Website Fundamentals

Local Business Website Security: How to Avoid Exposing Passwords in Shared Google Docs

Protect passwords, customer details, and website access by reviewing shared Google Docs, Sheets, and link permissions.

The StoopCraft Team
closeup photo of turned-on blue and white laptop computer

Shared Google Docs can create a real security risk

Shared documents are useful for running a local business. A team might use Google Docs or Sheets to track website updates, pass along customer inquiries, organize staff schedules, store vendor details, or keep a list of account logins.

The problem is not that every shared Google Doc is unsafe. The risk depends on what the document contains and who can access it.

Recent reporting highlighted why this deserves attention. Malwarebytes warned about the risks of using “anyone with the link” sharing for Google Docs, while The Register reported that passwords kept in a public Google Doc appeared in search results. Those reports show how sensitive information can be exposed when a document is shared too broadly or contains information that should not be stored there in the first place.

For a local business, an exposed document could include website credentials, customer contact details, inquiry exports, private notes, supplier information, or internal processes. That does not mean these outcomes have happened to every business using shared files. It does mean businesses should review their files before an accidental sharing setting becomes a larger issue.

In this guide:

  • What should never be stored in a shared document
  • How to review Google Docs and Sheets permissions
  • Safer ways to share website and lead-related information
  • What to do if a document may have been public
  • A practical recurring security checklist

Sources: Malwarebytes and The Register.

The simplest rule: do not store passwords in shared Docs or Sheets

A password should not live in a shared Google Doc, a team spreadsheet, an email thread, or a note pasted into a customer-management file.

This applies to passwords for:

  • Your website hosting or domain account
  • Website admin access
  • Business email
  • Google Business Profile access
  • Social media accounts
  • Payment processors
  • Booking, scheduling, or invoicing tools
  • Wi-Fi networks
  • Vendor portals
  • Shared software subscriptions

A document may feel private because it was created for internal use. But ownership can change, link settings can be updated, a file can be forwarded, and access can be left behind after a staff member or contractor moves on.

The safer approach is to use a reputable password manager designed for storing and sharing credentials. That allows a business owner to limit who receives access and to remove access when it is no longer needed—without leaving a password in a spreadsheet that may be copied or shared again.

If a password has already been placed in a document with broad access, assume it may need to be changed. Removing the password from the document is useful, but changing the password addresses the possibility that someone copied it before it was removed.

Link sharing is convenient. It can also be easy to overlook.

When a Google Doc or Sheet is set to “anyone with the link,” access is not limited to the specific people you intended to invite. Someone who receives the link may be able to open it, depending on the file’s setting. That link can also be forwarded, pasted into another document, included in an email, or added to a project-management tool.

The reporting from Malwarebytes and The Register is a reminder that publicly accessible documents can create search exposure risks, especially when they include passwords or other sensitive content.

This does not mean:

  • Every file with a share link appears in search results.
  • Every shared Google Doc is public.
  • Google Docs should never be used for collaboration.
  • Your website provider automatically controls or secures your Google account and third-party files.

It does mean that business owners should understand the difference between a file shared with named people and a file accessible to anyone who obtains the link.

Use named access for sensitive working documents

For files containing customer, employee, financial, operational, or website-related information, use the most limited sharing option that still lets the right people do their work.

A practical default is:

  1. Share with specific people rather than a general link.
  2. Give each person only the level of access they need.
  3. Review who has access when a project ends.
  4. Remove former employees, agencies, freelancers, and vendors promptly.
  5. Avoid using an old “team operations” document as a catch-all storage place for new sensitive information.

A small business often has a few people handling many responsibilities. That makes access reviews especially important. A document shared with a former assistant, web designer, office manager, or contractor may still be available long after the original task is complete.

Audit the documents connected to your website and leads

Start with documents that support your website, contact forms, and customer follow-up process. These are the files most likely to hold information that should not be broadly shared.

Review your website access notes

Look for documents with names such as:

  • Website logins
  • Website updates
  • Domain details
  • Hosting information
  • SEO notes
  • Social media passwords
  • Marketing access
  • Launch checklist
  • Vendor accounts

If a document includes a password, recovery code, API key, payment login, or other credential, remove it from the document and change the affected credential where appropriate.

Then move the replacement credential into a password manager rather than creating another “private passwords” spreadsheet.

Review contact-form exports and lead spreadsheets

Many local businesses export website inquiries to a spreadsheet for follow-up. That can be useful operationally, but it may contain names, phone numbers, email addresses, addresses, requested services, photos, and notes from prospective customers.

Check whether lead spreadsheets are shared outside the people who actively need them. Also check whether old exports are still sitting in shared folders.

A cleaner process may be:

  • Keep only the customer details needed to follow up.
  • Limit access to the staff responsible for responding to inquiries.
  • Avoid copying leads into multiple documents “just in case.”
  • Delete or archive old exports according to your business’s needs and policies.
  • Do not combine customer details with account passwords in the same file.

If your contact page sends inquiries into a shared inbox or spreadsheet, make sure your process is intentional. Our guide to local business lead follow-up can help you build a simpler workflow that does not require every team member to access every customer record.

Review shared folders, not just individual files

A document can be restricted while the folder around it is shared more broadly than expected. During your audit, look at:

  • Folder sharing settings
  • Shared drives or team folders
  • Old project folders
  • Documents created by former staff
  • Files owned by outside contractors
  • Spreadsheets linked in internal emails or chat messages

Pay special attention to folders created for a website redesign, marketing campaign, or business launch. They can contain copied logos, customer lists, old web copy, access notes, and project credentials.

A safer way to pass information to staff and contractors

The goal is not to stop collaboration. It is to separate information based on sensitivity.

Here is a practical division of what belongs where.

InformationSafer place to keep or share it
Website, email, and vendor passwordsA password manager
Customer inquiriesYour approved inbox, CRM, booking tool, or access-limited spreadsheet
Website page editsA shared document with named collaborators and no credentials
Photos and approved business assetsA controlled shared folder
Internal website update requestsA task list or project document with limited access
Recovery codes, payment details, and sensitive account informationA secure system with tightly limited access; seek qualified advice when needed

For example, a contractor updating your homepage may need your approved copy, logo files, service details, and photos. They usually do not need the password to your business email account or payment processor.

Likewise, a receptionist following up on contact-form submissions may need the customer’s name, contact details, and requested service. They usually do not need access to website administration, marketing accounts, or all historical customer exports.

This principle—give access only to what someone needs for the task—can reduce the impact of an accidental share or a former team member retaining access.

If you discover a document was publicly accessible

Act promptly, but do not panic. The first priority is limiting access and addressing any exposed secrets.

1. Restrict access to the document

Update the document’s sharing settings so it is no longer available through a broad public or link-based setting. Review both the file and its containing folder.

Do not rely only on deleting a link from an email or chat. If a document was broadly accessible, update the actual sharing permissions.

2. Identify what the document contained

Make a short list of the information that may have been exposed:

  • Passwords or login details
  • Password recovery information
  • Customer names, phone numbers, or email addresses
  • Payment-related information
  • Website or domain account details
  • Private employee or vendor details
  • Internal notes that should not be public

This review helps you prioritize the next actions.

3. Change exposed passwords and revoke unnecessary access

If the document contained passwords, change them. Start with high-impact accounts such as business email, domain management, website administration, payment tools, and any account used to reset other passwords.

Also review who can access those accounts. Remove old users and revoke access that is no longer required.

4. Check for copied or duplicated files

Search your Google Drive for copies, exports, downloaded versions, and older versions of the same information. A restricted original document does not help much if an exported spreadsheet remains widely shared.

5. Preserve enough information to understand the incident

Record the file name, the sharing setting you found, the type of information it contained, and the actions you took. This can make it easier to coordinate with a qualified security professional if the document involved sensitive customer, financial, or payment information.

6. Get professional help when the exposure is serious

This article is not comprehensive cybersecurity or legal advice. If the document may have exposed sensitive customer data, payment information, or important business account access, consult a qualified cybersecurity professional and, where appropriate, legal or compliance advisors.

Add shared-document checks to monthly website maintenance

Website maintenance is not only about updating service pages, checking forms, or replacing outdated photos. The processes around the website matter too.

Once a month, or after a major staffing or vendor change, review:

  • [ ] Who has access to your website, domain, and business email
  • [ ] Which Google Docs and Sheets contain website or customer information
  • [ ] Whether any sensitive file uses broad link sharing
  • [ ] Whether former staff or contractors still have file access
  • [ ] Whether passwords have been stored in documents
  • [ ] Whether customer inquiry exports are limited to necessary staff
  • [ ] Whether your website contact form is still working as expected
  • [ ] Whether your business has a clear owner for website and account access

For a broader recurring review, use our local business website maintenance checklist. If a form or website issue prevents customers from reaching you, see what to do when your local business website or booking form goes down.

Keep your website process separate from your password process

A well-managed local business website needs a clear path for updates, inquiries, and access. But it should not depend on a shared document full of credentials.

Keep website copy, service details, photos, and update requests in collaboration tools with sensible permissions. Keep passwords in a system intended for passwords. Keep customer inquiries available only to the people responsible for handling them.

StoopCraft builds done-for-you websites and performs on-page SEO for local businesses for $69/month. If you want a simpler website setup with a clear place to send updates—without turning a shared password document into your website-management system—visit StoopCraft.

Keep reading