How It Works

Transparent, owner-controlled review management

1. Connect your Google Business Profile

To use Restaurant Reputation Tools, restaurant owners connect their Google Business Profile through Google's standard OAuth 2.0 flow. The owner is in full control of the connection and can revoke access at any time through their Google Account settings.

2. OAuth Scopes We Request

We request only the minimum scopes necessary to provide our service:

  • businessmanagement.read — to read your business profile information and customer reviews.
  • businessmanagement.replies.write — to publish your approved replies to Google Business Profile (only after your explicit approval within our application).

We do not request access to other Google data, including Gmail, Drive, Calendar, or personal information beyond your Business Profile.

3. Review Workflow

  1. Reviews are fetched. We periodically fetch new reviews from your Google Business Profile via the Google API.
  2. AI generates a draft.Our system generates a draft reply using Anthropic's Claude API, taking into account the review content, rating, and your restaurant's tone of voice.
  3. Owner reviews and edits. The draft is displayed in your dashboard. You can review, edit, or discard it. Nothing is published without your explicit approval.
  4. Owner publishes.When you are satisfied with the response, you click "Publish" and we send the response to Google Business Profile via the API.

4. Data Handling and Security

We store the minimum data necessary to provide our service:

  • Reviews fetched from Google Business Profile (used to generate drafts and display in your dashboard).
  • AI-generated drafts and your edits (used to learn your preferences over time, never shared).
  • Your published responses (for your historical record).

All data is stored in encrypted databases hosted in the European Union (Supabase, EU region). We do not sell or transfer Google user data to third parties for any purpose, including advertising.

5. Google API Services User Data Policy Compliance

Restaurant Reputation Tools' use and transfer of information received from Google APIs to any other app will adhere to Google API Services User Data Policy, including the Limited Use requirements. We use Google user data only to provide and improve user-facing features that are prominent in the requesting application. We do not transfer this data to others unless doing so is necessary to provide and improve these features, comply with applicable law, or as part of a merger, acquisition, or sale of assets with notice to users. We do not use this data for serving advertisements. We do not allow humans to read this data unless we have the user's affirmative agreement for specific messages, doing so is necessary for security purposes such as investigating abuse, to comply with applicable law, or our use is for internal operations and the data has been aggregated and anonymized.

6. Disconnection and Data Deletion

You can disconnect Restaurant Reputation Tools from your Google Business Profile at any time:

  • Through Google Account settings: Security > Third-party apps with account access.
  • Through our application: Settings > Disconnect Google Business Profile.

Upon disconnection, we stop fetching new reviews and replying on your behalf immediately. To request full deletion of historical data we have stored, contact contact@restaurant-reputation-tools.fr. We will delete your data within 30 days of receiving the request.