Summer Deal · 25% OFF · Code SUMMER25Ends soon · 10 days onlySee plans →
Skip to content

Last updated · February 1, 2026 · v2026-02-01

Privacy Policy

This page is maintained by Reviews Uplift AI to answer common privacy questions about our product. It reflects the practices in place today.

0. Who we are & how to reach us

  • Controller / operator: Reviews Uplift AI (operating entity pending counsel confirmation)
  • Registered address: Registered address pending counsel confirmation
  • Governing jurisdiction: Governing jurisdiction pending counsel confirmation
  • Privacy contact: inquiry@reviewsuplift.com
  • Data protection contact: inquiry@reviewsuplift.com
  • Effective date: February 1, 2026 (version 2026-02-01). Prior versions preserved for audit.

We do not claim to be certified under GDPR, HIPAA, PCI-DSS, SOC 2, or ISO 27001. Where a subprocessor holds such a certification (for example Stripe for card processing), that certification is theirs, not ours. If your organisation requires a signed Data Processing Addendum (DPA), request one at inquiry@reviewsuplift.com.

1. Data categories, purposes and lawful basis

CategoryExamplesPurposeLawful basis
Account & workspaceName, email, hashed password, business name, timezoneProvide the service; authenticate youContract
BillingStripe customer ID, card brand + last 4, invoicesCharge you, produce tax recordsContract; legal obligation (tax records)
Google Business ProfileOAuth tokens, reviews, replies, locationsFetch reviews, post approved repliesContract; your OAuth consent to Google
Product usageFeature use, AI generations, audit trailsOperate, secure and improve the serviceLegitimate interest; contract
Optional analyticsPageviews, CTA clicks (IP anonymized)Measure funnel; improve marketing siteConsent (opt-in only, revocable)
Anti-abuse signalsIP, browser fingerprint, user agent at signupEnforce trial fairness; detect abuseLegitimate interest

1. What we collect

  • Account data — name, business name, email, hashed password, plan and billing history.
  • Payment information — handled entirely by our payment processor, Stripe, Inc. Stripe is PCI-DSS Level 1 certified (that is Stripe's certification, not ours). We never see or store full card numbers, CVCs, or bank account credentials. Stripe returns to us a tokenized reference, the last 4 digits, card brand, expiration month/year, billing country, and postal code so we can display and manage your subscription.
  • Google Business Profile data — reviews, ratings, review responses, and public business metadata you authorize us to access via Google OAuth 2.0.
  • Product usage — pages visited, features used, AI generations initiated, and CTA interactions, for improving the product and measuring conversion.
  • Support communications — messages you send us via the contact form or email.
  • Concierge chat & lead details — when you chat with our on-site concierge and choose to leave your name, business name, email, phone, and message, we store that submission and the associated chat transcript so our team can follow up personally.
  • Free AI demo usage signals — for the public AI reply demo on our marketing site, we keep a short-lived, one-way hashed technical fingerprint of the request (never a readable IP, name, or contact detail) so we can enforce fair-use limits and prevent abuse of the free demo. These hashes are not linked to any identifiable person and are periodically purged.
  • Anti-abuse signup signals — when you create an account or start a free trial, we record your IP address, browser fingerprint, and user agent to enforce a strict "one free trial per network / per browser" limit and investigate confirmed abuse. These signals are retained with your signup record and are visible only to our platform administrators for security review.
  • Email verification — new email/password accounts must confirm ownership of the mailbox with the verification link or 6-digit code sent by our authentication provider. We do not generate, store, or log a second competing signup code.
  • Prefill and Google Business audit logs — every URL prefill, Google Business prefill, and missing-field event during onboarding is written to an internal audit log along with your IP and user agent. This helps us troubleshoot integration failures and detect scraping abuse. Only super administrators can view or export this log.

2a. Signup restrictions

To keep the platform clean of spam and trial abuse, we may reject or review signups from:

  • Custom domains our administrators have confirmed are being used abusively.
  • Networks or browsers that have already started a free trial.

We do not broadly block mainstream providers or whole TLD categories. If your legitimate business email is affected by a targeted abuse control, contact inquiry@reviewsuplift.com and we'll allow-list it for you.

2. What we don't collect

  • We never see or store your Google account password.
  • We do not read your Google inbox, Drive, Calendar, or other Google services.
  • We do not sell personal data to third parties. Ever.

3. How we use data

  • Deliver the product: fetch reviews, generate replies, post responses on your behalf.
  • Provide analytics and dashboards inside your workspace.
  • Improve the AI models we operate — using only aggregated, de-identified signals.
  • Send transactional email (billing, account, security notices).
  • Send product email you can unsubscribe from at any time.

4. Subprocessors

We rely on the following subprocessors to operate the service. We keep this list current; material additions are announced by email at least 14 days before they take effect where reasonably possible.

SubprocessorPurposeDataRegion
Supabase (Cloud database & auth)Authentication, database, storageAccount, workspace, reviews, replies, audit logsUS / EU (per project region)
Stripe, Inc.Subscription billing and payment processingName, email, billing address, card token, invoicesUS (Stripe is the controller for card data)
ResendTransactional email deliveryEmail address, delivery metadataUS / EU
Google (Business Profile API)Read reviews and post replies on your behalfOAuth tokens, review content, business metadataUS
Uplift AI Brain (primary AI engine)Generate draft replies, refine templates, concierge chatPrompt text (review + your instructions), model completion. Content is not used to train public models per our upstream API policy.US / Global
Lovable AI Gateway (fallback AI routing)Bounded fallback for AI calls when the primary provider is unavailable or over quota. Routes to Google/OpenAI hosted models.Prompt text and model completion, only when fallback is exercised. Ephemeral; not used for training.US / EU

Stripe's own privacy practices are described in the Stripe Privacy Policy. AI providers process prompt text solely to return a completion under their standard paid API terms; we do not opt in to any provider training or human-review features.

5. Security

  • All traffic served over HTTPS.
  • Data at rest is encrypted by our cloud database provider using industry-standard AES-based encryption managed by the provider.
  • Row-level security enforced in our database.
  • Google API refresh and access tokens are additionally encrypted at the application layer with per-workspace envelope encryption before being stored.
  • Least-privilege access for internal team members.
  • OAuth 2.0 for Google integration — we never store your password.
  • Provider-issued email verification for all new email/password accounts.
  • Targeted custom domain denylist for confirmed abuse.
  • IP + browser-fingerprint trial-abuse throttling.
  • Card data is tokenized by Stripe in the browser and never touches our servers. Stripe is our card processor; their PCI-DSS certification is theirs, not ours.

Compliance status. Reviews Uplift AI is a general-purpose review management tool. We do not hold HIPAA, GDPR, SOC 2, ISO 27001, or PCI-DSS certification as an operator. We describe our practices honestly; we do not claim compliance we cannot prove. If your organization operates in a regulated vertical (healthcare, legal, financial services, services involving minors) you MUST NOT paste protected health information, patient identifiers, account numbers, minors' identifying details, or privileged legal content into AI instructions, templates, or the concierge chat. Regulated verticals require a manual Regulated Vertical Request — email inquiry@reviewsuplift.com.

5a. Sensitive content handling

We automatically scan incoming review text for medical, financial, minor-related, and legal signals. When any of these are detected:

  • The review text is minimized before being sent to the AI model — only the star rating, coarse length, and category flags are included; the raw content is not forwarded.
  • Any generated reply is force-flagged for manual review and cannot be auto-posted, even if your automation is enabled.
  • Workspaces classified as a regulated vertical have automated posting disabled entirely.

5b. AI provider disclosures

We route generative AI requests through our Uplift AI Brain — a proprietary gateway layered over vetted enterprise AI providers. We rely on each upstream provider's published API terms confirming that data submitted through their paid API is not used to train their public models, and we do not opt in to any optional training/logging features. Provider terms change; the current subprocessor list and the operator DPA checklist we use to verify these settings are available on request at inquiry@reviewsuplift.com.

6. Data retention

Retention is governed by our versioned retention policy, which is applied by a scheduled cleanup job. Current defaults:

  • Account & workspace records: for the life of your account, plus 30 days after cancellation to allow re-activation and data export.
  • Reviews and generated replies: your app-owned workflow metadata (status, approvals, audit references) is retained for the life of the account. Google Business Profile Content itself — reviewer name, reviewer photo, review text, and any Google-hosted reply text — is retained no longer than 30 calendar days from the moment we fetch it from Google, in line with Google Business Profile Terms. After that, only IDs and app metadata remain; the fields are permanently nulled.
  • Audit logs and security events: 12 months, then purged by the retention runner.
  • Google OAuth tokens: purged immediately on disconnect or account deletion.
  • Backups: cloud provider default rotation (typically 7–30 days); we do not maintain long-term backup archives.
  • Billing records (invoices, tax documents): retained by us and by Stripe for the period required by applicable tax and financial-record-keeping laws.

"Encrypted backups", "immutable backups" and specific backup windows are only claimed here for our own retention runner. Cloud-provider backup guarantees are the provider's, not ours.

7. Your rights & how to complain

Depending on where you live, you may have the following rights:

  • Access — request an export of your data (self-service in Dashboard → Settings → Privacy & Data).
  • Rectification — request correction of inaccurate data.
  • Erasure — request deletion of your account and data (self-service with a cancellation window).
  • Restriction / objection — ask us to pause processing while a request is investigated.
  • Portability — the export is JSON/CSV and portable to another provider.
  • Withdraw consent — opt out of optional analytics and marketing email at any time.

Send requests to inquiry@reviewsuplift.com. We respond within 30 days.

If you believe we have not handled your data properly, you may lodge a complaint with your local data-protection authority. In the EU/EEA, see the EDPB list of national authorities. In the UK, contact the Information Commissioner's Office.

8. Cookies, analytics & marketing

Essential cookies are required to run the service (authentication, session, CSRF). Optional product analytics and marketing emails are opt-in and can be turned on or off at any time from the Cookie & Preferences page or from Dashboard → Settings → Privacy & Data. We do not use third-party advertising cookies. Stripe may set its own cookies on checkout pages for fraud prevention.

9. Children

Reviews Uplift AI is a B2B tool intended for business owners. It is not directed to children under 16 and we do not knowingly collect data from them.

10. International transfers

Depending on the subprocessor, your data may be processed in the United States or the European Union. Cross-border transfer safeguards (for example Standard Contractual Clauses or an adequacy decision) are handled by each subprocessor under their own agreements — see the subprocessor table above and the linked provider policies. If your organisation requires a signed SCC or DPA with us directly, request one at inquiry@reviewsuplift.com; we execute customer DPAs on request rather than by default.

11. Changes to this policy

We may update this policy from time to time. Material changes are announced via email to the address on your account at least 14 days before they take effect.

12. Contact

Data-protection questions: inquiry@reviewsuplift.com. For payment-specific privacy questions, you may also contact Stripe directly via support.stripe.com.

Questions about this document? Contact us.