Privacy Policy

Last updated: January 6, 2026

Data Controller: Rich Plugins SL
Plaza San Cristóbal, 14, 03002 Alacant/Alicante, Spain
Email: support@trust.reviews
Website: https://trust.reviews

1. Scope of this Privacy Policy

This Privacy Policy explains how we collect, use, disclose and protect information when you:

  • visit any page on the trust.reviews website or its subdomains;
  • create and use an account on the Trust.Reviews SaaS platform (including free and paid plans);
  • connect your business profiles or pages on external platforms (such as Google Business Profile or Facebook Pages) to our service;
  • use our widgets, campaigns, or other tools to collect, display and manage reviews.

This notice describes what personal and non-personal data we collect, how we collect it, how and why we use it, how long we keep it, with whom we may share it, and what rights you have as a data subject and how you can exercise them.

Any capitalised terms not defined here have the meaning given elsewhere on our website or in our Terms of Service. By using Trust.Reviews, you agree to this Privacy Policy.

2. Roles: Data Controller and Data Processor

Depending on the context, Rich Plugins SL may act as a Data Controller or as a Data Processor.

2.1 Data Controller

We act as a Data Controller when we determine the purposes and means of processing your personal data, for example when:

  • you visit our website;
  • you register for a Trust.Reviews account (free or paid);
  • you use the Trust.Reviews platform and dashboard;
  • you communicate with us by email or support channels;
  • we send you service-related or marketing communications.

In these cases, we are responsible for deciding how your personal data is used and for complying with applicable data protection laws.

2.2 Data Processor

We act as a Data Processor when we process personal data on behalf of our business customers. This occurs, for example, when you:

  • connect your Google Business Profile to Trust.Reviews;
  • connect your Facebook Page or other supported review sources;
  • import, sync and display reviews through our platform.

In those cases, you (your business) are the Data Controller, and we process the relevant data only according to your instructions and our agreement with you. You are responsible for ensuring you have a lawful basis to collect and use such data and to appoint us as your processor.

3. Definitions

3.1 Personal Data (PD)

“Personal Data” means any information relating to an identified or identifiable natural person, such as:

  • name, email address, IP address;
  • account identifiers;
  • data that can be linked to an individual using reasonable means (alone or in combination with other data).

3.2 Non-Personal Data (NPD)

“Non-Personal Data” is information that does not identify an individual and cannot reasonably be used to identify them, for example:

  • aggregated usage statistics;
  • anonymised analytics data;
  • generic technical information that has been stripped of identifiers.

3.3 Sensitive Personal Data (SPD)

“Sensitive Personal Data” typically includes, for example:

  • government IDs;
  • precise geolocation;
  • financial account details with access credentials;
  • health-related data;
  • data about racial or ethnic origin, political opinions, religious or philosophical beliefs, trade union membership, sex life or sexual orientation;
  • biometric data for identification.

We do not intentionally collect Sensitive Personal Data through Trust.Reviews, and you should avoid submitting such information to us or storing it in the service.

4. Your Privacy Rights

Depending on where you live (for example under the EU GDPR, UK GDPR, CCPA/CPRA and other laws), you may have certain rights in relation to your Personal Data.

4.1 Rights under GDPR, UK GDPR and similar laws

  • Right to be informed – to receive clear information about what data we collect, how we use it and on what legal basis.
  • Right of access – to request confirmation whether we process your data and to receive a copy of your Personal Data.
  • Right to rectification – to have inaccurate or incomplete Personal Data corrected.
  • Right to erasure (“right to be forgotten”) – to request deletion of your Personal Data when there is no compelling reason for us to continue processing it (subject to legal and legitimate interest exceptions).
  • Right to restriction of processing – to request that we restrict the processing of your data in certain circumstances.
  • Right to data portability – to receive the Personal Data you provided to us in a structured, commonly used and machine-readable format and to transmit it to another controller, where technically feasible.
  • Right to object – to object to processing based on our legitimate interests, including profiling; and to object at any time to the use of your data for direct marketing.
  • Rights regarding automated decision-making – to not be subject to a decision based solely on automated processing (including profiling) that has legal or similarly significant effects.
  • Right to withdraw consent – where processing is based on consent, you can withdraw it at any time.
  • Right to lodge a complaint – you have the right to lodge a complaint with a supervisory authority if you believe your rights have been violated.

4.2 Additional rights for California residents (CCPA / CPRA)

If you are a resident of California, you may have additional rights under the California Consumer Privacy Act (CCPA), as amended by the California Privacy Rights Act (CPRA), including the right to:

  • Know the categories of Personal Information we collect, use, disclose and, where applicable, “sell” or “share”;
  • Access specific pieces of Personal Information we hold about you;
  • Request deletion of your Personal Information, subject to certain exceptions;
  • Correct inaccurate Personal Information we hold about you;
  • Opt out of the sale or sharing of your Personal Information, where our practices are considered a “sale” or “sharing” under CCPA/CPRA;
  • Limit the use and disclosure of sensitive Personal Information, where applicable;
  • Not be discriminated against for exercising your privacy rights.

We do not sell or share Personal Information in exchange for money or for cross-context behavioural advertising as those terms are defined under CCPA/CPRA. If our practices change, we will update this Policy and provide applicable opt-out mechanisms.

You can exercise your rights by contacting us at support@trust.reviews. We may need to verify your identity before responding to your request. We will respond within the time limits set by applicable law.

5. Data We Collect and How We Collect It

You generally control how much information you provide to us when using Trust.Reviews.

5.1 Automatic Information

When you visit our website or log into the dashboard, we may automatically receive:

  • IP address or proxy;
  • browser type and version;
  • device type and operating system;
  • time and date of access;
  • referring URLs;
  • basic usage data about the pages or screens you view;
  • server log data (for example, web server and application logs generated when you access or interact with our services).

We use this information to secure and improve our services, troubleshoot issues, detect abuse, and compile aggregated analytics. Server logs are kept only for limited periods necessary for security and diagnostics.

5.2 Cookies and Similar Technologies

When you accept cookies on our website or app, some of those cookies may contain identifiers that are considered Personal Data. See Section 9 (Cookies and Similar Technologies) for more details.

5.3 Account Registration and Use of the Service

When you create and use a Trust.Reviews account (free or paid), we may collect:

  • name;
  • email address;
  • password (stored in hashed form);
  • company name and website (if provided);
  • billing-related identifiers (handled by our payment provider);
  • IP address and login metadata;
  • your settings and configuration inside the dashboard.

5.4 Connecting External Platforms and Importing Reviews

When you connect external platforms (for example, Google Business Profile or Facebook Pages) to Trust.Reviews, we may access and process:

  • platform IDs (e.g. Google Place ID, Facebook Page ID);
  • access tokens and their expiration data (stored securely and used only to communicate with those platforms on your behalf);
  • public business details (name, address, rating, URLs, categories, opening hours, and similar);
  • public review data (review text, rating, language, timestamps, review replies and similar information displayed on the platform);
  • public reviewer information as provided by the platform, such as display name or initials and avatar/profile image URL.

We only access public or otherwise authorised data via official APIs and according to the permissions you grant. We do not attempt to circumvent platform restrictions or access private messages or content.

We do not permanently store review text, ratings, recommendations, reviewer names or avatars from these platforms on our servers. Such data may be accessed and temporarily cached only for technical performance reasons and is not used for any unrelated purposes.

Authentication tokens that we obtain from external platforms (such as Google or Facebook) are used strictly on a read-only basis in order to retrieve the business information that you explicitly authorize. We do not use these tokens for any actions other than securely accessing the permitted data required to operate the Service.

All such tokens are stored in encrypted form, access to them is restricted to authorised system components on a need-to-know basis, and they are never sold, shared or otherwise provided to unrelated third parties. When you disconnect an integration, revoke access from the external platform, or delete your Trust.Reviews account, the corresponding tokens are permanently deleted from our systems and cannot be recovered.

5.5 Invitations and Campaigns

If you use Trust.Reviews to send review invitations or feedback requests, we may process:

  • customer names;
  • customer email addresses and/or phone numbers;
  • status of invitation (sent, delivered, opened, clicked, completed);
  • associated review or feedback response.

Where required by law, you are responsible for ensuring that you have the necessary consent or lawful basis to use these contacts for invitations. We automatically delete contact data that has not resulted in a review or ongoing relationship within a limited time (for example, after 30 days or another configured period, if such setting exists).

5.6 Support, Chat and Contact Forms

When you contact us via email, contact forms or support tools, we may collect:

  • name and email address;
  • content of your messages;
  • technical information you choose to share (for example, browser information, screenshots, website URL);
  • any other information you voluntarily provide.

We recommend that you only share the information necessary for us to assist you.

7. Facebook Data Processing

7.1 Data We Access

When you connect your Facebook Page to Trust.Reviews, we access your Facebook data only through official Meta/Facebook APIs, based on your explicit authorization. We request only the minimum scope of permissions needed to enable the integration and to display your Page rating and public recommendations on your website.

During the authorization flow, our Facebook app uses Facebook Login and the Facebook Graph API to identify your account and list the Facebook Pages you manage. For this purpose, we may call the Graph API for the current user (for example /me?fields=id,name,email) to confirm your identity and to show you which assets (Pages) can be connected. We do not permanently store your personal Facebook profile data (such as your name or email) for purposes unrelated to this identification and connection flow, and we do not use it for advertising or profiling.

After that, we request the list of Pages you manage (for example via /me/accounts) and receive, for each Page, identifiers and access tokens necessary to access Page-level data. In practice, this means we may store:

  • Facebook Page ID;
  • Facebook Page name (to help you identify the Page inside the Trust.Reviews dashboard);
  • Facebook Page access token (and related technical metadata such as token expiry).

These data are used solely to maintain the connection between your Trust.Reviews account and the selected Facebook Page and to retrieve the Page's public rating and recommendations when requested by you.

To provide these features, the Trust.Reviews Facebook app may request the following permissions from you:

  • public_profile
  • email
  • pages_read_engagement
  • pages_read_user_content
  • pages_show_list
  • business_management

These permissions are used solely to:

  • identify and list the Facebook Pages you manage that can be connected to Trust.Reviews;
  • verify that you are authorized to manage the selected Page;
  • retrieve the public Page rating and the number of recommendations;
  • retrieve the Page's public recommendations (reviews) via the Facebook Ratings API and display them on your website through Trust.Reviews widgets, according to your configuration.

We do not use these permissions to post content on your behalf, manage your Page content, or contact your customers. Access is strictly read-only and limited to the public Page information and public recommendations required to provide the requested functionality.

Our Service only accesses and processes publicly available data from Facebook Pages that you explicitly authorise, such as the Page name, profile picture, rating, number of recommendations and, where permitted by Facebook, the text of public recommendations. We do not access or process private Facebook user data and we do not collect personal Facebook user profiles, build individual user identities, or create any form of behavioural profiles based on Facebook data.

We do not use Facebook data to track individual users across websites or apps, and we do not rely on Facebook data for behavioural advertising, retargeting, or any other cross-site tracking purposes. Facebook data is used solely to display your business's public Page information and public recommendations via the Trust.Reviews Service.

7.2 Temporary Caching and Storage

Certain data retrieved from Facebook APIs (such as public Page rating, number of recommendations and public recommendation content) may be temporarily cached to improve performance, reduce latency and API usage. Such cache is strictly temporary, technical in nature, securely stored, and is not used for any unrelated purposes.

We do not permanently store Facebook reviews, recommendation texts, reviewer names, avatars, comments, replies or any other Facebook user content on our servers. This information is retrieved on demand from Facebook and, where cached, is kept only for short technical periods necessary to operate the Service efficiently.

7.3 Purpose and Restrictions (Platform Policy Compliance)

Facebook data is used exclusively to:

  • connect your Facebook Page to Trust.Reviews;
  • fetch public Page information and recommendations, as requested by you;
  • display that information in your Trust.Reviews dashboard and on your website via our widgets.

We do not sell Facebook data, do not license it, and do not share Facebook data with unrelated third parties. We do not use Facebook data for advertising, profiling, building user audiences, retargeting, cross-site tracking or any form of data brokerage. We do not combine Facebook user data with data from data brokers or other external identity sources.

7.4 Revoking Access and Data Deletion

You may revoke Trust.Reviews access to your Facebook Page at any time from your Facebook account settings. If you disconnect your Page or delete your Trust.Reviews account, the stored Page identifiers and tokens will be deleted within a reasonable period and permanently removed from our systems.

Trust.Reviews also implements Meta’s User Data Deletion mechanism. This means that when a user initiates a data deletion request via Facebook settings or through Meta’s data deletion callback / User Data Deletion Request URL, we receive the request from Meta and delete Facebook-related data associated with that user/Page from our systems in accordance with Meta Developer Policies and applicable law. This includes deleting stored Page identifiers, access tokens and any temporary cached Meta data that may relate to the user or connected Page.

You may also request deletion of Facebook-related data by contacting us at support@trust.reviews. We process such requests in accordance with applicable law and Facebook Platform requirements.

We comply with the Meta/Facebook Platform Terms and Developer Policies, including all data protection, permissible use and user data deletion requirements.

8. Google API and Google Services

8.1 Google API Access

When you connect your Google Business Profile (GBP) to Trust.Reviews, we access your account only through official Google APIs, using your explicit authorization.

We only store the minimum information required to maintain the connection:

  • Google Business Profile (Place) ID
  • Access token
  • Refresh token

We do not permanently store Google reviews, review authors, ratings, review text, or any other Google user content on our servers.

The Google authentication tokens obtained during the connection process are used strictly on a read-only basis to retrieve the business information and reviews that you explicitly authorise. We do not use these tokens for any write operations or for actions beyond securely accessing the permitted data required to provide the Service.

All Google tokens are stored in encrypted form with restricted access limited to authorised system components, and they are never sold, shared, or otherwise provided to unrelated third parties. If you revoke access in your Google account, disconnect your Google Business Profile from Trust.Reviews, or delete your Trust.Reviews account, the associated identifiers and tokens are removed within a reasonable period and permanently deleted from our systems.

8.2 Temporary Caching

Data retrieved from Google APIs may be temporarily cached to improve performance, reduce latency and API usage. Such cache is strictly temporary and technical.

8.3 Purpose of Processing

Google API data is used exclusively for:

  • connecting your Google Business Profile to Trust.Reviews;
  • securely retrieving public business and review information when requested;
  • displaying such information to you or on your website as configured by you.

8.4 Compliance

We comply with the Google API Services User Data Policy and related Google requirements.

8.5 Revoking Access and Deletion

You may revoke access in your Google account at any time. If you disconnect your Google Business Profile or delete your Trust.Reviews account, your stored identifiers and tokens will be deleted within a reasonable period and permanently removed from our systems.

You may also request deletion of Google-related data by contacting us at support@trust.reviews.

9. Cookies and Similar Technologies

Cookies are small text files placed on your device when you visit certain websites. They may include identifiers that help us recognise your browser or device. By accepting cookies on our website, you allow us and selected third parties to place and read cookies as described below. You can manage your preferences through your browser settings and, where available, through a cookie banner or settings panel on our site.

We may use, for example, the following categories of cookies:

  • Strictly necessary cookies – required for the basic operation of the website and platform (for example login, session management, security). Without these cookies, certain core functions may not work.
  • Functional cookies – used to remember your preferences, such as language settings, saved options in the dashboard, and similar.
  • Session cookies – temporary cookies that exist only while your browser is open and are deleted when you close it. They support navigation and short-term actions.
  • Persistent cookies – stored on your device between sessions to remember your preferences or login state, or to support analytics.
  • Performance / analytics cookies – used to understand how visitors use our website, which pages they visit, and how they interact with our content. This helps us improve our services and user experience.

If we use third-party analytics (such as Google Analytics or similar services), those providers may place their own cookies subject to their privacy policies. You can usually configure your browser to block or delete cookies. However, doing so may affect the functionality of our website and platform.

10. Analytics and Measurement

We may use analytics tools to collect aggregated, non-personal information about:

  • how often users visit our website;
  • which pages or screens are visited;
  • approximate location (based on IP, not precise GPS);
  • general technical details (device type, operating system, browser, etc.).

We use this data to understand usage patterns, improve our service and measure the effectiveness of features and user flows. If we use Google Analytics, you may be able to opt out using browser add-ons or settings described in Google’s own documentation.

11. How We Use Your Data

We use Personal Data and Non-Personal Data for purposes such as:

  • providing, operating and maintaining the Trust.Reviews platform;
  • authenticating you and authorising access to your account;
  • connecting and synchronising with external review platforms (Google, Facebook, etc.) at your request;
  • displaying and managing reviews on your websites;
  • sending transactional communications (for example account notifications, subscription information, password resets);
  • providing support and responding to your requests;
  • improving and developing our services, including through analytics and feedback;
  • protecting our rights, property, users and the public (for example detecting abuse or security incidents);
  • complying with legal obligations.

Where permitted by law, we may also send you information about updates and improvements to Trust.Reviews or related services. You can opt out of non-essential marketing communications at any time.

12. Sharing of Personal Data

We do not sell your Personal Data.

We may share Personal Data with:

  • Service providers and processors – such as hosting providers, email delivery services, analytics providers, customer support tools and payment processors. They only process data on our behalf and according to our instructions.
  • Payment providers – for handling subscription payments and invoicing. These providers may process your payment data according to their own legal obligations and privacy policies.
  • Professional advisers – such as lawyers, accountants and auditors, where necessary.
  • Authorities and regulators – where required by law or to protect our rights, property or safety, or the rights, property or safety of others.

In all cases, we limit access to Personal Data to what is reasonably necessary for the specific purpose.

13. International Data Transfers

Depending on where you are located and where our infrastructure or service providers are based, your data may be processed in countries outside your own, including outside the European Economic Area (EEA) or the UK.

Where such transfers occur and relevant law requires additional safeguards, we will take appropriate steps, which may include:

  • using providers in countries recognised by the European Commission or UK authorities as providing an adequate level of data protection (adequacy decisions);
  • entering into Standard Contractual Clauses (SCCs) or equivalent contractual protections approved by the European Commission or UK authorities;
  • implementing technical and organisational measures to protect the data (such as encryption, access controls and minimisation).

14. Data Retention

We retain Personal Data only as long as reasonably necessary for the purposes described in this Policy, including:

  • provision of the service;
  • maintaining business and legal records;
  • resolving disputes;
  • enforcing agreements;
  • complying with legal obligations.

Examples:

  • Account data is retained while your account is active and for a limited period after closure, unless a longer period is required by law.
  • Data retrieved from external platforms (such as Google or Facebook) is accessed on demand and may be temporarily cached only for short technical periods. We do not permanently store review content or user-generated content from those platforms.
  • Technical logs are stored only for limited periods required for security, diagnostics and fraud prevention.
  • Contact and support data is stored as needed to handle your request and for a reasonable period afterwards.

Where possible, we anonymise data instead of deleting it, so that it can no longer be linked to an individual but may still be used for analytics and service improvement.

15. Security

We apply appropriate technical and organisational measures to protect Personal Data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure or access. These measures may include:

  • encryption in transit (HTTPS/TLS);
  • access controls and authentication;
  • separation of environments;
  • regular updates and security patches;
  • staff confidentiality and access-limitation principles.

However, no method of transmission over the internet or method of electronic storage is completely secure. While we strive to protect your data, we cannot guarantee absolute security.

16. Children’s Privacy

Trust.Reviews is not intended for use by children under the age where they can lawfully consent to data processing in their country (for example, 16 years in many EU countries).

We do not knowingly collect Personal Data from such children. If you believe that a child has provided us with Personal Data, please contact us at support@trust.reviews, and we will take appropriate steps to delete this information.

17. Changes to this Privacy Policy

We may update this Privacy Policy from time to time, for example to reflect changes in our services, changes in applicable laws, or new technical or organisational measures.

We will post the updated version on our website with a new “Last updated” date. In case of material changes, we may also notify you through the service or by email.

18. Contact Information

If you have any questions, requests or concerns about this Privacy Policy or our data practices, you can contact us at:

Rich Plugins SL
Plaza San Cristóbal, 14
03002 Alacant/Alicante, Spain
Email: support@trust.reviews