What we do with your data.
Who we are
Verdscore is a SaaS product that turns public restaurant and hotel reviews into actionable AI insights. We are the data controller for the personal data described here.
Data-protection contact: [email protected] (I read every message). Transactional emails are sent from [email protected] — that inbox isn't monitored, always reply to support@.
What we collect and why
- Public venue data. Place details and reviews from Google + TripAdvisor for the venues you track. Already public on those sources; we layer sentiment, themes, and suggested replies on top.
- Account data. Name, email, hashed password (we never see the plaintext), the venues you claim, your plan, reply-tone preferences, team and manager assignments.
- Billing data. Stripe handles payment cards directly — we never see or store the card number. We do see the email, name, country, and subscription state Stripe sends back.
- Usage and security data. Log lines, IP, request IDs, login attempts, cookies. Used to keep the service secure, debug, and (only with consent) understand usage.
Legal basis
- Account + venue data — Art. 6(1)(b) GDPR (necessary to perform our contract with you).
- Security + operational logs — Art. 6(1)(f) (our legitimate interest in keeping the service safe and debuggable).
- Public reviewer data from Google Maps + TripAdvisor — Art. 6(1)(f), read together with Recital 47 (legitimate interest of the venue owner in analysing feedback about their venue). A balancing test is on file.
- Analytics cookie — Art. 6(1)(a) (explicit consent via the cookie banner; withdrawable at any time from the same banner).
- Billing records — Art. 6(1)(c) (compliance with tax and accounting law).
Automated processing and AI
Verdscore does not make solely-automated decisions with legal or similarly significant effect on you or reviewers (Art. 22 GDPR). Sentiment scoring, theme extraction, and AI-drafted replies are decision-support outputs that a human operator reviews before any reply reaches a reviewer.
We do not use your account data or ingested review content to train Verdscore's or our vendors' AI models. LLM API calls run on zero-retention or no-training tiers with each provider.
Sub-processors
We list every third party that processes your data — vendor, purpose, region, certifications — on a dedicated page that we keep dated and current. See /legal/subprocessors. B2B customers can request a signed Data Processing Addendum via the DPA page.
We do not sell your data and we don't share it with advertisers.
Cookies
One strictly-necessary session cookie keeps you signed in. A consent-gated analytics cookie (Google Analytics 4 via Consent Mode v2) loads only after you accept the banner. No advertising or cross-site tracking cookies. Full detail in the cookie policy.
How long we keep data
We keep different categories for different lengths of time — driven by what we need to deliver the service, what tax law requires, and what's genuinely useful for you if you come back. The table below is the current schedule.
| Category | Kept for | Notes |
|---|---|---|
| Account profile + venue claims | Deleted or anonymised within 30 days of account closure | Kept during active life on Art. 6(1)(b); nulled on closure, aggregate counts retained |
| Reviews + analytics derived for your venues | Active + 30 days after account deletion | Storage capped at 30 days post-closure for reactivation; source-API terms also constrain cache duration |
| AI reply drafts you didn't send | Same as the underlying review | Drafts you marked done/skipped: kept with the review row |
| Auth + security logs | 90 days | Login attempts, session IPs, rate-limit hits |
| Admin audit log | 1 year | Every privileged action — impersonation, manual overrides |
| Stripe invoices + billing records | 7 years | Held by Stripe per EU/US tax retention law |
| Encrypted database backups | 30 days rolling | Then deleted automatically |
If something goes wrong (breach notification)
If we confirm a personal-data breach that's likely to put your rights or freedoms at risk, we'll notify affected users within 72 hours of becoming aware (GDPR Article 33). The notification will describe what happened, what data was involved, what we've done about it, and what you should do.
Security
Passwords are stored as bcrypt hashes. Data is encrypted in transit (TLS) and backups are encrypted at rest (AES-256). We rate-limit login attempts, use Cloudflare Turnstile on every public form, and run an admin audit log on every privileged action.
International transfers
The application + database are hosted in the EU (Hetzner Cloud, Nuremberg). Backups stay in the EU (AWS S3 Frankfurt). Some sub-processors above process data outside the EU — primarily LLM providers; we share only the data needed for that specific processing and rely on Standard Contractual Clauses where required.
Your rights
Under GDPR (and UK GDPR / DPA 2018 for UK residents) you can access, correct, delete, export, restrict, or object to the processing of your personal data, withdraw consent for analytics at any time, and lodge a complaint with your local supervisory authority — e.g. CNIL (France), GBA/APD (Belgium), Bayerisches LDA (Germany), ICO (UK), APDCAT (Catalonia).
- Access + correct: sign in and edit your profile at
/settings. - Export your data (portability): use the “Download my data” button on
/settingsfor a machine-readable, structured JSON snapshot of your account, venue claims, and per-venue stats. For anything beyond that summary, contact us. - Delete your account: use the “Delete my account” button on
/settings. Your active subscription is canceled, your PII is anonymised within minutes, and your sessions are revoked. Aggregate counts and invoices we're legally required to keep stay; see the retention table above. - Withdraw consent (analytics): re-open the cookie banner at any time and switch analytics off — future page loads stop reporting.
- Other rights (restrict, object, complain): send a request via /contact and we'll respond within 30 days (the GDPR SLA).
Children
Verdscore is a tool for business owners. It's not intended for anyone under 18 and we don't knowingly collect data from children.
Changes to this policy
When we make a meaningful change, we'll bump the date at the top and (where appropriate) notify signed-in users before it takes effect.