Data Deletion

Three ways to stop GReviewPilot from accessing your data, and how to have it permanently erased.

Last updated:

Option 1 — Disconnect Google (immediate, self-service)

This is the fastest route and it takes effect at once. It stops all access to your Google Business Profile and destroys the credentials we hold.

  1. Sign in to GReviewPilot.
  2. Go to Dashboard → Integrations → Google.
  3. Click Disconnect and confirm.

What happens the moment you confirm:

  • We call Google’s token revocation endpoint, which invalidates our refresh token and every access token derived from it.
  • We delete the stored connection record, including the encrypted access and refresh tokens.
  • We can no longer read your locations, reviews, or profile information.

Reviews and locations already synced into your workspace remain visible to you, because they are part of your own records. To erase those too, use Option 3.

Option 2 — Revoke from your Google Account

You can withdraw access from Google’s side without signing in to GReviewPilot at all.

  1. Open myaccount.google.com/permissions.
  2. Find GReviewPilot in the list of apps with account access.
  3. Click it, then choose Remove access.

Our access stops immediately. The next time GReviewPilot tries to sync, Google rejects the request and we mark the connection as needing reauthorisation.

Option 3 — Delete your account and all data

To have everything permanently erased, email us from the address registered on your account:

To: contact.greviewpilot@gmail.com
Subject: Data deletion request
Body: your workspace name and the email address on the account.

We verify the request comes from an account owner, then delete within 30 days:

  • Your user account, workspace, and team members.
  • All Google connection records and encrypted OAuth tokens (and we revoke the grant at Google).
  • All synced Google data — locations, reviews, reviewer display names and photo URLs, and stored API payloads.
  • Business profile details, review replies, posts, QR campaigns, websites, uploaded media, and analytics.

We send written confirmation when deletion is complete. Deletion is irreversible.

What we may retain, and why

After a deletion request we keep only what the law requires or what contains no personal data:

  • Invoices and payment records — retained as required by Indian tax and accounting law.
  • Security and audit logs — retained briefly where needed to investigate abuse or comply with a legal obligation.
  • Operational API logs — endpoint names, status codes, and timings. These contain no review content or tokens, and are deleted automatically on a rolling 14-day window.
  • Encrypted backups — expire on their normal cycle within 30 days of deletion.

Questions

Contact Brightwave Digital Products LLP at contact.greviewpilot@gmail.com. Full details of what we collect and why are in our Privacy Policy.