Privacy Policy

Last updated: July 24, 2026

Beacon ("Beacon," "we," "us") provides automated Google Business Profile audits for contractors. This policy explains what information we collect, how we use it, and the choices you have. Beacon is intended for businesses located in the United States, and your data is stored and processed in the United States.

Information we collect

  • Account information — your email address and login details when you create a Beacon account.
  • Google Business Profile data — after you connect your profile via Google OAuth, we access data such as your business hours, categories, photos, reviews, posts, and performance metrics (call clicks, website clicks, direction requests, profile views) in order to generate your audits.
  • Billing information — subscription and payment details, processed by our payment provider, Stripe. Beacon does not store your card number.
  • Usage data — basic information about how you use the dashboard, for the purpose of improving the product.

How we use your information

We use the information above solely to operate Beacon for you: running your weekly audit, scoring your profile, generating ranked recommendations, sending your weekly report email, and showing your historical trends on your dashboard. On Pro and Premium plans, it is also used to draft review responses and Google Post copy for your review and approval before anything is posted.

We do not sell your data, and we do not share your Google Business Profile data with any other Beacon customer. Where Beacon shows competitor benchmarking, it is based on publicly available data (Google Places, and aggregated third-party search data) and is presented only as anonymized, aggregate comparisons — never as another business's raw profile data.

Google user data & Limited Use

Beacon's use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

Your Google OAuth token is stored encrypted at rest and is never exposed to your browser. You can revoke Beacon's access to your Google account at any time from your Google Account permissions page, or by disconnecting your profile from Beacon's Settings page.

Third parties we work with

We use a small number of vetted service providers to run Beacon:

  • Google — source of your Business Profile data, via your explicit OAuth consent.
  • Supabase — our database, with row-level security so your data is only ever readable by your own account.
  • Stripe — subscription billing and payment processing.
  • Resend — delivery of your weekly report and account emails.
  • Anthropic (Claude) — generates suggested copy (keyword ideas, draft review replies, post copy) on Pro/Premium plans. Audit findings themselves are never AI-generated — only based on your real profile data.
  • DataForSEO — supplies aggregated, anonymized competitor benchmarking data.

None of these providers are permitted to use your data for their own purposes beyond providing their service to Beacon.

Data retention

We retain your audit history for as long as your account is active, so you can see your progress over time. If you close your account or request deletion, we delete your stored profile data and audit history, and disconnect your Google account access. Billing records are kept for as long as required for tax and accounting purposes, even after account closure.

Your rights & choices

  • Access: request a copy of the data we hold about you.
  • Correction: ask us to fix inaccurate account information.
  • Deletion: request deletion of your account and stored data at any time.
  • Marketing emails: unsubscribe from re-engagement/marketing emails via the link in those emails — you'll still receive your weekly audit report and essential account emails.

Reach us via the contact page below to exercise any of these.

Cookies

Beacon uses only essential cookies needed to keep you signed in and to remember your session — no third-party advertising or tracking cookies.

Legal disclosure

We may disclose information if required to do so by law, or in response to a valid legal request, but we don't otherwise share your data with third parties beyond the service providers listed above.

Security

All traffic to and from Beacon is encrypted over HTTPS. Google OAuth tokens are stored encrypted, never in browser storage. Database access is enforced with row-level security, so one customer's account can never read another customer's data. If we become aware of a security incident affecting your data, we'll notify affected users as required by law.

Children's privacy

Beacon is a business tool intended for contractors and business owners. It is not directed at, and we do not knowingly collect information from, children under 13.

Changes to this policy

We may update this policy as Beacon evolves. Material changes will be reflected by updating the "Last updated" date above. If we change how we use your Google user data in a way that goes beyond what's described here, we'll notify you and ask you to consent to the updated policy before that change applies to your account.

Contact us

Questions about this policy or your data? Reach us via the contact page.