Privacy Policy

Reviewdar is committed to protecting your privacy and complying with UK GDPR and the Data Protection Act 2018. This policy explains what information we collect, how we use it, and your rights regarding your data.

1. Data Controller

Reviewdar is operated by Workdeskpro Ltd, a company registered in England and Wales (Company Number: 08637510).

Registered Address: 8 Chantilly Corner, Cranfield, Bedford, England, MK43 0YT
Data Protection Contact: [email protected]

2. Information We Collect

2.1 Information You Provide

  • Account Information: Name, email address, phone number, job title, and company details when you register or update your profile.
  • Business Information: Business name, address, industry type, and location details for each business location you add.
  • Payment Information: Billing address and payment method details. Note: Full card details are processed and stored by our payment processor, Stripe, not by us.
  • Communications: Information you provide when contacting support, providing feedback, or participating in surveys.
  • Team Member Information: Names and email addresses of team members you invite to your account.

2.2 Information from Connected Platforms

When you connect third-party review platforms, we collect:

  • Google Business Profile: Business listings, reviews, ratings, reviewer names (as displayed publicly), review dates, and your responses.
  • Facebook: Page reviews, ratings, and recommendations from your connected Facebook Pages.
  • Trustpilot, Yelp, Tripadvisor: Public reviews and ratings associated with your business listings.

We only access data you explicitly authorize through OAuth connections or by providing your business identifiers. We never access your personal social media profiles.

2.3 Automatically Collected Information

  • Usage Data: Pages visited, features used, clicks, time spent on pages, and navigation patterns within Reviewdar.
  • Device Information: Browser type and version, operating system, device type, screen resolution, and language preferences.
  • Log Data: IP address, access times, referring URLs, and error logs for security and troubleshooting purposes.

3. Legal Basis for Processing

Under UK GDPR, we process your personal data based on the following legal grounds:

PurposeLegal Basis
Providing the Reviewdar servicePerformance of contract
Processing paymentsPerformance of contract
Sending service notificationsPerformance of contract
Customer supportPerformance of contract / Legitimate interest
Security and fraud preventionLegitimate interest
Product improvement and analyticsLegitimate interest
Marketing communicationsConsent (you can opt out anytime)
Legal complianceLegal obligation

4. How We Use Your Data

4.1 Core Service Delivery

  • Aggregating and displaying reviews from connected platforms
  • Performing sentiment analysis and generating insights
  • Generating AI-powered response suggestions
  • Providing analytics, reports, and dashboards
  • Sending notifications about new reviews and important updates
  • Managing your subscription and processing payments

4.2 AI Processing

We use artificial intelligence services to:

  • Analyze review sentiment (positive, negative, neutral)
  • Extract topics and themes from reviews
  • Generate suggested responses to reviews
  • Identify actionable insights and improvement opportunities

Important: Review text may be sent to third-party AI providers (OpenAI, Anthropic) for processing. These providers process data according to their data processing agreements with us and do not use your data to train their models. We have Data Processing Agreements (DPAs) in place with all AI providers.

4.3 Communication

  • Transactional emails: Account confirmations, password resets, billing receipts, and service notifications.
  • Product updates: New features, changes to the service, and important announcements.
  • Marketing: Tips, best practices, and promotional content (only with your consent; unsubscribe anytime).

5. Data Sharing and Third Parties

We share your data only with the following categories of recipients:

5.1 Service Providers

  • Stripe: Payment processing (PCI-DSS compliant)
  • Google: OAuth authentication and Google Business Profile integration
  • OpenAI / Anthropic: AI-powered analysis and response generation
  • Postmark / Resend: Transactional email delivery
  • Cloud hosting providers: Data storage and infrastructure

All service providers are contractually bound to protect your data and use it only for the purposes we specify.

5.2 Connected Platforms

When you post responses through Reviewdar, your response content is sent to the relevant platform (e.g., Google) and becomes subject to their privacy policies.

5.3 Legal Requirements

We may disclose data if required by law, court order, or to protect our legal rights, safety, or property.

5.4 Business Transfers

In the event of a merger, acquisition, or sale of assets, your data may be transferred as part of the transaction. We will notify you of any such change.

We never sell your personal data to third parties.

6. International Data Transfers

Your data may be transferred to and processed in countries outside the UK, including the United States (where some of our service providers are located).

When we transfer data internationally, we ensure appropriate safeguards are in place:

  • Standard Contractual Clauses (SCCs) approved by the UK ICO
  • Data Processing Agreements with all processors
  • Adequacy decisions where applicable

7. Data Retention

Data TypeRetention Period
Account informationDuration of account + 2 years after deletion
Review dataDuration of account + 30 days after deletion
Payment records7 years (legal requirement)
Support communications3 years from last interaction
Usage analytics2 years (aggregated indefinitely)
Security logs1 year

You can request earlier deletion of your data (except where we have legal obligations to retain it).

8. Data Security

We implement robust security measures to protect your data:

  • Encryption: All data is encrypted in transit (TLS 1.3) and at rest (AES-256)
  • Access Controls: Role-based access with multi-factor authentication for staff
  • Infrastructure: Hosted on secure, SOC 2 compliant cloud infrastructure
  • Monitoring: 24/7 security monitoring and intrusion detection
  • Audits: Regular security assessments and penetration testing
  • OAuth Tokens: Platform access tokens are encrypted and stored securely

9. Your Rights Under UK GDPR

You have the following rights regarding your personal data:

  • Right of Access: Request a copy of the personal data we hold about you
  • Right to Rectification: Correct inaccurate or incomplete data
  • Right to Erasure: Request deletion of your data ("right to be forgotten")
  • Right to Restrict Processing: Limit how we use your data
  • Right to Data Portability: Receive your data in a machine-readable format
  • Right to Object: Object to processing based on legitimate interests
  • Rights Related to Automated Decision-Making: Request human review of automated decisions
  • Right to Withdraw Consent: Where processing is based on consent, withdraw it at any time

To exercise any of these rights, contact us at [email protected]. We will respond within 30 days.

You also have the right to lodge a complaint with the Information Commissioner's Office (ICO) at ico.org.uk.

10. Cookies and Tracking

We use cookies and similar technologies for:

  • Essential cookies: Required for the platform to function (authentication, security, preferences)
  • Analytics cookies: Understanding how you use Reviewdar to improve the service
  • Preference cookies: Remembering your settings and preferences

We do not use advertising or tracking cookies. You can manage cookie preferences through your browser settings. Note that disabling essential cookies may prevent the platform from functioning correctly.

11. Children's Privacy

Reviewdar is a business service not intended for individuals under 18 years of age. We do not knowingly collect personal data from children. If you believe we have inadvertently collected such data, please contact us immediately.

12. Changes to This Policy

We may update this Privacy Policy to reflect changes in our practices or legal requirements. We will notify you of material changes via email or in-app notification at least 30 days before they take effect.

You can view previous versions of this policy by contacting us at [email protected].

13. Contact Us

For privacy-related inquiries, data requests, or complaints:

Email: [email protected]
General Support: [email protected]
Address: Workdeskpro Ltd, 8 Chantilly Corner, Cranfield, Bedford, MK43 0YT, United Kingdom


Last updated: January 2025

Reviewdar is a trading name of Workdeskpro Ltd, a company registered in England and Wales (Company Number: 08637510).