legal

Privacy Policy

Last updated 11 August 2026

This policy explains what personal data repuze collects, why we collect it, who we share it with, and the rights you have over it. It covers both the businesses who use repuze and the customers those businesses contact through us.

1. Who we are

repuze is operated by Factyze (“repuze”, “we”, “us”). We provide software that helps local businesses request, monitor and respond to online reviews.

For questions about this policy or to exercise any of the rights described below, contact privacy@repuze.com.

2. Our role — controller and processor

Our role depends on whose data is involved, and this distinction matters for your rights:

  • Account data — for the business owners and team members who sign up and use repuze, we are the data controller. We decide why and how that data is processed.
  • Customer data — for the end customers a business uploads or syncs into repuze in order to request reviews, we are a data processor. The business is the controller. We act on their instructions and do not use their customer lists for our own purposes.

If you received a review request from a business using repuze and want your data removed, the fastest route is to contact that business directly. You can also contact us and we will pass the request on.

3. What we collect

CategoryDataWhy
AccountName, email address, hashed password, profile image (if you sign in with Google)To create and secure your account
BusinessBusiness name, address, phone number, website, industryTo personalise review requests and connect your listings
Customer recordsName, email address, phone number, postal address, booking source and reference, unsubscribe statusTo send review requests on the business's behalf and honour opt-outs
AppointmentsAppointment times and service type, synced from your booking systemTo time review requests after a visit
MessagesThe content and delivery status of SMS and email we sendDelivery tracking, troubleshooting, and billing
Click eventsIP address, browser user-agent and timestamp when a review link is clickedFraud prevention and reporting on which requests led to a click
Google Business Profile dataLocation details, reviews and replies, performance metrics — see section 4To power the review inbox, profile tools and analytics
BillingSubscription status and payment metadata (handled by Stripe — we never see full card numbers)To operate paid plans

4. Google user data

When you connect a Google account, we request the business.manage scope through Google’s standard OAuth 2.0 consent flow. We never ask for or store your Google password, and we can only reach the profiles your Google account already owns or manages.

We use this access only to:

  • list the Business Profile locations you manage, so you can choose which to work with;
  • read and display your reviews, and publish replies that you have written and approved;
  • read and update profile fields (name, address, phone, website, hours, description) that you change in repuze;
  • detect unauthorised changes to fields you have locked, alert you, and restore your chosen value;
  • read performance metrics such as calls, direction requests and website clicks for your reports.

Limited Use: repuze’s use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. We do not sell Google user data, use it for advertising, or allow humans to read it except where required for security, to comply with the law, or where you have explicitly asked us to.

Your OAuth tokens are encrypted at rest using AES-256-GCM. You can disconnect Google at any time from Settings → Integrations, or revoke access directly at myaccount.google.com/permissions. Disconnecting stops all further syncing and deletes the stored tokens.

5. Review integrity

repuze invites customers to leave honest reviews. We do not screen, score or filter customers by predicted sentiment, and we never route unhappy customers away from Google. Every customer who receives a request is sent to the same public review destination. We do not write, buy, incentivise or alter review content.

7. Who we share data with

We do not sell personal data. We share it only with the service providers needed to run repuze:

ProviderPurposeRegion
NeonPrimary databaseEU (London)
CloudflareApplication hosting and CDNGlobal edge
TwilioSMS deliveryUS / global
ResendEmail deliveryUS / EU
StripePayment processingUS / EU
UpstashRate limiting and cachingEU
InngestBackground job schedulingUS
GoogleBusiness Profile and Calendar integrationsGlobal
Calendly, Square, AcuityBooking system integrations (only if you connect them)US / global
AI model providersDrafting suggested review replies and content — see section 8US / EU

Where data leaves the UK or EEA, transfers are covered by the UK International Data Transfer Addendum or the EU Standard Contractual Clauses.

8. AI-generated content

Some features draft suggested replies and marketing copy using third-party AI models. Review text and your business profile details may be sent to these providers to generate a suggestion. Suggested replies are never published automatically — a person at the business must review and approve them. We do not permit our AI providers to train their models on your data.

9. How long we keep data

  • Account data — for as long as your account is open, then deleted within 90 days of closure.
  • Customer records and messages — until the business deletes them or closes its account.
  • Click events — 24 months, then deleted.
  • Google OAuth tokens — deleted immediately when you disconnect the integration.
  • Billing records — retained as long as tax and accounting law requires.

10. Security

  • All traffic is served over HTTPS.
  • OAuth tokens and integration credentials are encrypted at rest with AES-256-GCM.
  • Passwords are hashed — never stored in readable form.
  • Access is scoped per business account; one customer cannot reach another’s data.
  • Authentication and API endpoints are rate limited to resist brute-force and abuse.

No system is perfectly secure. If we become aware of a breach affecting your personal data, we will notify you and the relevant supervisory authority as required by law.

11. Your rights

Depending on where you live, you may have the right to access, correct, delete, export or restrict the processing of your personal data, and to object to it. To exercise any of these, email privacy@repuze.com. We respond within 30 days.

If you are in the UK, you also have the right to complain to the Information Commissioner’s Office at ico.org.uk.

12. Cookies

We use only the cookies needed to run the service — a session cookie to keep you signed in and a CSRF token to protect form submissions. We do not use advertising or cross-site tracking cookies.

13. Children

repuze is a business tool and is not intended for anyone under 16. We do not knowingly collect data from children.

14. Changes to this policy

We will update this page when our practices change and revise the date at the top. If a change materially affects how we handle your data, we will email account holders before it takes effect.

See also our Terms of Service.