Please ensure Javascript is enabled for purposes of website accessibility
Home Digital Strategy Google Maps Business Data: What You Can Extract, Store, and Send

Google Maps Business Data: What You Can Extract, Store, and Send

image of local leads walking

Local prospecting comes down to one question: who, in this area, does this kind of work? BrightLocal’s 2026 Consumer Search Behavior research found 84% of consumers had searched for a local business in the past three months, and 52% started their most recent local search on Google, with 71% using Google Search at some point during it. The businesses you want to sell to maintain their own profiles there, sorted by category and location.

That is why every sales team eventually looks at Google Maps and thinks: list. The part almost nobody checks first is what Google’s terms permit you to take out of it, and what happens to that data once it sits in your CRM.

Key Takeaways

  • Google’s Maps Platform Terms of Service prohibit extracting Maps content for use outside the Services, in a clause titled “No Scraping.”
  • Place IDs may be stored indefinitely. Coordinates may be cached for 30 days. Everything else, including names, addresses, phone numbers and ratings, is not yours to keep.
  • The compliant pattern is to store IDs and re-request details, not to build a standing copy of Google’s database.
  • Ratings and review counts signal reputation and activity. They say nothing about size, budget or fit.
  • The rules that bite hardest apply after the list exists, at the point of calling or emailing.

What Google’s Terms Actually Say

The Maps Platform Terms of Service contain a clause headed “No Scraping.” It states that the customer will not export, extract, or otherwise scrape Google Maps Content for use outside the Services. There is no volume threshold and no exemption for public data. Loading Maps in a headless browser and parsing the result is the behavior described, and so is running a hosted extraction tool that does the same thing on your behalf. The tooling does not change the terms position.

Worth separating two things that get collapsed together. Breaching a platform’s contract is not the same as breaking a statute. US courts have generally held that collecting publicly visible data without bypassing an access control is not a computer-crime offense. What that protects you from is prosecution. What it does not protect you from is key revocation, IP blocking, account suspension, or a breach claim from the counterparty whose terms you accepted.

For a company that also depends on Google for organic visibility, the second column is the one that matters.

The Two Things You Are Allowed to Keep

Google’s Places API policies are specific about storage, and the permissions are narrower than most teams assume.

The place ID, which uniquely identifies a location, is exempt from the caching restrictions and can be stored indefinitely. Latitude and longitude values may be cached for up to 30 consecutive calendar days, after which they must be deleted, under the Maps Platform Service Specific Terms. Beyond those exceptions, you must not pre-fetch, cache or store Places API content.

Read that against a typical prospecting spreadsheet. Business name, formatted address, phone number, website, category, rating, review count: none of those fields are storable. Paying for API calls does not change this. The API is a query service, not a data licence.

The supported pattern is inverted from how most lead tools work. You keep the place ID as a stable reference, then re-request the details you need at the moment you need them. Your database holds pointers. Google holds the record.

That is less convenient. It is also the only version that survives an audit.

Where That Leaves Extraction Tools

A large market of extractors sells the convenience version: name, phone, website, address, category, rating, plus scraped emails and social links, delivered as a CSV. The output is genuinely useful. The mechanism is the one the terms name.

If your organisation has weighed that and accepted the contractual exposure, that is a business decision made with the facts in view. What should not happen is a team adopting one of these tools believing the data is public and therefore free of obligation. Public visibility and permitted reuse are different questions, and the scraped email addresses raise a third one: an address belonging to a named person at a business is personal data under UK GDPR and the EU GDPR regardless of where it was displayed.

The same gap between “technically available” and “actually permitted” shows up across grey-hat SEO tactics, which is why Google’s own spam documentation is usually a better guide than a vendor’s landing page.

Defining the Segment Before You Pull Anything

Whichever route you take, the query design does most of the work.

Location. The area you actually serve, cut down to neighbourhoods or postcodes where the market is dense. One “Chicago” query produces a list nobody can work. Six postcode queries produce six routes.

Category. Use Google’s category taxonomy, not your internal vocabulary. You may call them independent auto shops. Google calls them auto repair shops, and querying its term returns a cleaner set.

Write the definition down before you run it: category, area, expected result count. If the return is triple your estimate, the category is too broad and the segment is not a segment.

Which Fields Qualify a Lead, and Which Don’t

Not every field earns its column.

Phone number and website tell you how to reach them and whether there is anything to research first. Address groups them by area or route. Category sets the message. Ratings and review counts get over-read constantly. A 4.9 across eleven reviews and a 4.3 across nine hundred are not the same business, and neither number reveals revenue, headcount or budget. Rating is a reputation signal. Review count is an activity signal. That is the whole of what they carry, in the same way a view count measures playback volume rather than audience.

The field worth adding yourself is whether the website looks maintained. A site last touched in 2019 is a different conversation from one running a live booking widget. That judgment is not in any export.

The Rules That Apply After the List Exists

This is where the real exposure sits, and where most teams have no policy at all.

Calling

In the US, the FTC’s Telemarketing Sales Rule exempts most business-to-business solicitation calls, with a carve-out for the retail sale of nondurable office or cleaning supplies. The National Do Not Call Registry is a consumer tool and does not reach genuine business numbers. The complication is that sole proprietors routinely list a personal line as the business number, which pulls the call back under consumer protections. Screen rather than assume the exemption covers the whole file. Several states now run stricter regimes than the federal baseline, and consent-based rules still govern anything automated, which is a separate problem covered in this piece on real-time call routing and consent.

Emailing

In the UK, the ICO’s business-to-business guidance confirms that PECR permits direct marketing email to a corporate body without prior consent. Sole traders and some partnerships are treated as individual subscribers, so they can only be marketed by electronic mail with specific consent or where the soft opt-in applies. A freelance designer at their own domain is not a corporate subscriber. UK GDPR still applies on top of PECR wherever the address identifies a person, and the soft opt-in cannot be used for bought-in or broker-supplied lists, because it requires that you collected the details yourself.

Practical consequence: segment by subscriber type before you segment by industry. Limited companies and LLPs go one way. Sole traders and partnerships go another, and that second file needs a consent basis you can actually evidence.

Where Local Prospect Lists Go Wrong

The failures are predictable. Duplicates, where one business appears under two spellings and both get called. Chains, where a national brand’s twelve locations flood a file meant for independents. Closed businesses, which linger on maps longer than anyone expects. And over-pulling, where a team exports forty thousand rows nobody will ever work and then writes off the whole file as junk.

The fixes are dull and they hold. Deduplicate on phone number rather than name. Filter franchises unless franchises are the target. Hand-check twenty rows after every large pull. Pull small and often rather than once and enormously. Keep a suppression file and honour opt-outs across every list you own, not only the one they replied to.

TL;DR

  • Google’s Maps Platform terms prohibit extracting Maps content for use outside the Services.
  • Place IDs are storable indefinitely. Coordinates are cacheable for 30 days. Other fields are not storable at all.
  • Store IDs, re-request details. Do not build a standing copy of Google’s data.
  • Ratings and review counts are reputation and activity signals only.
  • Segment by subscriber type before outreach: corporate bodies and sole traders sit under different rules.

Conclusion

The question is not how to pull more rows faster. It is whether the pipeline you are building will still be standing in eighteen months, when a key gets revoked, a data protection query arrives, or a regulator asks where a phone number came from.

Design the query narrowly, keep only what the policies allow you to keep, and put the compliance decision at the top of the process rather than at the end. The list will be smaller. It will also be one you can defend.

Read Next

More on building outbound programs that hold up to scrutiny:

Frequently Asked Questions

Is it legal to scrape Google Maps business data?

Scraping publicly visible business listings is generally not a criminal matter under US law, since no access control is bypassed. It does breach Google’s Maps Platform Terms of Service, which prohibit extracting Maps content for use outside the Services. The consequences are contractual: key revocation, IP blocking, account suspension, or a breach claim.

Can I store Google Places API results in my CRM?

Only in part. Place IDs may be stored indefinitely and coordinates may be cached for up to 30 consecutive calendar days. Names, addresses, phone numbers, ratings, and review counts fall outside the caching exceptions. The supported approach is to store the place ID and re-request details when you need them.

Do ratings tell me which local leads are worth calling?

No. A rating is a rough reputation signal and a review count is a rough activity signal. Neither measures revenue, headcount, or budget. Qualify on category and location first, then use ratings to break ties.

Do I need consent to email a business I found on Google Maps?

It depends on the recipient type. Under UK PECR, marketing email to a corporate body does not require prior consent, but sole traders and most ordinary partnerships are individual subscribers and do require consent or a valid soft opt-in. UK GDPR applies on top wherever the address identifies a named person.

How often should a local prospect list be refreshed?

On the same cadence you work it. Businesses close, move, and change numbers, so a file left for six months will carry dead rows. Under the Places API model this is handled by re-requesting details against stored place IDs rather than refreshing a saved copy.

Subscribe

* indicates required