Vicarolo

Privacy Policy

Last updated: 1 August 2026

Vicarolo ("Vicarolo", "we", "us") provides software that helps organizations manage Google Business Profile listings across multiple locations. This policy explains what information we collect, why, and what we do with it.

Operated by Dominic Jalsevac, based in Ontario, Canada. For any privacy question or request, contact privacy@vicarolo.com and we will respond directly. A postal address is available on request.

Information we collect

Account information. When you create an account we collect your email address and, optionally, your name and organization name. We use email-based sign-in links, so we do not collect or store passwords.

Google account data. When you connect a Google account, Google provides us with an access token and a refresh token scoped to the Google Business Profile API (https://www.googleapis.com/auth/business.manage). We also receive the email address of the connected Google account so we can show you which account is connected.

Business Profile content. Once connected, we read the business information associated with the locations you manage. This includes business names, addresses, phone numbers, websites, categories, hours, service areas, descriptions, attributes, and profile status indicators. We store copies of this information so we can detect when it changes.

Usage and operational data. We log actions taken in the product, such as edits you queue and when they were sent, in order to provide an audit trail and to diagnose problems.

We do not collect personal information about your customers, and the service is not designed to receive it.

How we use information

We use the information above only to:

We do not use your Google Business Profile data to train machine learning models. We do not sell it, rent it, or use it for advertising.

Google API Services User Data Policy

Vicarolo's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. Specifically:

How we store and protect information

Google refresh tokens are encrypted at rest using AES-256-GCM before being written to our database. Data is stored on infrastructure located in the United States. If you require Canadian data residency, contact us before connecting an account. Access to production systems is limited to personnel who need it to operate the service.

Service providers

We use the following providers to operate Vicarolo, each of which may process data on our behalf: Vercel (application hosting), Neon (database hosting), Resend (sign-in links and alert emails), Inngest (scheduling background jobs), and Stripe (payment processing).

Retention and deletion

We retain your data for as long as your account is active.

You can disconnect a Google account at any time from within Vicarolo, which deletes the stored tokens. You can also revoke Vicarolo's access directly at myaccount.google.com/permissions.

You can request deletion of your account and associated data by emailing privacy@vicarolo.com. We will delete it within 30 days, except where we are required to retain records for legal or accounting purposes.

Your rights

Depending on where you live, you may have the right to access, correct, or delete the personal information we hold about you, and to request a copy of it. Email privacy@vicarolo.com and we will respond within the timeframe required by applicable law.

Changes

We will post any changes to this policy on this page and update the date above. If the changes are material we will notify account holders by email.