RATECARDS PRO
Privacy Policy
- Version
- 0.1-draft
- Status
- Draft — not yet in force
- Last updated
- 2026-09-08
This policy explains what personal data RATECARDS L.L.C-FZ collects when you use RATECARDS PRO, why, where it is processed, how long it is kept and what rights you have. It covers two situations: people who use the Service for a business, and reviewers whose public reviews the Service mirrors on that business's behalf.
1. Who we are
RATECARDS PRO is provided by RATECARDS L.L.C-FZ (Meydan Free Zone business licence 2305959.01), Meydan Grandstand, 6th floor, Meydan Road, Nad Al Sheba, Dubai, United Arab Emirates. Contact for anything in this policy: support@ratecards.co.
2. Two roles: when we decide, and when a business decides
- You use the Service for a business (you sign in, manage locations, reply to reviews). For your account data we are the controller: we decide what we collect and why, and this policy applies directly to you.
- You wrote a review on a platform such as Google Business Profile or Trustpilot, and a business that uses the Service mirrors that review into its workspace. For that data the business is the controller and we are its processor: we act on the business's instructions under a Data Processing Agreement. Requests about that data should go to the business; if you contact us instead, we will pass your request to the business and help it respond.
3. Data we collect from people who use the Service
| Data | What it contains | Where it comes from |
|---|---|---|
| Account | email address, display name, whether the email is verified, and — only if Google sign-in is offered and you use it — the profile picture URL Google provides | you, or Google when you use Google sign-in |
| Sign-in credentials | for password sign-in, a one-way hash of your password (never the password itself); for Google sign-in, the identifiers and tokens Google issues so we can confirm who you are | you / Google |
| Sessions | a session token, the IP address and browser (user-agent string) each session was created from, and timestamps | your browser, automatically |
| Verification and sign-in links | short-lived tokens for email verification, password reset and emailed sign-in links | generated by the Service |
| Workspace membership | your role in each workspace and which locations you may see; invitations you send or receive (invitee email and a hashed token) | your workspace's owners and admins, and you |
| Activity records | an append-only audit log of changes to important records. It stores record identifiers, the action, who did it and which fields changed — never the field values themselves | generated by the Service |
| Support messages | what you send us by email and our replies | you |
| Billing contact | the name, email address and company details of the person a business names for its invoices | the business |
We do not collect payment card data (fees are invoiced and paid by bank transfer), and the Service has no advertising or analytics trackers.
4. Data we process on a business's behalf
When a business connects a review platform to its workspace, the Service mirrors the reviews for its locations exactly as the platform makes them available: the platform's review identifier, the reviewer's platform identifier and display name, the review text, the rating, the language, the timestamps, and any reply. The Service also stores the replies the business publishes (with the workspace member who wrote them), earlier versions of a review when the platform reports an edit, the review's language and — when the AI features are enabled — a sentiment score and risk flags for each review, and, if the business uses AI drafting, each draft with its status.
The Service never asks a reviewer for anything and never contacts reviewers. A review that is removed on the platform is marked as removed in the workspace within the time the platform's rules require, is no longer shown or counted, and is deleted with the workspace. Where the Service mirrors Trustpilot content, it follows Trustpilot's content guidelines: new, changed and removed content is mirrored within 24 hours and a deletions sweep runs at least every 28 days. Tripadvisor content is not mirrored at all: the Service only links to a location's Tripadvisor page.
Touchpoints. A business can print QR codes or share short links that send its customers to a platform's review page. When you open one, our server checks the link and redirects you. We use your IP address in memory for a short time to limit abuse (120 requests per minute per address); we do not store the visit, set a cookie, or learn who you are.
5. Why we use personal data, and the legal basis
| Purpose | Data | Legal basis |
|---|---|---|
| Providing the Service to a business and its users (accounts, sign-in, workspaces, feeds, replies) | account, credentials, sessions, membership, review data | performance of the contract with the business; for review data, the business's instructions as controller |
| Keeping accounts and the Service secure (verifying email, rate-limiting sign-in attempts, recording the IP address and browser each session was created from so a session can be investigated and ended, audit trail) | credentials, sessions, verification tokens, activity records, IP addresses | our legitimate interest in securing the Service and the business's legitimate interest in an accountable workspace (GDPR); under the UAE PDPL, performance of the contract with the business and our legal obligations |
| Drafting and classifying replies with an AI model | review text, reviewer display name, location name, brand-voice settings | the business's instructions as controller (the business chooses to use the feature) |
| Sending transactional email (verification, sign-in links, password reset, invitations) | email address | performance of the contract |
| Invoicing and accounting | the business's billing contact and invoices | performance of the contract and our legal obligations (UAE tax law) |
| Responding to requests and enforcing our terms | support messages, account data | performance of the contract; legal obligations; our legitimate interests (GDPR) |
We do not sell personal data, use it for advertising, or make automated decisions with legal or similarly significant effects about individuals. AI drafts are suggestions that a person reviews before they are published, unless a workspace owner has chosen the risk-based mode described in the Terms.
6. AI processing
When the AI features are enabled for a workspace (they are not yet switched on), reply drafts and review classification use Claude models provided by Anthropic, called from our servers through Anthropic's commercial API. For each request we send the review text, the reviewer's display name as the platform shows it, the location's name, the business's brand-voice settings and our own instructions. Nothing else about the reviewer is sent.
- Inference runs in Anthropic-operated regions, which include the United States; Anthropic's first-party API cannot be pinned to the EU.
- Under Anthropic's commercial terms, content sent through the API is not used to train Anthropic's models. Anthropic deletes the inputs and outputs it holds within 30 days of receipt (longer only where its trust-and-safety systems flag the content or the law requires), and stores those copies in the United States — see the Data Processing Agreement.
- We keep a record of each AI attempt with the review it relates to (model, draft, status and confidence) so the business can audit what was generated and what was published.
8. Where data is processed and international transfers
The Service and its database run in Frankfurt, Germany (European Union). RATECARDS L.L.C-FZ is established in the United Arab Emirates, and our staff access the Service from there. Some sub-processors process data outside the EU and the UAE, as listed above.
Where the GDPR applies to a transfer, we rely on the European Commission's Standard Contractual Clauses with the recipient, together with the recipient's own safeguards, as set out in the Data Processing Agreement. Where the UAE Personal Data Protection Law applies, transfers are made under the contractual safeguards that law allows. You can ask us at the address below for a copy of the safeguards in place for a particular transfer.
9. How long we keep data
| Data | Retention |
|---|---|
| Workspace membership and invitations | deleted with the workspace 30 days after it is closed (the wind-down period in the Terms) |
| Account and credentials | for as long as your account exists — an account can belong to several workspaces; once it belongs to none you can ask us to delete it |
| Sessions | a session lasts up to 7 days and is renewed while you keep using it; you can end it by signing out |
| Verification, reset and sign-in tokens | minutes to hours (emailed sign-in links expire after 5 minutes) |
| Review data and replies | while the workspace exists (syncing stops when a platform connection is removed); reviews removed on the platform are marked as removed and no longer shown or counted; everything is deleted with the workspace 30 days after it is closed |
| AI attempts | with the review they relate to; Anthropic's own copy of a request is deleted within 30 days |
| Application logs at our hosting provider | 7 days (they carry record identifiers and error classes, not review text) |
| Audit log | for the life of the workspace (it holds identifiers only, never personal details) |
| Backups | point-in-time recovery data is kept for a rolling 3-day window (7 days on a larger hosting plan) and logical backups for 7 days, then overwritten; restored data is checked against an erasure list so erased data is not brought back |
| Invoices and accounting records | as long as UAE tax law requires |
10. How we protect data
- Every workspace's data is isolated in the database with row-level security enforced by the database itself, and tested continuously. The database, its replicas and all its backups are encrypted at rest (AES-256) by our hosting provider.
- Platform credentials are encrypted with per-record keys that are in turn wrapped by a key-encryption key held outside the database — a software key today, Google Cloud KMS once that sub-processor is active (see the Data Processing Agreement's Annex 3); they are never written to logs.
- Connections use TLS; passwords are stored as one-way hashes; sign-in endpoints are rate-limited; email addresses are verified before first sign-in.
- Changes to important records are written to an append-only audit log.
- Backups are taken continuously and restores are rehearsed against a written checklist that includes an erasure check.
No system is perfectly secure. If we learn of a personal-data breach affecting you or a business we work for, we will act as the Data Processing Agreement and the law require: telling the affected business immediately and, where we are the controller, notifying the UAE Data Office and the affected individuals as the PDPL requires.
12. Your rights
The UAE Personal Data Protection Law (Federal Decree-Law No. 45 of 2021) applies to RATECARDS as a company established in the UAE, and, depending on where you are, the EU General Data Protection Regulation may apply as well. These laws give you rights over your personal data:
- to access the personal data we hold about you and receive a copy;
- to have inaccurate data corrected;
- to have your data erased, where it is no longer needed or you withdraw consent, subject to legal retention duties;
- to restrict or object to processing based on legitimate interests (GDPR);
- to receive data you gave us in a portable format;
- to withdraw consent where processing relies on it, without affecting earlier processing;
- to complain to a supervisory authority — in the UAE, the UAE Data Office; in the EU, the data-protection authority of your country.
To exercise a right, email support@ratecards.co from the address on your account, or from any address with enough detail for us to verify you. We answer within one month; if a request is complex we may take up to two more months and will tell you why. If your request concerns a review that a business mirrors, we will pass it to that business as its processor and help it respond, and we will tell you which business it is.
When we erase personal data we overwrite the personal fields in place and record the subject on an erasure list, so that a later restore from backup cannot bring the data back. Identifiers in the audit log are kept because they contain no personal details.
13. Children
The Service is for businesses and their staff and is not directed at anyone under 18. We do not knowingly collect account data from children; tell us if you believe we have and we will delete it.
14. Changes to this policy
We may update this policy as the Service changes. The version and dates at the top of this page show when it last changed; for material changes we will also email the owners of every workspace before the change takes effect.
15. Contact
RATECARDS L.L.C-FZ, Meydan Grandstand, 6th floor, Meydan Road, Nad Al Sheba, Dubai, United Arab Emirates. Email: support@ratecards.co.