Last updated 19 August 2026
This document is not yet in force
The contracting entity has not been settled, so every place this document would name a company, a jurisdiction or a postal address reads ENTITY TBC. Nothing here binds anyone until those are filled in, and no invitation may be sent to a real customer while they are not.
This explains what Review Chaser does with personal information. It covers two different groups of people, and the distinction matters throughout: merchants, who hold an account with us, and customers, who receive an invitation or leave feedback about a merchant.
The service is operated by ENTITY TBC, registered in ENTITY TBC, at ENTITY TBC. Questions and complaints go to ENTITY TBC.
For customer feedback and invitation lists, the merchant is the data controller and we are the processor: they decide who is invited and why, and we act on their instructions. For merchant account data we are the controller.
We do not record how you feel before showing you your options, because the product has no rating step to record. There is no profile of you built anywhere in this system.
Every invitation carries a one-click unsubscribe link and the standard mail headers, so your mail provider can offer its own unsubscribe button. Using either stops invitations from that business permanently and immediately, cancels anything already queued for you, and needs no account and no reply. It applies to that business only.
Merchants choose retention periods for contact details, feedback content and the compliance record separately, within limits we set. When a period expires the data is removed by a scheduled job, not by anyone deciding to run something. Suppression records outlive the invitations they relate to, because forgetting that you asked us to stop would mean writing to you again.
You can ask for a copy of what is held about you, ask for it to be corrected, or ask for it to be erased. Where a merchant is the controller, ask them first and they can act on it in the product; ask us at ENTITY TBC and we will pass it on and make sure it happens. Erasure removes personal detail while leaving the compliance record able to show that a message was sent, because a record that can be emptied is not a record.
Three sub-processors, and no others. Supabase hosts the database. Resend delivers the email. And when a merchant asks for a suggested reply to one of their public Google reviews, Anthropic (Claude) receives the text of the public review, the reviewer’s Google display name, and your business name, for the sole purpose of drafting suggested replies to public Google reviews. It retains nothing on our behalf: the drafts are generated per request and are not used to train a model.
That last one processes a third party’s personal information: the review and the display name belong to the person who wrote them, not to the merchant and not to us. Nothing is sent unless a merchant presses the button on a specific review, and no private feedback, invitation list, email address or customer record is ever sent to it. The data processing agreement naming all three is between the merchant and ENTITY TBC, which is why it is not finished.
On Supabase infrastructure in Australia, with email delivered through Resend. This is why businesses in health-adjacent categories, including dental, medical, aged care and veterinary, are refused at signup: a health-related review carries more sensitivity than this arrangement should hold.
Reply drafting is the exception, and it is worth stating plainly: that request is processed on Anthropic’s infrastructure outside Australia. It happens only when a merchant asks for a draft, it carries a review that is already public, and it carries nothing else.