30 days
- Copies held in encrypted backups are removed on the normal backup rotation, which does not exceed 90 days
Posts that were already published to a Google Business Profile remain on that profile, because they are Google-hosted content owned by the business. They can be edited or removed by the business in Google Business Profile directly.
Deletion also happens without a revocation request when a STACKS account is closed, on the same timetable.
A plain-language description of the connection itself, including the authorization steps and what each permission is used for, is documented at stacks.tech/integrations/google-business-profile.
5. Other Connected Accounts
Some features let you connect an account you already control at another service, such as a marketplace, a payment processor, or an advertising platform. STACKS acts only within the permissions you grant at the time of connection, and only until you revoke them. You can disconnect any connected account from its settings in STACKS, or from the other service directly. Data from a connected account is used to provide the feature you connected it for, and the other service's own privacy policy continues to apply to the data it holds.
6. Data Security
We implement industry-standard security measures to protect your data, including encryption in transit and at rest, access controls, and regular security reviews. No method of transmission over the Internet is 100% secure, and we cannot guarantee absolute security.
7. Cookies and Tracking
We use cookies and similar technologies for site functionality, analytics, and marketing. You can control cookies through your browser settings. We use Google Tag Manager for analytics tracking. These technologies operate on our marketing website and never receive data obtained through Google APIs.
To protect our forms from automated abuse, we use Cloudflare Turnstile, which analyzes limited device and browser signals to distinguish humans from bots without presenting a visible challenge. Turnstile's handling of this data is described in the Cloudflare Turnstile Privacy Addendum and the Cloudflare Privacy Policy.
8. Your Rights
Depending on your location, you may have the right to:
- Access and receive a copy of your data
- Correct inaccurate data
- Request deletion of your data
- Object to data processing
- Data portability
To exercise these rights, contact us at yes@stacks.tech.
9. Data Retention
We retain your data for as long as your account is active or as needed to provide the Service. After account termination, we may retain certain data as required by law or for legitimate business purposes. Data obtained through Google APIs is retained and deleted on the shorter timetable set out in Section 4.7, which applies regardless of this section.
10. Third-Party Services
Our Service may contain links to third-party websites. We are not responsible for the privacy practices of these external sites. We encourage you to review their privacy policies.
11. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of material changes by posting the updated policy on our website and updating the "Last updated" date. If a change materially affects how we handle data obtained through Google APIs, we will describe that change in Section 4.
12. Contact Us
For privacy-related questions or concerns, including any question about Google user data, contact us at yes@stacks.tech.