Privacy Policy
GuestGem is built on trust. This policy explains how we collect, use, store, and protect your data — including data accessed through Google and other platform integrations.
1. Who We Are
GuestGem (operated by ReputeIQ, Inc.) provides AI-assisted reputation management for hospitality businesses. Our platform connects to review platforms — including Google Business Profile — to help hotel operators read and respond to guest reviews. Our registered address and contact information are available at guestgem.com/contact.
2. Data We Collect
We collect the following categories of data:
- Account data: Name, email address, role, and billing information provided during registration.
- Hotel data: Property name, address, and platform identifiers (e.g., Google Place ID) you configure in the platform.
- Review data: Guest reviews fetched from connected platforms, including review text, star rating, reviewer display name, and review date.
- Response drafts: AI-generated response drafts and any edits made by your team before publishing.
- Brand voice settings: Tone, greeting, and signature preferences you configure for each property.
- Usage analytics: Aggregated metrics on response rates, sentiment trends, and platform performance.
3. Google Business Profile API Access
When you connect your Google Business Profile account, GuestGem requests access to the business.manage scope via Google OAuth 2.0. This access allows us to:
- Read reviews posted to your Google Business Profile location(s).
- Post, update, or delete review replies on your behalf — only when you explicitly approve a response in GuestGem.
- List and identify which Google Business Profile locations are associated with your account.
What we do not do with Google data: We do not sell, transfer, or use data obtained through Google APIs for advertising, profiling, or any purpose other than providing the GuestGem service. We do not allow humans to read your Google data except when required to provide support you have explicitly requested.
Token storage: OAuth access tokens and refresh tokens are encrypted at rest and transmitted over TLS. Tokens are stored only for the purpose of maintaining your integration and are deleted when you disconnect your Google account.
Revoking access: You can disconnect your Google Business Profile at any time from the Integrations page in your GuestGem dashboard. You may also revoke access directly via your Google account permissions page. Upon revocation, we delete all stored tokens within 30 days.
GuestGem's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
4. How We Use Your Data
- Generating AI-drafted review responses tailored to your brand voice.
- Publishing approved responses to connected review platforms on your behalf.
- Providing analytics, sentiment analysis, and performance reporting for your properties.
- Sending operational alerts (e.g., new negative review notifications).
- Improving our AI models using anonymized, aggregated response quality data.
We never sell your data to third parties. We never use your data for advertising.
5. Data Sharing
We share data only with subprocessors necessary to operate the platform, including:
- AI providers (e.g., Google, Anthropic, OpenAI): Review text is sent to generate response drafts. These providers are bound by their own data processing terms.
- Supabase: Database and authentication infrastructure hosted in the United States.
- Railway / Vercel: Application hosting infrastructure.
We do not share your data with any other third parties without your explicit consent, except as required by law.
6. Data Retention & Deletion
Your data is retained for as long as your account is active. Upon cancellation, account data is retained for 30 days to allow for re-activation, then deleted. Review data and response history may be retained in anonymized form for up to 12 months for model quality purposes.
You can request full export or deletion of your data at any time via our Data Deletion page or by emailing privacy@guestgem.com.
7. Security
All data is encrypted in transit (TLS 1.2+) and at rest (AES-256). OAuth tokens are stored encrypted. We enforce role-based access controls and row-level security on all database tables. We conduct periodic security reviews and maintain an incident response process.
8. Your Rights
Depending on your jurisdiction, you may have rights to: access your personal data, correct inaccurate data, request deletion, restrict or object to processing, and data portability. To exercise any of these rights, contact privacy@guestgem.com. We will respond within 30 days.
9. Updates to This Policy
We may update this policy as our product evolves. Material changes will be notified via email to account holders. The effective date of the current version appears at the bottom of this page.
Effective date: April 13, 2026
10. Contact
For privacy-related questions or requests, email privacy@guestgem.com or use our contact form.