Colaka

Legal

Privacy Policy

Effective July 30, 2026

This policy explains how Colaka handles information when you use its visibility intelligence, website auditing, reporting, property marketing, public Google listing audit, and authenticated Google Business Profile tools. Questions about anything below are welcome at support@colaka.com.

Information we collect

We collect account and workspace details, property and website information you submit, audit inputs and outputs, notification preferences, and service usage records. Website audits also store information collected from publicly accessible pages, including URLs, metadata, headings, structured data, and crawl responses.

How we use information

We use this information to authenticate users, operate workspaces, run requested audits, calculate scores, generate reports and recommendations, enforce plan limits, send requested notifications, prevent abuse, and improve reliability.

Public Google Maps Platform and Places data

When the public listing audit is enabled and a manager requests a search, Colaka sends the property's canonical name and address, plus an approximate location bias when confirmed coordinates are available, to Places API (New). Google may return up to five public candidates with selected identity, address, location, type, business-status, Google Maps link, and attribution fields. After explicit confirmation, Colaka requests only the approved public Place Details fields needed for supported listing, contact, hours, status, rating-context, moved-listing, freshness, and consistency checks. Colaka does not request reviews, AI summaries, complete photos, posts, Q&A, owner responses, private performance, or authenticated management settings through this public flow.

Authenticated Google Business Profile data

Separately, if an authorized organization owner or administrator connects Google Business Profile, Colaka requests the business.manage OAuth scope and reads the accounts and locations available to that Google user. For the selected location, Colaka may read profile identity and contact fields, categories, address, website, hours, service-area and profile metadata, plus reviews, ratings, review text, review timestamps, and owner replies. This owner-authorized source is not inferred from a public Places match and has separate connection and revocation controls.

Why and how Google data is used

Colaka uses public Places observations to support an explicitly confirmed listing association and coverage-aware public listing audits. Colaka separately uses owner-authorized Business Profile data, when connected, for the authenticated features described above. User-entered observations, Google-provided observations, and Colaka-generated match analysis, findings, scores, recommendations, and workflow state are labeled separately. Google reviewer display names and profile photos are not persisted. Colaka's use and transfer of information received from Google APIs adheres to the applicable Google API terms and policies, including Limited Use requirements for Google user data; Google data is not sold or used for advertising.

Google data storage and retention

Google Place IDs may be retained as durable external identifiers, including confirmation and replacement history. Colaka does not persist complete raw Places responses. Candidate content and normalized public Place Details content are configured to expire no later than 30 calendar days after retrieval, while Colaka-owned audit lineage, hashes, coverage, workflow state, and findings may be retained longer. Reports may reproduce a point-in-time public observation with its retrieval time, freshness, coverage, source subtype, and attribution; the public Places feature remains disabled until report retention and export handling have passed Colaka's Google Maps Platform policy release review. For authenticated Business Profile, OAuth refresh tokens are encrypted server-side with AES-256-GCM, and source content receives explicit fetch and expiration times. Operational consent, revocation, security, and audit metadata may be retained longer where needed to operate and secure the service.

Service providers

Colaka uses Supabase for authentication and application data, Stripe for subscription billing, Resend for transactional email when configured, and OpenAI-compatible services for selected non-Google recommendations when configured. Payment card details are handled by Stripe and are not stored by Colaka.

AI processing

Colaka does not send Google Business Profile API content, review text, Google profile snapshots, or Google OAuth credentials to AI providers. When separate AI-assisted features are enabled, relevant non-Google audit findings and user-provided business context may be sent to the configured model provider. Colaka does not intentionally send passwords, payment card details, or authentication secrets to model providers.

Who can view Google data

Public Places observations and authenticated Google Business Profile content are available only to authenticated members who are authorized for the corresponding Colaka workspace and property, except when an authorized manager deliberately includes attributed public observations in a shared report. Organization owners and administrators manage public listing associations and the separate authenticated Google connection. Restricted service workers may process the content to run requested or scheduled read-only refreshes, syncs, report generation, and retention cleanup.

Sharing and disclosure

We do not sell personal information. We share information with service providers only as needed to operate Colaka, and may disclose information when required by law, to protect the service, or as part of a business transaction subject to appropriate safeguards.

Revoking Google access

An organization owner or administrator can choose Disconnect & revoke in the Google Business Profile module. Colaka stops future syncs, asks Google to revoke the token, and deletes the local credential after Google confirms. If Google does not confirm, Colaka marks revocation pending and retains the encrypted token only so revocation can be retried. A user may also remove Colaka from the third-party access section of their Google Account.

Retention and security

Other account and workspace records are retained while the account or workspace remains active and as needed for operational, legal, and security purposes. Colaka uses access controls, row-level database policies, encrypted transport, and restricted service credentials, but no online service can guarantee absolute security.

Export, correction, and deletion

Workspace owners may request access, correction, export, or deletion by following the Data export and deletion page or contacting support@colaka.com from the account email. Colaka verifies the requester and scope before acting. Deleting a property or Google connection removes provider records through database relationships; backup and legally required retention handling may vary and requires case-specific review.

Google privacy reference

Google's handling of information is described in the Google Privacy Policy. Google Maps Platform also publishes service-specific Places API policies and attribution requirements.

Questions: support@colaka.com · Terms · Data export and deletion · Support