Legal

Privacy policy

Template last updated 9 August 2026. Have qualified counsel adapt it before launch.

1. Information we process

We process account details, review content, company information, support correspondence and security metadata needed to operate and protect the service. Raw IP addresses are transformed into keyed hashes before storage.

2. Optional transaction proof

A reviewer may privately provide an order or case reference. When a company supports signed transaction matching, references and customer emails are stored as purpose-separated keyed hashes and only a short reference hint is displayed. A reference is not required for identity-level assessment.

3. Automated decisions

Proof level, risk signals, technical clusters and deterministic content rules are used to publish, hold or reject submissions. Identity-only reviews receive longer holds and stricter limits. The decision ledger records policy version, risk score and reason.

4. Review visibility

Published reviews display the reviewer’s chosen name, rating, content, experience date and accurate identity, invitation or transaction verification label. Private references and technical indicators remain restricted.

5. Why we process it

Purposes include account administration, proof-level verification, spam and manipulation prevention, service security and legal compliance. Rating sentiment is not evidence that a review is genuine or false.

6. Sharing

We do not sell personal data. Data may be shared with contracted infrastructure or email providers, professional advisers or lawful authorities where necessary and appropriately protected.

7. Retention

Reviews and limited integrity records may be retained while needed to operate the service, prevent abuse or resolve disputes.

8. Your rights

Depending on applicable law, you may request access, correction, deletion, restriction or portability and may object to certain processing.

9. Security

Controls include password hashing, CSRF protection, prepared queries, secure sessions, role boundaries, two-factor authentication, encryption, HMAC signing, replay prevention, rate limits, DNS challenges and audit logging.

10. Contact

Direct privacy requests to whitesparrowbd@gmail.com.