Privacy Policy
Last updated: 25 April 2026
SmartRating ("SmartRating", "we", "us", or "our") is operated by Web Ninja Solutions and accessible at smartrating.io. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our platform. Please read it carefully.
1. Information We Collect
Account information: When you create an account, we collect your name, email address, and password (stored as a bcrypt hash).
Business information: We collect business names, locations, Google review URLs, and any context you provide to customise your AI review prompts.
Customer review data: When your customers use the review flow, we collect their star rating, selected chips, and any text they type. We also collect an anonymised, one-way hash of their IP address (not the IP itself) to detect duplicate submissions.
Usage data: We automatically collect QR code scan events, timestamps, and device type (via User-Agent header) to power your analytics dashboard.
Payment information: Payments are processed by Stripe. We never see or store your card number. We store only your Stripe Customer ID, Subscription ID, and plan status.
Communication: If you contact us at support@smartrating.io, we retain that correspondence to assist you.
2. How We Use Your Information
- To provide, operate, and maintain the SmartRating platform
- To process payments and manage your subscription
- To generate AI-assisted review drafts for your customers using Anthropic Claude
- To send you negative-feedback alert emails and account notifications
- To display analytics about your locations' performance
- To respond to support requests
- To comply with legal obligations
We do not sell your data. We do not use your data to train AI models.
3. Third-Party Services
We use the following third-party processors to deliver the service:
- Supabase — Authentication and database hosting (EU data region)
- Anthropic — AI review draft generation (data is not used for model training)
- Stripe — Payment processing (PCI-DSS compliant)
- Resend — Transactional email delivery
- Vercel — Application hosting and edge delivery
- Upstash — Rate limiting (anonymised IP hashes only)
Each provider has its own privacy policy. We only share the minimum data required for each service to function.
4. Data Retention
We retain your account data for as long as your account is active. If you delete your account, all your data (businesses, locations, reviews, scans) is permanently deleted within 30 days.
Anonymised, aggregated analytics data may be retained indefinitely as it cannot be linked to an individual.
5. Your Rights
Depending on your location, you may have the following rights:
- Access: Request a copy of all personal data we hold about you
- Correction: Update inaccurate information via your Settings page
- Deletion: Delete your account and all associated data from Settings → Account → Delete account
- Portability: Export your data as JSON from Settings → Account → Export data
To exercise any right, or if you have a concern, email us at support@smartrating.io.
6. Cookies
We use only essential cookies required for authentication (Supabase session cookies). We do not use advertising or tracking cookies. We do not use Google Analytics or any third-party analytics trackers.
7. Security
We implement industry-standard security measures including HTTPS everywhere, bcrypt password hashing, JWT-based authentication, and encrypted environment variables. No transmission over the internet is 100% secure; use the platform at your own risk.
8. Children's Privacy
SmartRating is not directed at children under 16. We do not knowingly collect personal data from anyone under 16. If you believe a child has provided us data, contact us immediately.
9. Changes to This Policy
We may update this Privacy Policy from time to time. When we do, we will update the "last updated" date above. Continued use of SmartRating after changes constitutes acceptance of the updated policy.
10. Contact
For any privacy-related questions or requests, contact us at:
support@smartrating.io
Web Ninja Solutions · smartrating.io