Privacy Policy
Last updated
The short version
- To open an account we ask for one thing: your email address. There is no password — we sign you in with a code we email you.
- We use no advertising trackers, and the widgets we serve to your visitors carry no analytics and no cookies at all. On this website itself we use Google Analytics.
- We never sell personal data and never share it for advertising.
- Reviews from the platforms you connect reach us through their official APIs and are temporarily cached to show you — the platform stays the place they live.
- The only reviews we store are the ones collected through ReviewsPlugin itself, on your own website.
- You can disconnect a location or delete your account yourself, at any time, from inside the product.
This summary is a reading aid. The sections below are the policy itself, and they are what applies.
1. Who we are
ReviewsPlugin is a review management service operated by Rich Plugins SL. For the personal data described in this policy we are the data controller, except where we say we act on a customer's behalf — see section 8.
- Company: Rich Plugins SL
- CIF: B19806272
- Registered address: Plaza San Cristóbal, 14, 03002 Alacant/Alicante, Spain
- Email: support@reviewsplugin.com
We are established in Spain, so our supervisory authority is the Spanish data protection agency, the Agencia Española de Protección de Datos (AEPD).
2. Who this policy covers
This policy describes what we do with the personal data of three groups of people.
- Visitors to reviewsplugin.com, including anyone who tries the free widget builder without creating an account.
- Account holders — people who sign up and connect business locations, including merchants who install our Shopify app.
- People named in reviews we process — the authors of reviews on Google, Facebook, Yelp and Tripadvisor, and people who leave a review directly on a website that uses our widget.
If you are in the third group, you have rights here even though you have never used our service. Section 14 explains how to exercise them, and section 8 explains who to approach.
3. What we collect
3.1 When you use our website
Our home page lets you search for a business and preview a widget built from its real reviews. This works without an account, and we do not ask you for anything about yourself to use it.
- The business you search for. We send your search to the Google Places API to find the business, then fetch its publicly available reviews to render the preview.
- Your IP address, used as a counter so that one visitor cannot exhaust the free preview quota. The counter lives in our cache and expires by itself at the end of the quota window.
- Standard request data that every browser sends — IP address, user agent, referring page. Where this is written to technical logs, it is used for security and troubleshooting only.
- A reCAPTCHA check from Google, to tell people apart from automated abuse. The reCAPTCHA script is not loaded when the page opens; it loads only once you start building a preview.
- Google Analytics. We use it to understand how people find and use this website — which pages get visited, roughly where visitors come from, and on what kind of device. It sets cookies in your browser, and sends that data to Google, only once you have accepted it.
We run no advertising pixels, no session recording and no other third-party tracking. Google Analytics is on this website only: the widgets we serve to our customers' website visitors carry no analytics of any kind.
3.2 When you create an account
- Your email address. This is the only thing we require. We do not ask for your name, your company name or a password.
- Sign-in codes. Instead of a password we email you a one-time code, valid for a few minutes. We hold no password for your account, so there is no password of yours for anyone to steal from us.
- Workspace details you choose to enter — the business name shown in the product, and any logo or image you upload.
- Your widget configurations — the layouts, colours and settings you save.
- A session cookie, so you stay signed in. See section 9.
3.3 When you connect a review platform
Connecting a platform is always something you start and authorise. Until you do, we hold nothing from it.
- The credential that keeps the connection alive — a refresh token for Google, a Page Access Token for Facebook — together with the email address of the account you authorised, so we do not have to ask you to sign in again.
- The locations or pages you select — name, address, website, current rating and review count.
The reviews themselves are different, and this is the important part: ReviewsPlugin does not store them. We retrieve them from the platform through its official API when you use the service, and they are temporarily cached for a short period so the product stays responsive. The platform remains the place where those reviews live; we do not keep them as our own data.
Review authors are people, and their names and photos are personal data. While that data passes through our service, we use it only to show you the review and let you answer it — never for anything else.
3.4 Reviews collected through ReviewsPlugin
Our customers can collect reviews directly on their own website through our widget. These are the only reviews ReviewsPlugin stores. When a visitor leaves one, we store the display name they give, their photo or avatar if they provide one, the rating, the review text, the date and any images they attach.
For these reviews the website owner decides what is collected and what happens to it. We store and display them on that owner's instructions — see section 8.
3.5 Review request emails
Our customers can ask us to email their own customers inviting them to leave a review. In that case we process the recipient's email address, and their name where the customer supplies one, purely to deliver the message. Every such email carries a one-click unsubscribe link, and an address that unsubscribes receives no further review requests.
We do not build a marketing list of these recipients, we do not use their addresses for our own purposes, and we do not share them with anyone else.
3.6 When you install our Shopify app
Our Shopify app asks Shopify for no access to your store's data. It cannot read your customers, your orders, your products or your theme, and Shopify's install screen shows exactly that.
- Your store's
.myshopify.comaddress. Shopify signs it into every request the app makes, and we store it so your widgets can be found again on your next visit. - The widgets you build — the same layouts, colours and settings as any other workspace, and the business locations you connect to them.
- Your store's name and where it is based, read once and not kept. The first time you open the app it asks Shopify for the store name, city and country, purely to fill in the business search box for you. The answer goes to your browser and is never written down.
Installing any Shopify app also grants the developer access to the store owner's contact details. Our app never asks Shopify for them, so we do not receive or store them.
The widget on your storefront works the way it does anywhere else: a visitor's browser asks our servers for the reviews, so we see the request the same way we see one from any other website. Nothing about that visitor is written to your Shopify store, and nothing about your store is sent to anyone else.
Uninstalling the app tells us to stop. Shopify then asks us, on its own schedule, to erase the store's data, and we delete the widgets, the connected locations and the workspace itself — see section 12.
4. Why we process it, and our legal basis
| What | Why | Legal basis (GDPR Art. 6) |
|---|---|---|
| Email address and sign-in codes | To create your account and let you sign in | Performance of a contract, Art. 6(1)(b) |
| Connected locations, replies you post, widget settings | To provide the service you signed up for | Performance of a contract, Art. 6(1)(b) |
| OAuth tokens | To keep a connection you authorised working | Performance of a contract, Art. 6(1)(b) |
| Personal data inside reviews retrieved from platforms, while temporarily cached | So the business the review is about can read and answer it | Legitimate interests, Art. 6(1)(f) |
| Google Analytics on our website | To understand how the website is found and used | Consent, Art. 6(1)(a) |
| IP-based quotas, rate limits and reCAPTCHA | To keep the service available and prevent abuse | Legitimate interests, Art. 6(1)(f) |
| Service emails about your account | To tell you things you need to know to use the service | Performance of a contract, Art. 6(1)(b) |
| Reviews collected on a customer's website | On that customer's instructions | We act as processor — see section 8 |
| Review request emails | On that customer's instructions | We act as processor — see section 8 |
Where we rely on legitimate interests, we have weighed our interest in running the service against the rights of the people concerned. You can object to that processing at any time — see section 14.
5. Data we receive from Google
When you connect a Google Business Profile we ask for two permissions, and no more:
.../auth/business.manage— to read the locations and reviews of the profile you selected, and to post the replies you write or approve..../auth/userinfo.email— to record which Google account authorised the connection, so you can tell your connections apart and revoke the right one.
ReviewsPlugin's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
In practice that means:
- We use Google user data only to provide and improve the features you can see in the product.
- We do not store your Google review data. It is temporarily cached to provide those features, and is not retained by ReviewsPlugin as its own data. What we do keep is the refresh token that holds the connection open, until you disconnect.
- We do not sell it, and we do not use it for advertising of any kind.
- We do not use it to develop, improve or train generalised artificial intelligence or machine learning models. When you ask us to draft a reply, the review is sent to our AI provider to write that one reply for you and for nothing else — see section 7.
- No human at ReviewsPlugin reads your Google user data, except where you have asked us to, where it is necessary for security or to comply with the law, or where the data has been aggregated and made anonymous.
You can disconnect a location inside the product at any time, which deletes the tokens we hold for it. You can also revoke our access directly from your Google account at myaccount.google.com/permissions.
6. Data we receive from Facebook, Yelp and Tripadvisor
Connecting a Facebook Page uses the Facebook Graph API, and asks for the permissions needed to list the Pages you manage, read their reviews and recommendations, and post replies. We keep the Page Access Token, and the name and email of the Facebook account that authorised the connection. The reviews and recommendations themselves are retrieved through the API when you use the service and only temporarily cached — we do not store them.
Yelp and Tripadvisor content reaches us through the Yelp Fusion API and the Tripadvisor Content API, using our own API credentials. Connecting them does not involve signing in with your Yelp or Tripadvisor account, and gives us no access to any personal account of yours.
We obtain review data only through these official APIs. We do not crawl or scrape any of these platforms' websites.
To remove Facebook data, disconnect the Page in the product, or remove ReviewsPlugin under Settings → Apps and Websites in your Facebook account. You can also write to support@reviewsplugin.com and we will delete it.
7. AI-generated replies
The product can draft a reply to a review for you. This happens only when you ask for it, one review at a time — there is no background processing of your reviews by AI.
When you request a draft, we send to our AI provider, OpenAI:
- the review itself — its rating, text, date and the author's display name;
- the name and description of the location it belongs to;
- the tone, length and signature you selected.
OpenAI processes this as our service provider in order to return the draft. Under the OpenAI API terms that apply to us, data sent through the API is not used to train their models. The draft is shown to you, and you decide whether to edit it, publish it or discard it. We keep no separate record of the text sent for generation.
8. When we act on our customers' behalf
For two things in this policy, we are not the one deciding what happens to the data. The customer who uses ReviewsPlugin decides, and we act on their instructions: reviews collected on their own website (section 3.4) and review request emails sent to their customers (section 3.5). In data protection terms they are the controller and we are the processor.
If you left a review on a company's website, or received a review request from one, and you want that data corrected or deleted, the most direct route is to contact that company. You can also write to us at support@reviewsplugin.com: we will either act on it ourselves or pass your request to them promptly, and we will tell you which.
If you use ReviewsPlugin to collect reviews or send review requests, you are responsible for having a lawful basis to do so, and for telling the people concerned what you are doing with their data.
9. Cookies and browser storage
We use no advertising cookies anywhere. Apart from Google Analytics on this website, everything below is strictly necessary to make the service work.
| Name | Where | Purpose | Lifetime |
|---|---|---|---|
connect.sid |
Cookie, in the app | Keeps you signed in. Strictly necessary. | 7 days |
instant.build.v1 |
Local storage, on our website | Remembers the preview you were building so a reload does not lose it. | 30 days |
_ga, _ga_* |
Cookies, on our website | Google Analytics — tells us how the website is used. Not strictly necessary. | Up to 2 years, set by Google |
| reCAPTCHA | Our website and sign-in page | Google's check that you are not an automated script. Loaded only when you start building a preview or sign in. | Set by Google |
Google Analytics is the one item above that is not strictly necessary, so it runs on your consent and sets nothing until you give it. You can withdraw that consent at any time on our Cookie Policy page.
On our customers' websites, our widget sets no cookies at all. Two of the layouts — the flash popup and the badge — record in the browser's session storage that a visitor has dismissed them, so they do not reappear on every page. That record holds no identifier and is gone when the tab closes.
10. Who we share information with
We never sell personal data, and we never share it for advertising. We share it only with the service providers we need in order to run ReviewsPlugin, and only as far as each one needs.
| Who | What for | Where |
|---|---|---|
| Amazon Web Services | Hosting our servers, database and uploaded files | Norway (EEA) |
| Our email delivery provider | Sending sign-in codes, service emails and review requests | EEA or United States, depending on the provider in use |
| OpenAI | Drafting review replies, when you ask for one | United States |
| Google (reCAPTCHA) | Telling people apart from automated abuse | United States |
| Google (Analytics) | Measuring how our website is used | United States |
We may change email delivery provider from time to time; write to support@reviewsplugin.com if you need to know which one is in use.
Separately, when you act inside the product — publishing a reply, for instance — that content is sent to the platform the review came from, because that is the point of the action.
We will also disclose personal data where the law requires it, or to establish or defend legal claims. If ReviewsPlugin is ever sold or merged, personal data may transfer with the business; we would tell you before that happens and this policy would continue to apply until we told you otherwise.
11. Where we process your data
Our servers, database and file storage are hosted with Amazon Web Services in Norway. Norway is in the European Economic Area, so this data stays under the GDPR and no international transfer mechanism is needed for it.
Some things do leave the EEA. Replies drafted by AI involve sending the review to OpenAI in the United States, and both reCAPTCHA and Google Analytics involve Google in the United States. Depending on which email provider is in use, message delivery may also involve a transfer. These transfers are covered by the European Commission's Standard Contractual Clauses, and by the EU–US Data Privacy Framework where the provider is certified under it.
If we move our infrastructure outside the EEA, we will update this policy and put the appropriate safeguards in place before doing so.
12. How long we keep it
- Your account and workspace — for as long as the account exists. Delete the account and they go with it.
- OAuth tokens — until you disconnect the location or delete your account, whichever comes first.
- Reviews collected through ReviewsPlugin — while the location they belong to is connected and the account exists. Disconnect the location or delete the account and they go with it.
- Reviews from the platforms you connect — not retained. They are only temporarily cached while you use the service.
- Details of connected locations — name, address, rating and review count, for as long as the location is connected.
- Sign-in codes — a few minutes, then they expire and are discarded.
- Rate-limit and quota counters — until the window they belong to ends, typically hours.
- Session cookies — 7 days, or until you sign out.
- A Shopify store's workspace — until Shopify asks us to erase it, which it does after the app is uninstalled. We then delete the store's widgets, its connected locations and the workspace itself. Reinstall before that request arrives and your widgets are still there.
- Backups — deleted data can remain in our backups for up to 30 days after you delete it, after which those backups are overwritten and it is gone.
Where the law requires us to keep something for longer — accounting records, for instance — we keep only what the law asks for, and only for as long as it asks.
13. How we protect it
- All traffic to our website, the app and our API is encrypted in transit with TLS.
- Access to production systems is limited to the people who need it to operate the service.
- Session cookies are marked
Secure, so they are never sent over an unencrypted connection. - Because we use one-time email codes rather than passwords, we store no password database at all.
- OAuth tokens are stored so that they can be used by the service and are never exposed in the product interface or to your website visitors.
No service can promise perfect security, but if a breach ever affects your personal data we will notify the AEPD, and you, as the GDPR requires.
14. Your rights
Under the GDPR you have the right to:
- Access the personal data we hold about you, and receive a copy of it.
- Correct it, if it is wrong or incomplete.
- Erase it, in the circumstances the law provides for.
- Restrict or object to our processing, including any processing we base on legitimate interests.
- Portability — receive the data you gave us in a structured, machine-readable format.
- Withdraw consent at any time, where we relied on it. This does not affect what was lawful beforehand.
Some of these you can exercise yourself without asking us. You can disconnect any location, export your data to CSV, and delete your entire account from the product's settings — deletion asks you to confirm with an emailed code, then removes your account, your workspaces, your widgets, your uploads and the tokens for every platform you had connected.
For anything else, write to support@reviewsplugin.com. We answer within one month, free of charge. We may need to check that the request really comes from you before we act on it.
If you think we have handled your data badly, please tell us first — we would rather fix it. You also have the right to complain to the AEPD at aepd.es, or to the supervisory authority where you live or work.
15. Children
ReviewsPlugin is a tool for businesses and is not intended for children. We do not knowingly collect personal data from anyone under 16. If you believe a child's data has reached us, write to support@reviewsplugin.com and we will delete it.
16. Changes to this policy
We update this policy when the service changes. The date at the top always shows the current version. If a change materially affects how we handle your personal data, we will tell account holders by email before it takes effect, rather than relying on you to notice.
17. Contact us
For anything in this policy, including any request about your rights, write to support@reviewsplugin.com or by post:
Rich Plugins SL
Plaza San Cristóbal, 14
03002 Alacant/Alicante
Spain