Information we collect
Account information: your name, email address, account identifier, profile image if provided, and account creation and sign-in records. For email and password accounts, we store a password hash rather than your readable password. Authentication records may include your IP address, browser information, session identifiers and expiration times.
Workspace information: workspace name, membership and roles, selected businesses and competitors, business addresses and coordinates, website URLs, analysis history, action status, reports, sharing settings and usage allowances. Business coordinates identify the locations you select; the application does not request your device's precise location.
Public business information: business listings, ratings, review text, reviewer display information, review dates, business responses and website content obtained from our data providers or public websites. Public reviews can contain personal information supplied by their authors. We also store derived metrics, topic classifications, recommendations and supporting evidence.
Service and support information: request times, requested paths, response status, request identifiers, relevant workspace or business identifiers, provider usage and errors, and information you choose to include when contacting us. Our hosting provider also processes technical traffic information to deliver and protect the website.
Sign in with Google
Google sign-in is optional. If you choose it, we request the openid, email and profile permissions. Google provides an account identifier, email address and verification status, and basic profile information such as your name and profile image. Our authentication service may store the Google tokens, granted scopes and expiration information returned during sign-in to establish and maintain the account connection. We never receive your Google password.
We use this information to create or identify your account, authenticate you and maintain your session. Google sign-in does not grant us access to Gmail, Drive, Calendar, private Business Profile management data or permission to post on your behalf. Public business research uses separately configured data providers; it does not use your Google account to access those services.
We do not sell Google sign-in data, use it for advertising, or send your Google account profile or authentication tokens to our analysis models. We limit access and disclosure to providing the sign-in feature, necessary service operation, security and legal requirements. Our handling of Google user data is subject to the Google API Services User Data Policy, including applicable Limited Use requirements.
You can revoke the connection in your Google Account's third-party connections settings. Revoking Google access does not itself erase data already stored in LocalGrowthIQ; contact us to request account or data deletion.
How we use information
We use information to operate accounts and workspaces; find businesses and nearby competitors; collect and organize reviews and website observations; calculate metrics; generate recommendations and reports; retain your action history; enforce access and usage limits; investigate problems; prevent abuse; respond to requests; and meet applicable legal obligations.
When AI analysis is available, selected review text, ratings and identifiers, and business-observation evidence are sent to the configured model provider through Cloudflare AI Gateway. These inputs can contain personal information within the original public review or website content. Generated findings are saved with the analysis. Please do not submit confidential, sensitive or unnecessary personal information for analysis.
Service providers and sharing
Cloudflare hosts the application and processes its database, stored files, workflows, security and technical logs. SerpApi processes business searches and supplies public listings and review data. Cloudflare Browser Rendering processes public website URLs and content when website analysis is enabled. AI analysis uses Cloudflare AI Gateway and the configured model provider, currently OpenAI, when that feature is enabled and available. These providers receive information needed for their respective functions and handle it under the terms applicable to their services.
Google processes sign-in requests when you select Google sign-in. If password-reset email delivery is enabled, Resend processes the destination email address and reset email. If a separately agreed subscription is managed through Stripe, we may receive subscription identifiers, plan status and billing event metadata; the application does not collect or store payment-card numbers. Features that are not enabled do not transmit information to that provider through the corresponding feature.
Workspace information is available to authorized workspace members according to their access. Reports are private unless an authorized user enables a public sharing link. Anyone with that link can access and copy the shared report until the link is revoked. Revoking a link cannot recall copies already downloaded or shared elsewhere.
We do not sell personal information or provide it to advertising networks for targeted advertising. We may disclose information when required by law or when necessary to investigate abuse, protect the service or protect people's rights and safety. Any additional disclosure of Google user data remains subject to Google's applicable policy requirements.
Cookies and browser storage
We use essential cookies to keep you signed in and protect authentication, including temporary OAuth state. Sessions are configured to last up to seven days and can renew with use. Browser or infrastructure security mechanisms may also be needed to deliver the service. The application does not currently include advertising cookies or third-party marketing analytics.
You can remove or block cookies in your browser, but sign-in and authenticated features may stop working. Signing out ends the current application session; clearing cookies does not delete your account or stored business data.
Storage, security and retention
Account and workspace records are stored in Cloudflare's managed database, and analysis artifacts and reports are stored in private object storage. We use HTTPS, authentication and workspace access checks to protect data. No internet service can guarantee absolute security.
We retain account and workspace information while it is needed to provide the service and maintain your history, subject to deletion requests and any legal, security or dispute-resolution needs. Technical logs and provider-held records are subject to their applicable retention settings and requirements. We have not set a universal automatic deletion period for all records.
Archiving a business or removing a competitor from the active view does not permanently erase associated records. Deletion requests require a separate request to us. Backup or provider-held copies are subject to the relevant provider's retention processes; records required by law may need to be retained.
Cloudflare and other providers may process information in countries other than where you live. Privacy protections and legal requirements may differ between those locations. We use the safeguards available under our service-provider arrangements and applicable law.
Your choices and requests
You may contact us to request access to, correction of, a copy of, or deletion of your personal information or account. Depending on your location and applicable law, you may also have rights to object to or restrict processing, withdraw consent where processing relies on consent, or complain to your local privacy authority. We may need to verify your identity and authority over a workspace before acting on a request, and some requests may be subject to lawful exceptions.
There is currently no self-service account deletion or full account export control. To make a request, use the contact email below and tell us the email associated with your account and what you want us to do. Do not include passwords or authentication tokens. Workspace records that also concern other members may require additional verification and coordination.
Children
LocalGrowthIQ is a business service intended for adults, not a service directed to children. If you believe a child has provided personal information through an account, contact us so we can investigate and take appropriate action.
Changes to this policy
We may update this policy as the service changes. We will show the updated effective date on this page and provide additional notice for material changes where appropriate or required. If a new use of Google user data requires additional consent, we will obtain that consent before beginning that use.
Contact
getNearGrow
beywsong@gmail.com