EXIT.MARKETING MANAGERMAP · OPERATE · GROW Official home →
GOOGLE BUSINESS PROFILE API · REVIEWER INFORMATION

Clear purpose.
Human-controlled operations.

This public page explains the planned Google Business Profile API use of EXIT Marketing Manager, an internal, client-authorized marketing operations tool operated by 주식회사 이엑스잇 (EXIT).

Application status: Three earlier GBP API Basic Access applications were not approved; the application submitted on August 3, 2026 was rejected on August 7 because Google could not confirm the requestor email's Owner or Manager eligibility. On August 10, 2026, EXIT verified the currently active Daeboreum Cafe & Ground profile, the private requestor account's direct Manager role, and that same account's access to production project 730388533513, then submitted a fourth application. Google's submission confirmation opened a support case and stated an estimated review period of 7–10 business days. The application is currently under review, and GBP_API_ACCESS_APPROVED remains false until a decision is confirmed. Until GBP Basic Access is approved, the product does not perform automated collection or publishing through the Google Business Profile API.

01

Purpose and requested access

After approval, EXIT plans to request the minimum Google Business Profile scope needed for the authorized operating workflow: https://www.googleapis.com/auth/business.manage. The purpose is to identify locations that the connected Google account can manage, retrieve reviews and supported performance data, prepare reply or profile-update drafts, and publish a review reply only after a person approves that exact target and final text. Profile updates remain proposals handled manually in Google's official interface; the current product does not send profile updates through the API.

Google Ads is a separate product integration and is not requested or accessed through the Google Business Profile scope.

02

Who uses the product

The product is used by EXIT personnel for clients that have authorized the relevant work in writing. The client remains the owner of its Business Profile. EXIT uses a Manager role only for the locations, tasks, and period that the client has authorized. EXIT does not ask for, collect, or share a client's Google password.

03

Human approval is required

AI can create a draft or analysis, but it cannot independently publish a review reply, edit a profile, or change another external record. For the currently implemented external action, a person reviews the target location and final text, then gives a specific approval before that exact review reply is sent. Profile-change proposals are handled manually in Google's official interface and are not sent through the API. The system records the responsible actor and approval event for operational accountability.

04

Data handling and security

EXIT uses Firebase Authentication, tenant-level access controls, server-side ownership checks, encrypted OAuth token storage, and transport encryption. Google API data is used only to provide the authorized operational features. It is not sold, used for advertising targeting, made available to data brokers, or used to train a general-purpose AI model.

Source Google review and performance data is treated as temporary operational data and is retained for no more than 30 days before refresh or deletion. See the Privacy Notice and Security overview for details.

05

Revocation and offboarding

A client can revoke access at any time through the product or Google account controls. Tenant disconnect immediately deletes that client’s encrypted token, location mappings, temporary Google source data, and derived caches. It does not revoke an account-wide grant that may still support another authorized client; the user can separately revoke EXIT’s account-wide grant in Google Account security controls. Verified deletion or offboarding requests are normally completed within seven business days.

06

Eligibility is evidence-gated

Google publicly requires the applicant to manage a Business Profile that has been verified and active for 60+ days. EXIT does not mark this prerequisite complete from an unverified date or a manually selected status alone. The qualifying profile, verification evidence, current status, and the application email’s current Owner or Manager role must be documented. EXIT separately verifies the private requestor's direct profile role and the deliverability of its company-domain corporate and support contacts.

07

Application identity and support mailbox

all@exit.ai.kr is the company-domain Google Account used for EXIT's Agency Organization, Cloud administration and OAuth user support; it is not the current Basic Access requestor. The fourth application was submitted on August 10, 2026 by a separate private Google Account shown directly as a Manager in Daeboreum Cafe & Ground's People and access and verified against the same production project. Its address and the support-case identifier are retained only in owner-only evidence. ceo@exit.ai.kr is the receiving mailbox, public support address and OAuth developer contact.

08

Sanitized product walkthrough

The public walkthrough uses synthetic content and makes no Google API request. It demonstrates tenant context, AI-draft status, specific human approval, the pre-approval server guard and revocation without exposing a client account or token.

09

Independent service disclosure

Google Business Profile is provided by Google. EXIT is an independent software and marketing-operations provider; it is not affiliated with or endorsed by Google. EXIT does not guarantee a Google Search or Google Maps ranking, visibility, or business result.