Legal

Privacy Policy

This policy explains what personal data Reviewlico processes, why it is processed, and how to contact the project about privacy questions. Reviewlico is currently a free personal project and not a commercial business.

1. Who controls this data

For website, account, and project administration data, the controller is the operator of Reviewlico, reachable at support.reviewlico@gmail.com.

For customer-submitted review data handled on behalf of an organization using Reviewlico, Reviewlico generally acts as a service provider or processor and that organization is generally the controller for the review content it chooses to collect and manage.

2. Data Reviewlico collects

  • account data such as email address, password hash, and optional profile details;
  • authentication and session data such as access tokens, refresh-token hashes, and login state;
  • organization and team data such as organization names, slugs, invite details, and roles;
  • product data such as external IDs, names, descriptions, slugs, and product metadata;
  • review data such as reviewer name, reviewer email, rating, review text, timestamps, and moderation status;
  • analytics and export data generated from reviews and dashboard usage;
  • basic technical and performance information collected through Vercel hosting, Web Analytics, and Speed Insights.

3. How Reviewlico uses data

  • to create and manage accounts and organizations;
  • to authenticate users and keep the service secure;
  • to send verification and invitation emails when email delivery is configured;
  • to process review submissions and show approved public reviews;
  • to provide moderation, analytics, and CSV export features;
  • to monitor reliability, performance, misuse, and security;
  • to respond to support, abuse, and privacy requests.

4. Legal bases

Where GDPR or similar laws apply, Reviewlico generally relies on one or more of the following bases: performance of a contract, legitimate interests in operating and securing the service, compliance with legal obligations, and consent where consent is legally required.

5. Sharing and service providers

Reviewlico does not sell personal data.

Data may be shared with infrastructure and service providers that help run the project, including:

  • Vercel for hosting, web analytics, and performance monitoring;
  • MongoDB for application database hosting and storage;
  • a configured email delivery provider if account emails are enabled;
  • legal, safety, or compliance recipients where disclosure is required by law.

6. Cookies, local storage, and similar technologies

Reviewlico uses a combination of cookies, local storage, and privacy-focused analytics or performance tooling. Details are described in the Cookie & Storage Notice.

7. Retention

Reviewlico keeps personal data only for as long as reasonably necessary to operate the project, maintain security, provide requested functionality, and comply with legal obligations.

A formal retention schedule is not yet published for this personal project. If you want data deleted, contact support by email and the request will be handled manually.

8. International transfers

Reviewlico uses hosted infrastructure providers. Depending on where those providers process data, your information may be transferred to or stored in countries other than your own.

9. Your rights

Depending on where you live, you may have rights to access, correct, delete, restrict, object to, or export your personal data, and to lodge a complaint with a data protection authority.

Reviewlico currently handles these requests manually. Send requests to support.reviewlico@gmail.com.

10. Children

Reviewlico is meant for developers, project operators, and other business or technical users. It is not directed to children, and the service should not be used by anyone under 16 acting on their own behalf.

11. Changes to this policy

This policy may be updated as Reviewlico evolves. The “Last updated” date at the top of the page will change when material updates are published.