Google API Services — User Data Policy Disclosures

Last updated: 1 July 2026

Review Mitra ("we", "us", "our") uses Google API Services to help merchants read and reply to Google reviews on their own verified Google Business Profile locations. This page contains the disclosures Google requires for apps that access Google user data, and the addendums to our Privacy Notice and Merchant Terms that apply when a merchant connects their Google account to Review Mitra.

1. Google user data we access

When a merchant connects their Google account, we request the minimum OAuth scopes needed to deliver the connected feature:
  • https://www.googleapis.com/auth/business.manage — read the merchant's Google Business Profile locations, read reviews on those locations, and (once approved by Google) post the merchant's approved reply to a review.
  • openid, email, profile — identify the Google account being connected so we can show the merchant which account is linked and let them disconnect it.
We do not request Gmail, Calendar, Drive, Contacts, Photos, YouTube or any other Google user data scope.

2. How we use Google user data

Google user data obtained through the above scopes is used only to:
  • Show the merchant, inside their Review Mitra dashboard, the reviews posted on their own Google Business Profile.
  • Generate an AI-drafted reply that the merchant reviews, edits and approves before it is posted back to Google.
  • Post the approved reply to the specific review on the merchant's own Google Business Profile, at the merchant's explicit instruction.
We do not use Google user data for advertising, for training generalised AI/ML models, to build user profiles, or for any purpose unrelated to the feature the merchant enabled.

3. Limited Use compliance

Review Mitra's use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. Specifically:
  • No unrelated use. Google user data is used only to provide or improve user-facing features that are prominent in Review Mitra's UI and were requested by the merchant.
  • No transfer. We do not transfer Google user data to third parties except (a) as necessary to provide the feature (e.g. our hosting and database sub-processor), (b) for security or fraud prevention, (c) to comply with applicable law, or (d) as part of a merger/acquisition with continued privacy protections.
  • No advertising. Google user data is never used for serving ads, including retargeting, personalised or interest-based ads.
  • No human reading. Humans do not read Google user data unless (a) we have the merchant's affirmative consent for specific messages, (b) it is necessary for security (e.g. investigating abuse), (c) to comply with law, or (d) the data has been aggregated and anonymised.
  • No AI/ML training. We do not use Google user data to develop, improve or train generalised or non-personalised AI/ML models. AI-drafted review replies are generated per-request from the specific review and are not retained by the model provider for training.

4. Storage, retention and deletion

  • OAuth refresh tokens are stored encrypted at rest and are used only to make Google API calls on the merchant's behalf.
  • Reviews fetched from Google are cached temporarily to render the dashboard and are refreshed on demand; cached copies are deleted within 30 days.
  • The merchant can disconnect their Google account at any time from the dashboard, which revokes our refresh token with Google and deletes all cached Google user data within 7 days.
  • Merchants may also revoke access directly at myaccount.google.com/permissions.

5. Security

Data is transmitted over TLS. Tokens and sensitive fields are encrypted at rest. Access to production systems is restricted to authorised personnel, logged and reviewed. We follow reasonable industry practices to prevent unauthorised access, alteration, disclosure or destruction of Google user data.

6. Sub-processors

We use the following sub-processors to deliver the connected feature. Each is bound by confidentiality and data-protection obligations:
  • Lovable Cloud (Supabase) — application hosting, database, authentication.
  • Google LLC — source of the data (Google Business Profile API).
  • Lovable AI Gateway / Google Gemini — generating draft replies from the review text. Draft-reply prompts are not retained for model training.

7. Merchant responsibilities (Terms addendum)

By connecting a Google account to Review Mitra, the merchant confirms that:
  • They are an authorised owner or manager of the Google Business Profile location(s) they connect.
  • They will review and approve each AI-drafted reply before it is posted; Review Mitra does not post replies without merchant action.
  • Replies posted through Review Mitra remain the merchant's content and must comply with Google's review-reply policies and applicable law.
  • The merchant may disconnect at any time; Review Mitra may also suspend the integration in case of abuse, policy violation, or Google API-quota issues.

8. Children

Review Mitra is a B2B product for business owners. It is not directed to children under 16 and we do not knowingly collect Google user data of minors.

9. Changes and contact

We will update this page when our use of Google APIs changes. For questions, data-subject requests, or to report a security issue related to Google user data, email info@reviewmitra.co.in with the subject line "Google API — privacy request".

This disclosure is provided in good faith and does not constitute legal advice. Merchants should consult their own counsel for advice specific to their business.