Skip to content

Privacy Policy

Last updated: September 17, 2026

Who we are

ReviewNudger™ is review management software for service businesses. In this policy, “we” and “us” refer to ReviewNudger, and “you” refers to the business owner or operator using our service.

What information we collect

Account information. Your name, email address, business details, and timezone, collected when you create an account.

Customer contact information. Names, email addresses, and phone numbers of your customers, provided through payment triggers, integrations such as Zapier, or manual entry.

Connected payment app data. Merchant identifiers, payment identifiers, payment status, amount and currency, location and order identifiers, refund totals, and attached customer contact details needed to run the review-request workflow. Clover App Market installs also provide the merchant business and owner profile fields and app subscription status needed for onboarding and billing. We do not collect full card numbers from Clover, Square, or other connected payment apps.

Xero data. See the dedicated “Xero data” section below for the exact identity, organisation, invoice, credit, and contact data used by the Xero integration.

Google user data. See the dedicated “Google user data” section below for specifics.

Message and delivery data. Records of SMS and email messages sent on your behalf, including delivery status and timestamps.

Private feedback. Customer feedback submitted through the ReviewNudger-hosted feedback page.

Payment and billing information. Direct subscriptions are processed by Stripe. Clover App Market subscriptions are processed by Clover. We do not store full credit card or bank account numbers.

Usage data. Server logs including IP addresses, browser information, and pages visited, collected to operate and improve the service.

Clover data

When a Clover merchant installs ReviewNudger, Clover authorizes our app using OAuth. We use Merchant Read data to prefill setup, Payments Read and Orders Read data to confirm a fully paid order and handle refunds, Customers Read data to identify the customer the merchant chooses to contact, and app billing data to determine whether the Clover plan is active. We do not create or process customer payments.

Customer email addresses and phone numbers received from Clover are not enough by themselves to permit a message. ReviewNudger requires the merchant to record current, destination-specific contact consent before a Clover-triggered review request can be sent. Consent records are retained as compliance evidence.

We do not sell Clover merchant, employee, transaction, or customer data, and we do not share it with third parties for advertising or their own marketing. We disclose it only to the service providers listed below as needed to host ReviewNudger, deliver an authorized message, secure the service, or comply with law.

If Clover authorization is started before signup, the verified merchant profile, encrypted OAuth credentials, and billing snapshot are kept in a one-time handoff for up to 24 hours. A successful signup consumes and deletes that handoff. Unclaimed handoffs are automatically deleted when they expire.

When a merchant disconnects or uninstalls the Clover app, we delete Clover OAuth credentials and redact Clover-derived customer and transaction payloads. We retain non-personal identifiers, statuses, timestamps, and other tombstone facts needed to prevent duplicate processing, document delivery outcomes, and protect the service. If a customer record is also maintained through another integration or manual account use, that independently maintained record is not deleted solely because Clover was disconnected.

Xero data

ReviewNudger offers two separate Xero authorization flows. Optional Sign Up with Xero requests openid, profile, and email to verify and prefill your name and email for account creation. It does not connect a Xero organisation or grant access to accounting data.

When an account owner connects a Xero organisation, ReviewNudger requests offline_access, accounting.invoices.read, and accounting.contacts.read. Offline access lets the paid-invoice integration continue while you are not signed in. The accounting scopes are read-only; ReviewNudger does not create, change, or delete data in Xero.

What we access and store. The Xero organisation ID and name; OAuth access and refresh tokens stored encrypted; invoice IDs, type, status, amount paid, amount credited, currency, and relevant dates; attached contact IDs, names, email addresses, and phone numbers; credit note and allocation IDs and amounts; and webhook, processing, duplicate-protection, connection-health, and error records.

How we use it. We verify that a customer sales invoice is fully paid, identify its customer contact, create at most one review-request journey under your saved rules, stop unsent messages or follow-ups after an applied customer credit, keep the connection healthy, and show processing outcomes in your dashboard.

Who processes it. Supabase stores encrypted connection state and account records, and Vercel runs the application. When your sending rules create a message, the customer email address or phone number and message content are processed by Resend or Twilio for delivery. We do not sell Xero data or use it for advertising.

How to revoke access. Account owners can disconnect Xero from Dashboard → Settings → Connected apps. We delete the matching tenant connection at Xero and clear stored access and refresh tokens. You can also remove the connection through Xero.

What remains after disconnecting. While your account remains active, we retain the invoice-trigger facts, customer records, request journeys, and delivery history needed to show what the service did and prevent duplicate sends. Account deletion removes those account-owned records as described under Data retention.

Square seller data

When you connect Square, ReviewNudger requests read-only access to payments, customers, and your merchant profile. We use payment status, amount, location, order, refund, and attached customer contact facts only to identify a completed payment and run your saved review-request rules. We do not create payments, issue refunds, change customers, or access full card numbers in Square.

Square access and refresh tokens are encrypted at rest. The application secret and the encryption key are stored in managed server-side secrets, separate from source code.

When you disconnect Square, or Square tells us that authorization was revoked, we clear the usable tokens and remove stored Square seller content from raw event payloads, normalized payment facts, rendered delivery content, and customer contact fields that came only from Square. We retain non-content tombstone identifiers and an audit receipt only to prevent duplicate processing and prove that deletion occurred.

Cookies and analytics

Necessary cookies. Sign-in and security cookies keep your account working. The rn_cookie_consent cookie remembers your choices for up to 180 days. A matching browser-storage record signals changes to other open tabs. These preferences do not contain your name or contact details.

Referral offers. When you follow a valid referral link, our rn_referral cookie remembers the referral for up to 60 days so we can apply the requested trial offer and credit the referrer. It is separate from optional advertising measurement and does not follow you across websites.

Analytics. Unless you turn analytics off, we set rn_signup_attribution and rn_signup_last_touch. These server-set cookies remember your first visit and most recent campaign or referring website: source, medium, campaign name, creative, term, referring page, and landing path. They stay in your browser for up to 90 days. Links can identify Google or Meta ads, cold-call follow-ups, flyers, postcards, or other campaigns. Collection starts on your first visit; it cannot identify an offline interaction without a website visit. If you submit a lead form or create an account, we attach the available attribution to that record. You can also tell us how you heard about us in the optional signup question, even with cookies off.

With the same analytics permission, we use Vercel Analytics to count public site visits and actions such as trial starts. It does not use cookies and does not build a profile of you. We do not load optional measurement on private dashboard or customer-feedback pages.

We also use Google Analytics 4 under the analytics choice to understand which campaigns bring visitors and where people leave the signup process. Google receives browser and device information, IP addresses, permitted public page URLs and referrers, cookie identifiers, and selected actions such as signup and confirmed trial starts. Its _ga and _ga_* cookies are configured to expire after 90 days without extending that lifetime on each visit; browser restrictions can shorten it. We do not send form contents, contact details, payment details, account identifiers, reviews, or connected-provider customer records to Analytics. Google signals, personalized advertising, and automatic form and link tracking are disabled. See how Google uses information from partner sites.

Advertising measurement cookies. Google Ads and Meta run unless you turn advertising off or your browser sends Global Privacy Control. On public marketing and onboarding pages they measure visits, the type of marketing page viewed, lead-form submissions, account creation, reaching the checkout step, and confirmed free-trial starts. Meta also receives three engagement actions: clicking a start-trial button, playing the demo video, and completing the review calculator. Google uses advertising cookies such as _gcl_*; Meta uses _fbp and may use _fbc after an ad click. When you arrive from one of our Google or Meta ads, our own server-set rn_signup_ad_click cookie also remembers that ad click identifier for up to 90 days, because browsers can expire the providers’ own click cookies within a day. Provider cookie names and durations can vary; see Google’s cookie information and Meta’s cookie information. With advertising on, Google Ads and Meta may also use those visits to show you our ads later on their networks (remarketing) and to find audiences similar to our visitors. Turning advertising off stops our advertising measurement and remarketing; Google Analytics can still run if your separate analytics choice allows it.

ChatGPT advertising measurement. On the same public marketing and onboarding pages, OpenAI measures page visits, leads, completed registrations, checkout starts, and confirmed free-trial starts unless advertising is off or Global Privacy Control is enabled. Its pixel receives browser and device information, IP address, page origin, ad-click and browser identifiers, event types, and random or opaque event identifiers for duplicate protection. OpenAI uses __oppref (up to 30 days) and __obref (up to 365 days) cookies. Automatic advanced matching may detect supported contact information in website forms, normalize it, and send a SHA-256 hash to OpenAI to help match a conversion. Readable contact information is not sent through this matching. We do not manually send form contents, payment details, or reviews through this pixel. We mark these events as opted out of future ad personalization. Turning advertising off stops this tracking and removes these cookies.

What Google and Meta receive. Browser and device information, IP address, page URLs and the page type, advertising click and cookie identifiers, which form or step was completed (never its contents), random event identifiers that prevent double counting, an opaque identifier for a confirmed trial, and a SHA-256 hashed version of the email address (and phone number, when you give one) you submit in a lead form, at signup, or on your account when a trial starts, so the provider can match the action to its own account holder. Meta also receives hashed versions of the name you give us, your business’s city, state, ZIP code, and country, and an opaque hashed account identifier, for the same matching. Meta also receives a server-sent copy of those same events (lead, account created, checkout, confirmed trial) with your IP address, browser identifier, and the same hashed values, so an ad blocker cannot hide them; the two copies share an event identifier and count once. If advertising was on when you created your account, we save the ad click identifier and Meta’s browser identifier on the account, and when your free trial becomes a paid plan our server sends Meta one event with those identifiers, the same hashed values, and the plan price. We keep Google’s click identifier the same way so a paid plan can be reported to Google Ads. An account created with advertising off is never reported. The readable address or number is never sent, and neither is a readable name. We do not send form contents, payment details, reviews, or connected-provider customer records. Automatic advanced matching (form scanning) and automatic Meta event detection are off. Meta may use the activity it receives to personalize ads under its Privacy Policy. See also Google’s advertising privacy information.

Your cookie choices

Your choices. Optional analytics and advertising are on unless you turn them off; the first-visit cookie notice says so, and closing it records your acceptance. Accepting cookies does not give us permission to call, email, or text you. You can reject optional tracking or change individual choices here using Customize, or return through Manage Cookies on the notice or Cookie settings in the footer. Your choice is kept for 180 days; after that, optional cookies are on again until you choose. Global Privacy Control overrides advertising permission. Earlier Meta-only permission does not grant permission for this expanded setup.

Withdrawing permission stops subsequent optional measurement and removes the optional first-party cookies we control. The page may refresh to stop previously loaded scripts. It does not undo information already received by Google or Meta or erase attribution already attached to a submitted lead or account. Ad identifiers already saved on an account stay until the account is deleted; email support if you want them removed sooner. Cookies set on other providers’ domains must be managed through those providers or your browser. Consent choices expire after 180 days; attribution cookies expire after 90 days. Google Analytics and Meta trial-event deduplication identifiers are stored in this browser while their respective analytics or advertising choice allows it and removed when that choice is turned off. These browser records prevent repeated trial notifications; they are not customer account records.

Browser settings. You can clear or block cookies and browser storage at any time. Optional choices affect this browser, not every device you use. Marketing pages work with optional cookies off, and necessary sign-in cookies are required for the dashboard.

Google user data

ReviewNudger uses the Google Business Profile API to help you manage your business reviews. When you connect your Google Business Profile, you grant ReviewNudger access using the following OAuth scope:

https://www.googleapis.com/auth/business.manage

Through this scope, ReviewNudger accesses the following Google user data on your behalf:

  • Your Google Business Profile account list and location list
  • Reviewer display names, ratings, review text, review timestamps, and review reply data for your connected locations
  • The ability to publish review replies that you have approved through the ReviewNudger dashboard

We use this data only to provide the user-facing features you signed up for: syncing your existing Google reviews into your dashboard, generating an AI reply suggestion when you request one, publishing replies you approve back to Google, publishing AI-generated replies automatically only when you enable the per-location AI auto-reply setting, and checking each synced review once for likely violations of Google's review content policy so you can decide whether to report it to Google yourself (review protection, which is on by default and can be turned off per location).

Where we store it. Synced review data is stored in our database hosted on Supabase, in a record associated with your account.

Who we share it with. We do not sell or transfer Google user data to third parties for advertising or marketing. The only third parties that process Google user data on our behalf are: Supabase (database hosting), Vercel (application hosting), and OpenAI, which receives a review's text, star rating, and reviewer display name (with your business name) when a reply draft is generated or an enabled auto-reply is published, and for the review-protection check that screens each synced review once for likely Google review-policy violations (on by default; you can turn it off per location). We send every OpenAI request with response storage disabled. Under OpenAI's API data policy, that data is not used to train OpenAI's models and may be retained by OpenAI for up to 30 days for abuse and misuse monitoring, after which it is deleted.

How to revoke access. You can revoke ReviewNudger's access to your Google Business Profile at any time by visiting https://myaccount.google.com/permissions and removing ReviewNudger from your connected apps list, or by disconnecting the integration from your ReviewNudger dashboard settings.

Limited Use disclosure

ReviewNudger's use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. Specifically:

  • We only use Google user data to provide or improve the user-facing features described above.
  • We do not transfer Google user data to others except as necessary to provide or improve those features, to comply with applicable law, or as part of a merger, acquisition, or sale of assets with notice to users.
  • We do not use Google user data for serving advertisements, including retargeting, personalized, or interest-based advertising.
  • We do not allow humans to read Google user data, except: with your affirmative consent for specific reviews, when necessary for security purposes such as investigating abuse, when required by law, or when the data has been aggregated and anonymized for internal operations.

AI and machine learning

ReviewNudger uses OpenAI for two features. Reply drafts: when you ask for a suggested reply, or when AI auto-reply is enabled for a location and an eligible reply is generated for automatic publishing, the review's text, star rating, and reviewer display name are sent to OpenAI together with your business name. Suggested drafts appear in your dashboard for you to review, edit, and approve before publishing; auto-replies are published under that per-location setting. Review protection: each Google review synced into your dashboard is checked once for likely violations of Google's review content policy, so you can decide whether to report it through Google's own reporting tool. It is on by default and can be turned off per location in Settings; ReviewNudger never reports reviews to Google on your behalf. We send every OpenAI request with response storage disabled. Under OpenAI's API data policy, your data is not used to train OpenAI's models and may be retained by OpenAI for up to 30 days for abuse and misuse monitoring, after which it is deleted. The public Google review response generator also sends the business name, star rating, selected tone, and optional reviewer name and review text you submit to OpenAI, on the same terms. ReviewNudger does not store the public generator submission or its output.

How we use your information

Operate the service. Send review requests on your behalf, sync Google reviews, generate AI reply drafts, check synced reviews for likely policy violations, publish replies when authorized, and display operational dashboard data.

Communicate with you. Send account-related emails such as billing confirmations and service updates.

Improve the service. Fix bugs, understand usage patterns, and improve reliability and features.

Third-party services

We share data with the following providers to operate the service. Each provider’s own privacy policy applies.

Twilio. Phone numbers and message content for SMS delivery.

Resend. Email addresses and message content for email delivery.

Google. Review data accessed through the Google Business Profile API.

Xero. Optional signup identity and read-only accounting invoice and contact data for the connected paid-invoice integration.

Stripe. Payment and subscription information for billing.

Square. Merchant, completed-payment, refund, and attached customer data that you authorize through Square OAuth for the payment-trigger integration.

Clover. Merchant, app subscription, order, payment, refund, and customer information for Clover App Market installation and operation.

Supabase. Authentication and database hosting.

Vercel. Application hosting and cookieless site analytics.

Google Analytics. Public website traffic, campaign attribution, and signup-funnel measurement under the analytics choice.

Google Ads. Conversion measurement, remarketing audiences, and hashed contact identifiers for our own ads on public marketing and signup pages under the advertising choice.

Meta. Unless you turn advertising off, browser and server-sent advertising measurement, remarketing audiences, and hashed identifiers on public marketing and onboarding pages for Facebook and Instagram ads, plus one paid-plan event for accounts created with advertising on.

OpenAI. Review content processing for AI reply drafts and review-protection screening, plus ChatGPT advertising measurement and automatic hashed contact matching on public marketing and onboarding pages when advertising is allowed.

Data retention

We retain your data while your account is active. If you cancel your account and request deletion, we will delete your data within 30 days, except where retention is required by law. The shorter Clover-specific handoff, disconnect, and uninstall rules above apply to Clover data. If you disconnect your Google Business Profile without canceling your account, disconnecting in your dashboard removes the cached Google reviews and reply drafts immediately. If you revoke access through Google, we remove cached Google data within 30 days of detecting the revocation. Reconnecting before that cleanup retains the cached reviews. Square seller content is removed immediately when the Square connection is disconnected or revoked, as described above. If you disconnect Xero, we revoke the tenant connection and clear its OAuth tokens immediately; the already-recorded business history remains until account deletion so the dashboard and duplicate protection remain accurate.

Data security

We use industry-standard security measures including HTTPS, secure authentication, access controls, constant-time webhook signature verification, and AES-256-GCM encryption for connected-app credentials. Account-scoped authorization, authenticated webhook endpoints, duplicate-event protection, and operational logging further protect provider data. No system is perfectly secure, but we take reasonable steps to safeguard your information.

Your rights

You can access, update, or delete your account information from the dashboard at any time. To request a full data export or account deletion, contact us at support@reviewnudger.com. We will respond within 30 days.

Children’s privacy

ReviewNudger is a business tool and is not intended for use by anyone under 18 years of age.

Changes to this policy

We may update this privacy policy from time to time. If we make significant changes, we will notify you by email or through an in-product notice.

Contact us

If you have questions about this privacy policy or your data, contact us at support@reviewnudger.com.