Skip to content
Trust center

Trust and security

ReviewTactic reads your reviews, drafts replies and shows how your reputation compares locally. This page explains what data that takes, who processes it, how we protect it and what you can do about it.

At a glance

  • Google sign-in through Google itself. We never see your password.
  • Card payments handled by Stripe. We never store card numbers.
  • Encrypted in transit and at rest.
  • Your data is never used to train AI models.
Data

What we process and why

The reviews we work with are already public on Google Maps and the other review sites. We do not ask for your customers' private data. The only Google permission we request is the one needed to read and reply to your Business Profile reviews: no Gmail, no Drive, no other Google service.

Data Why we need it Source
Google account information Your email address and name, to create and secure your account and send account email. Google sign-in
Google Business Profile data Reviews, your replies, star ratings, business name and address, and profile metrics, used to draft and publish replies under your settings and to build your analytics. Your Business Profile, with your authorization
Reviews from other platforms Reviews from TripAdvisor, Booking.com, Yelp and others, so you can monitor them and draft replies outside Google. A review-data partner, after you confirm your listing
AI interaction logs Review text sent to the AI and the replies it generates, for replies, insights and reports. Produced by the service
Usage data Pages visited, features used and session length, to improve the product. Product analytics and website session recording (see the cookie policy)
Payment information Billing. Stripe. We do not store card numbers.
Review removal case data Violation category, case status, your approval decisions, comments and any evidence you upload. Only if you use the Review Removal Service. You, and your public reviews
Processors

Who processes it

Every provider that processes personal data for us. We give customers 30 days' notice before adding a new one.

Provider Purpose Data it handles Location
Supabase Database, sign-in, serverless functions, file storage and backups Account data, reviews and replies, settings, uploaded removal evidence UK (London)
Netlify Website and app hosting Website requests, IP address US
Stripe Checkout, subscription billing, invoices Billing name and email, payment history. Card details never reach us. US
Resend Account, billing, alert and customer email Email address, name, email content US
Anthropic (Claude API) AI reply drafting, brand voice, insight chat, reports Public review text and reviewer names, business context, your chat messages US
Google (Gemini API) AI analysis, competitor scoring, insights Public review text, business data US
OpenAI Text embeddings for searching your business context Business context text you provide (menu, FAQ, policies) US
Google (Places and Maps API) Business lookup in the app and free tools Business name and address, visitor IP address US
Outscraper Collects public Google reviews for audits Public reviews and reviewer names US
Zembra Review monitoring on other platforms (TripAdvisor, Booking.com, Yelp and others) Public reviews and reviewer names, listing details US
DataForSEO Local search ranking scans Business name, address and keywords EU (Estonia)
PostHog Product analytics Page views, feature usage, session length, user ID in the app US
Microsoft Clarity Website heatmaps and session recordings Clicks, scrolling, page interactions, IP address US
Sentry App error monitoring Error details, browser data, IP address EU (Germany)
Cloudflare (Turnstile) Bot protection on free tools Browser signals, IP address US
Google Workspace Our support mailbox Emails you send us US
Google Fonts Web fonts in the app IP address US
Telegram Internal alerts to our team Customer email address, business and location names UAE

Where a provider is in the United States, transfers from the EEA rely on Standard Contractual Clauses or an equivalent transfer mechanism, and we have accepted each provider's data processing agreement. Our own data processing agreement for customers is published at reviewtactic.com/dpa.

Protection

How we protect it

  • Encrypted in transit

    All traffic between your browser, our website, our app and our service providers runs over HTTPS, and browsers are told never to connect to us without it.

  • Encrypted at rest

    Your data is encrypted where it is stored. Documents you upload for review removal are accessible only to you and our operations team.

  • Google sign-in, not passwords

    You connect Google through Google's own consent screen. We never see or store your Google password, and you can revoke access at any time from your Google account.

  • Cards never touch our servers

    Payments run through Stripe Checkout and the Stripe billing portal. Card details are entered on Stripe-hosted pages only, and we never store them.

  • Hardened website

    Our pages tell browsers which content they may load and cannot be embedded inside other websites.

  • Protection against abuse

    Our public tools and the app are protected against automated abuse.

  • Verified integrations

    Data that partners send to us is accepted only after it is authenticated.

  • Secure account access

    Sign in with email and password or with Google. Google sign-in uses your Google account’s own 2-step verification.

  • Reviewed changes

    Changes to our website and app go through version control and review before release, and can be rolled back.

AI

AI and your data

  • Which models

    Replies, insights and reports are generated with Google Gemini and Anthropic Claude models through their commercial APIs.

  • Your data does not train the models

    We use the paid commercial APIs of Google and Anthropic. Both commit contractually that data sent through these services is not used to improve their models.

  • Only public text is sent

    The AI receives review text that is already public on Google Maps or the review site, plus the business context you set (menu, FAQ, policies, tone). Your data is never mixed with, or shown to, other customers.

  • You decide what gets published

    Every reply is a draft until your settings say otherwise. Choose manual approval (one by one or in bulk), automatic publishing for the star ratings you pick, or full automatic publishing. Change it at any time.

Want a person to look at an AI-generated reply? Email hello@reviewtactic.com.

Privacy

Your privacy rights

ReviewTactic is a US company serving customers in the EU and elsewhere, so we follow both GDPR and CCPA/CPRA.

  • Under GDPR

    Ask for access to your personal data, correction, erasure, restriction of processing or a machine-readable copy, object to processing based on legitimate interest, or complain to your local supervisory authority. Email hello@reviewtactic.com. We respond within 30 days.

  • Under CCPA/CPRA (California)

    Ask what we collect and why, request deletion or correction, and opt out of sale or sharing. We do not sell or share personal information as the CCPA defines it, and you are never treated differently for using these rights. Email hello@reviewtactic.com with the subject "CCPA Request". We respond within 45 days.

  • Data processing agreement

    Our data processing agreement applies automatically to every customer under GDPR and UK GDPR, with no signature needed. If you need a countersigned copy, email hello@reviewtactic.com.

  • Breach notification

    If a personal data breach is likely to put your rights at risk, we notify the relevant supervisory authority within 72 hours of becoming aware of it and tell affected customers by email without undue delay.

  • Cookies

    The app uses one essential sign-in cookie and a local setting that remembers your cookie choice. Visitors in Europe are asked before any analytics or session-recording cookies are set. Elsewhere, website session recording runs from the first visit. Anyone can reject at any time, and a reject, Do Not Track or Global Privacy Control signal stops it. See the cookie policy.

Your control

Disconnect, cancel, delete

  • No contract

    Plans are monthly with no setup fee. Cancel any time; access runs to the end of the billing period.

  • Disconnect Google, stop billing

    Removing the Google connection ends usage and billing stops with it. You can also revoke ReviewTactic from your Google account's third-party access page at any time.

  • Delete your account yourself

    Settings → Delete Account in the app. Deletion is immediate and cannot be undone. All associated data is permanently removed within 30 days, including backups and copies held by our service providers.

  • Automatic clean-up

    Accounts with no login for two years are deleted after a 30-day notice. Evidence uploaded for review removal is deleted within 90 days after the case is resolved.

Compliance

Compliance status

Where we stand today and what comes next.

Framework What it covers Status
GDPR and CCPA/CPRA Practices documented in our privacy policy, terms and cookie policy Published
PCI DSS Self-Assessment Questionnaire A, the scope that applies when Stripe hosts all card entry In progress
CSA STAR Level 1 Public self-assessment against the Cloud Security Alliance's Cloud Controls Matrix In progress
SOC 2 Type I audit, started as customer demand requires Planned
Responsible disclosure

Found a security issue?

Tell us what you found and how to reproduce it. We will acknowledge your report and keep you informed while we fix it. Please do not access other customers' data or run automated scans against our services.

Privacy and data requests: hello@reviewtactic.com · ReviewTactic LLC, 447 Sutter St, Ste 506-1210, San Francisco, CA 94108, United States

Last updated: October 2026 · Privacy policy · Terms of service · Cookie policy