Privacy Policy

Last updated: 26 May 2026

EasyReviewsAI ("we", "us", or "our") is operated by Altivex Technologies Limited. This Privacy Policy explains how we collect, use, and protect information when you use our platform at easyreviews.ai. It also describes your rights under the General Data Protection Regulation (GDPR) and other applicable privacy laws.

1. Data Controller

The data controller responsible for your personal data is:

Altivex Technologies Limited
Email: contact@easyreviews.ai

2. Information We Collect

Account information: When you register, we collect your name, email address, and password (hashed).

Business information: Business name, address, category, Google Place ID, and logo.

Customer review data: When customers scan your QR code and submit a review or feedback, we collect the star rating, review text, and optionally their name and phone number (only if they choose to provide it).

Usage data: QR code scan events, page visits, and feature usage to help improve the service.

Payment information: Subscription and payment processing is handled by Razorpay. We do not store your card details. We only store transaction IDs and subscription status.

3. Legal Basis for Processing

We process your personal data on the following legal grounds under GDPR Article 6:

  • Contract (Art. 6(1)(b)): Processing your account and business information is necessary to provide the EasyReviewsAI service you have signed up for.
  • Legitimate interests (Art. 6(1)(f)): We process usage data to improve our platform, detect abuse, and ensure security. These interests do not override your rights.
  • Legal obligation (Art. 6(1)(c)): We may retain billing records where required by applicable financial regulations.
  • Consent (Art. 6(1)(a)): Where we use non-essential cookies or send marketing communications, we rely on your explicit consent, which you may withdraw at any time.

4. How We Use Your Information

  • To provide and operate the EasyReviewsAI platform
  • To send review feedback to your business dashboard
  • To process subscription payments via Razorpay
  • To send transactional emails (account confirmation, billing receipts)
  • To improve our AI review enhancement features
  • To respond to your support requests

5. AI Features

Our "Enhance with AI" feature sends review text to an AI model to improve its quality before the customer posts it to Google. This text may be processed by our AI provider (Anthropic). We do not associate the review text with any personally identifiable information during this process.

6. Third-Party Processors

We share data only with the following sub-processors. Each has been assessed for GDPR compliance:

  • Supabase (database and authentication) — data stored on AWS infrastructure in your selected region. Privacy policy
  • Razorpay (payment processing) — PCI DSS Level 1 certified. We share only the minimum data needed to process subscriptions. Privacy policy
  • Anthropic (AI text enhancement) — review text is sent without personally identifiable information. Privacy policy
  • Google (Google Maps Places API, Google Reviews) — used to validate business details and redirect customers to your Google review page. Privacy policy

We do not sell your personal data to any third party.

7. Data Retention

  • Account and business data: Retained for the duration of your active account plus 30 days after account closure, to allow for recovery. Permanently deleted after this period.
  • Review and feedback data: Retained while your account is active. Deleted when you delete your account or upon request.
  • Billing records: Retained for 7 years where required by applicable tax and financial regulations.
  • Usage/analytics data: Aggregated and anonymised after 12 months; individual event logs deleted after 90 days.

8. Cookies

We use essential cookies for authentication (session management). We do not use tracking or advertising cookies. A cookie consent banner is shown on your first visit; you may reject non-essential cookies at any time.

9. Security

All data is encrypted in transit (HTTPS/TLS). Passwords are hashed using bcrypt and never stored in plain text. Access to your data is restricted to authenticated users only via row-level security (RLS) enforced at the database level.

10. Your Rights (GDPR)

If you are located in the European Economic Area (EEA), the United Kingdom, or another jurisdiction with similar privacy laws, you have the following rights:

  • Right of access (Art. 15): You may request a copy of all personal data we hold about you. Use the "Download my data" feature in Settings, or email us.
  • Right to rectification (Art. 16): You may correct inaccurate data at any time via your account Settings.
  • Right to erasure / "right to be forgotten" (Art. 17): You may delete your account and all associated data at any time via Settings. Some billing records may be retained as required by law.
  • Right to restriction of processing (Art. 18): You may request that we limit processing of your data in certain circumstances.
  • Right to data portability (Art. 20): You may download your data in machine-readable JSON format via the "Download my data" feature in Settings.
  • Right to object (Art. 21): You may object to processing based on legitimate interests at any time.
  • Right to withdraw consent: Where processing is based on consent (e.g., non-essential cookies), you may withdraw at any time without affecting prior processing.
  • Right to lodge a complaint: You have the right to lodge a complaint with your local supervisory authority (e.g., the ICO in the UK, or your country's data protection authority in the EEA).

To exercise any of these rights, email us at contact@easyreviews.ai. We will respond within 30 days.

11. International Transfers

Your data may be stored and processed in countries outside the EEA (including the United States) by our sub-processors. Where this occurs, we ensure appropriate safeguards are in place, including Standard Contractual Clauses (SCCs) as approved by the European Commission.

12. Children's Privacy

Our service is not directed to anyone under the age of 18. We do not knowingly collect personal data from minors.

13. Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of significant changes by email or by a notice on the platform. The "last updated" date at the top of this page reflects the most recent revision.

14. Contact Us

For any privacy-related questions or to exercise your rights, contact us at contact@easyreviews.ai or write to Altivex Technologies Limited.