Legal · Updated 2026-07-01

Privacy Policy

Mainstreet ("we", "us") provides done-for-you Google Business Profile management. This policy describes what we collect, how we use it, and your rights. It applies to mainstreet.sh, our dashboard, and any communications we send.

Data we collect

  • Account information: name, email, business name, phone, website, address — provided during signup.
  • Google Business Profile data — accessed via Google's OAuth consent flow using the business.manage scope. We request only the minimum access needed to serve you:
    • Read your business profile listing (name, address, hours, category, photos, verification status)
    • Read reviews left on your profile and the current response text
    • Post replies to reviews on your behalf, using drafts you (or your rules) approve
    • Publish weekly Google Posts you (or your rules) approve
  • Billing information: card details are collected and stored by Stripe. We never see or store your card number.
  • Product analytics: aggregated, non-identifying usage metrics (page views, feature clicks) to improve the dashboard. Fully first-party — every event is stored in our own Supabase database, never sent to a third-party analytics provider. We respect your browser's Do Not Track header: if it's on, we send no analytics events at all. EU visitors are opted OUT by default until they explicitly opt in via the consent banner. We do not use session recordings.
  • Email engagement (cold outreach only): when you open one of our emails or click a link, we log the event (with a hashed IP — never the raw address). This is standard for B2B outreach and lets us stop mailing people who don't engage. Unsubscribing purges these events within 30 days.
  • Cold-outreach prospects (people we email before they sign up): business name, address, phone, website, and public Google Business Profile data. Processed under GDPR Article 6(1)(f) — Legitimate Interest. Opt out at any time via the unsubscribe link in any message.

SMS and mobile messaging

When a Mainstreet customer (a small business we serve) uploads their end-customer contact list to our dashboard, those end-customers may receive a review-request SMS from us on the business’s behalf. Consent for these messages is obtained by the business at their point of sale or during booking — the end-customer verbally or in writing consents to receive one review-request text after their visit.

Your mobile information and any mobile opt-in data will not be sold or shared with third parties for promotional or marketing purposes. We use mobile phone numbers only to deliver the specific review-request messages the business has authorized. We do not use SMS opt-in data for any other product, service, or third-party marketing.

Every message includes a STOP keyword — replying STOP unsubscribes the number immediately and permanently. Reply HELP for support. Message and data rates may apply. Message frequency is capped at 2 per customer (one initial request and one 3-day follow-up if the first was not opened). Consent to receive SMS is not a condition of purchase.

How we use it

  • Operate the service: poll your reviews, draft replies in your brand voice, publish replies and posts to Google on your behalf.
  • Send service-related communications (delivery reports, billing receipts, escalation notices).
  • Improve our product using aggregated, non-identifying data.

Google user data is used only to provide the service you signed up for and directly-related user-facing features. We do not sell, transfer, or use Google user data for advertising, credit-scoring, or training AI models that are not tied to serving your account.

How long we keep it

  • While your account is active: as long as needed to operate the service.
  • After you cancel or delete your account: we retain your business data for 30 days to allow recovery, then permanently delete it from our production database. Backups are purged within a further 90 days.
  • Cold-outreach prospect data: purged 12 months after last activity, or immediately on opt-out.
  • Google OAuth tokens: purged the moment you revoke access, cancel, or delete your account.

How we protect it

  • All credentials and OAuth tokens encrypted at rest (Supabase Postgres with pgcrypto).
  • We never see your Google password — OAuth means we hold short-lived access tokens and refresh tokens, revocable by you at any time.
  • Traffic between browsers, our servers, and Google API endpoints is TLS-encrypted.
  • Production secrets are gitignored and rotated on compromise.

Your rights

  • Access, export, or delete your data: use Settings → Delete account in the dashboard, or email hello@mainstreet.sh. We respond within 30 days.
  • Revoke Google access at any time: visit myaccount.google.com/permissions and remove Mainstreet. Our access stops immediately.
  • GDPR / CCPA data subject requests: same channel — email hello@mainstreet.sh. Include your business name and email so we can verify.
  • Complain to a supervisory authority: EU residents may file complaints with their national data protection authority; US residents may contact their state attorney general.

Third parties we share data with

  • Google: to read your profile and publish replies/posts (the entire purpose of the service).
  • Stripe: payment processing.
  • Supabase: database hosting (Postgres, US-East).
  • Vercel + Render: application hosting.
  • OpenAI / Anthropic / DeepSeek: draft generation. We send only the review text and your brand voice config — no billing info, no PII beyond the reviewer's public Google-visible name.
  • No third-party analytics provider. Product events are stored in our own Supabase database only.
  • We do not sell your data. We do not share it with advertisers.

Changes to this policy

We'll notify active customers via email at least 14 days before any material change takes effect.

Contact

Email hello@mainstreet.sh for anything privacy-related. Mailing address available on request.