Skip to content
Trust

Security at ReviewNudger

Plain answers to the questions a business owner asks before handing over a customer list.

Last updated: September 18, 2026

  • Encrypted in transit and at rest

    HTTPS everywhere, the database encrypted at rest, and every connected-app credential encrypted with AES-256-GCM before it is stored.

  • Verified and disclosed SMS senders

    Your own number sends after carrier approval. While verification is pending or recently rejected, accounts that meet the sending conditions may use a ReviewNudger number, subject to limits and availability. See pricing for full terms.

  • Export or delete any time

    Download everything as a ZIP of spreadsheets, or delete the account and every row and file goes with it in one step.

  • No review gating, ever

    Every customer gets the same ask and the same public review link, including unhappy ones. That is how the FTC and Google require it.

What we protect

Two kinds of data pass through ReviewNudger. The first is yours: your account, your team, your billing status, your synced Google reviews, and the settings that shape each request. The second belongs to your customers: the name, phone number, or email address that lets us send the request, and the job or payment fact that triggered it. We treat both as confidential, scope every read and write to your account, and never sell, share, or use either for anything other than running the service for you.

Encryption

Every connection uses HTTPS, with HTTP Strict Transport Security for a year and a strict Content Security Policy on every page. Database connections are TLS-only, and the database and file storage are encrypted at rest by Supabase on AWS.

Credentials for your connected apps, your Twilio subaccount, and webhook signing secrets are encrypted with AES-256-GCM before they are stored. The master key lives only in the hosting provider's encrypted environment store, never in source control. A secret you create is shown to you once and never again; the sign-in codes and tokens our own integrations issue are stored as hashes.

Who can see your data

ReviewNudger is founder-run, and production access is limited to the founder. Every provider account uses its own credentials from a password manager with multi-factor authentication turned on. Any contractor who needs access gets the narrowest role for a defined period and is removed when the work ends.

Inside the app, every query is scoped to your account and Postgres row-level security means only the server can read business data. Team roles are owner, admin, and replier; billing and destructive actions are owner-only; and every operator action is written to an audit log that cannot be edited.

Your texting number is yours

Each account gets its own Twilio subaccount and toll-free number, registered under its business identity. Your own toll-free number can send only after carrier approval. While verification is pending, or for up to 30 days after rejection while you correct it, accounts with an active plan and sending turned on may send from a ReviewNudger number when available and within daily limits. These texts use the standard message and end with "Sent via ReviewNudger". Accounts marked "blocked" cannot use this number. Sending switches to your own number once approved; email requests remain available when your sending rules allow them.

Trial SMS includes up to 50 message attempts across the account, including initial requests, reminders, tests, and failed attempts. Failed attempts are not refunded; restarting a subscription or changing numbers does not reset the allowance.

STOP and HELP replies are honored at the carrier layer and recorded on the customer. Quiet hours, a cooldown between asks to the same customer, do-not-contact marks, and unsubscribe links in every email all apply automatically, whichever way a request was started.

Every customer gets the same ask

A review request is neutral and identical for every customer. When a location turns on the optional pre-screen, the unhappy path still shows the public Google review link. We do not filter, suppress, or delay negative reviews, and we never will. That is what the FTC's rule on consumer reviews and Google's review policies require, and it is what keeps your listing safe.

Connected apps

Integrations are read-only and pull only what a request needs: the customer's name and contact details, the job or payment id, amount, currency, and completion time. Nothing is written back to your payment or scheduling software beyond the connection handshake, and data from one customer's connected app is never combined with another's.

Every webhook is checked against that provider's signature or token using your connection's own secret before anything is stored; an unsigned or unknown delivery writes nothing. Provider-mandated deletions are honored: when you disconnect Square or Clover, the data that came from them is purged and an audit receipt records it.

AI features

Reply suggestions and review-policy screening send OpenAI only public review content: the review text, star rating, reviewer display name, and your business name. Your customer list and anything from a connected app never leave ReviewNudger. Requests are sent with provider-side storage turned off; under OpenAI's API terms, inputs may be kept for up to 30 days for abuse monitoring and are not used to train its models. We never use your data to train any model.

Your data stays yours

The account owner can export everything at any time as a ZIP of spreadsheets, one per business record. Deleting the account is a full hard delete of every row we hold for it, including the audit trail and uploaded files, together with the release of your Twilio number and subaccount and the cancellation of billing. You can also ask for deletion by emailing support@reviewnudger.com.

Where it runs

ReviewNudger runs as serverless functions and scheduled jobs on Vercel; the database, sign-in, and file storage are managed by Supabase on AWS in us-east-1. We operate no servers of our own, so patching, physical security, and network defense come from those platforms under their own audits. Vercel and Supabase each publish SOC 2 reports; ReviewNudger itself has not yet been independently audited, and we will say so here when that changes.

Backups are provider-managed and automatic. Every failed send, failed inbound event, and broken connection is recorded as visible state and reported to the founder in a daily digest, and a revoked connection also emails you with the fix. Independent scheduled checks watch public entry points and critical background jobs. Runtime error reports use limited diagnostic context, without customer content or request URLs.

How we build

Every change ships through a pull request and a full test, lint, build, and type-check gate; nothing is deployed from a working copy. Dependency alerts are on for the repository, and high or critical advisories are triaged within 7 days and fixed within 30. Secrets never enter source control, and local development uses its own databases with no production data.

If something goes wrong

A suspected exposure is treated as an incident: affected secrets are rotated and the affected endpoint or integration is paused within 24 hours of confirmation. If an incident touches your data, we tell you within 72 hours what happened, what data was involved, and what we did about it, and we write up the cause and the fix within 14 days.

Who processes customer data

  • VercelApplication hosting, scheduled jobs, and the encrypted secrets store
  • Supabase (on AWS, us-east-1)Postgres database, sign-in, and file storage, all encrypted at rest
  • TwilioText delivery from your own subaccount and toll-free number, plus carrier verification
  • ResendEmail delivery for review requests and account mail
  • GoogleReview sync and reply publishing for your connected Google Business Profile
  • OpenAIReply suggestions and review-policy screening, sent only public review content
  • StripeSubscription billing on Stripe-hosted checkout; card data never reaches us

Your own connected apps (Square, Jobber, QuickBooks, and the rest) send us data under the grant you approve; we only read from them. Marketing and advertising tools see pre-signup leads and consented visitor measurement only, never a customer record; the privacy policy lists them.

Report a security issue

Found something? Email support@reviewnudger.com with “Security” in the subject line. The founder reads it and replies within one business day. Please don't access other customers' data or run tests that could disrupt the service while you look.

This page summarizes ReviewNudger LLC's written information security policy (version 1.0, effective August 18, 2026), which is reviewed at least once a year, after any incident, and whenever a control described here changes.