Privacy Policy
Last updated: 2026
This policy explains how SmartReviewer AI ("we", "us", "our") — acting as the Data Fiduciary under India's Digital Personal Data Protection Act, 2023 (the "DPDP Act") — processes your personal data. By using the platform you give free, specific, informed, unconditional and unambiguous consent to the processing described below. You may withdraw consent any time (see §10).
1. Who we are (Data Fiduciary)
SmartReviewer AI, operated from Ahmedabad, Gujarat, India. Contact: contact@smartreviewer.in, +91 99980 98977.
2. Personal data we collect
- Account data: name, email, phone (optional), business profile details.
- Merchant content: business name, logo, keywords, review URL, brand color, manager email.
- Review content: star ratings, AI-drafted review text, chosen language, session identifier.
- Private feedback (from low-rated visits): the visitor's message and optionally the name, email or phone they choose to share so the merchant can respond.
- Google Business Profile data: when you connect Google, OAuth tokens plus your Google account ID and location name — used only to sync your review link and counts.
- Usage & device logs: QR scans, IP address, coarse location, browser, timestamps.
- Billing data: processed by Razorpay; we store only order ID, invoice metadata and the last 4 digits — never full card numbers or UPI PIN.
3. Purposes and lawful basis
We process personal data for the following specific purposes, on the basis of your consent (DPDP Act §6) or the Legitimate Uses exemption (§7) where applicable:
- Operating and improving the platform (consent).
- Generating AI-written review drafts and translations (consent).
- Routing low ratings privately to the merchant so they can resolve issues (consent).
- Processing payments, issuing invoices and tax compliance (legitimate use — legal obligation).
- Fraud prevention, abuse detection and platform security (legitimate use).
- Customer support and service communications (consent / legitimate use).
4. Sub-processors (who else touches your data)
- Hosting & database: Lovable Cloud (managed Supabase — data hosted in Asia region).
- Payments: Razorpay Software Pvt. Ltd. (India).
- AI model provider: Google Gemini via Lovable AI Gateway — inputs are used for generation only, not to train public models.
- Email delivery: transactional email provider used for invoices and notifications.
- Google APIs: if you connect Google Business Profile.
5. Cross-border transfers
Some sub-processors may process data outside India (e.g. Google AI, email delivery). Transfers are limited to countries not restricted by the Central Government under DPDP Act §16, and are protected by the sub-processor's data- protection commitments.
6. Retention
- Account & business data: while your account is active, plus 90 days after closure.
- Review sessions & QR scan logs: 24 months, then anonymised.
- Private feedback: 12 months, or until you delete it from the dashboard.
- Invoices & billing records: 8 financial years (Indian tax law).
- Google OAuth refresh tokens: until you disconnect or delete your account.
7. Security
TLS 1.2+ in transit, AES-256 encryption at rest, Row-Level Security on every database table, principle-of-least-privilege access, hashed passwords, and continuous logging. No system is perfect — please use a strong, unique password and enable Google sign-in where possible.
8. Children's data (Data Principals under 18)
The platform is intended for business owners and adult customers. We do not knowingly collect personal data of anyone under 18. If you believe a child's data has been shared with us, email us and we will delete it promptly. Per DPDP Act §9 we do not profile, track, or serve targeted ads to children.
9. Cookies & similar storage
We use strictly-necessary cookies and local storage to keep you signed in and remember UI preferences. We do not use third-party advertising or cross-site tracking cookies.
10. Your rights as a Data Principal
Under the DPDP Act you may:
- Access a summary of the personal data we hold about you (§11).
- Request correction or updation of inaccurate data (§12).
- Request erasure of your data, subject to legal retention (§12).
- Withdraw consent at any time — future processing will stop (§6(4)).
- Nominate another person to exercise these rights if you die or become incapacitated (§14).
- Raise a grievance (see §11 below) and, if unresolved, complain to the Data Protection Board of India.
11. Grievance Officer
As required by the DPDP Act §8(9) and Rule 3(11) of the Information Technology (Intermediary Guidelines) Rules, 2021:
Grievance Officer: Founder, SmartReviewer AI
Email: contact@smartreviewer.in
Address: Ahmedabad, Gujarat, India
Acknowledgement within 48 hours, resolution within 30 days.
Grievance Officer: Founder, SmartReviewer AI
Email: contact@smartreviewer.in
Address: Ahmedabad, Gujarat, India
Acknowledgement within 48 hours, resolution within 30 days.
12. Data breach notification
In the event of a personal-data breach, we will notify the Data Protection Board of India and every affected Data Principal without undue delay, in the manner prescribed under DPDP Act §8(6).
13. Changes to this policy
We may update this policy. Material changes will be announced by email and posted here with a new "Last updated" date. Continued use after the effective date means you accept the changes.