Service HubFor Contractors

Data and access

Privacy policy

Last updated: September 11, 2026

This policy explains how Service Hub for Contractors, operated by Amir Kheder, handles information through its Google Business Profile connection. Questions and requests can be sent to amir@amirkheder.com.

Information we access

With your Google authorization, we receive your verified email address and Google account identifier to confirm the approved account. For the specifically connected business, Service Hub can read account and location information, business profile details, customer reviews and existing replies, reviewer information made available by Google, and available Business Profile performance metrics.

Google's Business Profile permission also permits changes to listings. Our integration restricts its business-data API requests to reads; it does not edit listings, publish replies, or request Gmail, Calendar, Contacts, Google Ads, or Google Analytics access through this connection.

Purpose and use

We use this information to verify the connection and provide business reporting, review monitoring, and performance analysis within authorized Service Hub workflows. This public connection site does not display your business data or expose a data API.

Credentials and security

Google passwords are handled by Google and are not received by Service Hub. The OAuth client secret and user refresh credentials are stored in separate Google Cloud Secret Manager resources. The operational connection registry contains account bindings, connection health, and secret resource references, not secret payloads. Short-lived access tokens are used in server memory and are not returned to your browser.

Temporary browser cookies and one-use authorization state protect the sign-in flow. The callback accepts Google's temporary authorization response in a form POST body and displays a minimal confirmation without credentials. Service Hub does not use advertising trackers on these pages.

Retention

The integration does not persist copies of business profiles, review text, or performance responses in its connection registry. Information returned to an authorized connected tool or conversation is subject to that destination's retention settings.

Connection metadata and encrypted refresh credentials remain while the connection is maintained, until an operator completes a removal request. Credential rotation can leave older encrypted secret versions; removing the connection from Google alone does not erase those stored versions. Service Hub uses an operator-controlled deletion process rather than an automatic credential-deletion schedule.

Authorization transactions expire after ten minutes. On first use, their verifier and nonce are removed from the stored record. Expired transactions and short-lived rate-limit counters are scheduled for database TTL cleanup, which is asynchronous. The temporary authorization cookie expires after ten minutes; the outcome cookie expires after one minute.

Sharing

Google processes sign-in and Business Profile API requests. Google Cloud hosts the services and credential storage. Requested business information may be sent through Service Hub's private MCP connection to the authorized OpenAI tools or conversations that requested it. Access is limited to the configured business and authorized workflows; this integration does not sell Google user data or send it to advertising systems.

Revocation and deletion

You can revoke Service Hub's Google access in your Google Account connections. To request disconnection and removal of stored connection metadata and credential versions, contact amir@amirkheder.com from the authorized account. We verify the request before an operator revokes credentials and removes stored records. Information already delivered to a connected conversation must be managed in that service as well.

If access expires or is revoked, Service Hub requires a new Google authorization to reconnect. A reconnection does not authorize a different account or business.