← Back

Privacy Policy

Effective date: February 2026

Heard360 (“we”, “our”, “us”) provides review monitoring and response management for restaurants. This policy describes what data we collect, how we use it, and your rights.

What we collect

We collect the following data to provide our service:

  • Account information — name, email address, phone number
  • Google Business Profile review data — reviewer display names, star ratings, review text, and review dates for your connected business locations
  • Review responses — AI-generated drafts and human-edited responses that are posted to your Google listing
  • SMS message content — text messages exchanged through our notification system for review approval workflows

Google API Services — data use disclosure

Heard360 uses the Google Business Profile API to access review data for your connected business locations. Specifically, we access:

  • Reviews — we read reviews (reviewer name, rating, text, date) to display them in your dashboard and generate AI-drafted responses
  • Review replies — we post owner responses to your Google listing only when you explicitly approve them

We do not access your customers' personal information, location analytics, Google Ads data, or any other Google data beyond what is listed above.

Heard360's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.

How we use your data

  • To display your Google reviews in your Heard360 dashboard
  • To generate AI-drafted responses to your reviews using your configured brand voice
  • To send SMS notifications to your team when reviews need attention
  • To post approved responses to your Google Business Profile on your behalf
  • To provide review history and response audit trails

We use your data only to provide and improve the Heard360 service. We do not use your data for advertising, profiling, or any purpose unrelated to the service.

How we store your data

Your data is stored in a secured Supabase (PostgreSQL) database with row-level security policies that restrict access to authorized users for each business location. Data is encrypted in transit (TLS) and at rest.

Data sharing

We do not sell, rent, or trade your data. We share data only with the following third-party services, solely to operate Heard360:

  • Google Business Profile API — to read reviews and post approved replies
  • Anthropic (Claude API) — review text is sent to generate AI-drafted responses. Anthropic does not use API inputs for model training.
  • Twilio — phone numbers and message content for SMS notifications
  • Stripe — email and payment information for billing

Data retention and deletion

We retain your data for as long as your account is active. When you cancel your subscription, you may request deletion of all your data by contacting us. We will delete your data within 30 days of a deletion request, except where retention is required by law.

You may revoke Heard360's access to your Google Business Profile at any time by removing our service account from your listing's user management settings.

SMS notifications

By providing your phone number and opting in during account setup, you consent to receive SMS notifications about review activity at your connected locations. Message frequency varies based on review volume. Message and data rates may apply. Reply STOP to any message to unsubscribe at any time.

Your rights

  • Access a copy of the data we hold about you
  • Request correction of inaccurate data
  • Request deletion of your data
  • Revoke Google Business Profile access at any time
  • Unsubscribe from SMS notifications at any time

Contact

Questions about this policy? Email us at support@heard360.com.