RATECARDS PROSign in

RATECARDS PRO

Privacy Policy

Version
0.1-draft
Status
Draft — not yet in force
Last updated
2026-09-08

This policy explains what personal data RATECARDS L.L.C-FZ collects when you use RATECARDS PRO, why, where it is processed, how long it is kept and what rights you have. It covers two situations: people who use the Service for a business, and reviewers whose public reviews the Service mirrors on that business's behalf.

1. Who we are

RATECARDS PRO is provided by RATECARDS L.L.C-FZ (Meydan Free Zone business licence 2305959.01), Meydan Grandstand, 6th floor, Meydan Road, Nad Al Sheba, Dubai, United Arab Emirates. Contact for anything in this policy: support@ratecards.co.

2. Two roles: when we decide, and when a business decides

  • You use the Service for a business (you sign in, manage locations, reply to reviews). For your account data we are the controller: we decide what we collect and why, and this policy applies directly to you.
  • You wrote a review on a platform such as Google Business Profile or Trustpilot, and a business that uses the Service mirrors that review into its workspace. For that data the business is the controller and we are its processor: we act on the business's instructions under a Data Processing Agreement. Requests about that data should go to the business; if you contact us instead, we will pass your request to the business and help it respond.

3. Data we collect from people who use the Service

DataWhat it containsWhere it comes from
Accountemail address, display name, whether the email is verified, and — only if Google sign-in is offered and you use it — the profile picture URL Google providesyou, or Google when you use Google sign-in
Sign-in credentialsfor password sign-in, a one-way hash of your password (never the password itself); for Google sign-in, the identifiers and tokens Google issues so we can confirm who you areyou / Google
Sessionsa session token, the IP address and browser (user-agent string) each session was created from, and timestampsyour browser, automatically
Verification and sign-in linksshort-lived tokens for email verification, password reset and emailed sign-in linksgenerated by the Service
Workspace membershipyour role in each workspace and which locations you may see; invitations you send or receive (invitee email and a hashed token)your workspace's owners and admins, and you
Activity recordsan append-only audit log of changes to important records. It stores record identifiers, the action, who did it and which fields changed — never the field values themselvesgenerated by the Service
Support messageswhat you send us by email and our repliesyou
Billing contactthe name, email address and company details of the person a business names for its invoicesthe business

We do not collect payment card data (fees are invoiced and paid by bank transfer), and the Service has no advertising or analytics trackers.

4. Data we process on a business's behalf

When a business connects a review platform to its workspace, the Service mirrors the reviews for its locations exactly as the platform makes them available: the platform's review identifier, the reviewer's platform identifier and display name, the review text, the rating, the language, the timestamps, and any reply. The Service also stores the replies the business publishes (with the workspace member who wrote them), earlier versions of a review when the platform reports an edit, the review's language and — when the AI features are enabled — a sentiment score and risk flags for each review, and, if the business uses AI drafting, each draft with its status.

The Service never asks a reviewer for anything and never contacts reviewers. A review that is removed on the platform is marked as removed in the workspace within the time the platform's rules require, is no longer shown or counted, and is deleted with the workspace. Where the Service mirrors Trustpilot content, it follows Trustpilot's content guidelines: new, changed and removed content is mirrored within 24 hours and a deletions sweep runs at least every 28 days. Tripadvisor content is not mirrored at all: the Service only links to a location's Tripadvisor page.

Touchpoints. A business can print QR codes or share short links that send its customers to a platform's review page. When you open one, our server checks the link and redirects you. We use your IP address in memory for a short time to limit abuse (120 requests per minute per address); we do not store the visit, set a cookie, or learn who you are.

5. Why we use personal data, and the legal basis

PurposeDataLegal basis
Providing the Service to a business and its users (accounts, sign-in, workspaces, feeds, replies)account, credentials, sessions, membership, review dataperformance of the contract with the business; for review data, the business's instructions as controller
Keeping accounts and the Service secure (verifying email, rate-limiting sign-in attempts, recording the IP address and browser each session was created from so a session can be investigated and ended, audit trail)credentials, sessions, verification tokens, activity records, IP addressesour legitimate interest in securing the Service and the business's legitimate interest in an accountable workspace (GDPR); under the UAE PDPL, performance of the contract with the business and our legal obligations
Drafting and classifying replies with an AI modelreview text, reviewer display name, location name, brand-voice settingsthe business's instructions as controller (the business chooses to use the feature)
Sending transactional email (verification, sign-in links, password reset, invitations)email addressperformance of the contract
Invoicing and accountingthe business's billing contact and invoicesperformance of the contract and our legal obligations (UAE tax law)
Responding to requests and enforcing our termssupport messages, account dataperformance of the contract; legal obligations; our legitimate interests (GDPR)

We do not sell personal data, use it for advertising, or make automated decisions with legal or similarly significant effects about individuals. AI drafts are suggestions that a person reviews before they are published, unless a workspace owner has chosen the risk-based mode described in the Terms.

6. AI processing

When the AI features are enabled for a workspace (they are not yet switched on), reply drafts and review classification use Claude models provided by Anthropic, called from our servers through Anthropic's commercial API. For each request we send the review text, the reviewer's display name as the platform shows it, the location's name, the business's brand-voice settings and our own instructions. Nothing else about the reviewer is sent.

  • Inference runs in Anthropic-operated regions, which include the United States; Anthropic's first-party API cannot be pinned to the EU.
  • Under Anthropic's commercial terms, content sent through the API is not used to train Anthropic's models. Anthropic deletes the inputs and outputs it holds within 30 days of receipt (longer only where its trust-and-safety systems flag the content or the law requires), and stores those copies in the United States — see the Data Processing Agreement.
  • We keep a record of each AI attempt with the review it relates to (model, draft, status and confidence) so the business can audit what was generated and what was published.

7. Who we share data with

We share personal data only with the service providers below (our sub-processors), with the platforms a business connects, and where the law requires. Each sub-processor is engaged under the data-processing terms linked in the Data Processing Agreement. The full list, with each provider's location and safeguards, is in the Data Processing Agreement and is kept current there. Our invoices are issued and stored in Zoho Books, which therefore holds the billing contact details a business gives us; Zoho is the same provider as the email service in the table.

ProviderWhat it does for usWhere
Renderhosts the application, background workers and the databaseFrankfurt, Germany (EU)
AnthropicAI model for reply drafts and review classification (planned — not yet enabled)Anthropic-operated regions including the United States
Zoho (ZeptoMail)sends our transactional emailsUnited States (Zoho's data centres for accounts registered on zoho.com)
Google Cloud (Cloud KMS)protects the encryption keys that guard platform credentials; it never receives personal data (planned — not yet in use)Google Cloud, EU key location
Grafana Cloudoperational monitoring and alerting (metrics, traces, error logs — not review content; planned — not yet connected)United States by default; Grafana Cloud offers an EU (Frankfurt) region, which we will choose if our plan allows — otherwise telemetry (identifiers and timings, no review content) is processed in the United States under Grafana's standard contractual clauses

Platforms (Google Business Profile, Trustpilot and, by link only, Tripadvisor) are independent controllers: review data flows between the business's platform account and its workspace under the platform's own terms and privacy policy. Google Sign-In, where a user chooses it, is governed by Google's privacy policy.

We may also disclose personal data to comply with a legal obligation or a lawful request from a public authority, to protect the rights and safety of any person, or to a successor of our business, in each case only to the extent necessary.

8. Where data is processed and international transfers

The Service and its database run in Frankfurt, Germany (European Union). RATECARDS L.L.C-FZ is established in the United Arab Emirates, and our staff access the Service from there. Some sub-processors process data outside the EU and the UAE, as listed above.

Where the GDPR applies to a transfer, we rely on the European Commission's Standard Contractual Clauses with the recipient, together with the recipient's own safeguards, as set out in the Data Processing Agreement. Where the UAE Personal Data Protection Law applies, transfers are made under the contractual safeguards that law allows. You can ask us at the address below for a copy of the safeguards in place for a particular transfer.

9. How long we keep data

DataRetention
Workspace membership and invitationsdeleted with the workspace 30 days after it is closed (the wind-down period in the Terms)
Account and credentialsfor as long as your account exists — an account can belong to several workspaces; once it belongs to none you can ask us to delete it
Sessionsa session lasts up to 7 days and is renewed while you keep using it; you can end it by signing out
Verification, reset and sign-in tokensminutes to hours (emailed sign-in links expire after 5 minutes)
Review data and replieswhile the workspace exists (syncing stops when a platform connection is removed); reviews removed on the platform are marked as removed and no longer shown or counted; everything is deleted with the workspace 30 days after it is closed
AI attemptswith the review they relate to; Anthropic's own copy of a request is deleted within 30 days
Application logs at our hosting provider7 days (they carry record identifiers and error classes, not review text)
Audit logfor the life of the workspace (it holds identifiers only, never personal details)
Backupspoint-in-time recovery data is kept for a rolling 3-day window (7 days on a larger hosting plan) and logical backups for 7 days, then overwritten; restored data is checked against an erasure list so erased data is not brought back
Invoices and accounting recordsas long as UAE tax law requires

10. How we protect data

  • Every workspace's data is isolated in the database with row-level security enforced by the database itself, and tested continuously. The database, its replicas and all its backups are encrypted at rest (AES-256) by our hosting provider.
  • Platform credentials are encrypted with per-record keys that are in turn wrapped by a key-encryption key held outside the database — a software key today, Google Cloud KMS once that sub-processor is active (see the Data Processing Agreement's Annex 3); they are never written to logs.
  • Connections use TLS; passwords are stored as one-way hashes; sign-in endpoints are rate-limited; email addresses are verified before first sign-in.
  • Changes to important records are written to an append-only audit log.
  • Backups are taken continuously and restores are rehearsed against a written checklist that includes an erasure check.

No system is perfectly secure. If we learn of a personal-data breach affecting you or a business we work for, we will act as the Data Processing Agreement and the law require: telling the affected business immediately and, where we are the controller, notifying the UAE Data Office and the affected individuals as the PDPL requires.

11. Cookies

The Service sets only the cookies it needs to keep you signed in. There are no advertising, analytics or third-party cookies, and fonts are served from our own servers.

CookiePurposeLifetime
__Secure-better-auth.session_tokenidentifies your signed-in session (HttpOnly, secure; named better-auth.session_token on a non-HTTPS host)up to 7 days, renewed while you use the Service
__Secure-better-auth.session_dataa short cached copy of your session so pages load without a database round-trip on every request60 seconds
__Secure-better-auth.dont_rememberset only if you choose not to be remembered; makes the session end when you close the browsersession
Google sign-in state cookiesprotect the sign-in redirect while you sign in with Googleminutes

Because none of these cookies is optional, there is no cookie banner; you can clear them at any time by signing out or through your browser.

12. Your rights

The UAE Personal Data Protection Law (Federal Decree-Law No. 45 of 2021) applies to RATECARDS as a company established in the UAE, and, depending on where you are, the EU General Data Protection Regulation may apply as well. These laws give you rights over your personal data:

  • to access the personal data we hold about you and receive a copy;
  • to have inaccurate data corrected;
  • to have your data erased, where it is no longer needed or you withdraw consent, subject to legal retention duties;
  • to restrict or object to processing based on legitimate interests (GDPR);
  • to receive data you gave us in a portable format;
  • to withdraw consent where processing relies on it, without affecting earlier processing;
  • to complain to a supervisory authority — in the UAE, the UAE Data Office; in the EU, the data-protection authority of your country.

To exercise a right, email support@ratecards.co from the address on your account, or from any address with enough detail for us to verify you. We answer within one month; if a request is complex we may take up to two more months and will tell you why. If your request concerns a review that a business mirrors, we will pass it to that business as its processor and help it respond, and we will tell you which business it is.

When we erase personal data we overwrite the personal fields in place and record the subject on an erasure list, so that a later restore from backup cannot bring the data back. Identifiers in the audit log are kept because they contain no personal details.

13. Children

The Service is for businesses and their staff and is not directed at anyone under 18. We do not knowingly collect account data from children; tell us if you believe we have and we will delete it.

14. Changes to this policy

We may update this policy as the Service changes. The version and dates at the top of this page show when it last changed; for material changes we will also email the owners of every workspace before the change takes effect.

15. Contact

RATECARDS L.L.C-FZ, Meydan Grandstand, 6th floor, Meydan Road, Nad Al Sheba, Dubai, United Arab Emirates. Email: support@ratecards.co.