Legal

Information Security Policy

Wave Business Solutions LLC  ·  Effective Date: July 22, 2026  ·  Missouri, USA
This policy describes how Wave Business Solutions LLC protects the data entrusted to us by our clients and their customers. It is intended for clients, integration partners, and any organization evaluating our platform for use with their data.

1. Purpose and Scope

Wave Business Solutions LLC ("Wave Growth Engine," "we," "us," or "our") is committed to protecting the confidentiality, integrity, and availability of all data processed through our reputation management platform. This Information Security Policy applies to all systems, personnel, and third-party service providers involved in operating the Wave Growth Engine platform.

The data within scope includes:

  • Client account information (business owners and their employees)
  • Consumer contact data submitted by clients (names, email addresses, phone numbers)
  • OAuth authorization tokens for Google Business Profile and GoHighLevel
  • Google Business Profile review data retrieved on behalf of clients
  • Platform usage and log data

2. Security Controls

Encryption in Transit

All data transmitted between users and our platform is encrypted using TLS 1.2 or higher. We enforce HTTPS across all endpoints and do not accept unencrypted connections.

Credential Security

OAuth tokens and API credentials are stored in encrypted database fields. We do not log or expose access tokens in plaintext. Tokens are scoped to the minimum permissions required.

Access Controls

Access to production systems and data is limited to authorized personnel on a need-to-know basis. Client data is logically isolated by account — each client can only access their own records.

Authentication

Client accounts are protected by password authentication with password reset via verified email. OAuth flows use industry-standard authorization code grants for third-party integrations.

Infrastructure Security

The platform is hosted on Bubble.io, which maintains its own SOC 2-aligned security controls, physical data center security, and infrastructure monitoring. Data is stored in the United States.

Third-Party Vetting

We use only established, reputable third-party providers with published security practices. These include Google LLC, GoHighLevel (HighLevel, Inc.), Bubble.io, Stripe, and Twilio/SendGrid.

3. Token and Credential Management

The Wave Growth Engine platform manages OAuth tokens on behalf of our clients for two third-party integrations: Google Business Profile and GoHighLevel. Our practices for managing these credentials include:

  • Tokens are stored in encrypted database fields and are never exposed in URLs, logs, or client-facing interfaces
  • Access tokens are refreshed automatically using refresh token grants; expired tokens are replaced without exposing credentials to users
  • Each client's tokens are associated only with their account and cannot be accessed by other clients
  • Clients may revoke our access at any time by disconnecting their Google or GoHighLevel account through the Settings page, which removes stored tokens
  • API calls using client tokens are made server-side where possible and are scoped to the minimum permissions required to operate the platform

4. Data Minimization and Retention

We collect and retain only the data necessary to provide our services:

  • Consumer contact records are retained only while the client account is active
  • OAuth tokens are retained only as long as the associated integration is active
  • Log and usage data is retained for a reasonable period for security and diagnostic purposes
  • Upon account termination, client data is deleted within 90 days unless retention is required by law

5. Subprocessors and Third-Party Security

We rely on the following subprocessors to deliver our service. Each is selected based on their security posture and operates under data processing agreements or equivalent contractual protections:

  • Bubble.io (Bubble Group, Inc.) — Application hosting and database. Bubble maintains SOC 2 Type II certification and publishes its security practices at bubble.io/security.
  • Google LLC — Google Business Profile API and OAuth. Google maintains ISO 27001 certification and extensive security documentation.
  • GoHighLevel (HighLevel, Inc.) — CRM and messaging infrastructure. HighLevel publishes security and compliance information at gohighlevel.com.
  • Stripe, Inc. — Payment processing. Stripe is PCI DSS Level 1 certified. We do not store payment card data.
  • Twilio Inc. / SendGrid — Email delivery. Twilio maintains ISO 27001 certification.

6. Vulnerability Management

We take a proactive approach to identifying and addressing security vulnerabilities:

  • Platform dependencies and integrations are reviewed periodically for known vulnerabilities
  • We monitor security advisories from our key subprocessors
  • When vulnerabilities are identified, we prioritize remediation based on risk severity
  • We do not store sensitive data (credentials, tokens, PII) in client-side code, browser storage, or URL parameters

If you discover a potential security vulnerability in our platform, please report it responsibly to [email protected]. We will acknowledge your report within 3 business days and provide updates as we investigate.

7. Incident Response

In the event of a confirmed security incident affecting client or consumer data, Wave Growth Engine will:

  • Contain and assess the incident as quickly as possible
  • Notify affected clients within 72 hours of confirming a breach that poses a risk to their data
  • Provide a clear description of what data was involved, the likely cause, and the steps we are taking
  • Cooperate with clients to fulfill any legal notification obligations they may have to their own customers or regulators
  • Conduct a post-incident review and implement corrective measures

8. Employee and Contractor Access

Access to client data by Wave Growth Engine personnel is strictly limited:

  • Access to production data is granted only on a need-to-know basis for the purpose of supporting, debugging, or improving the platform
  • Any personnel with access to sensitive systems are subject to confidentiality obligations
  • We do not access client data for marketing, analysis, or any purpose beyond operating and improving the platform

9. Physical Security

Wave Growth Engine does not operate its own physical data centers. All data is stored with Bubble.io, whose infrastructure is hosted in secure, access-controlled facilities. Physical security controls are maintained by our hosting providers and are not within our direct control.

10. Compliance

Wave Growth Engine operates in compliance with applicable data protection laws, including:

  • Missouri state privacy and consumer protection laws
  • The California Consumer Privacy Act (CCPA) to the extent applicable
  • The Telephone Consumer Protection Act (TCPA) — our clients are responsible for their own compliance with TCPA when using our messaging features
  • Google API Services User Data Policy, including the Limited Use requirements

11. Policy Review

This Information Security Policy is reviewed at least annually and updated as needed to reflect changes in our platform, legal requirements, or the threat landscape. Material updates will be posted to this page with a revised effective date.

12. Contact

Wave Business Solutions LLC — Security Contact Security concerns: [email protected]
General inquiries: [email protected]
Website: wavegrowthengine.com
State of organization: Missouri, USA
© 2026 Wave Business Solutions LLC. All rights reserved.  ·  Privacy Policy  ·  Terms of Service