GBPly - Google Business Profile management software
    GBPly, a product of 3local Ltd

    Trust & Security

    Connecting a Google Business Profile — or a hundred client profiles — means trusting the software with access that matters. This page sets out who we are, exactly what access we ask for, how we protect it, and what we do not claim.

    Who operates GBPly

    GBPly is a product of 3local Ltd, a company registered in England and Wales under company number 16598862. Our registered office is 232 Stamford Street Central, Ashton-Under-Lyne, United Kingdom, OL6 7NQ.

    You can verify our company details independently on the UK register: Companies House record for 3local Ltd.

    GBPly is an independent product. It is not affiliated with, endorsed by, or certified by Google. Our authoritative website is gbply.net and our published contact address is support@gbply.net.

    Google account access

    GBPly connects to your Google Business Profile using Google's official OAuth flow. You sign in with Google directly; we never see, ask for, or store your Google password.

    We request only two scopes:

    • business.manage — to read and update the Business Profiles you choose to manage: business information, posts, photos, reviews and replies, and performance data.
    • userinfo.email — to identify which Google account is connected, so you can safely link and separate multiple accounts.

    We do not request access to Gmail, Google Drive, Google Ads, Search Console, or Google Analytics. You can disconnect a Google account from GBPly at any time, and you can also revoke access from your Google account security settings. When you delete your GBPly account, we revoke the tokens we hold with Google.

    How credentials are handled

    Google OAuth access and refresh tokens are encrypted with AES-256-GCM before they are stored, using a key held as a server-side secret that is never exposed to the browser. Tokens are decrypted only inside our server-side functions at the moment an API call to Google is made.

    Third-party integration credentials you supply yourself — for example SMS provider keys, email provider credentials, or a text-to-speech API key — are stored the same way, in a dedicated secrets table that is not readable from the browser and is not returned to ordinary workspace members.

    All traffic to GBPly and to our backend is served over HTTPS/TLS. Our database and file storage are hosted on Supabase infrastructure, which provides encryption at rest and managed backups.

    Workspace isolation and access control

    Data in GBPly is scoped to a workspace. Business profiles, posts, reviews, reports, scans, credits and integration settings all belong to a workspace, and access is enforced in the database itself using row-level security policies — not only in the interface. A member of one workspace cannot read another workspace's data even by calling our API directly.

    Within a workspace, members hold roles that determine what they can see and change. Roles are stored separately from user profiles and checked server-side on every request, so permissions cannot be escalated from the browser.

    Client portals are separate again: a portal link exposes only the single business profile it was issued for, and only the sections the agency has chosen to enable.

    Two-factor authentication

    Every GBPly account can enable app-based two-factor authentication (TOTP) using an authenticator app such as Google Authenticator, Authy or 1Password. You will find it under My Account.

    Workspace owners can additionally require two-factor authentication for their workspace. When that setting is on, members who have not enrolled are prompted to do so and the requirement is verified server-side before workspace data is returned — so it cannot be bypassed by manipulating the browser.

    Your data: export, retention and deletion

    Export. From My Account you can request a machine-readable (JSON) export of your account data. It is generated by a background job and delivered as a time-limited download link.

    Deletion. You can request account deletion yourself from My Account. The request enters a queue and is executed automatically after 30 days, which gives you a window to cancel if it was made in error. On execution we cancel any active subscription, revoke the Google tokens we hold, and delete or irreversibly anonymise your personal data.

    Retention. Retention periods, the lawful bases we rely on, and international transfer arrangements are set out in full in our Privacy Policy.

    Customer-uploaded contact data

    This covers contact details you upload or submit for review request campaigns — customer email addresses and mobile numbers, and the messages sent to them.

    • Our role. We process this data on your instructions, only to provide the Service to you. You decide who is contacted and why.
    • Storage. Uploaded recipients become scheduled or sent message records attached to the workspace and business profile they were sent from.
    • Encryption. TLS in transit; encrypted at rest by our hosting platform.
    • Access control. Limited to members of that workspace with a permitting role, enforced by per-workspace authorisation rules at the database level. Two-factor authentication is available and can be enforced workspace-wide.
    • No secondary use. Never sold, shared for anyone else's marketing, enriched from other sources, combined with other customers' data, or used to train AI models.
    • Delivery subprocessors. The email and SMS providers listed below, acting on our instructions — or your own email/SMS connector if you have configured one.
    • Retention. Retained until you request deletion, or until the workspace or account is deleted. No fixed maximum period is applied.
    • Deletion triggers. (1) a request to support@gbply.net, which we confirm once completed; (2) removing the business profile from GBPly, which deletes that profile's scheduled and sent review request records and its unsubscribe records; (3) deletion of the workspace or account.

    If you are an agency answering a client

    You can tell your client, accurately, that: their customer contact list stays inside your GBPly workspace and is visible only to people you have given access to; it is used only to send the review request campaigns you set up, plus the unsubscribe and delivery records that go with them; it is encrypted in transit and at rest; it is never sold, shared for other marketing, or used to train AI models; and it is deleted when you remove their business profile from GBPly, when you ask us to delete it, or when the workspace or account is closed. GBPly acts as a processor for that data on your instructions, and you remain the party responsible to your client for how the campaigns are run. The detail behind each of those points is published in our Privacy Policy (section 10) and Terms of Service, so you can link your client straight to the source rather than paraphrasing it.

    Payments

    Payments are processed by Paddle acting as merchant of record. Card details are entered on Paddle's own checkout and are never transmitted to or stored by GBPly. We receive only the subscription state and non-sensitive customer details needed to provision your plan.

    Our refund window, cancellation process and billing terms are set out in the Terms of Service.

    AI processing and subprocessors

    GBPly uses large language models to draft posts, review replies, question-and-answer content and profile recommendations. What is sent to the model is the context needed for that specific task — for example the business name, category, services, the review text being replied to, and your own instructions. AI generation is always initiated by an action you take.

    Google-connected business data is not used to train generalised AI models. AI output is a draft: you review and approve it before anything is published to Google.

    The main categories of subprocessor we rely on are:

    • Supabase — application database, authentication, file storage and server-side functions
    • Google — Business Profile APIs and Maps services, for the profiles you connect
    • Paddle — payments and billing as merchant of record
    • Large language model providers — AI drafting and summarisation
    • Email and SMS delivery providers — notifications, reports and review requests

    If you need a data processing agreement or a named, dated subprocessor list for your own compliance records, email support@gbply.net and we will provide one.

    Reporting a security problem

    We operate a published vulnerability disclosure policy with defined scope, response targets and safe-harbour protection for good-faith research. Report issues to support@gbply.net with the subject Security Disclosure.

    Full details: the Security Policy, our researcher acknowledgments, and our machine-readable security.txt (RFC 9116).

    Certifications and the platforms we build on

    GBPly does not operate its own data centres. The platforms that store, serve and bill for your data are independently audited, and you can verify each of them on the provider's own public compliance page:

    ProviderRoleIndependent assurance
    SupabaseDatabase, authentication, file storage and server-side functionsSOC 2 Type 2, ISO 27001, HIPAA-capable under a BAA, regular third-party penetration testing
    AWSUnderlying cloud regions our backend runs inSOC 1/2/3, ISO 27001, PCI DSS Level 1
    PaddlePayments and billing as merchant of recordPCI DSS Level 1 — card data is entered on Paddle and never reaches GBPly
    CloudflareCDN, TLS termination and DDoS protection in front of our servicesSOC 2 Type 2, ISO 27001

    These are the providers' certifications, not certifications of 3local Ltd. The controls we are responsible for in our own application layer — token encryption, workspace isolation, role checks and two-factor authentication — are described in the sections above.

    Our own certification status

    3local Ltd was incorporated in July 2025 and has not yet completed its own SOC 2 or ISO 27001 audit. In the meantime GBPly runs entirely on the independently certified infrastructure listed above, and card data is handled end to end by Paddle, which is PCI DSS Level 1. We have also not commissioned an independent third-party penetration test of the GBPly application itself; Supabase penetration-tests the platform layer we build on.

    We are an independent product by design: we are not a Google partner and claim no certification or endorsement from Google. We would rather state all of this plainly than display badges we have not earned, and we will update this page as each assurance is genuinely completed.

    If your procurement process needs more than this page provides, we will complete a security questionnaire and supply a data processing agreement and a named, dated subprocessor list on request — email support@gbply.net.