A regional reputation lead opens Monday morning to six new one-star reviews across four branches. Two names do not match the customer system. One review describes a service the company does not offer. Another may be a real customer writing under a spouse's Google Account.
The worst response is to treat all six reviews the same.
A business cannot delete a Google review from its own profile. Google says a merchant can report a review, but only content that violates policy is eligible for removal. If Google finds no violation, the merchant may have one appeal. Extortion uses a separate reporting path.
For a multi-location service brand, the work is a location-level incident process: classify the review, preserve the evidence, choose the correct Google path, answer future customers without exposing private details, and track the public result.
Important
A low rating is not a policy violation. Build the case around Google's rules and the facts of the affected location, not around how damaging or unfair the review feels.

Start with the policy, not the star rating
Google's review-reporting guidance says it does not remove a review just because a business disagrees with it. A real customer can be angry, mistaken, anonymous to the front-office team, or writing from a different account. None of those facts alone proves fake engagement.
The first review should separate four different cases:
- Real customer dispute: the business can match the person, job, appointment, property, invoice, or contact history, even if the facts are contested
- Possible fake engagement: the contribution appears not to reflect a genuine experience, was posted through coordinated accounts, was paid for, or comes from a conflict of interest named in Google's policy
- Another content violation: the review may contain harassment, personal information, profanity, off-topic material, impersonation, or another prohibited form of content
- Extortion: negative reviews arrive with a demand for money, goods, services, or another benefit in exchange for removal
Google's Maps content policy is the classification source. The dispatch record, booking system, call recording, and branch memory help test what happened, but the report still needs to identify the policy that the contribution appears to violate.
For an HVAC branch, "we cannot find this name" is not enough. The customer may be a tenant while the landlord paid. For a med spa, the appointment may sit under a partner's name. For a restoration company, an insurer or property manager may be the account holder. Check the location, service date, phone, address, technician, and related complaint before labeling the review fake.
Build one incident record before anyone reports
Every suspicious review should have one record owned by the central reputation or operations team. Capture the Business Profile name and location, review URL, reviewer-profile URL, rating, text, posting time, screenshot, service-record check, communications, suspected policy category, reporting owner, current Google status, and next permitted action.
That record prevents a branch manager, agency, and corporate marketer from reporting the same review with different explanations. It also preserves the original review if the text changes or disappears.
Access matters here. The person using Google's Reviews Management Tool must be signed into an account associated with the relevant Business Profile. The multi-location Business Profile access guide explains how owners, managers, business groups, and agency access should be organized before an incident.
For a 50-location plumbing platform, central marketing can own policy classification and Google status. The branch manager can own the customer-record check. Customer experience can own the public response. Legal or security can join when a threat, personal information, or extortion appears. One incident owner closes the loop.
If the portfolio still depends on inbox searches and branch memory to reconstruct review incidents, book a Cheers demo to map the location-level reputation workflow and the public visibility gaps around it.

Use the correct Google path for each case
For a review that appears to violate policy, Google directs merchants to the Reviews Management Tool. Confirm the Google Account, select the business, choose "Report a new review for removal," select the reason, and submit. Google says evaluation typically takes several days and lets the merchant return to the tool to check the status.
The status is part of the incident record. "Decision pending" means Google has not finished. "Report reviewed - no policy violation" means the report was denied and may be eligible for one appeal. "Escalated - check your email for updates" means the appeal is in its final review path.
Google says an eligible one-time appeal can include up to 10 reviews. Treat that limit as an appeal control, not as permission to bundle unrelated incidents. The evidence for each review should still map to its own location, facts, and policy category.
Google does not document a portfolio-wide review-removal button. The tool asks the merchant to select a business, so the scalable layer is the brand's own incident ledger and ownership model. Record what was submitted and wait for the actual status instead of having several users create duplicate reports.
If the same reviewer profile posts violating content across several branches, report the individual reviews and consider Google's separate user-profile reporting process. A reviewer-level report does not replace the review-specific incident records.
Use the extortion path when payment is part of the threat
Google has a dedicated negative-review extortion report. It describes scams in which a business receives a burst of low ratings and then a demand for money, goods, or services in exchange for removal.
Google says not to engage with or pay the malicious person. Payment does not guarantee removal and may encourage another attempt. Preserve every email, text, phone message, account, review URL, screenshot, timestamp, and payment demand. Submit the specialized report with all related communication.
Do not turn an extortion incident into a public argument under each review. The evidence belongs in the report and the internal incident record. If the messages include credible threats, private information, or another legal concern, route them to the company's counsel, security lead, insurer, or law enforcement as appropriate. This article is operational guidance, not legal advice.
Pro Tip
A review attack can span several locations while the demand arrives in one inbox. Connect the communication to every affected profile before the team starts reporting reviews independently.
Respond for future customers while Google reviews the case
A public reply cannot prove that a review is fake, and it should not expose customer records. Its job is to give the reviewer a resolution path and show future readers that the business checked the concern.
For a suspicious review, a neutral response can say:
We could not match this concern to a completed service at this location. Please use the customer experience number listed on this profile and share the service address and date so we can investigate privately.
Do not say the reviewer committed fraud. Do not reveal the addresses, phone numbers, appointment history, health information, access codes, or employee notes used in the internal check.
If the review belongs to a real customer, shift to service recovery. The negative-review response guide covers fact checking, accountability, privacy, and the offline handoff. A business should not misuse the fake-review process to suppress a legitimate complaint.

Do not counter fake reviews with risky review collection
An incoming fake-review incident and enforcement against the business are different problems. Google may restrict a Business Profile when it finds that the merchant violated the fake-engagement policy. The review-restriction recovery guide explains that separate notice, appeal, containment, and restart path.
Do not try to dilute suspicious ratings by buying positive reviews, asking employees or relatives to post, paying customers for a particular sentiment, or sending only happy customers to Google. Those actions can create a second incident owned by the business.
The compliant review collection playbook covers neutral eligibility, incentives, rating pressure, requested wording, and staff targets. The U.S. Federal Trade Commission's Consumer Reviews and Testimonials Rule also addresses fake reviews, sentiment-conditioned incentives, insider reviews, and review suppression. The FTC rule is a business-conduct standard, not a shortcut for removing a review from Google.
Continue the normal program only if it is already compliant and auditable. The response to an attack is better evidence and cleaner incident control, not a sudden burst of manufactured praise.
Run a 14-day portfolio response
The following cadence is a Cheers operating recommendation, not a Google decision timeline:
- Day 0: Name one incident owner, capture the original reviews and communications, identify every affected profile, and stop duplicate reporting
- Day 1: Have each branch check service, booking, dispatch, and complaint records; classify every review against one Google policy or the real-customer path
- Days 2 through 5: Submit review reports, use the extortion form where applicable, post privacy-safe replies, and record Google's live statuses
- When a decision appears: Submit the one eligible appeal only when the evidence supports it; keep each review tied to its location even when several are appealed together
- End of week 2: Read every affected profile publicly, close removed or resolved items, retain denied decisions, and document any reviewer pattern, training issue, or access gap for the next incident
The system is working when leadership can answer five questions for any suspicious review: which location is affected, what the service record shows, which policy may apply, which Google path was used, and what is visible now.
Sources
- Google Business Profile Help: report inappropriate reviews. Supports the Reviews Management Tool, status labels, typical review timing, one-time appeal, and the limit of up to 10 reviews per appeal.
- Google Maps User Contributed Content Policy: prohibited and restricted content. Defines genuine experience, fake engagement, conflicts of interest, off-topic content, harassment, personal information, and other reportable policy categories.
- Google Business Profile Help: report negative-review extortion scams. Supports the separate extortion path, evidence preservation, and Google's direction not to engage or pay.
- Google Maps User Contributed Content Policy: report inappropriate user profiles. Supports reporting a reviewer profile that contributes false information or takes other abusive actions.
- Google Business Profile Help: restrictions for policy violations. Separates incoming policy-violating reviews from fake-engagement enforcement against the business.
- FTC: Consumer Reviews and Testimonials Rule questions and answers. Supports the U.S. rules on fake reviews, sentiment-conditioned incentives, insider reviews, and suppression.
Dylan Allen-Arnegård is the CEO & Co-Founder of Cheers, the local search platform for multi-location service businesses.