Privacy Policy
This policy explains what newReview collects, what we do with it, who we share it with, and what control you have over it. We've tried to keep it plain. If anything is unclear, write to hello@newreview.co.
Who we are
newReview is a product of Fourdots Digital, a company based in Toronto, Ontario, Canada. When we say "we," "us," or "newReview" in this policy, that's who we mean. When we say "you," we mean the person or business operating a newReview account.
Two kinds of data
It helps to separate the data we handle into two buckets, because they have different rules:
- Your data. Things like your name, business name, email, billing details, and how you use the product. You're the subject of this data; we're the people handling it.
- Your customers' data. Things like the names, emails, and phone numbers of your customers — the people you send review requests to, and the reviews they leave. You're the controller of this data (you decide what to collect and what to do with it); we're the processor (we store and move it on your behalf).
This policy covers both, but where the distinction matters, we'll call it out.
What we collect
From you, the account holder
- Account info: name, email, password (stored hashed), business name, business address, business phone, time zone.
- Billing info: billing email, billing address, the last four digits and brand of your card. We never see or store your full card number — that's handled by Stripe.
- Usage data: what features you use, when you log in, what you click, what device and browser you're on. We use this to fix bugs, prioritize what to build next, and notice when something's broken.
- Communications: anything you write to us by email or in-app, and our replies. We keep these so we can refer back to ongoing conversations.
- Google Business Profile data: when you connect Google, we receive your reviews, ratings, business info, photos, posts, and Q&A. We only ask for the permissions needed to manage reviews and posts; we never modify your underlying business listing.
From your customers
- Contact info you provide: the names, emails, and phone numbers you upload or sync to send review requests.
- Review activity: whether they opened your request, clicked the link, what star rating they gave, and the text of any review or feedback they left.
- Recordings (only if you use video testimonials): the video files customers record, which we store on your behalf.
How we use it
- To operate the product (send your review requests, sync reviews from Google, post your replies, etc.).
- To bill you (process payments, send receipts, handle plan changes).
- To send you transactional emails (welcome, password resets, billing alerts, magic links).
- To improve the product (anonymized usage analytics).
- To support you (answer questions, troubleshoot issues).
- To enforce our Terms and prevent abuse.
- To comply with legal obligations.
We do not sell your data, your customers' data, or any of the reviews you collect, to anyone, ever.
Who we share it with
We use a small number of trusted sub-processors to actually run the service. Each one only sees the data they need to do their job:
Stripe (payments)
Stripe processes all subscription payments. They receive your billing email, name, address, and card details directly — we never see the card. Their privacy policy: stripe.com/privacy.
Resend (transactional email)
Resend sends our transactional emails — welcome messages, magic links, billing receipts. They receive recipient email addresses and the content of each message we send. Their privacy policy: resend.com/legal/privacy-policy.
MySaaS (review platform backend)
MySaaS provides the core review-collection infrastructure that powers newReview. They receive your business profile data and the data needed to operate your account.
Vercel (hosting)
Vercel hosts our website and serverless functions. They process traffic logs and standard request data (IP addresses, user-agents). Their privacy policy: vercel.com/legal/privacy-policy.
Google (your Google Business Profile)
When you connect Google, you authorize us to read and write to your Google Business Profile via Google's official API. Google's privacy policy: policies.google.com/privacy.
Anything else?
Beyond the sub-processors above, we only share data when legally required (e.g. a valid subpoena) or with your explicit consent. We'll tell you about a legal request unless we're prohibited from doing so.
Where data lives
Our infrastructure is primarily hosted in the United States and Europe via the providers above. By using newReview, you understand and consent to your data being processed in those regions, which may have different data-protection rules than your home country.
How long we keep it
- While your account is active: as long as needed to operate the service.
- After you cancel: your account data stays in a read-only state for 30 days in case you change your mind, then is queued for deletion. You can request immediate deletion any time.
- Billing records: kept for 7 years after the last transaction, as required by Canadian tax law.
- Support communications: kept for 2 years after the last reply.
- Anonymized usage analytics: kept indefinitely (no personal identifiers).
Your rights
Depending on where you live, you may have specific rights under laws like GDPR (EU/UK), PIPEDA (Canada), or CCPA (California). At minimum, you can always:
- Access the personal data we hold about you.
- Correct anything that's wrong or out of date.
- Delete your account and the personal data tied to it.
- Export your data in a portable format.
- Object to certain processing or withdraw consent where consent is the legal basis.
- Complain to your local data-protection authority.
To exercise any of these, email hello@newreview.co. We respond within 30 days.
Your customers' rights
Your customers (the people you send review requests to) have similar rights under their local laws. Because you control what data is collected and how it's used, those requests should go to you first. We'll help you fulfill them as the processor — including helping you delete a specific contact from your account on request.
Customers can opt out of further review requests from you at any time via the unsubscribe link in every email and SMS. Opt-outs are honored permanently across your account.
Cookies & tracking
Our marketing site (newreview.co) uses essential cookies only — for navigation, session, and security. The app (app.newreview.co) uses authentication and session cookies needed to keep you logged in. We do not use third-party advertising trackers on the app.
Security
We take reasonable steps to protect your data: HTTPS everywhere, encrypted-at-rest databases at our sub-processors, hashed password storage, signed magic links with short expiry, and least-privilege access for our team. No system is perfectly secure, but we treat your data the way we'd want our own treated.
If we ever discover a security incident affecting your data, we'll notify you within 72 hours of becoming aware of it, in line with our obligations under PIPEDA and equivalent laws.
Children
newReview is built for businesses. It is not directed at, and we do not knowingly collect personal information from, anyone under 16. If you believe a child has provided us data, write to hello@newreview.co and we'll delete it.
Changes to this policy
If we make material changes, we'll email you at least 30 days before they take effect. Minor wording or clarification updates may happen without notice but will be reflected in the "Last updated" date above.
Contact
Privacy questions, requests, and complaints all go to one place:
newReview · Fourdots Digital
hello@newreview.co
Toronto, Ontario, Canada