Privacy Policy
Last updated: June 5, 2026
Introduction
ReviewFlow is operated by the ReviewFlow team. The platform includes the business owner dashboard and the customer review experience available through QR codes. This Privacy Policy explains how we collect, use, disclose, and protect personal information when you use our services.
The ReviewFlow team is committed to handling your data responsibly. We do not sell personal information to third parties.
Who This Policy Applies To
This policy covers:
- Business owners who create accounts, manage QR campaigns, and subscribe to our service.
- Customers who scan a QR code and submit a star rating or private feedback.
- Visitors who browse our marketing website.
Information We Collect
Business owner accounts. When you register, we collect your email address, password (stored securely by our authentication provider — we never store plaintext passwords), first and last name, and optional profile photo. If you sign in with Google, we receive your email address and basic profile information as permitted by your Google account settings. We also store your language, timezone, and date format preferences, as well as your email notification settings.
Business and campaign data. To operate your review funnels, we collect your business name, category, contact details, address, Google Business Profile review link, logo, flyer designs, uploaded images, and campaign status.
Subscription and payment data. Payments are processed by Lemon Squeezy, which acts as our Merchant of Record. We do not collect or store full payment card numbers. We retain subscription status, billing period dates, and the card brand and last four digits for display in your dashboard. All card processing takes place on Lemon Squeezy's secure checkout and customer portal.
Customer review data. When a customer scans an active QR code, we collect their email address and password (for email sign-up) or Google account information (for Google sign-in). We record the star rating selected. For ratings of one to three stars, we may collect an optional private feedback message and the customer's name and email at the time of submission. For ratings of four or five stars, we record the rating and redirect the customer to Google to leave their review — we do not capture the text of reviews posted on Google. We limit each email address to three ratings per QR campaign to prevent abuse.
Scan and usage data. When an active QR code is scanned, we log the time of the scan, browser type, the visitor's country (country only — we do not store full IP addresses), and a pseudonymous identifier to count unique visits before login. Once authenticated, scans are linked to the customer account. We also generate analytics for business owners, such as scan counts, review counts, conversion rates, and star distributions.
Technical diagnostics. We use error monitoring tools to diagnose application issues. Personal data such as email addresses and names is filtered before transmission. These tools are not used for advertising or behavioral profiling.
How We Use Your Information
We use the information we collect to:
- Provide, maintain, and improve the ReviewFlow platform.
- Authenticate users and manage sessions.
- Process subscriptions and billing events.
- Send transactional emails, such as account verification, password reset, billing alerts, and negative feedback notifications.
- Display campaign analytics to business owners.
- Detect and prevent abuse, including bot protection and review limits.
- Comply with legal obligations and enforce our Terms of Service.
Cookies and Similar Technologies
We use cookies and similar technologies to keep you signed in, remember your language preference, and measure QR scan activity. We also use browser session storage to temporarily preserve a flyer download request while you complete payment checkout; this data is cleared once the export finishes.
Our bot-protection provider may set its own cookies during verification on registration and review submission forms.
You can control cookies through your browser settings. Disabling essential cookies may prevent you from signing in or completing review flows.
How We Share Information
We share personal information only with service providers that help us operate the platform, including our hosting, database, authentication, email delivery, payment processing, and security providers. Each provider receives only the data necessary to perform its function.
Within the platform, private feedback (one to three stars) is delivered to the relevant business owner through an in-app inbox and email notification. Positive ratings (four or five stars) redirect customers to the business's Google review page; ReviewFlow does not receive the review text.
We may disclose information if required by law, court order, or to protect the rights, safety, and security of ReviewFlow, our users, or the public. We do not sell personal information.
Data Retention
We retain account data while your account is active. If you request account deletion, we process the request subject to any legally required retention periods.
Campaign analytics remain available after a subscription is cancelled until you manually delete the campaign. Customer review data is retained for as long as the associated campaign exists, and may be anonymized upon a valid data-deletion request.
Billing and subscription records are retained as needed to manage your account and meet legal requirements.
Security
We implement industry-standard security measures, including encrypted connections, secure session cookies, access controls, and filtering of personal data in error reports. No method of transmission or storage is completely secure, and we cannot guarantee absolute security.
Your Rights and Choices
Depending on your jurisdiction, you may have the right to access, correct, delete, or export your personal data, object to or restrict certain processing, and withdraw consent for optional communications.
Business owners can manage email notification preferences in Dashboard → Settings → Notifications. To exercise any other privacy rights, contact us at support@reviewflow.app. We will respond within the timeframe required by applicable law.
International Data Transfers
Our service providers may process data in the United States and other countries. Where required by law, we rely on appropriate safeguards for cross-border data transfers.
Children's Privacy
ReviewFlow is not directed at individuals under 16 years of age. We do not knowingly collect personal information from children. If you believe a child has provided us with personal data, please contact us and we will delete it.
Changes to This Policy
We may update this Privacy Policy from time to time. We will post the revised version on this page with an updated date. Where changes are material, we will notify you by email or through an in-app notice.
Contact Us
For privacy-related questions or requests, email support@reviewflow.app.