Privacy Policy
Last updated: May 2026
StarReview (“we”, “us”) operates the platform starreview.ch. Protecting your data is important to us. This privacy policy explains what data we collect, how we use it, and what rights you have.
Data Controller
StarReview (sole proprietorship)
F. Weinhappl
Schönenbergstrasse 10
9543 St. Margarethen, Switzerland
Email: hello@starreview.ch
1. Data We Collect
We collect the following personal data:
- Name and email address (upon registration via Google sign-in)
- Google Business Profile data (location information, reviews, review texts, reviewer name)
- Payment information (processed by our payment processor, we do not store credit card data)
- Usage data (login times, features used)
- Customised replies (to improve the response style, “Style Memory”)
- When sending review requests via SMS: phone numbers of your end customers (used solely to send the request you initiated, no marketing)
2. How We Use Your Data
We use your data exclusively for the following purposes:
- Creating personalised replies to your Google reviews
- Managing your account and subscriptions
- Weekly and monthly summaries via email
- Notifications for negative reviews (1-2 stars)
- Style Memory: when you adjust a reply, the system learns your style for future suggestions in your account
- Improving our services
We do not train external AI models with your data. Your reviews, replies, and Style Memory entries stay in your account and are not used to train or fine-tune third-party AI models.
3. Data Sharing
We do not sell your data or share it with third parties for marketing purposes. The following service providers process data on our behalf:
- Google Business Profile API, to retrieve reviews and publish replies
- AI service provider, review texts are processed to generate reply suggestions, without permanent storage
- Payment processor, for secure payment processing (PCI-DSS compliant)
- Email service provider, for sending notifications
- Hosting, operation of our platform in EU data centres
StarReview's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. For more details, see our Google API disclosure.
4. Data Retention
Your data is stored as long as your account is active. After account deletion, all personal data is irrevocably deleted within 30 days. Anonymised data may be retained for statistical purposes.
5. Cookies and Analytics
StarReview does not use tracking cookies. For web analytics, we use a privacy-friendly analytics tool that does not collect personal data and does not set cookies. A session cookie is used solely for authentication.
6. Data Processing Location & International Transfer
Your account and review data is stored in EU data centres.
Our AI service provider for reply generation processes review texts in the USA. This international data transfer takes place on the basis of the EU Standard Contractual Clauses (Art. 46(2)(c) GDPR) and equivalent safeguards under the revised Swiss Federal Act on Data Protection (nFADP). Review texts are processed in real time and not permanently stored by the AI provider.
7. Your Rights (nFADP + GDPR)
Under the Swiss Federal Act on Data Protection (nFADP) and the EU GDPR, you have the right to:
- Access your stored data
- Rectify inaccurate data
- Delete your data
- Data portability
- Withdraw your consent
- Restrict processing
- Lodge a complaint with the competent data protection authority, in Switzerland, the Federal Data Protection and Information Commissioner (FDPIC); in EU member states, the relevant national supervisory authority
8. Legal Basis
The processing of your data is based on the Swiss Federal Act on Data Protection (nFADP) of 1 September 2023 and, where applicable, the EU General Data Protection Regulation (GDPR).
9. Automated Decision-Making
Reply suggestions are generated algorithmically. With automatic publishing enabled, replies are published without renewed manual review in each individual case, but always based on your explicit per-star-rating setting. By default, every reply requires your manual approval. This is not a decision producing legal or similarly significant effects within the meaning of Art. 22 GDPR or Art. 21 nFADP, but the publication of content you have previously authorised per star rating. You can deactivate auto-publishing at any time.