Legal
Privacy Policy
This policy explains how Ezi GBP Access collects, uses, stores, and shares information when agencies, team members, and their clients use the service.
Effective July 2, 2026
1. Who we are and when this policy applies
Ezi GBP Access is operated by EZI BUSINESS TECHNOLOGIES LLC, a Wyoming limited liability company (“Ezi,” “we,” “us,” or “our”). We provide software that helps agencies request and manage access to client business platforms. This policy applies to our website, authenticated application, public request links, and related support communications.
An agency using Ezi may independently decide why it requests access to a client's information. Agencies are responsible for their own instructions, disclosures, and lawful use of information they receive through Ezi.
2. Information we collect
Depending on how you use Ezi, we collect the following categories of information:
- Account and workspace information: email address, agency name, contact email, workspace role, team invitations, public link slugs, branding, and request-template settings.
- Google account information: Google email address, OAuth authorization details, encrypted access or refresh credentials, and connection timestamps.
- Google integration information: Business Profile account and location identifiers; Tag Manager account and container identifiers; Analytics account and property identifiers; Google Ads manager and advertising account identifiers; resource names, selected resources, requested access levels, grant or invitation outcomes, and related status information.
- Meta account and integration information: Meta user and Business Portfolio identifiers, display names, encrypted OAuth credentials, advertising account identifiers, selected accounts, requested access levels, partner-access outcomes, and connection status.
- Request and activity information: access requests, integration selections, connection history, operational results, audit events, and error information.
- Subscription information: subscription status, billing period, Stripe customer and subscription identifiers, and payment events. Payment-card and bank-account details are collected and processed by Stripe, not stored by Ezi.
- Technical information: security and rate-limit identifiers, browser storage used for authentication or preferences, and service logs needed to operate, secure, and troubleshoot Ezi.
- First-party usage analytics: a random browser identifier, page path, referring website hostname, campaign parameters, and product actions such as viewing or completing the interactive demo. These events do not contain email addresses, raw IP addresses, full referring URLs, OAuth data, or provider credentials.
We do not receive or store your Google or Meta password.
3. How we use information
We use information to:
- authenticate users and operate agency workspaces;
- connect authorized Google accounts and discover eligible Business Profile locations, Tag Manager containers, Analytics properties, and Google Ads accounts;
- connect authorized Meta accounts, discover eligible owned advertising accounts, and share selected accounts with the agency's configured Business Portfolio;
- let clients select resources and grant or invite the agency to the access level shown in the request;
- create and track request links, integrations, status, and activity history;
- process subscriptions, send transactional messages, and provide support;
- prevent abuse, enforce usage limits, maintain security, and diagnose failures; and
- understand the product funnel and improve onboarding and site usability;
- comply with law and enforce our agreements.
Where applicable law requires a legal basis, we process information as needed to provide the service under our agreement, based on legitimate interests such as security and service improvement, with consent where requested, or to comply with legal obligations.
4. Google and Meta provider data
Ezi requests only the Google permissions required by the integrations included in a request. These may include Business Profile management, Tag Manager read and user management, Google Analytics read and user management, and Google Ads account management permissions, together with basic identity permissions. We use Google user data solely to provide the visible connection, resource-selection, and access-request features described in the product.
We do not sell Google user data, use it for advertising, or transfer it to data brokers. Ezi's use and transfer of information received from Google APIs complies with the Google API Services User Data Policy, including its Limited Use requirements.
Agency Google credentials are encrypted at rest and used server-side. Client credentials are used to complete the access request initiated by the client. Users can disconnect an agency Google account in Ezi and can also revoke Ezi's permission through their Google Account connections.
For Meta Ads requests, Ezi uses the permissions approved by the user to identify accessible Business Portfolios, list eligible owned advertising accounts, and request the selected partner access. Meta credentials are encrypted at rest and used server-side only for these requested workflows. Users can revoke access through their Meta Business Integration settings.
5. How we share information
We share information only as needed for the following purposes:
- Agencies and clients: the requesting agency receives the client identity, selected provider resource details, and request status needed to provide its services. Clients see the identity and request configuration of the agency whose link they opened.
- Service providers: Supabase for database, authentication, and storage; Google for identity, Business Profile, Tag Manager, Analytics, and Ads operations; Meta for identity, Business Portfolio, and advertising account operations; Stripe for billing; Resend for transactional email; and Lovable and Cloudflare for application hosting and delivery.
- Legal and safety: when reasonably necessary to comply with law, protect users, investigate abuse, or secure the service.
- Business changes: as part of a merger, financing, acquisition, reorganization, or sale of assets, subject to applicable law and the restrictions governing Google user data.
We do not sell personal information.
6. Retention and deletion
We retain information for as long as reasonably necessary to provide Ezi, maintain security and audit history, resolve disputes, and meet legal obligations. Retention periods vary by record type. Operational diagnostics have defined cleanup boundaries; first-party usage analytics are eligible for deletion after 180 days; billing and audit records may be retained longer where required for fraud prevention, accounting, or legal compliance.
Disconnecting an agency Google or Meta account removes its stored provider credentials from the active connection. You may request deletion of your account or personal information by emailing privacy@ezi-business.com. We may need to verify your identity and may retain limited records when legally required or necessary to protect the service. Information may remain temporarily in secured backups until those backups cycle out.
7. Security
We use administrative, technical, and organizational safeguards designed to protect information. These include encryption in transit, encryption of stored provider credentials, server-side secret handling, access controls, and activity logging. No method of storage or transmission is completely secure, so we cannot guarantee absolute security.
8. Your choices and privacy rights
You can update workspace information in Ezi, disconnect Google or Meta, revoke provider permission, and cancel your subscription through the available account controls. Depending on where you live, you may also have rights to access, correct, delete, restrict, object to, or obtain a copy of your personal information.
To make a privacy request, email privacy@ezi-business.com. You may also have the right to complain to your local privacy or data-protection authority.
9. International data transfers
Ezi and its service providers may process information in the United States and other countries. Where required, we rely on appropriate safeguards for international transfers of personal information.
10. Children
Ezi is a business service and is not directed to children under 18. We do not knowingly collect personal information from children.
11. Changes and contact
We may update this policy as Ezi changes. We will post the revised policy here, update its effective date, and provide additional notice when a material change requires it.
Questions or privacy requests can be sent to privacy@ezi-business.com, or by mail to EZI BUSINESS TECHNOLOGIES LLC, 5830 E 2nd St, Ste 7000 #34733, Casper, WY 82609, United States.