The short version
Wexnex connects to your Google Business Profile on your behalf using Google's official API. We only access data we need to run the service. We never sell your data. You can revoke our access at any time from your Google Account settings.
Who We Are
YAWA DIGITAL ("we", "our", "us") operates Wexnex, an AI-powered Google Business Profile management service from India. GSTIN: 23GKOPD3691A1ZC. Wexnex helps small businesses manage their online presence on Google Search and Google Maps.
YAWA DIGITAL, India. GSTIN: 23GKOPD3691A1ZC. For privacy matters, contact us at privacy@wexnex.com. For Google API review questions, contact api@wexnex.com.
This Privacy Policy applies to all users of Wexnex and explains what data we collect, how we use it, and what rights you have over it. By using Wexnex, you agree to the practices described in this policy.
Information We Collect
2.1 Information you give us directly
- Account details: Your name, email address, and password (stored as a one-way hash — we never store plain-text passwords)
- Business information: Business name, address, phone number, website URL, business category, and target city during onboarding
- Billing information: Plan selection and payment. Card details are processed directly by Razorpay — we do not store card numbers, CVVs, or bank credentials
- Support communications: Messages you send us via email or our contact form
- Content preferences: Your preferred post language, approval settings, and notification preferences
2.2 Data accessed from Google Business Profile via the Google API
When you connect your Google Business Profile (GBP) to Wexnex, we access the following data through Google's official Business Profile API, authorized by you through the Google OAuth 2.0 consent flow:
| Data type | What we access | Why |
|---|---|---|
| Profile information | Business name, address, phone, website, hours, description, categories, attributes, service area | To run the profile audit and apply optimizations |
| Posts | Existing posts on your GBP; we create and publish new posts | To maintain active posting schedule for SEO |
| Customer reviews | Review text, star rating, reviewer name, date | To generate and post AI reply responses on your behalf |
| Media | Existing photos; we upload new photos on your behalf | To maintain photo freshness for ranking |
| Insights / Analytics | Profile views, search queries, direction requests, call counts, website clicks | To generate your monthly performance report |
| OAuth tokens | Access token and refresh token | To maintain ongoing authorized access to act on your behalf |
We access your GBP data only to perform actions you have authorized. We do not access any other Google services, your Google Drive, Gmail, YouTube, or any other Google product.
2.3 Automatically collected technical data
- IP address, browser type, device type, and operating system
- Pages visited within the Wexnex dashboard, time spent, and actions taken
- Error logs and API call performance data (used for debugging)
- Session identifiers and authentication tokens
How We Use Your Information
We use your information only for the following purposes:
- To provide the Service: Reading your GBP profile to run audits, generate AI content, publish posts, post review replies, upload photos, and track your ranking
- To generate AI content: Passing your business name, category, city, and keyword targets to our AI models to create relevant, accurate posts and review replies
- To send reports and alerts: Monthly performance reports, rank change alerts, and new review notifications via email
- To process billing: Managing your subscription, charging your card through Razorpay, and issuing GST-compliant invoices
- To provide customer support: Responding to your questions and resolving issues
- To improve the Service: Analysing aggregated, anonymised usage patterns to improve our AI models and features — we never use individual GBP content for model training without explicit consent
- To comply with the law: Responding to lawful requests from courts, regulators, or government authorities as required under Indian law
We do not use your data for advertising. We do not serve ads to you, and we do not share your data with advertisers or ad networks under any circumstances.
How We Handle Google API Data
Our access to and use of data obtained through Google APIs is governed by Google's API Services User Data Policy, including the Limited Use requirements. We take this seriously.
Google Limited Use Compliance Declaration
Our use of Google API data strictly complies with the following requirements:
- We only request Google API scopes that are strictly necessary for the Wexnex service to function (business.manage)
- We use Google user data only to provide the Wexnex service to the specific user who authorized that access — not for any other users or purposes
- We do not use Google user data to serve advertisements of any kind
- We do not sell, transfer, or disclose Google user data to third parties, except as strictly necessary to provide the Wexnex service (e.g. passing business context to our AI provider to generate content)
- We do not use Google user data for any purpose that the authorizing user has not consented to
- We do not allow humans to read Google user data unless we have the user's explicit consent, or it is necessary for security purposes, or required by law
- We never use Google user data to develop, improve, or train generalised AI or ML models
- Customers may revoke our access at any time through myaccount.google.com/permissions — all automated actions stop immediately upon revocation
What happens to GBP data when you disconnect
If you disconnect your Google Business Profile from Wexnex (either by revoking access in your Google Account or by cancelling your subscription):
- Your Google OAuth access and refresh tokens are deleted immediately and permanently from our servers
- All automated actions (posting, review replies, photo uploads) stop immediately
- Your historical report data is retained for 90 days, after which it is permanently deleted
- Your Google Business Profile itself is unaffected — all previously published posts, photos, and review replies remain on Google's servers under your account
How We Share Your Information
We do not sell, rent, or trade your personal information or your GBP data to any third party. Ever.
We share data only in these limited, specific circumstances:
| Recipient | What we share | Why |
|---|---|---|
| Google LLC | Posts, review replies, photos, profile updates | To publish authorized actions to your GBP via Google's official API |
| Anthropic (Claude AI) | Business name, category, city, keywords, review text (anonymised) | To generate AI posts and review replies specific to your business |
| Razorpay | Email address, billing plan | To process subscription payments. Card data goes directly to Razorpay — we never see it |
| Resend (email) | Your email address and report content | To deliver your monthly reports and notifications |
| Hosting provider | All data (encrypted at rest) | Infrastructure to run the Service. Servers located in India |
| Legal / regulatory | Minimum required by law | When required by a valid court order or statutory authority under Indian law |
All third-party service providers we use are contractually required to use your data only for the specific purpose of providing their service to Wexnex, and not for any other purpose.
Security
We take security seriously. The following measures protect your data:
- Encryption in transit: All data between your browser and our servers is encrypted using TLS 1.2 or higher (HTTPS enforced site-wide)
- Encryption at rest: Google OAuth tokens are encrypted at rest using AES-256 encryption before being stored in our database
- Password hashing: Passwords are hashed using bcrypt with a salt — we cannot reverse or read your password
- Access control: Database access is restricted to authorized personnel only, with multi-factor authentication required
- Audit logging: All access to your GBP data through our systems is logged with timestamps and identifiers
- Token scoping: We request the minimum Google API permissions necessary and do not store tokens with broader access than needed
- Regular security reviews: We conduct periodic vulnerability assessments of our infrastructure and codebase
While we implement strong security measures, no system is completely invulnerable. In the event of a data breach that affects your personal data, we will notify you by email within 72 hours of becoming aware of it.
Data Retention
| Data type | Retention period |
|---|---|
| Account data (name, email) | Until account is deleted, then 90 days |
| Google OAuth tokens | Deleted immediately when account is disconnected or cancelled |
| GBP profile data (cached) | Refreshed every 24 hours; deleted within 90 days of account closure |
| AI-generated post content | Retained in your dashboard until account closure + 90 days |
| Review reply logs | Retained in your dashboard until account closure + 90 days |
| Billing and payment records | 7 years (as required by the Income Tax Act, 1961 and GST law) |
| Error logs and technical data | 30 days rolling |
You may request deletion of your account and all associated data at any time by emailing privacy@wexnex.com. Deletion is completed within 90 days of your request, except for billing records which must be retained for legal compliance.
Your Rights
You have the following rights over your data. To exercise any of them, email privacy@wexnex.com — we will respond within 30 days.
- Access: Request a full copy of all personal data we hold about you
- Correction: Request correction of any inaccurate or incomplete data
- Deletion: Request deletion of your account and all associated data (subject to legal retention requirements)
- Portability: Request an export of your data in JSON format
- Objection: Object to any processing of your data that you believe is not lawful
- Revoke Google access: Disconnect Wexnex from your Google Account at any time via myaccount.google.com/permissions. All automated actions stop immediately
- Opt out of emails: Unsubscribe from non-essential emails using the unsubscribe link in any email we send. Transactional emails (invoices, security alerts) cannot be opted out of while you have an active account
Cookies
We use only essential cookies that are necessary for the Service to function. We do not use advertising cookies, retargeting pixels, or third-party tracking.
| Cookie | Purpose | Duration |
|---|---|---|
| session_id | Maintains your login session | 7 days |
| csrf_token | Prevents cross-site request forgery attacks | Session |
| preferences | Remembers your language and dashboard layout preferences | 1 year |
You can block cookies in your browser settings. Essential cookies are required for the dashboard to function — blocking them may prevent you from logging in.
Children's Privacy
Wexnex is a business tool intended for users aged 18 and above. We do not knowingly collect personal information from anyone under 18 years of age. If you believe a minor has created an account, please contact us at privacy@wexnex.com and we will delete the account immediately.
Changes to This Policy
We may update this Privacy Policy from time to time. When we make material changes, we will:
- Send you a notification email at least 14 days before the changes take effect
- Display a prominent notice on your dashboard when you next log in
- Update the "Last updated" date at the top of this page
Your continued use of Wexnex after the effective date of changes constitutes acceptance of the updated Privacy Policy. If you do not agree, you may cancel your account before the changes take effect.
Contact Us
For any privacy questions, data requests, or concerns:
Privacy enquiries
Google API enquiries (for Google reviewers)
Registered address
YAWA DIGITAL, India. GSTIN: 23GKOPD3691A1ZC. Email: support@wexnex.com
Response time
Within 30 days of receiving your request