This policy explains how Usereviews.io handles personal data during our free beta, across two settings: our public website (marketing pages, newsletter, contact forms) and the Usereviews product (the beta app you sign in to). It covers what we collect, the legal bases we rely on, who we share it with, and the rights you have. For any privacy question, get in touch.
01Who We Are & Scope
Usereviews.io is operated by the Usereviews team (“we”, “us”), based in Luxembourg. Our role under data-protection law depends on the setting:
- Website & account data — we are the controller. We decide why and how we process visitor and account data (see sections 02, 04).
- Product content you bring in — when you use the app to ingest and analyse reviews and reviewer contacts, that data belongs to you and we act as a processor on your instructions (see section 03). If you are a business customer, our Data Processing Agreement governs that processing.
02Information We Collect (Website)
Personal Information
We may collect your name and email address if you sign up for our newsletter, contact us, or create an account.
Non-Personal Information
We use cookies and analytics tools (like Google Analytics) to collect browser type, approximate location, IP address, and page views to understand and improve how the site is used. Where required by law, this is done only after you consent via our cookie banner.
03Product Data We Process (Account & Service Data)
When you use the Usereviews app, we process two kinds of data:
Account data — we are the controller
- Identity & profile — name, work email, organisation, role, password credentials
- Billing — during the beta the Service is free and we do not collect payment or card data. If paid plans are introduced later, billing would be handled by Stripe (we would not store full card numbers).
- Usage & security — log-in events, feature usage, and audit logs needed to run and secure the Service
Customer content — we are the processor
To provide the Service, we process the review and contact data you connect or import, on your behalf and on your instructions. This can include:
- Reviews and feedback aggregated from platforms you connect (e.g. G2, Trustpilot, app stores)
- Reviewer and contact records — names, email addresses, company, and the review history attached to them
- AI-derived insights, signals, and suggested responses generated from that content
You (or the business customer whose account you use) determine what content enters the Service and for how long it is kept. To generate insights we rely on AI sub-processors (currently Google Gemini and Anthropic) and a content-retrieval sub-processor (Bright Data); these are listed in our DPA. On the paid API tiers we use, these providers do not use your content to train or improve their models, and we do not permit such use. We do not use customer content for our own purposes, and we do not sell it. Where you are a business customer, the DPA sets out our obligations as processor in full.
04How We Use Your Information & Legal Bases
We use the information we collect to:
- Provide, secure, and support the Service you signed up for — legal basis: contract
- Send newsletters or product updates, where you’ve opted in — legal basis: consent
- Measure and improve website and product performance, and prevent abuse — legal basis: legitimate interests
- Meet our legal, tax, and accounting obligations — legal basis: legal obligation
You can withdraw consent at any time — for newsletters, use the unsubscribe link; for cookies, use the “Manage cookies” link in the footer.
05Cookies & Consent
When you use our site, cookies may be placed on your browser to keep it working properly (necessary cookies) and to measure how the site is used (analytics cookies). Non-essential cookies are set only after you accept them in our consent banner. You can change your choice anytime via “Manage cookies” in the footer, or disable cookies in your browser settings.
06Sharing & Sub-processors
We do not sell your personal information or share it for cross-context behavioural advertising. We disclose data only to service providers (“processors” / “sub-processors”) who process it on our instructions to help us run the website and the Service, under contract and limited to what they need:
- Application hosting & edge compute — Cloudflare
- Database, authentication & storage — Supabase
- Subscription billing & payments — Stripe (inactive during the free beta — no payments are processed)
- Website analytics — Google Analytics
- Email & CRM — HubSpot
- Transactional & notification email — Resend
AI sub-processors that process customer content (Google Gemini, Anthropic, Bright Data) are described in section 03 and listed in our DPA.
Sharing with a processor acting on our instructions is not a “sale” or a “share” under applicable privacy law.
07International Transfers & DPA
Some of our processors are based outside the European Economic Area (for example, in the United States), so providing our services involves transferring personal data internationally. Where we transfer personal data outside the EEA, we rely on appropriate safeguards to protect it — principally the European Commission’s Standard Contractual Clauses (SCCs), or an adequacy decision where one applies to the destination country. We enter into the SCCs (and, where relevant, the UK Addendum) with each such processor, and apply additional measures where a transfer risk assessment calls for them.
Where we process personal data on behalf of a business customer (for example, the reviews and contacts in your account), our Data Processing Agreement (DPA) governs that processing — including our confidentiality and security obligations, the sub-processors we use, how we assist with data-subject requests and breach notification, and the SCCs for onward transfers. Business customers can request and countersign the current DPA by contacting us.
08Data Retention
We keep personal data only as long as needed for the purpose it was collected:
- Newsletter data — until you unsubscribe
- Account data — for the life of your account, then deleted within 30 days unless the law requires otherwise
- Customer content — for as long as it stays in your account; on deletion or account closure it is removed within 30 days, subject to backups cycling out
- Analytics data — for the retention period configured in our analytics tools
09Data Security
We implement standard security measures — encryption in transit, access controls, and least-privilege practices — to protect your information. However, no method of transmission over the internet is 100% secure.
10Your Rights (GDPR / CCPA)
Depending on where you live, you may have the right to access, correct, delete, port, or restrict the use of your personal data, and to object to certain processing or withdraw consent. Under the GDPR you may also lodge a complaint with your supervisory authority (in Luxembourg, the CNPD).
Under the CCPA, California residents have the right to know, delete, and opt out — and we confirm that we do not sell or share personal information. To exercise any of these rights, contact us. If your request concerns customer content held in a business customer’s account, we will refer it to that customer as the controller and assist them in responding.
11Changes to This Policy
We may update this policy from time to time. When we make material changes, we’ll update the “Last updated” date above and, where appropriate, notify you.
Questions about your privacy?
For any privacy request or question about this policy, get in touch. Business customers looking for our processor terms can request the Data Processing Agreement.