Privacy Policy

Last updated: May 24, 2026

ReviewBeam is operated by Digitsflow, Inc. (“Digitsflow,” “we,” “us,” or “our”). This Privacy Policy explains what personal information we collect from users of https://reviewbeam.netand the ReviewBeam platform (collectively, the “Service”), how we use it, who we share it with, and what rights you have regarding your data.

We are committed to protecting your privacy and handling your data transparently. This policy applies to all visitors and registered users of ReviewBeam. If you do not agree with any part of this policy, please do not use the Service.

1. Introduction

Digitsflow, Inc. operates ReviewBeam, an AI-powered review reply generation SaaS platform for small business owners. We take your privacy seriously. This Privacy Policy is designed to help you understand what data we collect, why we collect it, and how it is protected.

2. Information We Collect

2.1 Information You Provide Directly

We collect the following information that you provide to us directly:

  • Name: Collected during account registration via Clerk to identify your account.
  • Email address: Collected during account registration to authenticate you and send account/billing notifications.
  • Profile photo: Optional, imported if you choose to use social login via Clerk.
  • Google Maps / Google Business Profile URL: Collected when you connect your business listing to fetch and display your reviews.
  • Business name and listing details: Imported from your Google Maps link to provide context for AI reply generation.
  • Customer review content: Fetched from your connected Google Business Profile to generate AI-powered reply suggestions.
  • Payment information: Submitted when you subscribe to the Growth plan; processed entirely by Stripe. We do not store or directly access your credit card numbers.

2.2 Information Collected Automatically

When you use the Service, we collect certain technical information automatically:

  • IP address: Collected server-side for security monitoring and abuse prevention.
  • Browser type and version: Collected via server logs.
  • Operating system: Collected via server logs.
  • Referring URL: The page that referred you to the Service.
  • Pages visited / features used: Interaction logs (e.g., when replies are generated or copied).
  • Session duration: The length of your authenticated sessions.
  • Timestamp data: The date and time of actions taken within the Service.

This data is collected via server logs, standard web infrastructure, and our product analytics platform, PostHog, which helps us understand how users interact with the Service so we can improve the application.

2.3 Information from Third Parties

We receive information from the following third parties:

  • Authentication Provider (Clerk): Identity verification tokens, email, and social profile data (if social login is used).
  • Payment Processor (Stripe): Subscription status, billing history, and the last 4 digits of your payment card.
  • Google (public data): Customer reviews fetched from your connected Google Business Profile URL.

2.4 Cookies and Similar Technologies

We use essential and preference cookies to provide the Service:

  • Essential Cookies: Used for user authentication, session state, and CSRF protection (managed via Clerk). These cookies generally expire when the session ends or within 30 days.
  • Preference Cookies: Used to store user settings (such as your selected tone or dashboard preferences).

We use essential, preference, and analytics cookies. We use PostHog to analyze product usage and session interactions to optimize the platform experience. We do not use advertising or marketing tracking pixels, and we do not sell or share your behavioral data with third-party advertisers.

You can disable cookies in your browser settings, but doing so may prevent you from logging into or using the Service.

3. How We Use Your Information

We process your personal information for the following specific purposes:

  • Account creation and management: To manage your user record and login details. (Legal basis: Contractual necessity).
  • Authentication and security: To secure your account and prevent unauthorized access. (Legal basis: Contractual necessity / Legitimate interests).
  • Fetching Google reviews: To display reviews from your connected business. (Legal basis: Contractual necessity).
  • Generating AI reply suggestions: To process review text and generate AI response drafts. (Legal basis: Contractual necessity).
  • Subscription billing: To manage payments, invoices, and subscription plans via Stripe. (Legal basis: Contractual necessity).
  • Customer support: To communicate with you and answer help queries. (Legal basis: Legitimate interests).
  • Service improvement and debugging: To analyze errors and optimize app performance. (Legal basis: Legitimate interests).
  • Fraud detection and abuse prevention: To block malicious behavior or exploit attempts. (Legal basis: Legitimate interests).
  • Compliance with legal obligations: To comply with legal, tax, or regulatory requirements. (Legal basis: Legal obligation).
  • Marketing communications: To send updates or promotional emails (only with your explicit consent).

We do not use your data for targeted advertising, selling to data brokers, or training third-party AI models.

3.1 AI Processing

To generate reply suggestions, we send the following data to our AI processing provider via API:

  • The text content of a customer review
  • The star rating
  • Your selected tone configuration

We do not send your personally identifiable information (name, email, account ID) to our AI processing provider. Per their API policies, data sent via the API is not used to train their foundation models and is retained only for a limited period for compliance and safety monitoring.

4. How We Share Your Information

We share your information only as described below. We do not sell your personal information.

  • Authentication Provider: We share authentication tokens and basic account details to manage secure user sessions. (Data processed in the USA).
  • Payment Processor: We share billing info and subscription details to process transactions. (Data processed in the USA).
  • AI Processing Provider: We share review content and tone settings (no account PII) to generate replies. (Data processed in the USA).
  • Database Provider: We store account details, connected listings, reviews, and logs in a secure Postgres database. (Data processed in the USA).
  • Hosting & CDN Provider: Request metadata (IP, headers) is processed to host the app and deliver content. (Data processed in the USA / Globally).

All third-party service providers are contractually obligated to protect your data and are prohibited from using it for any other purpose. A full list of named service providers is available upon request at support@reviewbeam.net.

4.1 Legal Requirements

We may disclose your information if required by law, subpoena, court order, or regulatory authority, or if we reasonably believe disclosure is necessary to comply with a legal obligation, protect Digitsflow's legal rights, prevent fraud/abuse, or protect the safety of our users or the public.

4.2 Business Transfers

In the event of a merger, acquisition, reorganization, or sale of assets, your information may be transferred to the acquiring entity. We will notify you via email or a prominent notice on the Service if such a transfer materially affects your rights.

5. Data Retention

We retain your data only for as long as necessary to provide the Service or comply with legal requirements:

  • Account data, business URLs, fetched reviews, and AI replies: Retained for the duration of your active account, plus 3 years post-deletion (for account history and compliance audits).
  • Transaction & billing records: Retained for 7 years to satisfy legal and tax requirements.
  • Server and access logs: Retained for 90 days for security auditing and debugging.
  • Marketing email list: Retained until you withdraw consent (unsubscribe).

Upon account deletion, we will initiate deletion of your user record and associated data, which is completed within 30 days.

6. Data Security

We implement appropriate technical and organizational measures to protect your personal data against unauthorized access, loss, alteration, or disclosure:

  • Encryption in transit: All data transmitted between your browser and our servers uses HTTPS/TLS encryption.
  • Encryption at rest: Databases and servers utilize encryption at rest.
  • Payment security: Stripe handles payments securely in compliance with PCI-DSS Level 1 standards.
  • Access controls: Internal data access is restricted to authorized personnel on a need-to-know basis.
  • Authentication security: Managed by an enterprise-grade identity provider supporting secure sessions and passkeys.

No method of transmission or storage is 100% secure. While we strive to protect your data, we cannot guarantee absolute security against all threats.

7. Your Rights Under GDPR (EEA / UK Residents)

If you are located in the European Economic Area (EEA) or United Kingdom, you have the following rights regarding your personal data:

  • Right of Access: Request a copy of the personal data we hold about you.
  • Right to Rectification: Request correction of inaccurate or incomplete data.
  • Right to Erasure (“Right to be Forgotten”): Request deletion of your personal data.
  • Right to Restrict Processing: Request that we limit how we process your data.
  • Right to Data Portability: Receive your data in a structured, machine-readable format.
  • Right to Object: Object to processing based on legitimate interests.
  • Right to Withdraw Consent: Withdraw any consent at any time.
  • Right to Lodge a Complaint: File a complaint with your local Data Protection Authority.

To exercise any of these rights, contact us at support@reviewbeam.net. We will respond within 30 days. We may need to verify your identity before processing your request.

Data Protection Officer: We do not currently designate a formal Data Protection Officer. All data protection inquiries should be directed to the support email above.

8. Your Rights Under CCPA / CPRA (California Residents)

If you are a California resident, you have the following rights:

  • Right to Know: What personal information we collect, use, and share.
  • Right to Delete: Request deletion of your personal information.
  • Right to Correct: Request correction of inaccurate personal information.
  • Right to Opt-Out of Sale/Sharing: We do not sell or share personal information for advertising or data broker purposes.
  • Right to Limit Use of Sensitive PI: Limit use of sensitive personal information to necessary service provision.
  • Right to Non-Discrimination: We will not discriminate against you for exercising your rights.

To exercise these rights, contact us at support@reviewbeam.net.

9. Children's Privacy (COPPA)

ReviewBeam is a B2B service intended exclusively for use by adults (18 years or older) managing business accounts. The Service is not directed at or intended for children under the age of 13 (or 16 in the EEA). We do not knowingly collect personal information from anyone under the age of 13. If you believe a child has provided us with personal information, please contact us immediately at support@reviewbeam.net and we will promptly delete it.

10. International Data Transfers

Your information may be transferred to and processed in the United States by our service providers. The United States may have different data protection laws than your home country.

For transfers from the EEA/UK to the United States, we ensure appropriate safeguards are in place, including Standard Contractual Clauses (SCCs) approved by the European Commission, which are incorporated into our Data Processing Agreements with service providers.

11. Changes to This Privacy Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, technology, or legal requirements. We will notify you of material changes by posting the updated policy on this page, updating the “Last Updated” date, and sending an email notification to your registered address (where appropriate).

12. Contact Information

If you have any questions about this Privacy Policy, wish to exercise your data rights, or have concerns about our data practices, please contact us at:

Digitsflow, Inc.
Email: support@reviewbeam.net