Privacy Policy
How Reviyo collects, uses, shares, and deletes personal data — written to match what the product actually does, under the Digital Personal Data Protection Act, 2023 (DPDPA).
Last updated: 30 September 2026 · Version 2026-09-30.1
1. Who we are
Reviyo is operated by Naga Durga Prasad Chunduru, trading as Reviyo, a sole proprietorship registered at Vijayawada, India.
Under the DPDPA we are the Data Fiduciary for the personal data described in this policy, and you are a Data Principal. If you are in the EEA or UK, the equivalent terms are “controller” and “data subject”.
Questions about this policy or about your data go to support@reviyo.in.
2. Two different groups of people
Reviyo handles personal data about two separate groups, and the rules differ for each.
- Business owners — the people who sign up for a Reviyo account, set up a business profile, and pay for a subscription. We are the Data Fiduciary for this data.
- Customers of those businesses — people who scan a business’s QR code and use the review page. We process this data on behalf of the business, which decides to deploy Reviyo and sees the resulting feedback. For this data we act largely as a Data Processor for that business, and this policy tells you what we do with it either way.
3. What we collect, and why
3.1 If you are a business owner with a Reviyo account
| What | Why | Legal basis (DPDPA) |
|---|---|---|
| Email address, and your name if you gave one | To create and secure your account, sign you in, send password resets, and contact you about your subscription. | Consent given at signup; and necessary to provide the service you asked for. |
| Password | Authentication. Stored only as a salted hash by our authentication provider. We never see or store your plaintext password. | Necessary to provide the service. |
| Business profile — business name, category, Google review link, logo, welcome message, review topics | To build your public review page and QR code. | Necessary to provide the service. |
| Payment records — plan, amount, Razorpay order and payment identifiers, payment status | To activate your subscription, show your payment history, and meet tax and accounting obligations. | Necessary to provide the service; and legal obligation for retention. |
We do not collect your card, UPI, or bank details. Those are entered directly into Razorpay’s checkout and never reach our servers or our database. We only ever receive an order identifier, a payment identifier, an amount, and a status.
3.2 If you are a customer using a business’s review page
The review page is anonymous by design. We do not ask for your name, email, phone number, or address, and we do not require you to create an account or install anything. We collect only the following:
| What | Why | Legal basis (DPDPA) |
|---|---|---|
| A random session identifier generated when you open the page | To tie the steps of a single visit together and to rate-limit abuse of the AI. It is a random value, not an identifier of you, and it is not shared across businesses or visits. | Necessary to provide the service you requested. |
| The topics you tap | To draft the review you asked for, and to show the business aggregate feedback. | Your consent, given on the review page. |
| Any free-text comment you choose to write (optional) | To draft the review you asked for. It is sent to our AI provider for that purpose and is visible to the business. | Your consent, given on the review page. |
| The review text the AI drafts for you | So you can read, edit, and copy it. The business can also see it. | Your consent, given on the review page. |
| Any private feedback message you choose to send (optional) | To pass it to the business. It is not published. | Your consent, given when you send it. |
| Counts of steps reached — page opened, review started, review generated, Google opened — and which of the business’s QR codes or shared links you used to get there | To show the business how many people used its page and which of its QR codes or links works best. These are counts tied to a session identifier, not to you; the QR code tag names a place, such as a table or desk, never a person using the page. | Necessary to provide the service to the business. |
We do not store your IP address, device fingerprint, advertising identifier, or precise location, and we do not build a profile of you. Like any website, our hosting providers receive your IP address in order to deliver the page, and may keep it for a short time in their security logs; we never copy it into our database or use it to identify you. We do not use tracking pixels, advertising tags, or third-party analytics on the review page.
Please do not type personal details into the comment box. The review you are drafting is meant to be posted publicly on Google. Do not include your own or anyone else’s full name, phone number, address, medical details, financial details, or any other sensitive information. If you do, we will still process it, but you are choosing to share it — and once you paste the review onto Google, it is public.
The review page is not intended for children. If you are under 18, please do not use it. See clause 10.
4. How the AI works, and what it is sent
When you ask Reviyo to draft a review, we send the following to our AI provider, Anthropic, PBC (Claude API): the business’s name and category, the topics you selected, your optional comment, and the length you asked for. That is all. We do not send your session identifier, and we have nothing else about you to send.
When a business owner asks Reviyo to suggest review topics, we send the same AI provider the business’s name, its category, and the topics the owner already has. No customer data is included.
The AI is instructed to use only what you gave it and never to invent experiences, staff names, services, prices, or facts. It drafts text; you read it, edit it if you want, and decide whether to post it. Reviyo never posts a review to Google on your behalf, and never submits anything automatically.
Our AI provider’s own privacy terms apply at the moment of processing. You can read them at https://www.anthropic.com/legal/privacy. We use the provider’s paid API, which under that provider’s business terms is not used to train their general models by default. We have not opted in to such training.
6. Where your data is stored
Our database and servers are hosted by Supabase in the Northeast Asia (Seoul) region. Our AI provider and Razorpay may process data outside India.
Section 16 of the DPDPA permits transfer of personal data outside India except to countries the Central Government specifically restricts. We do not transfer data to any country currently on that restricted list, and we will stop any transfer that becomes restricted. For anyone in the EEA or UK, transfers out are made under the relevant provider’s standard contractual clauses.
7. How long we keep data
We delete data on a schedule rather than keeping it indefinitely:
| Data | Kept for | Then |
|---|---|---|
| Customer review sessions — topics, comment, drafted review (and, for visits before this version, a star rating) | 90 days from the visit | Permanently deleted. The business keeps only aggregate counts. |
| Private feedback messages | 365 days, or until the business deletes them | Permanently deleted. |
| Analytics counts | 395 days | Permanently deleted. |
| Business owner account and business profile | For as long as your account is open | Deleted when you delete your account. |
| Payment and invoice records | 8 years | Retained because Indian tax and company law requires it, then deleted. This survives account deletion. |
8. Your rights
Under the DPDPA, as a Data Principal you have the right to:
- Access a summary of the personal data we hold about you and who we have shared it with (s.11).
- Correct, complete, update, or erase your personal data (s.12).
- Withdraw your consent at any time, as easily as you gave it (s.6(4)). Withdrawing does not undo processing that already happened lawfully.
- Nominate another person to exercise these rights on your behalf if you die or become incapacitated (s.14).
- Raise a grievance with us, and escalate to the Data Protection Board of India if you are not satisfied with our answer (s.13).
How to exercise them
- Business owners: you can correct your own data at any time in Settings. To download everything we hold, or to delete your account and all of its data, use Settings → Account → Your data. Deletion is permanent.
- Customers: because the review page is anonymous, we usually cannot find your session again — there is nothing tying it to you. If you want a specific submission deleted sooner than the 90-day schedule, email support@reviyo.in with the business name and the approximate date and time, and we will do our best to locate and delete it.
We answer rights requests within 30 days and we do not charge for this. We may ask you to verify your identity before we act on a request about an account.
9. Grievance redressal
Our grievance officer under section 13 of the DPDPA is:
We will acknowledge your grievance and respond within 30 days. If you are not satisfied with our response, you may complain to the Data Protection Board of India.
10. Children
Reviyo is a business tool. You must be 18 or older to hold a Reviyo account, and the review page is not directed at children.
Section 9 of the DPDPA requires verifiable parental consent before processing a child’s personal data, and prohibits tracking, behavioural advertising, and any processing likely to cause a detrimental effect on a child. We do not knowingly collect data from anyone under 18, we do not track or profile anyone on the review page, and we serve no advertising. If you believe a child has submitted data through Reviyo, email support@reviyo.in and we will delete it.
11. How we protect data
We take the following specific measures:
- All traffic to and from the site is encrypted in transit with HTTPS/TLS.
- Data is encrypted at rest by our hosting provider.
- Row-level security is enabled on every database table, so a business owner can only read their own data and one customer can never read another customer’s session.
- Passwords are stored only as salted hashes, by our authentication provider.
- Payment card details never touch our systems; they go directly to Razorpay, which is PCI-DSS Level 1 certified.
- API keys for the AI provider and Razorpay are held as server-side secrets and are never sent to the browser.
No system is perfectly secure, and we do not claim otherwise. If we become aware of a personal data breach we will notify the Data Protection Board of India and every affected person, as section 8(6) of the DPDPA requires.
13. Changes to this policy
If we change this policy in a way that materially affects how we handle your data, we will update the version number at the top and email account holders before the change takes effect. Continuing to use Reviyo after that means you accept the updated policy. If you do not, you can delete your account.
