Privacy Policy
Last updated: September 17, 2026
Who we are
ReviewNudger™ is review management software for service businesses. In this policy, “we” and “us” refer to ReviewNudger, and “you” refers to the business owner or operator using our service.
What information we collect
Account information. Your name, email address, business details, and timezone, collected when you create an account.
Customer contact information. Names, email addresses, and phone numbers of your customers, provided through payment triggers, integrations such as Zapier, or manual entry.
Connected payment app data. Merchant identifiers, payment identifiers, payment status, amount and currency, location and order identifiers, refund totals, and attached customer contact details needed to run the review-request workflow. Clover App Market installs also provide the merchant business and owner profile fields and app subscription status needed for onboarding and billing. We do not collect full card numbers from Clover, Square, or other connected payment apps.
Xero data. See the dedicated “Xero data” section below for the exact identity, organisation, invoice, credit, and contact data used by the Xero integration.
Google user data. See the dedicated “Google user data” section below for specifics.
Message and delivery data. Records of SMS and email messages sent on your behalf, including delivery status and timestamps.
Private feedback. Customer feedback submitted through the ReviewNudger-hosted feedback page.
Payment and billing information. Direct subscriptions are processed by Stripe. Clover App Market subscriptions are processed by Clover. We do not store full credit card or bank account numbers.
Usage data. Server logs including IP addresses, browser information, and pages visited, collected to operate and improve the service.
Clover data
When a Clover merchant installs ReviewNudger, Clover authorizes our app using OAuth. We use Merchant Read data to prefill setup, Payments Read and Orders Read data to confirm a fully paid order and handle refunds, Customers Read data to identify the customer the merchant chooses to contact, and app billing data to determine whether the Clover plan is active. We do not create or process customer payments.
Customer email addresses and phone numbers received from Clover are not enough by themselves to permit a message. ReviewNudger requires the merchant to record current, destination-specific contact consent before a Clover-triggered review request can be sent. Consent records are retained as compliance evidence.
We do not sell Clover merchant, employee, transaction, or customer data, and we do not share it with third parties for advertising or their own marketing. We disclose it only to the service providers listed below as needed to host ReviewNudger, deliver an authorized message, secure the service, or comply with law.
If Clover authorization is started before signup, the verified merchant profile, encrypted OAuth credentials, and billing snapshot are kept in a one-time handoff for up to 24 hours. A successful signup consumes and deletes that handoff. Unclaimed handoffs are automatically deleted when they expire.
When a merchant disconnects or uninstalls the Clover app, we delete Clover OAuth credentials and redact Clover-derived customer and transaction payloads. We retain non-personal identifiers, statuses, timestamps, and other tombstone facts needed to prevent duplicate processing, document delivery outcomes, and protect the service. If a customer record is also maintained through another integration or manual account use, that independently maintained record is not deleted solely because Clover was disconnected.
Xero data
ReviewNudger offers two separate Xero authorization flows. Optional Sign Up with Xero requests openid, profile, and email to verify and prefill your name and email for account creation. It does not connect a Xero organisation or grant access to accounting data.
When an account owner connects a Xero organisation, ReviewNudger requests offline_access, accounting.invoices.read, and accounting.contacts.read. Offline access lets the paid-invoice integration continue while you are not signed in. The accounting scopes are read-only; ReviewNudger does not create, change, or delete data in Xero.
What we access and store. The Xero organisation ID and name; OAuth access and refresh tokens stored encrypted; invoice IDs, type, status, amount paid, amount credited, currency, and relevant dates; attached contact IDs, names, email addresses, and phone numbers; credit note and allocation IDs and amounts; and webhook, processing, duplicate-protection, connection-health, and error records.
How we use it. We verify that a customer sales invoice is fully paid, identify its customer contact, create at most one review-request journey under your saved rules, stop unsent messages or follow-ups after an applied customer credit, keep the connection healthy, and show processing outcomes in your dashboard.
Who processes it. Supabase stores encrypted connection state and account records, and Vercel runs the application. When your sending rules create a message, the customer email address or phone number and message content are processed by Resend or Twilio for delivery. We do not sell Xero data or use it for advertising.
How to revoke access. Account owners can disconnect Xero from Dashboard → Settings → Connected apps. We delete the matching tenant connection at Xero and clear stored access and refresh tokens. You can also remove the connection through Xero.
What remains after disconnecting. While your account remains active, we retain the invoice-trigger facts, customer records, request journeys, and delivery history needed to show what the service did and prevent duplicate sends. Account deletion removes those account-owned records as described under Data retention.
Square seller data
When you connect Square, ReviewNudger requests read-only access to payments, customers, and your merchant profile. We use payment status, amount, location, order, refund, and attached customer contact facts only to identify a completed payment and run your saved review-request rules. We do not create payments, issue refunds, change customers, or access full card numbers in Square.
Square access and refresh tokens are encrypted at rest. The application secret and the encryption key are stored in managed server-side secrets, separate from source code.
When you disconnect Square, or Square tells us that authorization was revoked, we clear the usable tokens and remove stored Square seller content from raw event payloads, normalized payment facts, rendered delivery content, and customer contact fields that came only from Square. We retain non-content tombstone identifiers and an audit receipt only to prevent duplicate processing and prove that deletion occurred.
Google user data
ReviewNudger uses the Google Business Profile API to help you manage your business reviews. When you connect your Google Business Profile, you grant ReviewNudger access using the following OAuth scope:
https://www.googleapis.com/auth/business.manage
Through this scope, ReviewNudger accesses the following Google user data on your behalf:
- Your Google Business Profile account list and location list
- Reviewer display names, ratings, review text, review timestamps, and review reply data for your connected locations
- The ability to publish review replies that you have approved through the ReviewNudger dashboard
We use this data only to provide the user-facing features you signed up for: syncing your existing Google reviews into your dashboard, generating an AI reply suggestion when you request one, publishing replies you approve back to Google, publishing AI-generated replies automatically only when you enable the per-location AI auto-reply setting, and checking each synced review once for likely violations of Google's review content policy so you can decide whether to report it to Google yourself (review protection, which is on by default and can be turned off per location).
Where we store it. Synced review data is stored in our database hosted on Supabase, in a record associated with your account.
Who we share it with. We do not sell or transfer Google user data to third parties for advertising or marketing. The only third parties that process Google user data on our behalf are: Supabase (database hosting), Vercel (application hosting), and OpenAI, which receives a review's text, star rating, and reviewer display name (with your business name) when a reply draft is generated or an enabled auto-reply is published, and for the review-protection check that screens each synced review once for likely Google review-policy violations (on by default; you can turn it off per location). We send every OpenAI request with response storage disabled. Under OpenAI's API data policy, that data is not used to train OpenAI's models and may be retained by OpenAI for up to 30 days for abuse and misuse monitoring, after which it is deleted.
How to revoke access. You can revoke ReviewNudger's access to your Google Business Profile at any time by visiting https://myaccount.google.com/permissions and removing ReviewNudger from your connected apps list, or by disconnecting the integration from your ReviewNudger dashboard settings.
Limited Use disclosure
ReviewNudger's use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. Specifically:
- We only use Google user data to provide or improve the user-facing features described above.
- We do not transfer Google user data to others except as necessary to provide or improve those features, to comply with applicable law, or as part of a merger, acquisition, or sale of assets with notice to users.
- We do not use Google user data for serving advertisements, including retargeting, personalized, or interest-based advertising.
- We do not allow humans to read Google user data, except: with your affirmative consent for specific reviews, when necessary for security purposes such as investigating abuse, when required by law, or when the data has been aggregated and anonymized for internal operations.
AI and machine learning
ReviewNudger uses OpenAI for two features. Reply drafts: when you ask for a suggested reply, or when AI auto-reply is enabled for a location and an eligible reply is generated for automatic publishing, the review's text, star rating, and reviewer display name are sent to OpenAI together with your business name. Suggested drafts appear in your dashboard for you to review, edit, and approve before publishing; auto-replies are published under that per-location setting. Review protection: each Google review synced into your dashboard is checked once for likely violations of Google's review content policy, so you can decide whether to report it through Google's own reporting tool. It is on by default and can be turned off per location in Settings; ReviewNudger never reports reviews to Google on your behalf. We send every OpenAI request with response storage disabled. Under OpenAI's API data policy, your data is not used to train OpenAI's models and may be retained by OpenAI for up to 30 days for abuse and misuse monitoring, after which it is deleted. The public Google review response generator also sends the business name, star rating, selected tone, and optional reviewer name and review text you submit to OpenAI, on the same terms. ReviewNudger does not store the public generator submission or its output.
How we use your information
Operate the service. Send review requests on your behalf, sync Google reviews, generate AI reply drafts, check synced reviews for likely policy violations, publish replies when authorized, and display operational dashboard data.
Communicate with you. Send account-related emails such as billing confirmations and service updates.
Improve the service. Fix bugs, understand usage patterns, and improve reliability and features.
Third-party services
We share data with the following providers to operate the service. Each provider’s own privacy policy applies.
Twilio. Phone numbers and message content for SMS delivery.
Resend. Email addresses and message content for email delivery.
Google. Review data accessed through the Google Business Profile API.
Xero. Optional signup identity and read-only accounting invoice and contact data for the connected paid-invoice integration.
Stripe. Payment and subscription information for billing.
Square. Merchant, completed-payment, refund, and attached customer data that you authorize through Square OAuth for the payment-trigger integration.
Clover. Merchant, app subscription, order, payment, refund, and customer information for Clover App Market installation and operation.
Supabase. Authentication and database hosting.
Vercel. Application hosting and cookieless site analytics.
Google Analytics. Public website traffic, campaign attribution, and signup-funnel measurement under the analytics choice.
Google Ads. Conversion measurement, remarketing audiences, and hashed contact identifiers for our own ads on public marketing and signup pages under the advertising choice.
Meta. Unless you turn advertising off, browser and server-sent advertising measurement, remarketing audiences, and hashed identifiers on public marketing and onboarding pages for Facebook and Instagram ads, plus one paid-plan event for accounts created with advertising on.
OpenAI. Review content processing for AI reply drafts and review-protection screening, plus ChatGPT advertising measurement and automatic hashed contact matching on public marketing and onboarding pages when advertising is allowed.
SMS and messaging consent
Messages are sent only when triggered by the business owner through an eligible payment or appointment event or a manual request, and only when the selected channel has the required consent. Customers can opt out at any time by replying STOP to any SMS message or using the unsubscribe link in emails.
Mobile opt-in information and phone numbers are used to provide the review request messaging service. We do not sell that information or share it with third parties for their marketing.
Data retention
We retain your data while your account is active. If you cancel your account and request deletion, we will delete your data within 30 days, except where retention is required by law. The shorter Clover-specific handoff, disconnect, and uninstall rules above apply to Clover data. If you disconnect your Google Business Profile without canceling your account, disconnecting in your dashboard removes the cached Google reviews and reply drafts immediately. If you revoke access through Google, we remove cached Google data within 30 days of detecting the revocation. Reconnecting before that cleanup retains the cached reviews. Square seller content is removed immediately when the Square connection is disconnected or revoked, as described above. If you disconnect Xero, we revoke the tenant connection and clear its OAuth tokens immediately; the already-recorded business history remains until account deletion so the dashboard and duplicate protection remain accurate.
Data security
We use industry-standard security measures including HTTPS, secure authentication, access controls, constant-time webhook signature verification, and AES-256-GCM encryption for connected-app credentials. Account-scoped authorization, authenticated webhook endpoints, duplicate-event protection, and operational logging further protect provider data. No system is perfectly secure, but we take reasonable steps to safeguard your information.
Your rights
You can access, update, or delete your account information from the dashboard at any time. To request a full data export or account deletion, contact us at support@reviewnudger.com. We will respond within 30 days.
Children’s privacy
ReviewNudger is a business tool and is not intended for use by anyone under 18 years of age.
Changes to this policy
We may update this privacy policy from time to time. If we make significant changes, we will notify you by email or through an in-product notice.
Contact us
If you have questions about this privacy policy or your data, contact us at support@reviewnudger.com.