Privacy Policy
Last updated: 2026-06-09 · Effective date: 2026-06-09
1. Who we are
AHA REVIEW ("we", "us", "the Service") is a software-as-a-service product that helps small business owners and multi-location operators manage their Google Maps reviews and Google Business Profile (GBP) information across one or more stores. The Service is operated by the AHA REVIEW team and accessible at https://ahareview.com.
2. Data we collect
2.1 Account data (you provide directly)
- Email address — used for sign-in, account recovery, and transactional emails (e.g., review alerts, billing receipts).
- Display name — shown in the dashboard and used to personalise reply tone when you allow it.
- Password — stored only as a salted hash by our authentication provider (Supabase Auth). We never see your plain-text password.
- Locale preference — to render the dashboard in your language.
2.2 Google Business Profile data (with your consent)
When you click "Connect Google" and approve the OAuth consent screen, we request the scope https://www.googleapis.com/auth/business.manage and access the following from Google APIs on your behalf:
- Location (store) metadata — name, address, phone, business hours, category, website, opening status. Used to list the stores you manage and to apply changes you request.
- Reviews — author name, star rating, review text, language, timestamp, and the review's Google identifier. Used to display reviews in the dashboard and to track removal status.
- Owner replies — replies you have already posted on Google and replies you post through our app. Used to display reply history and to learn your writing style for AI drafts (only if you opt in).
- Performance metrics — views, search queries, calls, direction requests, and website clicks for each location, aggregated by day. Used to populate the Insights dashboard.
- Account information — your Google Account email and the GBP accounts and locations you have access to. Used to verify which stores you may manage.
2.3 Content you upload
- Photo uploads — images you upload for posting or scheduled posting to your GBP location. Stored in our private object storage and posted to Google when you schedule or publish.
- Reply drafts — the text you type or edit before publishing to Google.
- Support attachments — screenshots you attach to a bug report or inquiry form. Stored privately and reviewed only by our support team.
2.4 Usage and billing data
- Plan, options, and usage counters — your current plan tier, optional add-ons, and per-month counts of AI replies generated, removal analyses, and scheduled photos. Used to enforce plan limits.
- Billing identifiers — once payments are enabled, our payment processor (Paddle) will issue a subscription identifier that we store to link your account to the active subscription. We do not see or store credit card numbers, CVCs, or full payment instruments.
2.5 Automatic / technical data
- Authentication tokens — issued by Supabase Auth (JWT) and stored locally in your browser to keep you signed in.
- Google OAuth refresh tokens — encrypted at rest and used solely to call Google APIs on your behalf while your connection is active.
- Minimal server logs — IP address, request method, and timestamp for security and abuse-prevention purposes, retained for up to 30 days.
3. How we use the data
- To provide the core features you signed up for — listing your stores, showing your Google reviews, generating AI-assisted reply drafts you can edit, publishing replies to Google when you click "Publish", analysing reviews for potential Google policy violations and generating reportable text, scheduling photo posts, and tracking the status of reviews you have reported.
- To enforce your plan limits (reviews handled per month, photo posts, etc.) on the server side.
- To send transactional emails — sign-up confirmation, password reset, billing receipts, alerts for new or potentially policy-violating reviews when you have enabled those alerts.
- To respond to your support requests.
- To debug, secure, and improve the Service (aggregate, non-identifying analysis only).
We do not sell your data, do not use it to train any third-party AI model, and do not use your data for advertising.
4. Google user data — Limited Use disclosure
AHA REVIEW's use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
Specifically, Google user data is used only to:
- Provide and improve the user-facing features described in §3 (reviews dashboard, reply publishing, insights, scheduled photo posts, policy-violation analysis).
- Support those features (debugging, security, abuse prevention).
We do not:
- Transfer Google user data to third parties except (a) as necessary to provide the user-facing features (e.g., sending review text to our AI provider for draft generation — see §5), (b) for security and fraud purposes, (c) to comply with applicable law, or (d) with your explicit consent.
- Use Google user data for personalised advertising.
- Allow humans to read Google user data, except (a) with your explicit consent for specific reviews, (b) for security purposes such as investigating abuse, (c) to comply with applicable law, or (d) where the data has been aggregated and anonymised.
- Sell Google user data.
Honest deletion policy. Google does not provide an API for businesses to delete customer reviews. We therefore do not claim to delete reviews. What we do is: (1) analyse a review for likely Google policy violations using AI, (2) draft a reportable text you can use to flag it to Google, (3) link you to Google's own reporting page, and (4) periodically check the review's existence so we can mark it as removed if Google removes it. The decision to remove is always Google's.
5. Third parties we share data with
We share only the minimum data necessary for the listed purpose. We do not sell or rent your data.
5.1 Subprocessors
- Supabase (database, authentication, file storage, edge functions) — our core backend infrastructure. Hosts your account, your stores, cached reviews, replies, photos, and usage counters. Data residency: AWS Asia-Pacific (Seoul) region.
- Cloudflare (web hosting and CDN) — serves the dashboard frontend and terminates TLS.
- Anthropic, PBC (Claude API) — when you click "Generate" or "Regenerate" on an AI reply, we send the review text, the star rating, and (if you opt in to "tone learning") a small number of your previously published replies so the AI can draft a reply in your style. We do not send your Google OAuth tokens, your email, or any data unrelated to that single review. Anthropic processes this on a no-train, zero-retention basis per its API terms. See Anthropic Privacy Policy.
- Paddle (planned — subscription billing, sales-tax compliance, invoicing) — once we enable billing, your name, email, and transaction history will be processed by Paddle as the merchant of record. Card details go directly to Paddle and are never seen by us. See Paddle Privacy Notice.
- Email delivery provider (to be enabled — e.g., Resend or a comparable transactional mail service) — used to send sign-up confirmation, password reset, and alert emails.
5.2 Legal & safety
We may disclose information when we have a good-faith belief that disclosure is necessary to comply with applicable law, valid legal process, or to protect the safety, rights, or property of the Service or its users.
6. Retention & deletion
6.1 While your account is active
We retain your data for as long as your account is active and to provide the Service. Usage counters are retained for billing and limit-enforcement purposes.
6.2 When you disconnect Google
When you click "Disconnect Google" in Settings (or revoke our access from your Google Account permissions):
- Your Google OAuth access and refresh tokens are immediately deleted from our database.
- Your cached Google review data, store metadata, and Performance API metrics are deleted within 30 days. The 30-day window allows you to reconnect without losing reply drafts you were working on.
- Reply drafts you typed yourself and have not published remain (since they are your content, not Google's). You can delete them manually at any time.
6.3 When you delete your account
You can delete your account from Settings → Account or by emailing [email protected]. We will delete:
- Your profile (email, name, locale).
- All your stores, cached reviews, reply drafts, replies you published through us, photos you uploaded, removal analyses, and notifications.
- Your usage counters (after the current billing cycle is closed).
- Backups containing your data will roll off within 35 days.
6.4 Legal hold
We may retain limited data (e.g., transaction records) where required by tax, accounting, or anti-fraud law, typically up to 7 years.
7. Your rights
Depending on where you live, you have one or more of the following rights regarding your personal data. To exercise any of them, email [email protected] from the address on your account. We respond within 30 days.
- Access — request a copy of the personal data we hold about you.
- Rectification — correct inaccurate or incomplete data.
- Erasure ("right to be forgotten") — delete your account and associated data, subject to §6.4.
- Restriction — temporarily stop processing in defined cases.
- Portability — receive your data in a machine-readable JSON export.
- Objection — object to processing based on our legitimate interests.
- Withdraw consent — disconnect Google or revoke the Anthropic-reply opt-in at any time.
- Complaint — lodge a complaint with your local data-protection authority (e.g., EU/EEA: your national DPA; UK: ICO; California: CA Attorney General).
California residents (CCPA/CPRA) additionally have the right to know what categories of personal information we collect and disclose, and the right to opt out of any "sale" or "sharing" of personal information. We do not sell or share personal information for cross-context behavioural advertising.
8. Security
- TLS in transit for all client-to-server traffic.
- Row-level security (RLS) on every database table, enforced by Supabase, scoped to your user ID; one user cannot read or modify another user's data even if they manipulate API requests.
- Server-side validation of every privileged operation (AI reply generation, plan-limit enforcement, photo upload re-encoding) through Edge Functions; secret API keys are never present in the browser bundle.
- Image uploads are re-encoded server-side, with magic-byte format detection and explicit blocking of SVG and other markup-based formats, to neutralise polyglot and decoder-bomb attacks.
- Encrypted backups via our infrastructure provider.
No system can be 100% secure. If you believe you have discovered a vulnerability, please email [email protected] with a subject starting with [security].
9. Cookies and local storage
We use the browser's localStorage to store your Supabase Auth session (so you stay logged in). We do not set advertising or analytics cookies. We do not fingerprint visitors.
10. Children
The Service is intended for business owners and operators. We do not knowingly collect personal data from anyone under 16. If you believe a minor has created an account, contact us and we will delete it.
11. Changes to this policy
We will update this page when our practices change, and update the "Last updated" date at the top. For material changes, we will additionally email account holders before the change takes effect.