1. Who we are
ReviewInbox is operated by Benjamin Bush, trading as ReviewInbox.
Registered business address: ReviewInbox, 5 Brayford Square, London, E1 0SG
Contact: benjamin@reviewinbox.io
We are the data controller for personal data collected through reviewinbox.io and are registered with the UK Information Commissioner's Office (ICO).
2. What data we collect
- Account information: name and email via Google sign-in
- Business information: name, category, city, reply tone
- Review data: reviews fetched from connected platforms on your behalf
- Payment information: processed by Stripe — we do not store card details
- Usage data: how you interact with our service
- Waitlist data: emails from our coming soon page
- Essential cookies: for authentication and session management only
3. How we use your data
- To provide the ReviewInbox service
- To generate AI reply drafts using Anthropic Claude API
- To send service notifications, weekly digests, and account emails
- To process payments via Stripe
- To send subscription renewal reminders as required by UK consumer law
- To improve our product
- To comply with legal obligations
4. Legal basis for processing
- Contract: to provide the service you signed up for
- Legitimate interests: to improve our product and prevent fraud
- Recognised legitimate interest (RLI): as introduced by the Data (Use and Access) Act 2025
- Consent: for marketing emails — unsubscribe at any time
- Legal obligation: where required by law
5. Third-party services
- Supabase — database and authentication (EU servers)
- Vercel — hosting and infrastructure
- Stripe — payment processing
- Anthropic — AI reply generation
- Resend — transactional email
- Google — OAuth and Business Profile API
6. Cookies
We use essential cookies only for authentication and session management. We do not use advertising or tracking cookies. You can control cookies through your browser settings.
7. Data retention
We retain your data while your account is active. On deletion, personal data is removed within 30 days except where required by law (financial records kept 6 years under HMRC requirements).
8. Your rights
Under UK GDPR you have the right to: access, correct, delete, object to, and port your data, withdraw consent, and not be subject to solely automated decisions. Email us to exercise these rights — we respond within 30 days.
9. Data security
We implement appropriate technical and organisational measures. All data is encrypted in transit and at rest. We follow data protection by design principles as required by UK GDPR.
10. Contact and complaints
Email: benjamin@reviewinbox.io
Address: ReviewInbox, 5 Brayford Square, London, E1 0SG
You have the right to complain to the ICO at ico.org.uk or 0303 123 1113.