Skip to main content

Privacy Policy

How Reviyo collects, uses, shares, and deletes personal data — written to match what the product actually does, under the Digital Personal Data Protection Act, 2023 (DPDPA).

Last updated: 30 September 2026 · Version 2026-09-30.1

1. Who we are

Reviyo is operated by Naga Durga Prasad Chunduru, trading as Reviyo, a sole proprietorship registered at Vijayawada, India.

Under the DPDPA we are the Data Fiduciary for the personal data described in this policy, and you are a Data Principal. If you are in the EEA or UK, the equivalent terms are “controller” and “data subject”.

Questions about this policy or about your data go to support@reviyo.in.

2. Two different groups of people

Reviyo handles personal data about two separate groups, and the rules differ for each.

  • Business owners — the people who sign up for a Reviyo account, set up a business profile, and pay for a subscription. We are the Data Fiduciary for this data.
  • Customers of those businesses — people who scan a business’s QR code and use the review page. We process this data on behalf of the business, which decides to deploy Reviyo and sees the resulting feedback. For this data we act largely as a Data Processor for that business, and this policy tells you what we do with it either way.

3. What we collect, and why

3.1 If you are a business owner with a Reviyo account

Personal data collected from business owners
WhatWhyLegal basis (DPDPA)
Email address, and your name if you gave oneTo create and secure your account, sign you in, send password resets, and contact you about your subscription.Consent given at signup; and necessary to provide the service you asked for.
PasswordAuthentication. Stored only as a salted hash by our authentication provider. We never see or store your plaintext password.Necessary to provide the service.
Business profile — business name, category, Google review link, logo, welcome message, review topicsTo build your public review page and QR code.Necessary to provide the service.
Payment records — plan, amount, Razorpay order and payment identifiers, payment statusTo activate your subscription, show your payment history, and meet tax and accounting obligations.Necessary to provide the service; and legal obligation for retention.

We do not collect your card, UPI, or bank details. Those are entered directly into Razorpay’s checkout and never reach our servers or our database. We only ever receive an order identifier, a payment identifier, an amount, and a status.

3.2 If you are a customer using a business’s review page

The review page is anonymous by design. We do not ask for your name, email, phone number, or address, and we do not require you to create an account or install anything. We collect only the following:

Data collected from customers using a review page
WhatWhyLegal basis (DPDPA)
A random session identifier generated when you open the pageTo tie the steps of a single visit together and to rate-limit abuse of the AI. It is a random value, not an identifier of you, and it is not shared across businesses or visits.Necessary to provide the service you requested.
The topics you tapTo draft the review you asked for, and to show the business aggregate feedback.Your consent, given on the review page.
Any free-text comment you choose to write (optional)To draft the review you asked for. It is sent to our AI provider for that purpose and is visible to the business.Your consent, given on the review page.
The review text the AI drafts for youSo you can read, edit, and copy it. The business can also see it.Your consent, given on the review page.
Any private feedback message you choose to send (optional)To pass it to the business. It is not published.Your consent, given when you send it.
Counts of steps reached — page opened, review started, review generated, Google opened — and which of the business’s QR codes or shared links you used to get thereTo show the business how many people used its page and which of its QR codes or links works best. These are counts tied to a session identifier, not to you; the QR code tag names a place, such as a table or desk, never a person using the page.Necessary to provide the service to the business.

We do not store your IP address, device fingerprint, advertising identifier, or precise location, and we do not build a profile of you. Like any website, our hosting providers receive your IP address in order to deliver the page, and may keep it for a short time in their security logs; we never copy it into our database or use it to identify you. We do not use tracking pixels, advertising tags, or third-party analytics on the review page.

Please do not type personal details into the comment box. The review you are drafting is meant to be posted publicly on Google. Do not include your own or anyone else’s full name, phone number, address, medical details, financial details, or any other sensitive information. If you do, we will still process it, but you are choosing to share it — and once you paste the review onto Google, it is public.

The review page is not intended for children. If you are under 18, please do not use it. See clause 10.

4. How the AI works, and what it is sent

When you ask Reviyo to draft a review, we send the following to our AI provider, Anthropic, PBC (Claude API): the business’s name and category, the topics you selected, your optional comment, and the length you asked for. That is all. We do not send your session identifier, and we have nothing else about you to send.

When a business owner asks Reviyo to suggest review topics, we send the same AI provider the business’s name, its category, and the topics the owner already has. No customer data is included.

The AI is instructed to use only what you gave it and never to invent experiences, staff names, services, prices, or facts. It drafts text; you read it, edit it if you want, and decide whether to post it. Reviyo never posts a review to Google on your behalf, and never submits anything automatically.

Our AI provider’s own privacy terms apply at the moment of processing. You can read them at https://www.anthropic.com/legal/privacy. We use the provider’s paid API, which under that provider’s business terms is not used to train their general models by default. We have not opted in to such training.

5. Who we share data with

We do not sell personal data. We have never sold personal data, and we do not share it for advertising or cross-context behavioural advertising. We share it only with the following processors, each for a single, stated purpose:

Third parties that process personal data for Reviyo
WhoWhat they processWhy
SupabaseAll account data, business profiles, review sessions, private feedback, and analytics counts.Database, authentication, and server hosting.
Anthropic, PBC (Claude API)Business name and category, topics, and your optional comment — at the moment you ask for a draft. For owners who ask for topic suggestions: the business name, category, and existing topics.Generating the review draft you requested, and suggesting review topics to business owners.
Razorpay Software Private LimitedYour name (or your business name if you did not give one), email, plan, and amount. Card, UPI, and bank details go directly to Razorpay and never reach us.Processing subscription payments. Razorpay is an RBI-authorised payment aggregator.
Hostinger (email)Business owners’ email address and the content of the emails we send them: sign-in codes, account emails, payment receipts, and billing reminders. Customers who scan a QR code are never emailed.Sending those emails from our support address.
The business whose QR code you scannedYour selected topics, comment, drafted review, and any private feedback.That is the point of the product — the business asked for feedback and you chose to give it.

We may also disclose data where we are legally required to — a valid court order, a lawful request from a government agency, or to establish or defend a legal claim. If we are permitted to tell you, we will.

If Reviyo is ever sold or merged, personal data may transfer to the acquirer. We will tell you before that happens, and you will be able to delete your data first.

6. Where your data is stored

Our database and servers are hosted by Supabase in the Northeast Asia (Seoul) region. Our AI provider and Razorpay may process data outside India.

Section 16 of the DPDPA permits transfer of personal data outside India except to countries the Central Government specifically restricts. We do not transfer data to any country currently on that restricted list, and we will stop any transfer that becomes restricted. For anyone in the EEA or UK, transfers out are made under the relevant provider’s standard contractual clauses.

7. How long we keep data

We delete data on a schedule rather than keeping it indefinitely:

Data retention periods
DataKept forThen
Customer review sessions — topics, comment, drafted review (and, for visits before this version, a star rating)90 days from the visitPermanently deleted. The business keeps only aggregate counts.
Private feedback messages365 days, or until the business deletes themPermanently deleted.
Analytics counts395 daysPermanently deleted.
Business owner account and business profileFor as long as your account is openDeleted when you delete your account.
Payment and invoice records8 yearsRetained because Indian tax and company law requires it, then deleted. This survives account deletion.

8. Your rights

Under the DPDPA, as a Data Principal you have the right to:

  • Access a summary of the personal data we hold about you and who we have shared it with (s.11).
  • Correct, complete, update, or erase your personal data (s.12).
  • Withdraw your consent at any time, as easily as you gave it (s.6(4)). Withdrawing does not undo processing that already happened lawfully.
  • Nominate another person to exercise these rights on your behalf if you die or become incapacitated (s.14).
  • Raise a grievance with us, and escalate to the Data Protection Board of India if you are not satisfied with our answer (s.13).

How to exercise them

  • Business owners: you can correct your own data at any time in Settings. To download everything we hold, or to delete your account and all of its data, use Settings → Account → Your data. Deletion is permanent.
  • Customers: because the review page is anonymous, we usually cannot find your session again — there is nothing tying it to you. If you want a specific submission deleted sooner than the 90-day schedule, email support@reviyo.in with the business name and the approximate date and time, and we will do our best to locate and delete it.

We answer rights requests within 30 days and we do not charge for this. We may ask you to verify your identity before we act on a request about an account.

9. Grievance redressal

Our grievance officer under section 13 of the DPDPA is:

Naga Durga Prasad Chunduru

Naga Durga Prasad Chunduru, trading as Reviyo

Vijayawada

support@reviyo.in

We will acknowledge your grievance and respond within 30 days. If you are not satisfied with our response, you may complain to the Data Protection Board of India.

10. Children

Reviyo is a business tool. You must be 18 or older to hold a Reviyo account, and the review page is not directed at children.

Section 9 of the DPDPA requires verifiable parental consent before processing a child’s personal data, and prohibits tracking, behavioural advertising, and any processing likely to cause a detrimental effect on a child. We do not knowingly collect data from anyone under 18, we do not track or profile anyone on the review page, and we serve no advertising. If you believe a child has submitted data through Reviyo, email support@reviyo.in and we will delete it.

11. How we protect data

We take the following specific measures:

  • All traffic to and from the site is encrypted in transit with HTTPS/TLS.
  • Data is encrypted at rest by our hosting provider.
  • Row-level security is enabled on every database table, so a business owner can only read their own data and one customer can never read another customer’s session.
  • Passwords are stored only as salted hashes, by our authentication provider.
  • Payment card details never touch our systems; they go directly to Razorpay, which is PCI-DSS Level 1 certified.
  • API keys for the AI provider and Razorpay are held as server-side secrets and are never sent to the browser.

No system is perfectly secure, and we do not claim otherwise. If we become aware of a personal data breach we will notify the Data Protection Board of India and every affected person, as section 8(6) of the DPDPA requires.

12. Cookies and local storage

Reviyo uses no advertising cookies, no analytics cookies, and no third-party tracking. The only browser storage we use is for signed-in business owners: their sign-in session, and text they typed into two dashboard tools, kept on their own device. We count visits to our public pages as daily totals per page, with the linking website’s name and no cookie or identifier. The full detail — and why we therefore do not show you a cookie consent banner — is in our Cookie Policy.

13. Changes to this policy

If we change this policy in a way that materially affects how we handle your data, we will update the version number at the top and email account holders before the change takes effect. Continuing to use Reviyo after that means you accept the updated policy. If you do not, you can delete your account.