API transparency

How Pinn uses your Google Business Profile

Pinn integrates with the Google Business Profile API to read your reviews and business information so we can deliver theme analysis, draft replies, and competitor benchmarks. We treat that access with strict limits, post nothing without your approval, and never use your data to train AI models.

Last reviewed:
The problem

Why Pinn needs Google Business Profile access

The customer problem

Local business owners receive dozens — sometimes hundreds — of reviews each month. Reading them all is unrealistic. Patterns and warnings get missed. Reply turnaround slips from hours to weeks. And no one has time to track what competitors a few blocks away are doing.

The signal is in the reviews — but only if someone is actually paying attention to all of it, every week.

What Pinn does about it

Pinn reads every review on the locations you connect, groups them into themes, surfaces rating shifts and crises, drafts replies in your voice, and benchmarks your performance against the competitors you choose. You get a weekly intelligence brief and a clear list of what to do next.

To deliver this, Pinn must read your reviews and business profile data through the official Google Business Profile API — the only legitimate way to access this information at scale.

Permissions

What Pinn accesses

Pinn requests only the Google API scopes it needs to deliver the product. Each scope, how we use it, and why it's required is listed below.

ScopeWhat we do with itWhy it's needed
business.manage
Read business locations
Sync the list of locations the user has authorized us to analyze.Required to display your businesses inside Pinn so you can choose which ones to monitor.
Reviews
Read
Fetch new and historical reviews so our AI can analyze themes, sentiment, and rating shifts.Core to the product — without review data, Pinn cannot generate analysis or briefs.
Reviews
Reply
Post user-approved replies back to reviews when you click "approve" on an AI-drafted reply.You explicitly approve every reply before it is published. Pinn never replies on its own.
Account Management
Identify user & accounts
Identify the user and the accounts they manage on Google Business Profile.Required for authentication and authorization so we know which accounts you can analyze.
Our limits

What Pinn does NOT do

A short list, on purpose. These are the lines we draw and do not cross.

  • We do NOT generate fake, fraudulent, or incentivized reviews.
  • We do NOT post replies automatically — every reply requires explicit user approval.
  • We do NOT manipulate ratings, review counts, or any metric on Google Business Profile.
  • We do NOT access the data of businesses you have not connected to Pinn.
  • We do NOT sell, lease, or share your Google data with third parties for advertising.
  • We do NOT use your Google data to train artificial intelligence models — ours or our subprocessors’.
  • We do NOT access private, non-public competitor data — only publicly available information.
Process

How it works, step by step

From signup to a weekly intelligence brief, here is the full path your data takes.

  1. 01

    Sign up

    Create your Pinn account at usepinn.com. Email and password or Sign in with Google — your choice.

  2. 02

    Connect your Google Business Profile

    Authorize Pinn through Google’s official OAuth consent screen. You will see exactly what we are requesting before approving.

  3. 03

    Pinn analyzes

    Our AI processes your reviews and — if you opt in — public competitor data to surface themes, trends, and draft replies.

  4. 04

    You stay in control

    Review and approve every AI-generated reply before it is published. Disconnect Pinn from your Google Account at any time.

Privacy

How we handle your data

Where it lives, how long it stays, and who can see it.

Where your data lives
Pinn is hosted in Germany within the European Union. Your data is processed and stored on EU infrastructure.
How long we keep it
Active accounts: data is retained while your subscription is active. After cancellation, data is retained for up to 3 months and then deleted or anonymized. See our Terms for the precise schedule.
Who can access it
Only authorized Pinn personnel for operational reasons — debugging, abuse review, and customer support. Every internal access is logged.
AI processing
Reviews and business data are sent to OpenAI and Anthropic to generate analysis and reply drafts. We have contractual safeguards with both providers ensuring your data is NOT used to train their models.
Security

Security

The technical controls that keep your data safe in transit and at rest.

  • All data encrypted in transit (TLS 1.2+) and at rest (AES-256).
  • Role-based access controls within Pinn — least-privilege by default.
  • Regular internal security reviews and dependency audits.
  • Subprocessors fully disclosed in our Data Processing Agreement (DPA).
Control

You stay in control

Disconnect, delete, or export at any time. No support ticket required.

Revoke Pinn's access at any time

You can revoke Pinn’s access in two ways:

  1. From your Pinn dashboard: go to Settings → Integrations → Disconnect.
  2. From your Google Account, visit myaccount.google.com/permissions and remove Pinn from your authorized apps.

Delete your data

Use the in-app deletion option in Settings → Account, or email support@usepinn.com and we will permanently delete your data.

Export your data

Download a machine-readable copy of your account data — including connected business profiles, reviews, and analysis — at any time from Settings → Privacy → Export.

Compliance

Compliance and policies

The frameworks that govern how Pinn uses your Google data and your rights as a Pinn user.

  • Google API Services User Data Policy

    Pinn’s use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.

  • GDPR (EU/UK)

    Pinn provides a Data Processing Agreement under GDPR Article 28. Users have full rights to access, rectify, port, and delete their data.

  • Consumer rights

    EU and UK consumers have statutory 14-day withdrawal rights for paid subscriptions (see Terms section 7.2).

Contact

Questions about your data?

Our team answers every message about data, access, and privacy. We aim to respond within one business day.

Talenthaus Teknoloji Limited Şirketi
Barbaros Mahallesi Nida Kule No:1
Istanbul, Ataşehir 34750
Turkey
Related policies