LocalSync by August SEO

Privacy and data handling

What we hold, why, and for how long.

This page covers two things: this website, and the LocalSync system that manages business listings for clients who have authorized it.

Effective 2026-09-15

Who we are

LocalSync is operated by August SEO, LLC, a search marketing agency in Spokane, Washington, United States. Questions about this page, or requests about your data, go to hello@augustseo.net. A person reads that inbox.

This website

The site is static. It has no accounts, no forms, no analytics, and sets no cookies. The web server keeps ordinary access logs (address, user agent, page, time) for operational and security purposes and discards them on a short rotation. The light or dark theme choice is stored in your browser's local storage and never leaves your device.

The LocalSync system

LocalSync keeps one canonical record per business location for clients who have authorized listing management in writing. That record is business information: the legal and trading name, address, phone numbers, website, hours, categories, attributes, descriptions, and photos. It is the information a business publishes about itself so customers can find it.

The system does not collect information about consumers. It does not read, store, or respond to reviews, and it does not gather profile data about the people who interact with a listing. Scope is listings only, in the United States.

To do its job the system holds delegated access to the places a listing appears: a manager role a client granted us, an API token a platform issued, or a login the client created and can revoke. Those credentials belong to the client. They are encrypted at rest with a key held in the operating system keychain of hardware we control, are never written to a repository or an environment file, and are destroyed when the engagement ends.

Data received from platform APIs

Where a platform such as Google, Meta, Apple, or Microsoft provides an API, LocalSync uses it for one purpose: to read the current state of a listing the client has authorized us to manage, compare it against the canonical record, and update the fields that differ. Every write is preceded by a diff a person can review and followed by a separate read to confirm the result.

Information received through a platform API is used only to provide that service to the client whose listing it concerns. It is not sold. It is not used for advertising. It is not used to build profiles, to train models, or for any purpose unrelated to keeping that listing accurate. It is not transferred to anyone else except the platform it came from, on the client's instruction, or where the law requires it. A person reads it only with the client's consent, for security or abuse investigation, or to comply with the law.

LocalSync's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

Retention

Every change the system makes produces evidence: the payload it sent, the response or screenshot it received, the timestamp, and the outcome. That change log is retained for 24 months so a client can see what was done on their behalf and when. Where a platform's API terms set a shorter limit on how long its own content may be cached, that limit governs the content the platform supplied; the system keeps the record of what it sent and what happened, not a running copy of the platform's data.

Credentials and tokens are removed at offboarding. Client records are soft-deleted on request and purged after the evidence window closes.

Security

The system runs on hardware we own, not on a shared cloud tenant. Credentials are encrypted at rest. No client data or credential material is sent to a third-party error reporting or analytics service. Evidence artifacts are scrubbed of session tokens before storage, and screenshots that would show a credential are cropped or discarded.

Deletion and your rights

A client can ask at any time what we hold about their locations, ask for it to be corrected, or ask for it to be deleted. Email hello@augustseo.net from an address associated with the engagement. We remove stored credentials immediately and complete the deletion within 30 days, and we confirm when it is done. Revoking our access on the platform side, for example by removing the manager role or the app permission, has the same effect on our ability to touch that listing and can be done without contacting us.

Changes

When this page changes, the effective date at the top changes with it. Material changes to how client data is handled are communicated to affected clients directly.