1. Introduction
AI Review Manager ("we," "us," or "our") respects your privacy and is committed to protecting your personal information. This Privacy Policy explains how we collect, use, store, and protect your data when you use our Service.
Key Principle: We collect only the data necessary to provide our automated review response service. We never sell your data to third parties.
2. Information We Collect
2.1 Information You Provide
- Account Information: Email address, business name, contact details
- Payment Information: Credit card details (processed securely by Stripe, not stored by us)
- Business Information: Google Business Profile details, business category, location
2.2 Information Collected Automatically
- OAuth Tokens: Access tokens and refresh tokens from Google OAuth 2.0 (securely encrypted)
- Review Data: Customer reviews from your Google Business Profile, including reviewer names, review text, ratings, and timestamps
- Usage Data: Service usage metrics, feature interactions, response analytics
- Technical Data: IP address, browser type, device information, cookies
2.3 Third-Party Data
- Google Business Profile: We access your Google Business Profile data through authorized OAuth 2.0 integration
- Stripe: Payment processing information (we do not store credit card numbers)
3. How We Use Your Information
| Purpose |
Data Used |
| Provide automated review responses |
Review data, business information, OAuth tokens |
| Generate AI-powered responses |
Review content, business category, tone preferences |
| Send negative review alerts |
Email address, review data, sentiment analysis |
| Process payments |
Payment information (via Stripe) |
| Improve our Service |
Usage data, analytics, feedback |
| Customer support |
Account information, support inquiries |
| Security and fraud prevention |
Technical data, IP addresses, usage patterns |
4. Data Storage and Security
4.1 Where We Store Data
- Primary Infrastructure: Cloudflare (global network with data centers worldwide)
- Database: Cloudflare KV (key-value storage)
- Payment Processing: Stripe (PCI-DSS compliant)
4.2 Security Measures
- Encryption: All data in transit uses TLS/SSL encryption
- OAuth 2.0: Secure authentication without storing passwords
- Access Control: Restricted access to customer data by authorized personnel only
- Token Security: OAuth tokens are encrypted at rest
- Regular Audits: Security monitoring and vulnerability assessments
4.3 Data Retention
We retain your data for as long as your account is active plus:
- Review Data: 12 months after account cancellation (for analytics and compliance)
- Account Information: 90 days after account cancellation
- Payment Records: 7 years (for tax and legal compliance)
5. Data Sharing and Disclosure
5.1 We Share Data With:
- Google: To access your Google Business Profile and post responses (via authorized API)
- Stripe: To process payments securely
- OpenAI: To generate AI-powered review responses (review text only, no personal identifiable information)
- Cloudflare: Infrastructure and hosting services
5.2 We Do NOT:
- Sell your personal information to third parties
- Share your data with advertisers
- Use your data for purposes beyond providing the Service
5.3 Legal Disclosure
We may disclose your information if required by law, court order, or to:
- Comply with legal obligations
- Protect our rights or property
- Prevent fraud or abuse
- Protect user safety
6. Cookies and Tracking
We use cookies and similar technologies to:
- Essential Cookies: Required for authentication and Service functionality
- Analytics Cookies: Google Analytics (G-VTBMJW5333) to understand usage patterns
- Preference Cookies: Remember your settings and preferences
You can control cookies through your browser settings, but disabling essential cookies may affect Service functionality.
7. Your Rights and Choices
You Have the Right To:
- Access: Request a copy of your personal data
- Correction: Update inaccurate or incomplete information
- Deletion: Request deletion of your data (subject to legal retention requirements)
- Portability: Export your data in a machine-readable format
- Opt-Out: Unsubscribe from marketing emails (service emails required for account management)
- Revoke Access: Disconnect your Google Business Profile at any time through your Google Account settings
To exercise these rights, contact us at privacy@ai-review-manager.com
8. Third-Party Services
Our Service integrates with third-party services that have their own privacy policies:
9. Children's Privacy
Our Service is not intended for individuals under 18 years of age. We do not knowingly collect personal information from children. If you believe we have collected data from a child, please contact us immediately.
10. International Data Transfers
Your data may be transferred to and processed in countries outside your country of residence, including the United States. We ensure appropriate safeguards are in place to protect your data in accordance with this Privacy Policy.
11. Changes to This Privacy Policy
We may update this Privacy Policy from time to time. We will notify you of material changes by:
- Email notification
- Notice on our website
- In-Service notification
Your continued use of the Service after changes take effect constitutes acceptance of the updated Privacy Policy.
12. GDPR Compliance (European Users)
If you are located in the European Economic Area (EEA), you have additional rights under the General Data Protection Regulation (GDPR):
- Legal Basis: We process your data based on: (a) your consent, (b) performance of a contract with you, (c) our legitimate business interests, or (d) compliance with legal obligations
- Right to Access: Request a copy of all personal data we hold about you
- Right to Rectification: Correct any inaccurate personal data
- Right to Erasure: Request deletion of your personal data ("right to be forgotten")
- Right to Restriction: Request that we limit the processing of your data
- Right to Data Portability: Receive your data in a structured, machine-readable format
- Right to Object: Object to processing based on legitimate interests
- Right to Withdraw Consent: Withdraw consent at any time where processing is based on consent
To exercise any of these rights, contact us at privacy@ai-review-manager.com. We will respond within 30 days.
Data Protection Officer: Andrii Marenkov — privacy@ai-review-manager.com
13. CCPA Compliance (California Residents)
If you are a California resident, the California Consumer Privacy Act (CCPA) provides you with additional rights:
- Right to Know: Request information about the categories and specific pieces of personal information we have collected
- Right to Delete: Request deletion of your personal information
- Right to Opt-Out: Opt out of the sale of your personal information (note: we do NOT sell personal information)
- Right to Non-Discrimination: We will not discriminate against you for exercising your CCPA rights
To submit a CCPA request, email us at privacy@ai-review-manager.com with the subject line "CCPA Request".
14. Google API Services User Data Policy Compliance
Important: AI Review Manager's use and transfer of information received from Google APIs adheres to the
Google API Services User Data Policy, including the Limited Use requirements.
14.1 Data We Access from Google Business Profile
When you connect your Google Business Profile, we access the following data:
- Business Information: Business name, address, phone number, hours of operation, website, business category
- Customer Reviews: Review text, reviewer name (public), star rating, review date, review language
- Review Responses: Existing responses to reviews (if any)
- Business Photos: Profile photos and cover images (for display purposes only)
14.2 How We Use Google API Data
Data accessed from Google APIs is used exclusively for:
- Displaying Reviews: Show your reviews in your AI Review Manager dashboard
- Generating Responses: Create AI-powered responses tailored to each review
- Posting Responses: Publish approved responses to your Google Business Profile
- Analytics & Reporting: Provide insights on review sentiment, response rates, and trends
- Notifications: Alert you about new reviews, especially negative ones requiring attention
14.3 Limited Use Requirements
We strictly comply with Google's Limited Use requirements:
- No Sale of Data: We do not sell, rent, or trade any data obtained from Google APIs
- No Advertising: We do not use Google API data for serving advertisements
- No Human Reading: Review data is processed automatically by AI; no human reads your reviews unless you request support
- Minimal Data Transfer: Review text is sent to Claude AI (Anthropic) only for generating responses - no other personal identifiable information is shared
- Purpose Limitation: Data is used solely for providing our core review management service, not for any unrelated purposes
14.4 Data Security for Google API Data
- OAuth 2.0: We use Google's secure OAuth 2.0 protocol - we never see or store your Google password
- Encrypted Tokens: OAuth access tokens are encrypted at rest and in transit
- Token Revocation: You can revoke AI Review Manager's access anytime through your Google Account permissions page
- Automatic Cleanup: When you disconnect your account, we delete all Google API data within 30 days
14.5 Your Control Over Google Data
You maintain full control over your Google Business Profile data:
- Revoke Access Anytime: Disconnect AI Review Manager through Google Account settings or your dashboard
- Request Data Deletion: Email privacy@ai-review-manager.com to delete all stored Google API data
- Export Your Data: Request a copy of data we've accessed from your Google Business Profile
- Granular Permissions: During OAuth, you can see exactly what permissions we request
14.6 Third-Party AI Processing
To generate review responses, we send review text to:
- Claude AI (Anthropic): Review text only is sent to generate responses. Anthropic does not store or use this data to train models. See Anthropic's Privacy Policy
- Data Minimization: We send only the review text and business category - no customer names, emails, or personal identifiable information
15. Contact Us
If you have questions or concerns about this Privacy Policy or our data practices, please contact us:
Email: privacy@ai-review-manager.com
General Inquiries: contact@ai-review-manager.com