Rviewo Logo
HomeAbout
Free Reputation Audit
PricingFor RviewersBlogLog In

Privacy Policy

Effective Date: April 10, 2026

1. Introduction

Post Holdings LLC, d/b/a Rviewo ("Rviewo," "we," "us") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, store, and share your personal data when you use our website, web application, mobile application, and services (the "Service"), or otherwise interact with us. This policy is designed to comply with the EU's General Data Protection Regulation (GDPR), the California Consumer Privacy Act (CCPA), and other applicable privacy laws.

2. Who We Are (Data Controller)

The data controller responsible for your personal data is:
Post Holdings LLC
2308 Plum Woods Dr, Sellersburg, IN 47172, USA
contact@rviewo.com

3. Our Role as a Data Controller and Processor

Our role under data protection laws varies depending on the situation:

  • When you create a Business User or Consumer account, we act as the Data Controller for your account and profile data.
  • When we process feedback and chat data collected from Guest Respondents on behalf of a Business User, the Business User is the Data Controller, and Rviewo acts as the Data Processor for that session data.
  • When Rviewo independently stores anonymized behavioral signals (hashed email identifiers, sentiment trends) for fraud prevention and AI improvement purposes, Rviewo acts as an independent Data Controller for that processing. Guest Respondents' email addresses are held exclusively by Rviewo and are never provided to Business Users in any form.
  • When a Consumer submits feedback through a mission, Rviewo acts as the Data Controller for that interaction, as we facilitate the mission and award points.

4. Data We Collect

We collect different types of data depending on how you interact with our Service.

a. For Business Users (Account Holders)

  • Account Data: Email address, hashed password (or OAuth provider identity for social sign-in).
  • Business Profile Data: Business name, type, location, description, logo, profile picture, Google Place ID, hours of operation, phone number, website URL.
  • User Content: Survey configurations, AI knowledge base entries, chat agent instructions, reward/incentive settings.
  • Payment Data: Billing information is collected and processed by Stripe. We do not store your full credit card number.
  • Uploaded Files: Profile pictures, business logos, and any images uploaded by customers during chat sessions.

b. For Consumers (Rviewers with Accounts)

  • Account Data: Full name, email address, hashed password, city of residence.
  • Profile Data: Display name, avatar, profile visibility setting, referral code.
  • Activity Data: Points balance, total reviews, average quality grade, average satisfaction score, mission completion records, businesses interacted with, invite code used.
  • Feedback Data: Chat messages, star ratings, text feedback, uploaded images, sentiment scores, and AI-generated review drafts associated with your interactions.

c. For Guest Respondents (No Account)

  • Chat Data: Messages exchanged with the AI agent, star ratings, text feedback, and uploaded images.
  • Email Address: Only if you provide it voluntarily to receive a reward code or a copy of your chat. Your email address is stored by Rviewo and is never shared with or directly visible to the business you are providing feedback for.
  • Derived Data: Sentiment analysis, AI-generated review summaries, and pain point analysis derived from your chat.
  • Session Memory: To maintain conversation continuity in longer sessions, the AI may generate and store a brief summary of earlier parts of your conversation. This summary is used only during your active session and to improve Quilly's responses within that session.
  • Anonymized Behavioral Signals: If you provide your email, we store anonymized behavioral signals (visit count, sentiment trend, topics discussed) under a one-way cryptographic hash of your email. These signals are used internally by Rviewo for fraud prevention, AI improvement, and — if a business claims their Rviewo account — to provide them with aggregate visit pattern data. Businesses never receive your email address or any directly identifying information through this system.

d. Automatically Collected Data (All Visitors)

  • Usage Data: IP address, browser type and version, device type, pages visited, time spent on pages, and other diagnostic data.
  • Session Data: Chat session identifiers, session duration, and chat history stored temporarily in your browser's local storage for session continuity.

e. Data from Public Sources

For Pre-Built Business Profiles (Shadow Accounts), we collect publicly available business information from sources including Google Places, such as business name, address, phone number, website, hours of operation, Google rating, and review count. This data is used to create profiles that business owners can claim.

5. How We Use Your Data and Our Legal Basis (GDPR)

Purpose of ProcessingData UsedLegal Basis
To provide and manage Business User accountsAccount & Profile DataPerformance of a contract
To provide and manage Consumer accounts, including points, missions, and profilesAccount, Profile & Activity DataPerformance of a contract
To power the AI chat agent (Quilly) and generate feedback insightsChat messages, ratings, User ContentPerformance of a contract; Legitimate Interest
To perform sentiment analysis and generate review draftsChat data, feedback textLegitimate Interest (service improvement)
To display public reviewer profilesDisplay name, city, review statsConsent (profile visibility setting)
To create Pre-Built Business Profiles from public dataPublicly available business dataLegitimate Interest
To process rewards, discount codes, and incentivesEmail Address, reward detailsConsent; Performance of a contract
To process payments for subscriptionsPayment data (via Stripe)Performance of a contract
To send transactional emails (reward codes, chat copies, notifications)Email Address, chat/reward dataConsent; Performance of a contract
To improve our Service and train our AI modelsPseudonymized and aggregated User Content & responsesLegitimate Interest
To maintain session memory and provide conversation continuity within a Quilly chat sessionConversation history (summarized, not stored verbatim beyond the session)Legitimate Interest (service delivery)
To build anonymized cross-session behavioral signals (fraud prevention, repeat-visit detection, AI improvement)Hashed email identifier, visit count, sentiment trend, session IDsLegitimate Interest
To ensure security and prevent abuse (bot detection, anti-gaming)Usage Data, behavioral signals, hashed emailLegitimate Interest
To send marketing communications (if opted in)Email AddressConsent

6. Data Sharing and Third-Party Sub-processors

We do not sell your personal data. We only share it with trusted third-party service providers (sub-processors) to operate our Service:

  • Google Cloud / Firebase (USA): Hosting, database storage (Firestore), authentication, cloud functions, and file storage.
  • Google Vertex AI (USA): AI processing of chat conversations, sentiment analysis, review draft generation, and knowledge base queries.
  • Google Maps Platform (USA): Business data enrichment, location autocomplete, and Google Places integration for shadow account creation.
  • Google reCAPTCHA v3 (USA): Bot detection and abuse prevention. reCAPTCHA collects hardware and software information (such as device and application data) and sends it to Google for analysis. By using the Service, you acknowledge that your use is subject to Google's Privacy Policy and Terms of Service.
  • Stripe (USA): Payment processing for Business User subscriptions. Stripe collects and processes payment information under its own privacy policy.
  • Resend (USA): Transactional email delivery for reward codes, chat transcript copies, manager alerts, and account notifications.

7. Public Profiles and Visibility

a. Consumer Reviewer Profiles

When you create a Consumer account, a public reviewer profile is created. By default, the following information may be publicly visible:

  • Display name
  • City
  • Total review count
  • Average quality grade

You can change your profile visibility to private in your account settings. Private profiles are not displayed publicly.

b. Business Profiles

Business profiles, including business name, location, and customer feedback statistics, are publicly visible. Pre-Built Profiles created from public data are also visible until claimed or removed upon request.

8. Cookies and Tracking Technologies

  • Essential Cookies: Firebase authentication tokens and session identifiers required for the Service to function.
  • Analytics: We use Google Analytics (with Google Consent Mode) to understand how users interact with the Service. Analytics data is collected in a privacy-respecting manner based on your consent preferences.
  • Local Storage: We use browser local storage to persist chat session data, allowing you to resume conversations if you navigate away. This data is stored only on your device and is cleared when the chat session completes.
  • reCAPTCHA: Google reCAPTCHA v3 may set cookies to assess browser behavior for bot detection purposes.

9. International Data Transfers

Rviewo is based in the United States. Your personal data is processed and stored on servers located in the USA. For users in the European Economic Area (EEA), this constitutes a transfer of personal data outside the EEA. We ensure this transfer is lawful by relying on Standard Contractual Clauses (SCCs) as the legal basis, which are incorporated into our data processing agreements with our sub-processors.

10. Data Security and Retention

Security: We implement appropriate technical and organizational measures (including encryption, access controls, and AppCheck verification) to protect your personal data against unauthorized access, loss, or destruction.

Retention: We retain your data for the following periods:

  • Account Information: Deleted 90 days after you request account closure.
  • Chat Session Data: Active session data is retained for the duration of the business relationship. Completed sessions are retained for analytics and dispute resolution purposes.
  • Consumer Activity Data: Points, review history, and mission records are retained as long as your account is active.
  • Pseudonymized Data: May be retained indefinitely for analytical and service improvement purposes, as this data is no longer directly attributable to an individual.
  • Legal Acceptance Records: Immutable records of your terms/privacy acceptance (including timestamp, version, IP, and method) are retained indefinitely for legal compliance.

11. Your Data Protection Rights

a. Rights Under GDPR (EEA Residents)

  • Right to access: You can request copies of your personal data.
  • Right to rectification: You can request correction of inaccurate data.
  • Right to erasure: You can request deletion of your personal data, subject to legal retention requirements.
  • Right to restrict processing: You can request that we limit how we process your data.
  • Right to data portability: You can request your data in a machine-readable format.
  • Right to object: You can object to processing based on legitimate interest.

To exercise these rights, contact us at contact@rviewo.com. We will respond within 30 days. You also have the right to lodge a complaint with a data protection authority.

b. Rights Under CCPA/CPRA (California Residents)

  • Right to know: You can request what personal information we collect, use, and disclose.
  • Right to delete: You can request deletion of your personal information.
  • Right to opt-out of sale: We do not sell your personal information to third parties.
  • Right to non-discrimination: We will not discriminate against you for exercising your privacy rights.

To exercise these rights, contact us at contact@rviewo.com.

c. Other US State Privacy Laws

If you are a resident of Virginia, Colorado, Connecticut, or other states with comprehensive privacy legislation, you may have similar rights to those described above. Contact us to exercise any applicable rights.

12. Children's Privacy

Our Service is not intended for individuals under the age of 18. We do not knowingly collect personal data from anyone under 18. If we learn that we have collected data from a person under 18, we will promptly delete it.

13. Changes to This Privacy Policy

We may update this policy from time to time. For material changes, we will require you to re-accept the updated Privacy Policy before continuing to use the Service. The effective date at the top of this page indicates when the policy was last revised.

14. Contact Us

For any questions about this Privacy Policy, to exercise your data protection rights, or to report a privacy concern, please contact us at:

Post Holdings LLC
Email: contact@rviewo.com
Address: 2308 Plum Woods Dr, Sellersburg, IN 47172, USA

Rviewo Logo

Reputation management built for local businesses. More reviews, fewer bad ones. All on autopilot.

Product

  • Features
  • Pricing
  • Free Reputation Audit
  • Compare vs. competitors
  • In-Person Feedback
  • Online Reviews

Company

  • About Us
  • Blog
  • Resources
  • Local Guides
  • Industries
  • Contact
  • FAQ

Get Started

  • For Businesses
  • For Rviewers
  • Best Tools Ranked

Legal

  • Terms of Service
  • Privacy Policy
  • Cookie Policy

Follow Us

© 2026 Rviewo. All Rights Reserved.