Legal
Privacy Policy
Effective July 18, 2026
This policy explains how Colaka handles information when you use its visibility intelligence, website auditing, reporting, property marketing, and Google Business Profile tools. Have qualified counsel review this policy before relying on it for a production launch.
Information we collect
We collect account and workspace details, property and website information you submit, audit inputs and outputs, notification preferences, and service usage records. Website audits also store information collected from publicly accessible pages, including URLs, metadata, headings, structured data, and crawl responses.
How we use information
We use this information to authenticate users, operate workspaces, run requested audits, calculate scores, generate reports and recommendations, enforce plan limits, send requested notifications, prevent abuse, and improve reliability.
Google Business Profile data
If an authorized organization owner or administrator connects Google Business Profile, Colaka requests the business.manage OAuth scope and reads the accounts and locations available to that Google user. For the selected location, Colaka reads profile identity and contact fields, categories, address, website, hours, service-area and profile metadata, plus reviews, ratings, review text, review timestamps, and owner replies. Colaka does not currently edit profiles, publish posts, change managers, claim or verify locations, or post review replies.
Why and how Google data is used
Colaka uses the selected profile to measure completeness, consistency with user-confirmed property facts, review volume and response coverage, and meaningful changes. It produces visibility findings, action recommendations, and short-lived derived evidence for authorized workspace members. Google reviewer display names and profile photos are not persisted. User-entered observations and user-confirmed facts are stored separately from provider data.
Google data storage and retention
Google OAuth refresh tokens are encrypted server-side with AES-256-GCM and stored outside the browser-readable database schema. Raw Google profile snapshots, location payload fields, review text, review replies, and source-linked derived evidence receive a source, fetch time, and expiration time and expire no later than 30 calendar days after fetch. A scheduled worker removes expired records. Long-term Google-derived trend retention is disabled unless Colaka separately enables its policy feature flag after review. Operational connection, consent, revocation, security, and mutation-audit metadata may be retained longer where needed to operate and secure the service.
Service providers
Colaka uses Supabase for authentication and application data, Stripe for subscription billing, Resend for transactional email when configured, and OpenAI-compatible services for selected non-Google recommendations when configured. Payment card details are handled by Stripe and are not stored by Colaka.
AI processing
Colaka does not send Google Business Profile API content, review text, Google profile snapshots, or Google OAuth credentials to AI providers. When separate AI-assisted features are enabled, relevant non-Google audit findings and user-provided business context may be sent to the configured model provider. Colaka does not intentionally send passwords, payment card details, or authentication secrets to model providers.
Who can view Google data
Google Business Profile content is available only to authenticated members who are authorized for the corresponding Colaka workspace and property. Organization owners and administrators manage the Google connection. Restricted service workers may process the content to run requested or scheduled read-only syncs and retention cleanup.
Sharing and disclosure
We do not sell personal information. We share information with service providers only as needed to operate Colaka, and may disclose information when required by law, to protect the service, or as part of a business transaction subject to appropriate safeguards.
Revoking Google access
An organization owner or administrator can choose Disconnect & revoke in the Google Business Profile module. Colaka stops future syncs, asks Google to revoke the token, and deletes the local credential after Google confirms. If Google does not confirm, Colaka marks revocation pending and retains the encrypted token only so revocation can be retried. A user may also remove Colaka from the third-party access section of their Google Account.
Retention and security
Other account and workspace records are retained while the account or workspace remains active and as needed for operational, legal, and security purposes. Colaka uses access controls, row-level database policies, encrypted transport, and restricted service credentials, but no online service can guarantee absolute security.
Export, correction, and deletion
Workspace owners may request access, correction, export, or deletion by following the Data export and deletion page or contacting support@colaka.com from the account email. Colaka verifies the requester and scope before acting. Deleting a property or Google connection removes provider records through database relationships; backup and legally required retention handling may vary and requires case-specific review.
Questions: support@colaka.com · Terms · Data export and deletion · Support