Privacy Policy
What personal data we collect, why, who we share it with, how long we keep it, and the rights you have over it.
_Last updated: 3 August 2026_
This Privacy Policy explains what personal data TrustRating ("we", "us") collects when you use trustrating.ai, business.trustrating.ai, our widgets, APIs and related services (the "Service"), why we collect it, who we share it with, how long we keep it, and the rights you have over it. It applies to consumers, reviewers, business users, affiliates and visitors alike. It should be read together with the Cookie Policy and, for business customers on whose behalf we process customer contact data, the Data Processing Addendum.
TrustRating is the controller of the personal data described in this Policy, except where the DPA states that we act as a processor for a business customer. You can reach our privacy team at any time via the contact page.
1. Data we collect
Account data. When you register we collect your name or display name, email address, password (stored only as a salted hash), account type (personal or business), language and country preferences, and profile details you choose to add such as an avatar or username. Business accounts additionally include your role at the company you represent and the linkage between your personal and business identities.
Reviews and public content. Reviews, star ratings, titles, review text, dates of experience, replies, flags you raise, helpful votes, and edits are collected and — by design — published. Your public reviewer profile shows your display name, review history and statistics.
Verification data. To keep reviews genuine we process verification signals: the email verification status of your account, evidence linking a review to a real transaction where provided (for example an invitation token from a business), and, for company claims, proof that you control the company domain (DNS records you create or a mailbox on the company domain).
Payment and billing data. For paid subscriptions and affiliate payouts we process billing name and address, VAT or company number where given, invoice history, plan and payment status, and payout details you provide (for example bank account/IBAN or a crypto wallet address). Card data is handled by our payment processors (Stripe, and NOWPayments for cryptocurrency) and never touches our servers — we receive only tokens, status events and the last digits needed to show you which card was used.
Technical data. Like every website we process IP addresses, browser and device information, requested pages, referrers and timestamps in server logs; and we set the cookies described in the Cookie Policy, including a short-lived attribution cookie when you arrive through an affiliate link.
Claim and verification evidence. When a business account claims a company under the Company Claims & Domain Verification Policy, we process the evidence involved: the verification tokens and DNS records used, the domain mailbox that confirmed the claim, and any supplementary documents you submit to prove your role. This evidence is used only for the claim decision and for defending it if the claim is later disputed.
Affiliate program data. If you join the affiliate program, we process your application answers, the statistics snapshot attached to it, your referral link activity (clicks, attributed signups, conversions), your commission ledger (accruals, maturation, reversals, clawbacks, payouts) and the payout details you provide. Attribution relies on the referral cookie described in the Cookie Policy.
Moderation and integrity data. To keep reviews genuine we retain records connected to moderation: flags you raise or receive, TrustGuard risk assessments, evidence submitted in disputes, enforcement decisions affecting your account and their reasons, and appeal correspondence. This is what allows us to apply sanctions consistently and to reverse them when an appeal succeeds.
Communications. Support tickets, contact-form messages, emails you send us, delivery and open events for transactional email, and notification preferences (including unsubscribe status).
2. Where data comes from
Most data comes directly from you. Some comes from your use of the Service (technical data, votes, flags). Company profile information — names, domains, categories, publicly available descriptions — may come from public sources, from the company itself, or from users who add a business to the directory. Review-invitation recipient data (name, email, order reference) comes from the business that invites you, acting as controller of its own customer list; our role in that flow is described in the DPA.
3. Why we process data (purposes and legal bases)
Where EU/UK data-protection law applies, we rely on the following legal bases: Contract — creating and operating your account, publishing your reviews, providing business subscriptions, processing payments, running the affiliate program you joined. Legitimate interests — publishing company profiles and trust information about businesses (an interest shared by consumers and honest businesses), fraud prevention and TrustGuard moderation, securing the Service, measuring and improving features, sending service notifications, and defending legal claims; we balance these interests against your rights and you may object at any time. Consent — non-essential cookies and any marketing communications; consent can be withdrawn as easily as it was given. Legal obligation — tax and accounting retention of invoices, responding to lawful orders, and content-moderation transparency duties.
4. Automated analysis and AI
TrustScores are produced automatically by combining human reviews with assessments from third-party AI models that analyse a company's public footprint. This processing concerns companies, not individual reviewers; review text is processed as input in aggregate. TrustGuard, our fraud-prevention system, automatically screens reviews and accounts for signals of manipulation (for example bot patterns, coordinated bombing, or self-reviews) and may quarantine content pending human review. Significant enforcement decisions — suspensions, bans, review removals with account consequences — always involve human review, and every decision can be appealed as described in the Review Verification, Moderation & Appeals Policy. We do not use automated decision-making that produces legal or similarly significant effects on you without human involvement.
5. Who we share data with
We share personal data only as needed to run the Service: Processors — hosting and infrastructure providers, email delivery providers, error-monitoring and analytics providers, all bound by data-processing agreements. Payment providers — Stripe and NOWPayments process payments as independent controllers of the data they need for that purpose; banks receive transfer details you gave us for payouts. The public — content you publish (reviews, replies, public profile) is, by definition, public; company replies are visible to everyone. Businesses — a business you review sees your public review and display name; if you were invited through that business, it can match the review to its own customer record. Authorities and legal — where required by law, to enforce our terms, or to protect the rights, safety and integrity of the Service and its users. Corporate transactions — a successor in a merger or acquisition, under the same commitments. We do not sell personal data.
6. International transfers
Our providers may process data outside your country. Where data leaves the EU/EEA or UK, we use recognised safeguards — adequacy decisions where available, otherwise Standard Contractual Clauses plus supplementary measures. Details of current sub-processors and transfer mechanisms are available on request via the contact page.
7. Retention
We keep personal data only as long as needed for the purposes above, and different categories have different clocks: account data lives for the life of the account; published reviews remain while they are published (see the Terms of Service on why genuine reviews persist); server logs and raw security data are kept for short rolling windows measured in weeks, unless a specific incident requires preserving a slice of them; invoices and billing records are kept for the statutory tax-retention period that applies to us, typically several years, because the law requires it; moderation and enforcement records are kept while they remain relevant to applying our rules consistently — a record of a fraud ban, for example, must outlive the banned account or the ban means nothing; claim-verification evidence is kept while the claim stands and for a reasonable period afterwards to resolve disputes; affiliate commission ledgers are kept as financial records; support tickets are kept as long as needed to handle follow-ups and recurring issues; and backup copies exist on a fixed rotation schedule — half-hourly, daily, monthly and yearly tiers — after which each tier is overwritten, so deleted data ages out of backups automatically rather than persisting indefinitely.
When you delete your account we delete or irreversibly anonymise the personal data we no longer need, within the limits of legal retention duties and the published-content rules described above. Where deletion is deferred by such a duty, the data is locked away from everyday processing until the duty lapses, then removed.
8. Your rights
Depending on your location you have the right to: access the personal data we hold about you; rectify inaccurate data; erase data (the "right to be forgotten"); restrict or object to processing based on legitimate interests; port data you provided to another service in a machine-readable format; and withdraw consent at any time where processing is based on consent. You can exercise most of these directly in your account settings (profile editing, review deletion, account deletion, notification preferences, cookie settings at cookie settings) or by contacting us through the contact page. We respond within the statutory deadline (one month under GDPR, extendable where the law allows). You also have the right to complain to your data-protection authority, though we would appreciate the chance to resolve your concern first.
If you are a California resident, equivalent rights (know, delete, correct, opt out of "sale"/"sharing" — which we do not do — and non-discrimination) apply under the CCPA/CPRA.
Two practical notes on requests. First, we must be sure a request really comes from the person it concerns, so we verify identity proportionately — usually by requiring the request from the account's registered email address; for high-impact requests (full export, erasure) we may ask you to confirm through the account itself. We never demand more identification than the request warrants. Second, some requests have inherent limits we will explain in our answer: erasure cannot reach data we are legally required to keep (invoices, for instance) and cannot be used by a business to erase truthful reviews about it, and objection to fraud-prevention processing cannot override the platform's overriding interest in staying honest — but in each case we tell you exactly what we did, what we did not do, and why.
9. Security
We protect data with encryption in transit, hashed credentials, role-based access controls within our team, network-level protections, rate limiting, audit logging of administrative actions, and a tested backup and restore regime. Access to production personal data inside TrustRating is restricted to the staff whose role requires it, is logged, and is never used for curiosity; administrative "assist" access to user accounts is itself audited. No system is perfectly secure; if we learn of a breach affecting your personal data we will notify you and the competent authority as required by law, tell you plainly what happened and what we are doing about it, and never bury the notice in marketing language. You can help on your side: use a strong unique password, keep your email account (the key to password resets) secure, and tell us immediately about anything suspicious via the contact page.
10. Children
The Service is not directed at children under 16, and we do not knowingly collect their data. If you believe a child has created an account, contact us and we will remove it. Where a review legitimately concerns a child's experience — a family purchase, a service used by the household — the account holder writes it as their own experience as the paying customer, without publishing the child's personal details, consistent with the Reviewer Guidelines.
11. Cookies
We use strictly necessary cookies for sign-in, security and preferences, and optional cookies only with your consent. The full list — names, purposes, durations — and the settings panel are in the Cookie Policy, reachable at any time from the footer.
12. Changes to this Policy
We will update this Policy when our processing or the law changes. Material changes are announced in advance by email or in-product notice. The "Last updated" date above identifies the current version; earlier versions are available on request.
13. Contact
For any privacy question, request or complaint, use the contact page and select the privacy topic, or write to the postal address published on that page. We answer every request.