Legal
Privacy Policy
Last updated: July 28, 2026
1. Controller
The controller for personal data processed via this website and the BridgeReview.AI service is the operating entity disclosed in the Impressum. For privacy enquiries contact privacy@bridgereview.ai. A formal Data Protection Officer (DPO), an EU representative (Art. 27 GDPR), and a UK representative will be appointed prior to public commercial launch and listed at the same address.
2. Overview and scope
BridgeReview.AI helps ecommerce brands manage and respond to customer reviews. This policy explains what data we process, why we process it, on which legal basis, and how customers and visitors can exercise their rights. The service is offered internationally: this policy applies to visitors and customers worldwide. The specific rights available to you depend on where you live. The region-specific sections below cover the EEA and UK (section 11), the United States (section 12), and other regions (section 13), and explain how those rights apply to you.
3. Our roles: controller and processor
For website visitors and for account, billing, and support data, BridgeReview.AI is the controller. For customer content — imported reviews, reviewer details inside them, AI draft replies, and workspace team-member data — the customer (the brand using BridgeReview.AI) is the controller and BridgeReview.AI acts as a processor (service provider under the CCPA/CPRA) on the customer's documented instructions. Business customers can review our processor terms, including the Data Processing Agreement and subprocessor list, on the GDPR & Data Processing page. If you are a reviewer whose review was imported by one of our customers, please direct requests to that business first; we support them in fulfilling your rights and forward requests we receive.
4. Data we process
We process account details (name, email, hashed password), workspace settings, connected review-platform metadata, review content imported with your consent, AI-generated draft text, billing metadata, support messages, consent records, and technical logs needed to operate the service.
5. Legal bases
Contractual necessity (Art. 6(1)(b) GDPR) for service delivery and billing; legitimate interests (Art. 6(1)(f) GDPR) for security, abuse prevention, and product reliability; consent (Art. 6(1)(a) GDPR) for optional analytics and marketing communications; and legal obligation (Art. 6(1)(c) GDPR) for tax and accounting retention. Where other jurisdictions require a comparable basis (for example "lawful processing grounds" under the LGPD or "consent or legitimate purposes" under PIPEDA and Quebec Law 25), we rely on the equivalent ground for the same purpose.
6. AI, review content, and automated decision-making
Review text and AI-generated replies are treated as customer content. They are not logged into analytics or error-monitoring tools. AI providers (Anthropic, OpenAI) are used only to generate the drafts you request, governed by DPAs that prohibit training on customer content.
BridgeReview.AI does not make decisions based solely on automated processing that produce legal effects or similarly significant effects on individuals (Art. 22 GDPR; automated decision-making technology rules under the CPRA). AI-generated reply drafts are suggestions, and by default a human in the customer's workspace reviews, edits, approves, and publishes each one.
Customers on higher plans can additionally switch on automation rules that publish a draft once a cancellation window has elapsed (24 hours by default) unless someone intervenes. Where a customer enables this, that customer decides to publish without reading each individual draft; the automated safety checks still run immediately before publication, and the customer remains responsible for the published text. Automation is off unless a customer turns it on, and it can be switched off or a queued reply cancelled at any time.
7. Cookies, analytics, and opt-out preference signals
Essential cookies support authentication, security, and consent state. We use Vercel Web Analytics and Speed Insights in cookieless mode for page-view and performance aggregates; they operate without setting cookies and without storing IP addresses. We run no advertising or retargeting pixels. See the Cookie Policy for the individual cookies and lifetimes.
Browser analytics are strictly opt-in. PostHog (product analytics, EU ingest) and Google Analytics 4 (website traffic) are not downloaded and write no cookie until you accept analytics in the cookie banner; withdrawing consent stops collection.
Product telemetry inside the signed-in application is separate and is not consent-gated. When a signed-in user performs an action in the workspace — for example approving, rejecting or publishing a reply, or completing an onboarding step — we send a server-side event to PostHog recording that the action happened, linked to the account identifier. These events carry no review text, no reviewer details and no free-text content: they are limited to event names and enumerated or boolean values, and that restriction is enforced by an automated test. We rely on legitimate interests (Art. 6(1)(f) GDPR) in operating a reliable service for this telemetry, not on consent, so it continues to run when analytics cookies are declined. It sets no cookie and reads nothing from your device.
We honour the Global Privacy Control (GPC) opt-out preference signal, as required by the CPRA and the Colorado, Connecticut, Texas, and other US state laws. If your browser sends GPC, we record an opt-out for you automatically on arrival: the optional analytics described above are switched off, their scripts are never loaded, and we do not ask you to reconsider with a banner. You can still opt in deliberately at any time through the footer "Cookie settings" link. Separately, we do not sell your personal information and do not share it for cross-context behavioural advertising, so there is no advertising sale or sharing for the signal to switch off in the first place.
8. Subprocessors
We engage the following subprocessors under Art. 28 GDPR. A 30-day notice for material changes will be sent to the customer contact on file.
| Provider | Purpose | Hosting region |
|---|---|---|
| Supabase | Postgres DB + Auth (customer + review data) | US-East-1 (N. Virginia) |
| Vercel | Application hosting, edge runtime | fra1 (Frankfurt, Germany) |
| Anthropic | Primary AI provider (Claude) for reply drafting | US (DPA in place) |
| OpenAI | Fallback AI provider | US (DPA in place) |
| Stripe | Billing, invoicing, customer portal | IE/US |
| Resend | Transactional email delivery | EU + US |
| Sentry | Error monitoring (no customer review text) | EU (Frankfurt) |
| PostHog | Product analytics: opt-in browser analytics + server-side telemetry of in-app actions (no review or reply content) | EU (eu.i.posthog.com) |
| Google Analytics | Website traffic analytics (consent-gated; marketing pages) | US/Global |
| Upstash | Rate-limiting + cache (no PII) | EU-West-1 |
| Apify | Public-URL review scraping for opt-in imports | EU + US |
| Inngest | Background job orchestration (no review content) | US |
| Google Business Profile API for opted-in connections | Global |
9. Retention
We keep workspace data — including imported reviews and generated replies — for as long as the workspace exists. Cancelling a subscription stops billing but does not by itself delete data, and there is no automatic expiry after a fixed period: deletion is triggered by you.
You can start deletion at any time from Settings. The request is confirmed, then held for a 30-day grace period during which you can cancel it; after that a daily job erases the workspace table by table and anonymises the organisation record. Two categories are deliberately kept: billing records, because tax and commercial law require it (typically 7 years), and a PII-sanitised audit trail, as permitted by Art. 17(3)(b) GDPR and equivalent provisions elsewhere. Personal data may also persist briefly in encrypted infrastructure backups after erasure.
The workspace and your personal login are two separate erasures. By default the login survives, so you can still sign in and start a new workspace. When you tick “Also delete my personal login and profile” in the deletion dialog, the same job additionally erases your user account, name and email address at the end of the grace period — unless you still belong to another workspace, in which case the login is kept and only the workspace is erased. Records that must survive under Art. 17(3)(b) keep a reference to a deleted user, but that reference is set to null, so nothing points back to you. You can also request the same erasure by email at privacy@bridgereview.ai.
Two logs have their own clocks. Email delivery events (sends, opens, bounces, complaints) are deleted automatically 180 days after they are recorded. Our unsubscribe and bounce suppression list is the one thing we deliberately keep: removing an address from it would allow us to email you again, so an entry is only removed when the address itself is erased.
10. Security
We protect personal data with technical and organizational measures appropriate to the risk (Art. 32 GDPR and comparable duties under the CPRA, LGPD, PIPEDA, and the Australian Privacy Act): encryption in transit and at rest, field-level encryption for review and reply content, role-based access control with row-level tenant isolation, audit logging, and vetted subprocessors. The full statement of technical and organizational measures is published at bridgereview.ai/tom.
11. Your rights (EEA and UK)
If you are in the European Economic Area or the United Kingdom, under the GDPR and UK GDPR you can request access, correction, deletion, portability, restriction, or objection to processing, and you may withdraw consent at any time. Contact privacy@bridgereview.ai. You also have the right to lodge a complaint with your supervisory authority: in the UK, the Information Commissioner's Office (ICO); in the EEA, your national data-protection authority.
12. United States privacy rights
If you are a resident of California (CCPA/CPRA) or of a US state with a comprehensive privacy law (including Virginia, Colorado, Connecticut, Utah, Texas, Oregon, Montana, and other states as their laws take effect), you have rights over your personal information.
In the past 12 months we have collected the categories described in section 4, which map to the statutory categories of identifiers, commercial information, internet/network activity, and customer-provided content. We collect this information to provide, secure, and bill for the service, as described in sections 4 and 5.
We do not sell your personal information, and we do not share it for cross-context behavioral advertising. We do not use or disclose sensitive personal information for purposes beyond providing the service you requested. Because there is no sale or sharing, no opt-out is required, but you may still exercise it as a matter of choice — including via the Global Privacy Control signal described in section 7.
Subject to your state's law, you may request to know or access the personal information we hold, request correction, request deletion, opt out of any sale or sharing, and limit the use of sensitive personal information. We will not discriminate against you for exercising these rights. You may use an authorized agent to submit a request. Contact privacy@bridgereview.ai; we verify requests against the account on file before acting and respond within the timeframe your state's law requires. If we refuse a request, you may appeal by replying to our decision email with "Appeal" in the subject; we answer appeals within the statutory period of your state (for example 60 days in Virginia) and include instructions for contacting your state attorney general if the appeal is unsuccessful.
13. Other regions
Where local law grants comparable rights, we honour them for residents of those regions, including Switzerland (revised FADP; supervisory authority: the FDPIC), Brazil (LGPD; authority: the ANPD), Canada (PIPEDA and, for Quebec residents, Law 25; authorities: the OPC and the CAI), Australia (Privacy Act; authority: the OAIC), New Zealand (Privacy Act 2020; authority: the OPC NZ), Japan (APPI; authority: the PPC), and South Korea (PIPA; authority: the PIPC). To exercise any of these rights, contact privacy@bridgereview.ai. If we cannot resolve your concern, you may complain to the supervisory authority of your jurisdiction.
14. Children's privacy
BridgeReview.AI is a business tool that is not directed to children. We do not knowingly collect personal information from anyone under 16, and the service is not intended for use by children under 13 in any jurisdiction. If we learn that we have collected such data, we delete it promptly.
15. International data transfers
We operate globally, so your data may be processed in a country other than your own. Where subprocessors process data outside the EEA, the UK, or Switzerland (notably Supabase, Anthropic, OpenAI, Stripe, and Inngest in the US), transfers are protected by the appropriate safeguards: the EU Standard Contractual Clauses (SCCs) under Commission Implementing Decision (EU) 2021/914 for EEA data, the UK International Data Transfer Addendum for UK data, and the Swiss addendum for Swiss data, together with supplementary technical and organizational measures. Where a US recipient is certified under the EU-U.S. Data Privacy Framework (and its UK and Swiss extensions), we may additionally rely on that certification. For transfers from other jurisdictions with transfer rules (for example Brazil or the UAE), we use the mechanism that jurisdiction recognizes, such as contractual clauses. A copy of the relevant safeguards is available on request via privacy@bridgereview.ai.
16. Data breach notification
If a personal-data breach is likely to result in a risk to your rights and freedoms, we notify the competent supervisory authority without undue delay (within 72 hours where Art. 33 GDPR applies) and inform affected customers and individuals as required by the law of their jurisdiction, including US state breach-notification statutes and the Australian Notifiable Data Breaches scheme.
17. Changes to this policy
We update this policy when the service, our subprocessors, or the law changes. The date at the top reflects the latest revision. For material changes we notify account owners by email at least 30 days before the change takes effect; continued use after that date constitutes acceptance where the law allows, and consent is re-requested where it does not.