Legal

What we do with your data.

Last updated · 27 June 2026
The position
I built Verdscore on public Google Maps + TripAdvisor data plus what you type into the app. I name every sub-processor below. I don't sell your data and I don't share it with advertisers. EU-hosted, encrypted backups in the EU. One session cookie always; analytics only if you accept the banner.

Who we are

Verdscore is a SaaS product that turns public restaurant and hotel reviews into actionable AI insights. We are the data controller for the personal data described here.

Data-protection contact: [email protected] (I read every message). Transactional emails are sent from [email protected] — that inbox isn't monitored, always reply to support@.

What we collect and why

  • Public venue data. Place details and reviews from Google + TripAdvisor for the venues you track. Already public on those sources; we layer sentiment, themes, and suggested replies on top.
  • Account data. Name, email, hashed password (we never see the plaintext), the venues you claim, your plan, reply-tone preferences, team and manager assignments.
  • Billing data. Stripe handles payment cards directly — we never see or store the card number. We do see the email, name, country, and subscription state Stripe sends back.
  • Usage and security data. Log lines, IP, request IDs, login attempts, cookies. Used to keep the service secure, debug, and (only with consent) understand usage.

Legal basis

  • Account + venue data — Art. 6(1)(b) GDPR (necessary to perform our contract with you).
  • Security + operational logs — Art. 6(1)(f) (our legitimate interest in keeping the service safe and debuggable).
  • Public reviewer data from Google Maps + TripAdvisor — Art. 6(1)(f), read together with Recital 47 (legitimate interest of the venue owner in analysing feedback about their venue). A balancing test is on file.
  • Analytics cookie — Art. 6(1)(a) (explicit consent via the cookie banner; withdrawable at any time from the same banner).
  • Billing records — Art. 6(1)(c) (compliance with tax and accounting law).

Automated processing and AI

Verdscore does not make solely-automated decisions with legal or similarly significant effect on you or reviewers (Art. 22 GDPR). Sentiment scoring, theme extraction, and AI-drafted replies are decision-support outputs that a human operator reviews before any reply reaches a reviewer.

We do not use your account data or ingested review content to train Verdscore's or our vendors' AI models. LLM API calls run on zero-retention or no-training tiers with each provider.

Sub-processors

We list every third party that processes your data — vendor, purpose, region, certifications — on a dedicated page that we keep dated and current. See /legal/subprocessors. B2B customers can request a signed Data Processing Addendum via the DPA page.

We do not sell your data and we don't share it with advertisers.

Cookies

One strictly-necessary session cookie keeps you signed in. A consent-gated analytics cookie (Google Analytics 4 via Consent Mode v2) loads only after you accept the banner. No advertising or cross-site tracking cookies. Full detail in the cookie policy.

How long we keep data

We keep different categories for different lengths of time — driven by what we need to deliver the service, what tax law requires, and what's genuinely useful for you if you come back. The table below is the current schedule.

CategoryKept forNotes
Account profile + venue claimsDeleted or anonymised within 30 days of account closureKept during active life on Art. 6(1)(b); nulled on closure, aggregate counts retained
Reviews + analytics derived for your venuesActive + 30 days after account deletionStorage capped at 30 days post-closure for reactivation; source-API terms also constrain cache duration
AI reply drafts you didn't sendSame as the underlying reviewDrafts you marked done/skipped: kept with the review row
Auth + security logs90 daysLogin attempts, session IPs, rate-limit hits
Admin audit log1 yearEvery privileged action — impersonation, manual overrides
Stripe invoices + billing records7 yearsHeld by Stripe per EU/US tax retention law
Encrypted database backups30 days rollingThen deleted automatically

If something goes wrong (breach notification)

If we confirm a personal-data breach that's likely to put your rights or freedoms at risk, we'll notify affected users within 72 hours of becoming aware (GDPR Article 33). The notification will describe what happened, what data was involved, what we've done about it, and what you should do.

Security

Passwords are stored as bcrypt hashes. Data is encrypted in transit (TLS) and backups are encrypted at rest (AES-256). We rate-limit login attempts, use Cloudflare Turnstile on every public form, and run an admin audit log on every privileged action.

International transfers

The application + database are hosted in the EU (Hetzner Cloud, Nuremberg). Backups stay in the EU (AWS S3 Frankfurt). Some sub-processors above process data outside the EU — primarily LLM providers; we share only the data needed for that specific processing and rely on Standard Contractual Clauses where required.

Your rights

Under GDPR (and UK GDPR / DPA 2018 for UK residents) you can access, correct, delete, export, restrict, or object to the processing of your personal data, withdraw consent for analytics at any time, and lodge a complaint with your local supervisory authority — e.g. CNIL (France), GBA/APD (Belgium), Bayerisches LDA (Germany), ICO (UK), APDCAT (Catalonia).

  • Access + correct: sign in and edit your profile at /settings.
  • Export your data (portability): use the “Download my data” button on /settings for a machine-readable, structured JSON snapshot of your account, venue claims, and per-venue stats. For anything beyond that summary, contact us.
  • Delete your account: use the “Delete my account” button on /settings. Your active subscription is canceled, your PII is anonymised within minutes, and your sessions are revoked. Aggregate counts and invoices we're legally required to keep stay; see the retention table above.
  • Withdraw consent (analytics): re-open the cookie banner at any time and switch analytics off — future page loads stop reporting.
  • Other rights (restrict, object, complain): send a request via /contact and we'll respond within 30 days (the GDPR SLA).

Children

Verdscore is a tool for business owners. It's not intended for anyone under 18 and we don't knowingly collect data from children.

Changes to this policy

When we make a meaningful change, we'll bump the date at the top and (where appropriate) notify signed-in users before it takes effect.

Questions about this document? Send me a message — I read every one.
Privacy · Verdscore.ai · Verdscore