Privacy Policy
Last updated: May 2025
1. Who we are
MyReputation.ie is operated by Sevenoways ("we", "us", "our"), a company based in Ireland. We act as the data controller for personal data processed through this service.
Contact us at: privacy@myreputation.ie
2. What data we collect
- Account information: Your name, email address, and profile picture, obtained via Google OAuth when you sign in.
- Google OAuth tokens: Access and refresh tokens that allow us to read and write to your Google Business Profile on your behalf. These are encrypted in our database and never shared.
- Google Business Profile data: Snapshots of your business listing fields (name, address, phone, website, category, hours) to detect changes over time.
- Change logs: A history of detected changes to your profile, including the old and new values.
- Billing data: Payment is handled entirely by Stripe. We store only your Stripe customer ID and subscription status — we never see or store your card details.
- Usage data: Basic server logs (IP address, browser type, pages accessed) for security and performance monitoring.
3. Why we collect it (legal basis)
- Contract performance (Art. 6(1)(b) GDPR): To provide the monitoring and alerting service you signed up for.
- Legitimate interest (Art. 6(1)(f) GDPR): To maintain system security, prevent abuse, and improve the service.
- Consent (Art. 6(1)(a) GDPR): When you grant us OAuth access to your Google Business Profile via the Google sign-in consent screen.
4. How we use your data
- To monitor your Google Business Profile for unauthorised changes (polling every 4 hours)
- To send you email alerts when changes are detected
- To allow you to revert changes to your profile from your dashboard
- To manage your subscription and billing via Stripe
- To respond to support queries
We do not sell your data, use it for advertising, or share it with any third party except as described below.
5. Third-party services
- Google LLC: We access your Google Business Profile data via Google's APIs under your OAuth authorisation. Google's privacy policy applies to their services: policies.google.com/privacy
- Stripe Inc.: Processes all payments. Stripe is PCI DSS compliant. See stripe.com/privacy
- Amazon Web Services (SES): Used to send transactional emails (change alerts, welcome emails). Emails are not used for marketing.
6. Data retention
- Your account data is retained for as long as your account is active.
- Change logs and snapshots are retained for 12 months and then automatically deleted.
- If you delete your account, all your personal data is permanently deleted within 30 days.
- Billing records may be retained for up to 7 years to comply with Irish tax and accounting obligations.
7. Your rights (GDPR)
As a user in the EU/EEA, you have the following rights:
- Access: Request a copy of the data we hold about you.
- Rectification: Ask us to correct inaccurate data.
- Erasure: Ask us to delete your account and associated data.
- Portability: Receive your data in a machine-readable format.
- Objection: Object to processing based on legitimate interest.
- Withdraw consent: Revoke your Google OAuth access at any time via your Google Account security settings.
To exercise any of these rights, email us at privacy@myreputation.ie. We will respond within 30 days.
You also have the right to lodge a complaint with the Irish supervisory authority, the Data Protection Commission (DPC).
8. Cookies
We use only strictly necessary cookies — specifically a session cookie to keep you logged in. We do not use tracking, analytics, or advertising cookies. No cookie consent banner is required under ePrivacy rules for strictly necessary cookies.
9. Security
All data is transmitted over HTTPS (TLS 1.2+). OAuth tokens are stored encrypted at rest. We follow industry-standard security practices and conduct regular reviews of our infrastructure. However, no system is 100% secure — if you believe your account has been compromised, contact us immediately.
10. Changes to this policy
We may update this policy from time to time. We will notify you of material changes by email. The date at the top of this page shows when it was last updated.