ReviewReply

Legal

Privacy Policy

Last updated: May 25, 2026

ReviewReply, Inc. ("ReviewReply", "we", "our", or "us") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our platform, website, or services (collectively, the "Services"). Please read this policy carefully.

1. Information We Collect

Information you provide directly

  • Account information: Name, email address, password, and restaurant name when you register.
  • Business information: Restaurant details, Google Business Profile connection data, menu information, and brand voice settings you configure.
  • Payment information: Billing details processed securely by our payment processor (Stripe). We do not store full card numbers.
  • Communications: Support messages, feedback, and correspondence you send us.

Information collected automatically

  • Usage data: Pages visited, features used, time spent, click patterns, and session duration.
  • Device information: IP address, browser type, operating system, referring URLs, and device identifiers.
  • Cookies and trackers: We use cookies and similar tracking technologies as described in our Cookie Policy.
  • Review data: Google review content pulled via Google Business Profile API on your behalf.

Information from third parties

  • Google: When you connect your Google Business Profile, we receive your business name, location, reviews, and ratings via the Google My Business API.
  • Analytics providers: Aggregated analytics from providers such as Vercel Analytics.

2. How We Use Your Information

We use the information we collect to:

  • Provide, operate, and improve the Services.
  • Generate AI-powered review replies tailored to your restaurant's voice and menu.
  • Detect and flag high-risk or negative reviews for your attention.
  • Send you transactional emails (account creation, password reset, billing receipts).
  • Send product updates and marketing communications (you may opt out at any time).
  • Respond to your support inquiries.
  • Enforce our Terms of Service and prevent fraud or abuse.
  • Comply with legal obligations.

We process your data on the lawful bases of contract performance (to provide the service you signed up for), legitimate interests (to improve and secure the platform), and consent (for marketing communications).

3. AI Processing & Review Data

ReviewReply uses large language models (LLMs) including OpenAI's GPT models to generate review replies. When you use our AI reply features:

  • Review text and your configured brand voice/menu data are sent to our AI provider to generate responses.
  • We do not use your review data to train third-party AI models under any current agreements.
  • Generated replies are stored so you can view history and improve future outputs.
  • You retain full ownership of your business data and generated content.

4. How We Share Your Information

We do not sell your personal information. We may share information with:

  • Service providers: Trusted vendors who help us operate (Supabase for database, OpenAI for AI, Stripe for billing, Vercel for hosting, Convex for real-time data). All are bound by data processing agreements.
  • Google APIs: Data from your connected Google Business Profile is processed according to Google's API Terms of Service.
  • Legal requirements: When required by law, court order, or to protect the rights and safety of ReviewReply or others.
  • Business transfers: If we merge with or are acquired by another company, your data may transfer as part of that transaction. We will notify you before your data is subject to a different privacy policy.

5. Data Retention

We retain your account data for as long as your account is active or as needed to provide you the Services. If you close your account, we will delete or anonymize your personal information within 90 days, except where we are required to retain it for legal, tax, or fraud-prevention purposes.

Review response history is retained for 24 months to provide analytics and improve your AI voice model.

6. Cookies & Tracking Technologies

We use the following types of cookies:

  • Essential cookies: Required for authentication, session management, and core platform functionality.
  • Analytics cookies: Help us understand how users interact with the platform (e.g., Vercel Analytics).
  • Preference cookies: Store your settings and preferences.

You can control cookies through your browser settings. Disabling essential cookies may affect platform functionality. See our Cookie Policy for full details.

7. Your Rights & Choices

Depending on your location, you may have the following rights:

  • Access: Request a copy of the personal data we hold about you.
  • Correction: Ask us to correct inaccurate or incomplete data.
  • Deletion: Request deletion of your personal data ("right to be forgotten").
  • Portability: Receive your data in a structured, machine-readable format.
  • Objection: Object to certain processing activities, including direct marketing.
  • Opt-out of marketing: Use the unsubscribe link in any marketing email, or email us at privacy@reviewreply.com.

To exercise any of these rights, email us at privacy@reviewreply.com. We will respond within 30 days.

8. Data Security

We implement industry-standard security measures to protect your information, including:

  • TLS/HTTPS encryption for all data in transit.
  • AES-256 encryption for sensitive data at rest.
  • Role-based access controls limiting employee access to personal data.
  • Regular security audits and penetration testing.
  • Incident response procedures for data breaches (we will notify you within 72 hours of becoming aware of a breach affecting your data).

9. International Data Transfers

ReviewReply is based in the United States. If you are accessing our Services from outside the US, your information may be transferred to and processed in the US, where data protection laws may differ from your jurisdiction.

For users in the European Economic Area (EEA) or UK, we rely on Standard Contractual Clauses (SCCs) approved by the European Commission as the legal mechanism for international transfers.

10. Children's Privacy

Our Services are not directed at children under 13. We do not knowingly collect personal information from children under 13. If we learn we have collected such information, we will delete it promptly. If you believe we have inadvertently collected data from a child, please contact us at privacy@reviewreply.com.

11. Changes to This Policy

We may update this Privacy Policy from time to time. When we make material changes, we will notify you by email and/or by posting a prominent notice on the platform at least 14 days before the changes take effect. Your continued use of the Services after the effective date constitutes acceptance of the updated policy.

12. Contact Us

If you have questions about this Privacy Policy or how we handle your data:

ReviewReply, Inc.

Privacy Team

privacy@reviewreply.com
Terms of Service →Cookie Policy →AI Policy →