Privacy Policy

Last updated: March 24th 2026

This Privacy Policy describes how REVIEWFLOWZ SAS, a French société par actions simplifiée registered under SIREN 928798891, with its registered office at 870 chemin du vallon des mourgues, 13090 Aix-en-Provence, France ("Reviewflowz", "we", "us", or "our"), collects, uses, stores, and protects your personal data when you use our platform and services.

Reviewflowz is the data controller for the personal data described in this Privacy Policy. For data processed on behalf of our customers (Customer Data), we act as a data processor — see Section 7 below.

For any questions about this Privacy Policy or to exercise your rights, contact us at hello@reviewflowz.com.

1. Data We Collect

1.1 Account Data

When you create an account, we collect:

  • Your name and email address
  • Your company name
  • Your password (stored in hashed form)
  • Billing information (processed by Stripe; we do not store full card details)

If you register or log in via a third-party provider (Slack, Google), we receive your name, email address, and profile picture from that provider.

1.2 Service Usage Data

We automatically collect data about how you and your users interact with the platform, including:

  • User session recordings (including clicks, scrolls, page navigation, and form interactions)
  • Feature usage patterns
  • Navigation behaviour
  • Platform performance metrics
  • IP addresses, browser type, device type, operating system
  • Referring URLs and pages visited

Service Usage Data may include identifiable information such as your name, email address, and account details. We use this data to monitor, improve, and enhance the Services, diagnose issues, and inform product development. Service Usage Data is collected via PostHog (hosted in the EU).

1.3 Customer Data

When you use Reviewflowz, you and your users may upload or configure data including:

  • Business listing information and review platform credentials
  • Review response templates and AI configuration settings
  • Contact information for review request recipients (email addresses, phone numbers, names)

We process Customer Data solely on your behalf as a data processor. See Section 7 for details.

1.4 Third-Party Review Data

The Services collect reviews, ratings, comments, reviewer names, profile information, and associated metadata from Third-Party Platforms (such as Google, Trustpilot, Apple App Store, Google Play Store, and others) on your behalf. This data may include personal data of third-party reviewers (names, profile pictures, review content). We process this data on your behalf as a data processor and at your instruction.

1.5 Support Data

When you contact us via Intercom or email, we collect the content of your messages, your email address, and any attachments you provide.

1.6 Cookies and Tracking Technologies

See Section 5 below for our full cookie policy.

2. How We Use Your Data

We use your personal data for the following purposes, with the corresponding legal basis under GDPR:

Performance of contract (Article 6(1)(b) GDPR)

  • Providing and maintaining the Services
  • Managing your account and authentication
  • Processing payments and billing
  • Sending transactional communications (account confirmations, invoices, service notifications)
  • Making Customer Data available for export upon termination

Legitimate interest (Article 6(1)(f) GDPR)

  • Monitoring and improving the Services through session recordings and usage analytics
  • Diagnosing issues and ensuring platform stability
  • Informing product development based on feature usage patterns
  • Detecting and preventing fraud, abuse, and security incidents
  • Sending you information about product updates, new features, and service changes relevant to your subscription
  • Using your company name and logo in marketing materials (you may opt out at any time)
  • Placing analytics and advertising cookies to improve the Services and measure advertising effectiveness

Legal obligation (Article 6(1)(c) GDPR)

  • Complying with applicable tax, accounting, and regulatory requirements
  • Responding to lawful requests from public authorities

Consent (Article 6(1)(a) GDPR)

  • Sending you marketing communications unrelated to your current subscription (where applicable)

You may withdraw consent at any time without affecting the lawfulness of processing carried out before withdrawal.

3. How We Share Your Data

We do not sell your personal data. We share personal data only in the following circumstances:

  • With our sub-processors, as listed in Section 4, to provide and support the Services.
  • With payment processors (Stripe), to process your payments. We do not store full payment card details.
  • With AI service providers, when you use AI-powered features. Review data and configuration settings are transmitted to third-party AI providers for processing. No personal account data (your name, email, billing) is shared with AI providers.
  • In the event of a business transfer (merger, acquisition, or sale of assets), your data may be transferred to the acquiring entity. We will notify you before your data becomes subject to a different privacy policy.
  • To comply with the law, where we are required to disclose data by law, regulation, court order, or lawful request from a public authority.
  • To protect our rights, where necessary to enforce our Terms of Service, protect our property, or protect the safety of our users or the public.

4. Sub-Processors

We use the following sub-processors to provide the Services. All sub-processors processing personal data are based in the EU or process data within the EU:

  • Heroku Shield (Salesforce) — Application hosting, database — EU (Dublin)
  • PostHog — Analytics, session recordings — EU
  • Brevo — Transactional email (account notifications) — EU
  • SendGrid (Twilio) — Transactional email (review requests on behalf of customers) — EU
  • Stripe — Payment processing — EU, with data mirrored in US under SCCs
  • Intercom — Customer support and help centre — EU/US (user email only; see note)
  • OpenAI (OpenAI Ireland Ltd) — AI-powered review reply generation and sentiment analysis — US (data processed under DPA with SCCs; API data retained for a maximum of 30 days)
  • Anthropic — AI-powered review reply generation and sentiment analysis — US (data processed under DPA with SCCs)

Note on Intercom: Intercom processes user email addresses for the purpose of providing in-app support. Intercom may transfer data to the US under Standard Contractual Clauses (SCCs). No other personal data is shared with Intercom.

Note on AI providers: When you use AI-powered features, review data and your configuration settings are transmitted to third-party AI providers for processing. These providers process data as sub-processors under our instructions. Their processing is limited to generating the requested output and they do not retain your data for their own purposes.

We may update this list from time to time. Material changes to sub-processors will be communicated via email or notice within the Services.

5. Cookies and Tracking Technologies

We use cookies and similar technologies on our website and platform.

Strictly Necessary Cookies

These cookies are essential for the platform to function. They handle authentication, session management, and security. They are always active.

Analytics Cookies

We use PostHog (hosted in the EU) for analytics and user session recordings. These cookies help us understand how users interact with the platform, diagnose issues, and improve the Services.

Advertising Cookies

We use cookies from Google Ads and LinkedIn Ads to measure the effectiveness of our advertising campaigns and to serve relevant ads to visitors on other platforms.

Support Cookies

Intercom places cookies to provide in-app messaging and support functionality.

For more information about cookies and how to manage or delete them in your browser, visit www.allaboutcookies.org.

6. Data Retention

We retain your data for the following periods:

  • Account data (name, email, company) — Retained for the duration of your account. Accounts remain active in a free-trial state after subscription ends. Deleted within 30 days of a deletion request.
  • Customer Data (listings, configurations, review data) — Retained for the duration of your account. Available for export for 30 days after account deletion, then permanently deleted.
  • Session recordings (PostHog) — 90 days
  • Transactional email logs (Brevo, SendGrid) — Retained indefinitely for delivery tracking and troubleshooting
  • Support conversations (Intercom) — Retained indefinitely unless deletion is requested
  • Billing data (Stripe) — Retained as required by applicable tax and accounting law (minimum 10 years under French law)
  • Server logs — Retained by Heroku in accordance with their data retention policies

You may request deletion of your account and personal data at any time by contacting us at hello@reviewflowz.com. We will process your request within 30 days. Certain data may be retained where required by law.

7. Processing on Behalf of Customers (Processor Role)

When you use Reviewflowz, you may instruct us to process personal data on your behalf — for example, reviewer names and profile information in Third-Party Review Data, or email addresses and phone numbers of recipients of review requests. In this context:

  • You are the data controller and are responsible for ensuring you have a lawful basis to process the data you provide to us or instruct us to collect.
  • We are the data processor and process this data solely on your instructions and for the purpose of providing the Services.

Our processing activities as a data processor are governed by our Data Processing Agreement (DPA), available upon request. Enterprise customers with a signed SaaS Services Agreement have a DPA attached as an annex to that agreement.

If you send review requests through the Services (via email, SMS, or WhatsApp), you are responsible for ensuring you have appropriate consent or another lawful basis to contact those individuals. We process their contact information solely to send the review request on your behalf and do not use it for any other purpose.

8. International Data Transfers

Your personal data is stored and processed within the European Union. Our primary infrastructure is hosted on in the EU (Dublin).

We do not transfer personal data outside the EU as a matter of course. Where a sub-processor may process data outside the EU (see Section 4), we ensure appropriate safeguards are in place, including Standard Contractual Clauses (SCCs) approved by the European Commission.

9. Data Security

We implement appropriate technical and organisational measures to protect your personal data, including:

  • Encryption of data in transit (TLS) and at rest
  • Role-based access controls and secure authentication
  • Regular security monitoring and incident response procedures
  • Hashed password storage

No method of transmission over the internet or electronic storage is 100% secure. While we take commercially reasonable measures to protect your data, we cannot guarantee absolute security. If you become aware of any security issue, please notify us immediately at hello@reviewflowz.com.

10. Your Rights Under GDPR

If you are located in the European Economic Area (EEA), you have the following rights regarding your personal data:

  • Right of access — You can request a copy of the personal data we hold about you.
  • Right to rectification — You can ask us to correct inaccurate or incomplete personal data.
  • Right to erasure — You can ask us to delete your personal data, subject to legal retention requirements.
  • Right to restriction — You can ask us to restrict the processing of your personal data in certain circumstances.
  • Right to data portability — You can request your personal data in a structured, commonly used, machine-readable format.
  • Right to object — You can object to processing based on legitimate interest, including for direct marketing purposes.
  • Right to withdraw consent — Where processing is based on consent, you can withdraw it at any time.

To exercise any of these rights, contact us at hello@reviewflowz.com. We will respond within 30 days. If we need more time (up to an additional 60 days for complex requests), we will inform you within the initial 30-day period.

If you are unsatisfied with our response, you have the right to lodge a complaint with your local data protection authority.

11. Automated Decision-Making

We do not engage in automated decision-making or profiling that produces legal effects or similarly significant effects on individuals (within the meaning of Article 22 GDPR). Our AI-powered features may generate and publish review responses automatically based on rules configured by the customer. This does not constitute automated decision-making within the meaning of GDPR, as it does not produce legal or similarly significant effects on any individual.

12. Children's Privacy

The Services are intended for business use and are not directed at individuals under the age of 18. We do not knowingly collect personal data from anyone under 18. If we become aware that we have collected personal data from a minor, we will take steps to delete it promptly. If you believe a minor has provided us with personal data, please contact us at hello@reviewflowz.com.

13. Changes to This Privacy Policy

We may update this Privacy Policy from time to time. We will notify you of material changes by updating the "Last updated" date at the top of this page and, for significant changes, by email or prominent notice within the Services. Your continued use of the Services after such changes constitutes acceptance of the revised Privacy Policy.

14. Contact

For any questions about this Privacy Policy, to exercise your data rights, or to raise a privacy concern, please contact us at:

REVIEWFLOWZ SAS

870 chemin du vallon des mourgues, 13090 Aix-en-Provence, France

Email: hello@reviewflowz.com

We do not have a Data Protection Officer, as we are not required to appoint one under Article 37 GDPR (we employ fewer than 250 people and do not carry out large-scale processing of special categories of data or systematic monitoring of individuals). All privacy inquiries are handled directly by the company's management.