Legal

Privacy Policy

Last updated: July 19, 2026

1. Who controls your data

AI For Local Businesses ("AIFLB", "we", "us") is the controller of personal data processed through the AIFLB website, dashboard and Chrome extension, except where a service provider acts as an independent controller under its own terms.

Operating address: Cowork, Bratstvo Inox admin building, 7-mi Noemvri 179, 6000 Ohrid, North Macedonia.
Privacy and business email: [email protected]
Office hours: Monday-Friday, 09:00-17:00 local time, excluding public holidays.

2. Scope

This policy explains what we collect, where it comes from, why we use it, who receives it, how long we retain it, and the choices and rights available to you. It applies to visitors, account holders and Chrome extension users.

3. Information we process

  • Account and authentication data: name, email address, password hash, account status, Google sign-in identifier if you choose Google login, session information and security events. We do not store plain-text passwords.
  • Extension consent, authentication and connection data: consent version and timestamps, revocation timestamp, connection timestamp, extension identifier and a one-way index of the extension bearer token. The usable token is authentication information stored in extension-local Chrome storage and is sent only to AIFLB to authenticate extension requests. The server stores a purpose-separated one-way index rather than the usable token.
  • Business-profile and audit data: the business name, address, contact details, website, identifiers, coordinates, categories, services, attributes, hours, description, rating, review statistics and other profile fields needed for a requested audit.
  • Review and post audit data: visible review or post text loaded for the audit, rating, relative date, limited reviewer identification such as the displayed first name, and audit results. Review and Post Audits are limited to up to 50 loaded items per user-initiated audit.
  • Supported-page navigation and search context: the current supported Google Maps, Google Search, local-review or Business Profile management URL; a Maps search keyword; the selected or general map area; source business URLs; and map-center coordinates when needed for the feature you start. AIFLB does not collect URLs from unrelated websites or create a general history of the websites you visit.
  • Local Scan data: search keyword, general search location, source Google Maps URL, map-center coordinates and business records collected for up to 20 displayed results per user-initiated scan.
  • Website and AI inputs: website URLs and publicly available website content analyzed at your request, prompts, instructions, generated drafts and related output.
  • Usage and diagnostics: actions performed, allowances consumed, timestamps, error details, approximate security information derived from IP addresses, and performance information needed to operate and protect the service.
  • Billing and licensing: plan, order, customer and license identifiers, purchase email, currency, amount, refund status and entitlement status supplied by Lemon Squeezy. Card details do not touch AIFLB servers.
  • Optional provider credentials: Gemini or DataForSEO credentials you choose to add. Secret values are encrypted at rest and are not displayed again after saving.
  • Support and contact data: name, email, subject, chat messages, correspondence, pages viewed while the support widget is active, technical connection details and information you choose to provide when requesting support.

4. Chrome extension disclosure and consent

Before AIFLB enables its Google-page tools, the extension displays a prominent disclosure and requires you to click Agree & Enable AIFLB. Until the current consent version is accepted, AIFLB controls remain disabled and the MAIN-world Maps reader remains dormant. When you connect an account, the consent is recorded in that account. You may revoke the connection and consent from the extension popup or account dashboard.

After consent, the extension runs only on the Google Maps, Google Search, local-review and Google Business Profile management URLs listed in its manifest. These include public Maps and Search pages and, when you open them while signed in to Google, owner-facing Business Profile management pages. The extension reads visible page content and relevant structured business-profile responses delivered by Google to those supported pages so it can display categories and AIFLB controls.

On Google Maps, an in-page reader observes same-origin place and search responses after consent so categories and selected business details remain accurate as Maps changes pages without a full reload. It does not observe cross-origin traffic, read your Google password or authentication cookies, request Google Account API access, or execute code received from Google or AIFLB. The managed Business Profile editor can appear inside a matching Google child frame; the managed-profile script therefore uses all_frames so the same user-facing tools can appear in that editor. This does not grant access to unrelated websites or non-matching frames.

Page reading used only to display AIFLB controls happens locally. Connection and consent checks send the extension credential and return limited account status information. Business-profile content, supported-page URLs, search context, reviews, posts and scan results are sent to AIFLB only when you connect the extension or start the corresponding audit, generator, capture or scan. AIFLB does not build a general browsing history or edit, save or publish Google Business Profile fields.

5. Bounded Maps analysis

AIFLB is designed for user-initiated analysis of selected business-profile information. This may include publicly accessible profile information and, when you deliberately use AIFLB on a Business Profile you manage, owner-facing information displayed in Google's management interface. It is not designed to mass-download Google Maps, create a bulk data feed, reproduce Google Maps, or provide a substitute mapping or business-listings service. Local Scan is capped at 20 displayed businesses per action, and review and post audits are capped at 50 loaded items per action. We do not sell or redistribute captured Google content as a raw data feed.

Google and third parties retain their rights in their services and content. AIFLB does not grant you rights to Google content and does not authorize conduct prohibited by Google's terms or applicable law. You are responsible for using AIFLB and any resulting reports lawfully. When you request an AI analysis, the minimum relevant audit data may be included in a prompt sent to the Gemini API to produce the requested analysis.

6. Why we process information

  • Contract: to create your account, connect the extension, provide audits and reports, administer plans, process entitlements, provide support and maintain the service you requested.
  • Consent: to enable extension handling of Google-page content. Consent may be revoked at any time without affecting processing already performed lawfully.
  • Legitimate interests: to secure the service, prevent abuse, diagnose faults, measure reliability, maintain records, improve directly related functionality and establish or defend legal claims, where those interests are not overridden by your rights.
  • Legal obligations: to keep required financial records, respond to lawful requests and comply with applicable tax, accounting, consumer and data-protection law.

7. Service providers and disclosures

We disclose only information reasonably necessary for the requested function:

  • Contabo: server hosting and infrastructure.
  • Google Gemini API: AI prompts and relevant requested context used to generate analyses or drafts.
  • DataForSEO: keywords, locations, business identifiers and related inputs for rank, client-finder and fallback business-data functions.
  • Lemon Squeezy: hosted checkout, licensing, payment, tax, receipt, refund and customer-portal functions.
  • Brevo Conversations: website and in-app support chat, message delivery, visitor recognition and support conversation history. Signed-in account details may be supplied to Brevo so the support agent can identify the account requesting help.
  • Google OAuth: optional account sign-in and identity verification.
  • OpenStreetMap and Open-Meteo: map tiles and limited location/geocoding functions used in dashboard tools.
  • Thum.io: website URL supplied for a website preview where that preview is displayed.
  • Professional advisers and authorities: only when reasonably necessary for legal advice, security, fraud prevention, enforcing agreements or complying with law.

Providers may process data in other countries. Where data-protection law requires a transfer safeguard, we use the provider's applicable data-processing terms and a legally recognized safeguard such as an adequacy decision or standard contractual clauses. Provider services also operate under their own privacy terms where they act independently.

8. Chrome Web Store Limited Use

AIFLB's use and transfer of information received through the Chrome extension complies with the Chrome Web Store User Data Policy, including the Limited Use requirements:

  • Allowed use: we use extension data only to provide or improve the extension's disclosed Google Business Profile audit and local SEO workflow features.
  • Allowed transfer: we transfer only the information necessary to provide a feature you request, secure the service, comply with law, or complete a permitted business transfer subject to appropriate safeguards.
  • No advertising or lending use: we do not sell extension data or use or transfer it for personalized advertising, creditworthiness or lending.
  • Restricted human access: humans may read extension data only with your specific consent for support, when necessary for security, to comply with law, or after aggregation and anonymization for permitted internal operations.

9. No sale, behavioral advertising or unrelated profiling

We do not sell personal data or extension data, provide it to data brokers, use it for cross-context behavioral advertising, or use Google-page content to build unrelated user profiles. Brevo Conversations is used for customer support, not advertising.

10. Retention and deletion

  • Account, saved-business, audit, scan, report and AI workspace data, including supported-page source URLs saved with those records, is retained while your account remains active or until you delete the relevant record.
  • Extension consent records are retained while active and for up to 24 months after revocation as an audit trail, unless a longer period is required to resolve a dispute or comply with law.
  • Routine usage and security logs are generally retained for up to 12 months.
  • Support messages are generally retained for up to 24 months after the request is closed.
  • Billing, licensing, tax and transaction records are retained for the period required by applicable financial and tax law.

After a verified full-account deletion request, we will delete or irreversibly anonymize data not subject to a legal retention requirement from active systems within 30 days. Residual copies in protected backups are not restored for ordinary use and are overwritten or deleted within the normal backup cycle, targeted not to exceed 90 days. See the data deletion page.

11. Security and human access

We use HTTPS, password hashing, encrypted storage for optional provider secrets, server-side token hashing, access controls, CSRF protection, rate controls, backups and security logging. No online service can promise absolute security. Personnel may access user data only when permitted by the Limited Use rules described above and subject to confidentiality and least-access expectations.

12. Your rights

Subject to applicable law, you may request access, a copy, correction, deletion, restriction or portability of your personal data; object to processing based on legitimate interests; withdraw consent; and complain to a supervisory authority. We may request reasonable identity verification and may retain information where law permits or requires it. Rights can be exercised at [email protected].

If North Macedonian law applies, you may contact the Agency for Personal Data Protection at azlp.mk. If you are in the EEA, United Kingdom or another jurisdiction with a local authority, you may also complain to the authority responsible for your usual residence or workplace.

13. Cookies and browser storage

The dashboard uses an essential session cookie for login and form security. The support chat may use browser storage or a visitor identifier to deliver and retain the conversation. The extension stores the consent record in Chrome sync storage, which may be synchronized by Chrome under your Google Account settings, and stores the revocable connection token in extension-local storage restricted to trusted extension contexts. Google handles Chrome Sync under its own privacy terms. See the cookie policy.

14. Children

AIFLB is a business service and is not directed to children. You must be at least 18, or the age of legal majority where you live, to create an account unless a parent, guardian or authorized organization validly accepts responsibility.

15. Independence, competitors and intellectual property

AIFLB is independent and is not affiliated with, endorsed by, sponsored by or operated by Google, GMB Everywhere, PlePer, Local Falcon, BrightLocal or any other referenced tool or platform. Third-party names and trademarks belong to their owners and are used only to identify or compare compatible products and services. AIFLB's software, branding and original design elements are proprietary to AIFLB or its licensors.

16. Changes

We may update this policy when our practices, providers or legal obligations change. We will update the date above and provide an in-product notice or request renewed consent before newly disclosed extension data handling begins where a material change affects extension users.

17. Contact

Email [email protected], use the contact form, or write to AIFLB at Cowork, Bratstvo Inox admin building, 7-mi Noemvri 179, 6000 Ohrid, North Macedonia. Normal response hours are Monday-Friday, 09:00-17:00 local time.