Legal
Privacy Policy
Effective from 25 September 2026. Version 2.0.
This policy covers thereviews.net, the business dashboard, the widgets, the API, and every email we send. It is written for the person whose data it is. Where a sentence would need a lawyer to decode, we have tried again.
1. Who we are
TheReviews, a TJG venture operated by Ikaroa is the data controller for the service (“we”, “TheReviews”). Registered address available on request. For anything in this policy, write to email@thereviews.net.
Two roles, and it matters which one applies to you:
- For reviewers, visitors, business users and anyone who receives an email from us, we are an independent controller. We decide what is collected and why, and this policy is the whole story.
- For the customer lists a business uploads or connects so that we can send review invitations, we are a processor acting on the business's instructions until the moment the customer clicks through and creates an account with us. The business is the controller of that list, and our obligations to the business are in the Data Processing Addendum. Once you create an account, we become the controller of your account and your review, as above.
2. What we collect and why
2.1 Reviewer accounts
- Name, email address, a bcrypt hash of your password, country, and an optional bio. We need these to run your account and to show a name next to your reviews. Your email address is never shown publicly and never given to a business.
- A session record. When you sign in we set a session cookie that lasts 30 days. The database holds a hash of the session token, not the token itself, and the record is deleted 30 days after your last activity.
- Sign-in and password-reset tokens. Stored as SHA-256 hashes, single use, and expired within an hour.
2.2 Reviews
- Your rating, title, text, the date, and every edit. Published under your display name, by design. Reviews are your content, licensed to us to display; the licence terms are in the Terms and Conditions. A business cannot pay to remove a review, and we do not remove reviews on request from a business except for the reasons in the guidelines.
- Whether the review is verified. A verified review arrived through an invitation, our API, or a store integration tied to a real order. For those we hold the order reference the business gave us. Organic reviews carry no order data.
- A keyed hash of your IP address and a keyed hash of your browser fingerprint at the time you post. The hash is HMAC-SHA256 under a secret key that is held separately from the database and is never stored with the data. The raw IP address and the raw fingerprint are not written anywhere. We use the hashes for one thing: spotting several reviews from the same network or device inside a short window, and reviews of a business sent from the network that claimed it. The fraud signals we look for, and the points each one scores, are published on the trust page. The public log shows the signal name, never the hash.
- The moderation record. Every hold, publication, edit, removal, restoration and report is written to a public log with the date and the reason category. The log never contains your email address or any hash.
- Reports you make about other reviews. Kept with the review so a moderator can act on them. The person you report does not learn who reported them.
- Editor's reviews are written by our staff after a visit we paid for ourselves. They are signed by the team, not by a personal account, and no reviewer data is involved.
2.3 Business accounts
- Your name, work email address, the organisation, your role, and the plan. To run the dashboard and to know who is allowed to act for which business.
- Verification evidence. A confirmed email address at the business's domain, or a DNS record, kept while the claim stands so we can show why the profile is marked as claimed.
- Billing. Payments go through Stripe. Card numbers are entered on Stripe's pages and never reach our servers. We hold your Stripe customer reference, the plan, the interval and the invoice history Stripe reports back to us.
- API keys, webhook endpoints and integration secrets. API keys are stored as a SHA-256 hash plus their first twelve characters; secrets are stored hashed or encrypted. We record when a key was last used.
- Session IP hashes. Used in a single fraud check, described in 2.2: whether a review of your business was sent from a network your team has signed in from. Hashed, never raw.
- Connected review sources. On a paid plan you can connect Google, Facebook, Trustpilot and Yelp through those platforms' official interfaces. We store the access token the platform issues, encrypted, and the reviews we fetch: rating, text, author display name, date and the link back. Imported reviews are shown with their source label and never count towards the score. Google's terms do not allow Places content to be cached beyond 30 days, so those rows carry an expiry and are refreshed or dropped.
2.4 People a business invites to review
- Email address, an optional name, an order reference, and the order date. Supplied by the business through its store integration, the API, a CSV upload or the dashboard, so that we can send one invitation for that order. We store the invitation, whether it was sent, opened and used, and the expiry. Invitation links expire after 30 days.
- The invitation email itself is sent through Open Doors, a CRM operated by Ikaroa on the LeadConnector platform, with Mailgun as the mail carrier. Your email address and name are stored as a contact in Open Doors so that the email can be sent and its delivery tracked. Section 5 has the detail.
- Your unsubscribe. Every invitation and notification carries an unsubscribe link. Using it adds your address to a suppression list that we keep indefinitely, because the only way to honour an unsubscribe is to remember it. No business can see or clear that list.
2.5 Website visitors
- Request logs. Our hosting provider, Vercel, records the IP address, user agent and URL of each request for security and debugging. We do not copy these into our own database and they are not kept beyond 30 days.
- Counts, not visitors. We count profile views and widget views per business per day. There is no record of who viewed what.
- No advertising trackers and no third-party analytics. The Cookie Policy lists the two cookies we set.
2.6 Email recipients
A moderation notice to a reviewer, a new-review alert to a business owner, an invitation to a customer: each is sent through Open Doors and carried by Mailgun. Those systems record that the message was sent, whether it bounced, and whether it was opened where your mail client reports that. Every email carries an unsubscribe link. Unsubscribing from notifications does not close your account; you can still sign in.
3. The legal basis for each use
Under the UK GDPR and the EU GDPR we need a lawful basis for each thing we do. Here they are, without hedging.
| What we do | Lawful basis |
|---|---|
| Running your account, publishing your review, showing your display name | Performance of our contract with you (the Terms and Conditions) |
| Running a business account, billing, the dashboard, the API and widgets | Performance of our contract with the business (the Terms for Businesses) |
| Hashing IP and device values, scoring fraud signals, holding suspicious reviews | Our legitimate interest in keeping fake reviews off the site, which is the whole point of the site. We judged that a keyed hash, with the raw value never stored, is the least intrusive way to do it. |
| Keeping a public moderation log | Our legitimate interest in a review platform whose decisions can be checked by anyone, and the public interest in that |
| Sending a review invitation on a business's behalf | We act as the business's processor. The business is responsible for its own basis, usually the existing-customer exemption for its own products, or consent. |
| Sending you notices about your own reviews or account | Performance of our contract with you |
| Keeping the unsubscribe suppression list | Legal obligation: we must honour an unsubscribe, and the only way to do that is to keep the address |
| Keeping invoices and payment records | Legal obligation under tax and accounting law |
| Responding to a court order, a regulator or a valid legal request | Legal obligation |
| Fetching reviews from a connected Google, Facebook, Trustpilot or Yelp source | Performance of our contract with the business, which must hold the rights to connect the source. The reviews themselves are already public on the source platform. |
We never rely on consent for anything essential to the service, because consent you cannot refuse is not consent. Where we do rely on legitimate interest, you can object; section 8 says how.
4. Cookies
We set two cookies, both essential: tr_session, which keeps you signed in for 30 days, and tr_business, which remembers which business the dashboard is showing. We keep your cookie preference in your browser's local storage, not in a cookie. We run no advertising cookies and no third-party analytics, and the review widgets set no cookies on the sites that embed them. Stripe sets its own cookies on its own checkout pages. The full list, and the control to manage your preferences, is on the Cookie Policy page.
5. Who else sees your data
5.1 The public
Your published reviews, your display name, your country, your review count and the moderation log are public. That is what a review site is. A review may also appear in a business's widget on its own site, in our emails, and through our API, always attributed to your display name and linked back to the original.
5.2 Businesses
A business sees published reviews of its profile and the reviewer's public profile. For a verified review it also sees its own order reference, because it supplied it. It never sees your email address, your IP hash, your account details, or a review that has been held.
5.3 Processors we use
These companies process data for us, on our instructions, under written terms. We do not sell personal data and we do not share it with advertisers.
| Provider | What it does | Where |
|---|---|---|
| Vercel | Hosts the website, the dashboard and the API, and keeps short-lived request logs | United States |
| Neon | Runs the Postgres database that holds accounts, reviews, invitations and the log | United States, region us-east-1 at the time of writing |
| Open Doors (operated by Ikaroa on the LeadConnector platform) | Stores email contacts and sends every transactional email: invitations, notices, sign-in links | United States |
| Mailgun | The mail carrier behind Open Doors. Handles delivery, bounces and complaints | United States |
| Stripe | Takes payment for business plans. Card data is entered on Stripe's pages and never reaches us | United States, with EU entities for EU customers |
5.4 Review platforms a business connects
When a business connects Google, Facebook, Trustpilot or Yelp, we call that platform's official API with the credentials the business authorised. Data flows towards us, not away: we receive reviews that are already public on that platform. We do not send reviewer data from TheReviews to those platforms.
5.5 The law
We disclose data where a court order, a regulator with the power to compel, or a law requires it. We check that the request is valid and as narrow as it claims to be. We tell you, unless the law prohibits it or telling you would put someone at risk. The number of legal requests we receive, and how many led to a removal, is published each quarter on the transparency page.
5.6 If the business changes hands
If TheReviews is sold or merged, the data goes with it under this policy, and we tell account holders before it happens.
6. Where data is stored and international transfers
Our database and hosting are in the United States. The Neon region is us-east-1 today; if that changes, this section will. Email contacts sit in Open Doors and Mailgun, also in the United States. That means data about people in the United Kingdom and the European Economic Area is transferred outside those territories.
For transfers from the United Kingdom we rely on the International Data Transfer Agreement (IDTA) or the UK Addendum to the EU Standard Contractual Clauses. For transfers from the EEA we rely on the EU Standard Contractual Clauses. Where a provider is certified under the EU-US Data Privacy Framework or its UK extension, we rely on that in addition. You can ask for a copy of the clauses we hold with each provider at email@thereviews.net; commercial terms will be redacted.
7. How long we keep things
| Data | Kept for | Then |
|---|---|---|
| Account details | Until you delete your account from settings | Deleted. Backups roll off within 30 days. |
| Published reviews | While the business profile exists, unless you delete the review first | Deleted. The log keeps a dated entry without the text. |
| Removed reviews | The log entry, without the text, is kept for 24 months | Log entry stays as a dated record; the text is gone from the point of removal |
| Keyed IP and device hashes on a review | 24 months | Cleared from the review; the review stays |
| Sessions | 30 days from last activity | Deleted |
| Invitation records (email, name, order reference, status) | 24 months from the send date | Deleted. Monthly counts stay for the business's statistics. Enterprise contracts can set a shorter period. |
| Unsubscribe suppression list | Indefinitely | Kept, so that the unsubscribe holds |
| Webhook delivery logs (payloads sent to a business's endpoint) | 30 days | Deleted |
| Reports and evidence | 12 months after the report is resolved | Deleted |
| Imported reviews from a connected source | While the source stays connected. Google Places content, 30 days at most before refresh | Deleted when the source is disconnected |
| Invoices and payment records | Six years, as tax law requires | Deleted |
| Hosting request logs | No more than 30 days | Deleted by Vercel |
8. Your rights
Under the UK GDPR and the EU GDPR you can ask us to:
- give you a copy of the personal data we hold about you (access);
- correct it (rectification);
- delete it (erasure);
- stop or limit what we do with it (restriction);
- give it to you in a machine-readable form (portability);
- stop processing that rests on legitimate interest (objection).
Most of this you can do yourself, without asking. Your account settings let you change your details, edit or delete individual reviews, and delete your account altogether. When you delete your account, your reviews are deleted, the business's score is recomputed without them, and your name is replaced with “a former reviewer” on any business reply.
For anything else, email email@thereviews.net from the address on your account. We answer within 30 days. If a request is complicated we may take longer, and we will tell you within the first 30 days if so. We do not charge for requests unless they are plainly repetitive.
One limit, stated plainly rather than hidden. If you delete a review, or ask us to, the moderation log keeps the dated fact that a review existed and what happened to it. That entry does not contain the text and does not identify you. The log is the product's audit trail and we do not take entries out of it except for a legal reason, in which case the gap itself is shown.
If you object to fraud checking, we will consider the objection, but be candid: a review that cannot be checked for fraud cannot be published, because publishing unchecked reviews would defeat the purpose of the platform for everyone else.
9. How we protect it
Passwords are hashed with bcrypt. Session tokens are 40 random characters, held in an httpOnly, Secure cookie, and stored server-side only as a SHA-256 hash. One-time tokens are single use and expire within the hour. API keys are stored hashed. Outbound webhooks are signed with HMAC-SHA256 so a business can verify they came from us. All traffic is over TLS. Access to the production database is limited to the people who run the service. None of this is a guarantee; it is the current list, and we update it when it changes.
10. Children
You must be 18 or over to hold an account or post a review. We do not knowingly collect data from anyone younger. If you believe we hold an account for someone under 18, tell us at email@thereviews.net and we will close it and delete the data.
11. Changes to this policy
Each version carries its number and effective date at the top. Changes that matter to you (a new processor, a new use of data, a longer retention period) are announced on the transparency page 30 days before they take effect and emailed to account holders. Corrections and clarifications that do not change what we do are published straight away.
12. Contact and complaints
Controller: TheReviews, a TJG venture operated by Ikaroa. Registered address available on request. Email: email@thereviews.net.
If you are unhappy with how we have handled your data, we would like the chance to put it right first. You also have the right to complain to a supervisory authority. In the United Kingdom that is the Information Commissioner's Office (ico.org.uk). In the European Economic Area it is the data protection authority of the country where you live or work; the European Data Protection Board keeps the list at edpb.europa.eu. Complaining to us first is not a condition of complaining to them.