Trust and security
ReviewTactic reads your reviews, drafts replies and shows how your reputation compares locally. This page explains what data that takes, who processes it, how we protect it and what you can do about it.
At a glance
- Google sign-in through Google itself. We never see your password.
- Card payments handled by Stripe. We never store card numbers.
- Encrypted in transit and at rest.
- Your data is never used to train AI models.
What we process and why
The reviews we work with are already public on Google Maps and the other review sites. We do not ask for your customers' private data. The only Google permission we request is the one needed to read and reply to your Business Profile reviews: no Gmail, no Drive, no other Google service.
| Data | Why we need it | Source |
|---|---|---|
| Google account information | Your email address and name, to create and secure your account and send account email. | Google sign-in |
| Google Business Profile data | Reviews, your replies, star ratings, business name and address, and profile metrics, used to draft and publish replies under your settings and to build your analytics. | Your Business Profile, with your authorization |
| Reviews from other platforms | Reviews from TripAdvisor, Booking.com, Yelp and others, so you can monitor them and draft replies outside Google. | A review-data partner, after you confirm your listing |
| AI interaction logs | Review text sent to the AI and the replies it generates, for replies, insights and reports. | Produced by the service |
| Usage data | Pages visited, features used and session length, to improve the product. | Product analytics and website session recording (see the cookie policy) |
| Payment information | Billing. | Stripe. We do not store card numbers. |
| Review removal case data | Violation category, case status, your approval decisions, comments and any evidence you upload. Only if you use the Review Removal Service. | You, and your public reviews |
Who processes it
Every provider that processes personal data for us. We give customers 30 days' notice before adding a new one.
| Provider | Purpose | Data it handles | Location |
|---|---|---|---|
| Supabase | Database, sign-in, serverless functions, file storage and backups | Account data, reviews and replies, settings, uploaded removal evidence | UK (London) |
| Netlify | Website and app hosting | Website requests, IP address | US |
| Stripe | Checkout, subscription billing, invoices | Billing name and email, payment history. Card details never reach us. | US |
| Resend | Account, billing, alert and customer email | Email address, name, email content | US |
| Anthropic (Claude API) | AI reply drafting, brand voice, insight chat, reports | Public review text and reviewer names, business context, your chat messages | US |
| Google (Gemini API) | AI analysis, competitor scoring, insights | Public review text, business data | US |
| OpenAI | Text embeddings for searching your business context | Business context text you provide (menu, FAQ, policies) | US |
| Google (Places and Maps API) | Business lookup in the app and free tools | Business name and address, visitor IP address | US |
| Outscraper | Collects public Google reviews for audits | Public reviews and reviewer names | US |
| Zembra | Review monitoring on other platforms (TripAdvisor, Booking.com, Yelp and others) | Public reviews and reviewer names, listing details | US |
| DataForSEO | Local search ranking scans | Business name, address and keywords | EU (Estonia) |
| PostHog | Product analytics | Page views, feature usage, session length, user ID in the app | US |
| Microsoft Clarity | Website heatmaps and session recordings | Clicks, scrolling, page interactions, IP address | US |
| Sentry | App error monitoring | Error details, browser data, IP address | EU (Germany) |
| Cloudflare (Turnstile) | Bot protection on free tools | Browser signals, IP address | US |
| Google Workspace | Our support mailbox | Emails you send us | US |
| Google Fonts | Web fonts in the app | IP address | US |
| Telegram | Internal alerts to our team | Customer email address, business and location names | UAE |
Where a provider is in the United States, transfers from the EEA rely on Standard Contractual Clauses or an equivalent transfer mechanism, and we have accepted each provider's data processing agreement. Our own data processing agreement for customers is published at reviewtactic.com/dpa.
How we protect it
-
Encrypted in transit
All traffic between your browser, our website, our app and our service providers runs over HTTPS, and browsers are told never to connect to us without it.
-
Encrypted at rest
Your data is encrypted where it is stored. Documents you upload for review removal are accessible only to you and our operations team.
-
Google sign-in, not passwords
You connect Google through Google's own consent screen. We never see or store your Google password, and you can revoke access at any time from your Google account.
-
Cards never touch our servers
Payments run through Stripe Checkout and the Stripe billing portal. Card details are entered on Stripe-hosted pages only, and we never store them.
-
Hardened website
Our pages tell browsers which content they may load and cannot be embedded inside other websites.
-
Protection against abuse
Our public tools and the app are protected against automated abuse.
-
Verified integrations
Data that partners send to us is accepted only after it is authenticated.
-
Secure account access
Sign in with email and password or with Google. Google sign-in uses your Google account’s own 2-step verification.
-
Reviewed changes
Changes to our website and app go through version control and review before release, and can be rolled back.
AI and your data
-
Which models
Replies, insights and reports are generated with Google Gemini and Anthropic Claude models through their commercial APIs.
-
Your data does not train the models
We use the paid commercial APIs of Google and Anthropic. Both commit contractually that data sent through these services is not used to improve their models.
-
Only public text is sent
The AI receives review text that is already public on Google Maps or the review site, plus the business context you set (menu, FAQ, policies, tone). Your data is never mixed with, or shown to, other customers.
-
You decide what gets published
Every reply is a draft until your settings say otherwise. Choose manual approval (one by one or in bulk), automatic publishing for the star ratings you pick, or full automatic publishing. Change it at any time.
Want a person to look at an AI-generated reply? Email hello@reviewtactic.com.
Your privacy rights
ReviewTactic is a US company serving customers in the EU and elsewhere, so we follow both GDPR and CCPA/CPRA.
-
Under GDPR
Ask for access to your personal data, correction, erasure, restriction of processing or a machine-readable copy, object to processing based on legitimate interest, or complain to your local supervisory authority. Email hello@reviewtactic.com. We respond within 30 days.
-
Under CCPA/CPRA (California)
Ask what we collect and why, request deletion or correction, and opt out of sale or sharing. We do not sell or share personal information as the CCPA defines it, and you are never treated differently for using these rights. Email hello@reviewtactic.com with the subject "CCPA Request". We respond within 45 days.
-
Data processing agreement
Our data processing agreement applies automatically to every customer under GDPR and UK GDPR, with no signature needed. If you need a countersigned copy, email hello@reviewtactic.com.
-
Breach notification
If a personal data breach is likely to put your rights at risk, we notify the relevant supervisory authority within 72 hours of becoming aware of it and tell affected customers by email without undue delay.
-
Cookies
The app uses one essential sign-in cookie and a local setting that remembers your cookie choice. Visitors in Europe are asked before any analytics or session-recording cookies are set. Elsewhere, website session recording runs from the first visit. Anyone can reject at any time, and a reject, Do Not Track or Global Privacy Control signal stops it. See the cookie policy.
Disconnect, cancel, delete
-
No contract
Plans are monthly with no setup fee. Cancel any time; access runs to the end of the billing period.
-
Disconnect Google, stop billing
Removing the Google connection ends usage and billing stops with it. You can also revoke ReviewTactic from your Google account's third-party access page at any time.
-
Delete your account yourself
Settings → Delete Account in the app. Deletion is immediate and cannot be undone. All associated data is permanently removed within 30 days, including backups and copies held by our service providers.
-
Automatic clean-up
Accounts with no login for two years are deleted after a 30-day notice. Evidence uploaded for review removal is deleted within 90 days after the case is resolved.
Compliance status
Where we stand today and what comes next.
| Framework | What it covers | Status |
|---|---|---|
| GDPR and CCPA/CPRA | Practices documented in our privacy policy, terms and cookie policy | Published |
| PCI DSS | Self-Assessment Questionnaire A, the scope that applies when Stripe hosts all card entry | In progress |
| CSA STAR Level 1 | Public self-assessment against the Cloud Security Alliance's Cloud Controls Matrix | In progress |
| SOC 2 | Type I audit, started as customer demand requires | Planned |
Found a security issue?
Tell us what you found and how to reproduce it. We will acknowledge your report and keep you informed while we fix it. Please do not access other customers' data or run automated scans against our services.
Privacy and data requests: hello@reviewtactic.com · ReviewTactic LLC, 447 Sutter St, Ste 506-1210, San Francisco, CA 94108, United States
Last updated: October 2026 · Privacy policy · Terms of service · Cookie policy