Privacy Policy for Reviewhelden
Last updated: November 3, 2025
This Privacy Policy explains how Reviewhelden (“the Software,” “we,” “our,” “us”) collects, uses, and shares personal information from users of our platform. Reviewhelden provides tools that help local businesses enhance their online reputation (e.g., review aggregation, automated replies, review request campaigns, analytics, and process automation). We are committed to complying with applicable data protection laws, including the General Data Protection Regulation (GDPR) and the California Consumer Privacy Act (CCPA).
1. Personal Data We Collect
- Identifying and contact information: name, email address, IP address, phone number, login credentials.
- Platform usage data: information about reviews, responses sent via the platform, interactions with widgets, performance and reputation analytics.
- Data from automations & campaigns: end-customer data provided by our business users (e.g., names, email addresses, private feedback, public reviews, video testimonials, and submissions via landing pages).
- Browsing data: IP address, device information, and platform usage details (including via cookies and similar technologies).
- AI processing data: content of reviews and generated responses when using AI-assisted reply features.
2. Purposes of Data Processing
- Review aggregation: collect reviews from multiple platforms (e.g., Google, Facebook) and present them in one interface.
- Automated AI responses: generate suggested or automated replies based on review content and configured parameters.
- Review request campaigns: send requests to end-customers for public reviews or private feedback, including optional video testimonials.
- Review sharing: publish reviews via website widgets and generate assets for social media sharing.
- Analytics and reporting: provide insights on reputation and campaign performance.
- Process automation: automate review requests and follow-ups via configurable workflows.
- Security and integrity: protect accounts, prevent abuse, and maintain platform reliability.
3. Legal Basis for Data Processing (GDPR)
- Consent: for sending marketing/review request communications and for using non-essential cookies or AI auto-posting where required.
- Performance of a contract: to provide and support the services requested by our users.
- Legal obligations: to comply with applicable laws and regulatory requirements.
- Legitimate interests: to improve services, ensure security, measure performance, and support business operations in ways that respect users’ privacy.
4. User Rights (GDPR and CCPA)
GDPR (EU/EEA/UK) rights include:
- Access: request details about the personal data we hold about you.
- Rectification: request correction of inaccurate or incomplete data.
- Erasure: request deletion of your personal data (“right to be forgotten”).
- Restriction: request limited processing in certain circumstances.
- Portability: receive your data in a structured, commonly used, machine-readable format.
- Objection: object to processing based on legitimate interests, including profiling; object to direct marketing at any time.
CCPA (California) rights include:
- Right to know: request information about categories and specific pieces of personal data collected, purposes, and third parties.
- Right to delete: request deletion of personal data, subject to exemptions.
- Right to opt-out of sale/share: opt-out of the sale or sharing of personal information, if applicable.
- Non-discrimination: you will not be discriminated against for exercising your rights.
To exercise your rights, contact us at info@reviewhelden.com. We may need to verify your identity before fulfilling requests. Authorized agents may submit requests where permitted by law.
5. Data Sharing
- Service providers: trusted vendors (e.g., hosting, email/SMS delivery, analytics, customer support) under contractual confidentiality and data-processing obligations.
- Third-party integrations: connections to platforms (e.g., Google, Facebook, Booking, TripAdvisor, Yelp, Trustpilot) to collect/display reviews or share content, per your configuration.
- Legal reasons: when required to comply with law, enforce our terms, or protect rights, safety, and security of users or the public.
- Business transfers: in connection with a merger, acquisition, financing, or sale of assets, subject to ongoing privacy safeguards.
6. Data Security
We implement appropriate technical and organizational measures to protect personal data against unauthorized access, alteration, disclosure, or destruction. However, no system is completely secure, and we cannot guarantee absolute security.
7. Data Retention
We retain personal data only as long as necessary for the purposes described above, to comply with legal obligations, resolve disputes, and enforce agreements. Retention periods may vary based on data type and legal requirements.
8. International Data Transfers
If personal data is transferred across borders, we will implement appropriate safeguards (e.g., Standard Contractual Clauses, adequacy decisions) as required by applicable law.
9. Changes to This Privacy Policy
We may update this Privacy Policy from time to time. Material changes will be communicated via the platform or email. The “Last updated” date reflects the latest revision.
10. Contact Information
For questions or requests regarding this Privacy Policy or our processing of personal data, contact us at: info@reviewhelden.com
If you are located in the EU/EEA/UK: For non-essential cookies and certain marketing uses, we rely on your consent. For essential processing, we rely on contract or legitimate interests. See also our Cookie Policy for details.
