Data practices

Privacy Policy

How Chorus Local collects, uses, shares, protects, retains, and deletes personal information and workspace data.

Last updated May 6, 2026

Scope

This Privacy Policy explains how Chorus Local handles personal information in the service, public pages, signup flows, support conversations, billing flows, integrations, and product analytics.

Chorus Local is operated by Shreekaram Global LLC. Shreekaram Global LLC is responsible for the privacy practices described in this policy unless a customer agreement says otherwise.

For customer workspace content, the customer is generally responsible for deciding what information is submitted to the service. Chorus Local processes that information to provide the product, maintain security, support customers, and meet legal obligations.

Information we collect

We collect information provided directly by users, information generated through use of the service, information from connected integrations, and information from service providers that help run the product.

  • Account information such as name, email address, authentication events, role, and workspace membership.
  • Business information such as business name, location, website, phone, brand profile, voice guidance, compliance notes, integrations, and workspace settings.
  • Operational content such as reviews, reply drafts, content drafts, approvals, edits, audit events, media, summaries, and usage ledgers.
  • Billing information such as selected plan, trial status, Stripe customer identifiers, subscription identifiers, invoices, and payment status. Chorus Local does not store full card numbers.
  • Technical information such as IP address in security logs, device and browser data, session events, logs, security events, diagnostics, and cookie or similar technology identifiers. Product analytics do not store raw IP addresses; they may store rough IP-derived location and a daily rotating HMAC visitor fingerprint when trusted proxy headers are configured.
  • Feedback information such as category, message, optional email, page path, approximate request context, spam signals, and any signed-in user or workspace context attached server-side.

Connected integrations

When a workspace connects Google, Facebook, Instagram, or another supported provider, Chorus Local may receive OAuth authorization codes, access tokens, refresh tokens where granted, account identifiers, Page or business account identifiers, profile names, location identifiers, review or engagement data, media references, publishing eligibility information, and provider error details needed to operate the connected workflow.

For Google Business Profile, Chorus Local may use the Google Business Profile API and permissions such as business profile management access to sync authorized account, location, review, reply, and profile workflow data for the connected workspace. Chorus Local uses this data for owner-visible product features such as review workflows, draft generation, approval trails, integration health, support, security, and compliance with user instructions.

For Meta integrations, Chorus Local uses the permissions granted through Facebook Login and the Instagram Graph API to connect eligible Facebook Pages and Instagram business accounts. The service uses those permissions for owner-approved workflows such as account connection, publishing handoffs, Page or account status checks, and Meta-required deauthorization or data deletion callbacks, subject to Meta's platform rules and the access level granted to the app.

Disconnecting an integration stops future provider actions through Chorus Local, but it may not delete historical drafts, approvals, audit logs, billing records, or content already published to a third-party platform.

How we use information

We use information to operate Chorus Local, personalize workspace workflows, generate and validate drafts, synchronize integrations, manage billing, secure the service, provide support, improve reliability, and comply with legal obligations.

We may use aggregated or de-identified information to understand product usage, improve quality, evaluate AI performance, and operate the business. We do not sell personal information, use customer workspace content for advertising profiles, or use Google or Meta integration data for cross-site advertising or retargeting.

AI processing

AI-assisted workflows may process reviews, business profile details, approved edits, prior drafts, compliance notes, and related workspace context to produce drafts, summaries, safety checks, and recommendations.

Where AI providers are used, Chorus Local sends only the information reasonably needed for the requested workflow and expects providers to process that information under contractual service terms. Chorus Local does not use Google API user data, Meta integration data, or customer workspace content to train advertising systems or build unrelated profiles. Customers should not submit unnecessary sensitive personal information into prompts or drafts.

How we share information

We share information with service providers and subprocessors that help provide hosting, authentication, email, billing, analytics, AI processing, media storage, support, security, and integration workflows.

We may also share information with connected third-party platforms at your direction, including Google and Meta services when an authorized workspace user starts OAuth, approves content, requests a sync, or asks the service to publish through a supported official flow. Information is shared with workspace members based on their roles, when required by law, to protect rights and security, or as part of a merger, financing, acquisition, or sale of assets.

Google API Limited Use

Chorus Local's use and transfer of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

Google Business Profile data is used only to provide and improve user-facing features that the connected workspace requests, maintain security, troubleshoot integration issues, comply with law and platform rules, and support approved product operations. We do not sell Google API user data, use it for advertising, or transfer it except as needed to provide the service through subprocessors, comply with law, protect security, or follow the customer's instructions.

Workspace owners can disconnect Google integrations in the product, revoke access through Google account controls, or request deletion through https://choruslocal.com/data-deletion or legal@choruslocal.com.

Cookies and analytics

We use essential cookies or similar technologies for authentication, security, routing, preferences, and product operation. We use first-party product analytics to understand page views, navigation, traffic sources, rough geography, device mix, authenticated funnel drop-off, and product feedback.

We may store limited first-party browser state to remember that a feedback prompt was shown, dismissed, or submitted, so the product does not repeatedly ask for feedback during the same visit or cooldown period.

Anonymous visitors are limited to aggregate page/navigation/source/geography signals. Detailed click, form, workflow, and funnel analytics are retained only for authenticated sessions and workspaces. We do not use browser geolocation permission, advertising cookies, cross-site tracking, session replay, keystroke logging, screenshots, or page form-field capture for product analytics.

More detail is available in the Cookie Policy.

Retention and deletion

We retain information for as long as needed to provide the service, maintain auditability, comply with legal and tax obligations, resolve disputes, enforce agreements, and protect security.

Default product analytics retention is 180 days for raw events and 25 months for aggregated usage summaries. Feedback is retained for 24 months unless it becomes part of an active support, security, or product record. Rate-limit buckets are short-lived operational records retained for up to 48 hours.

Workspace content may be deleted or exported according to product controls, written agreement, or support request, subject to backups, immutable approval and publish audit logs, billing records, legal holds, and security records that may need to be retained for a limited period. Deletion instructions are available at https://choruslocal.com/data-deletion. Data already sent to connected platforms such as Facebook, Instagram, Google, or Stripe must also be managed through those providers' tools and policies.

Your choices and rights

Depending on where you live, you may have rights to access, correct, delete, export, restrict, or object to certain processing of personal information. You may also have rights to opt out of certain disclosures or marketing communications.

To exercise privacy rights, contact legal@choruslocal.com. We may need to verify your identity and workspace authority before acting on a request.

Security

Chorus Local uses administrative, technical, and organizational safeguards designed to protect information, including role-based workspace access, audit logging, encrypted transport, secret management, least-privilege access, and monitored operational processes.

No system is perfectly secure. Customers are responsible for maintaining strong account security, limiting workspace roles, and promptly reporting suspected unauthorized access.

International transfers

Information may be processed in the United States and other countries where Chorus Local or its providers operate. Where required, Chorus Local uses appropriate contractual or legal mechanisms for cross-border processing.

Children

Chorus Local is a business service and is not intended for children under 13 or the minimum age required by applicable law. We do not knowingly collect children's personal information.

Contact

Questions about privacy or data protection can be sent to legal@choruslocal.com. Shreekaram Global LLC operates Chorus Local.