BGR REVIEWBGR REVIEW
LoginSign up
Back to home
Privacy

Privacy Policy

This policy explains what data BGR Review collects, why we collect it, how we protect it, and the rights you have over it. This page is maintained by BGR Review to answer common privacy and data-handling questions about our services.

Last updated: November 15, 2025

At a glance

We do

  • Collect only what we need to deliver your orders.
  • Encrypt data in transit (TLS) and at rest.
  • Use Stripe for all payment card handling.
  • Honor access, correction and deletion requests.

We do not

  • Sell or rent your personal information.
  • Store full payment card numbers on our servers.
  • Send marketing emails without opt-in.
  • Share order details beyond what fulfillment requires.

Scope & controller

This policy applies to the BGR Review public website, client dashboard, team dashboard, checkout flow, transactional emails, and any related services (collectively, the "Services"). The data controller is BGR Review, with operating offices in New York (United States), London (United Kingdom), and Thornhill (Canada). Contact details are in the Contact section.

BGR Review acts as a controller for account, billing, marketing and website-analytics data, and as a processor for the specific order content (such as review links and target URLs) you submit for fulfillment.

Information we collect

Account information

Name, business name, email address, hashed password, phone number (optional), country, account role, notification preferences, and profile URLs you add to your account.

Order information

Selected package, target platform, review links, profile URLs, reviewer names you supply, replacement requests, delivery status, uploaded files, and free-text notes exchanged with our team.

Payment information

Card data is collected, tokenized and stored by Stripe, our PCI-DSS Level 1 payment processor. BGR Review receives only a payment token, card brand, last four digits, expiration month/year, country of the issuing bank, and the status of authorizations and charges. We do not store full card numbers or CVCs on our servers.

Communications

The content of messages you send us (support tickets, replacement requests, chat, email), plus metadata such as timestamps and delivery status.

Device & technical information

IP address, approximate location derived from IP, browser type and version, operating system, device type, referring URL, pages viewed, actions taken, and error logs. Web push notification subscriptions include an endpoint URL and cryptographic keys provided by your browser.

Cookies & similar technologies

See Cookies Policy for the complete list and controls.

Where we get it from

  • Directly from you - when you create an account, place an order, contact support, or update your profile.
  • Automatically - through cookies, log files, and analytics as you use the Services.
  • From our payment processor - Stripe returns payment status and card metadata after checkout.
  • From authentication providers - if you sign in with Google, we receive your email, name and profile picture.
  • From public sources - for removal orders, we may review publicly available information about the target review to verify eligibility.

How we use information

  • Create and secure your BGR Review account.
  • Deliver, verify, and support the orders you place.
  • Process payments, authorize saved cards, and prevent fraud.
  • Send transactional messages (order confirmation, delivery, replacement updates, notification alerts, password resets, support replies).
  • Send push notifications where you have granted browser permission.
  • Provide customer support and resolve disputes.
  • Detect, investigate and prevent abuse, chargeback fraud, and violations of our Terms.
  • Improve the Services, diagnose issues, and develop new features.
  • Comply with legal, tax, accounting, and regulatory obligations.
  • Enforce our agreements, including the Refund & Dispute Policy.

Where GDPR or UK GDPR applies, we rely on the following legal bases:

  • Contract - to create your account, fulfill orders, take payment, and provide support.
  • Legitimate interests - to secure the Services, prevent fraud and chargeback abuse, improve the product, and communicate about your account. We balance these interests against your rights and freedoms.
  • Consent - for optional cookies, marketing emails, and web push notifications. You can withdraw consent at any time.
  • Legal obligation - to comply with tax, accounting, anti-money-laundering and other laws.

Sharing & subprocessors

We do not sell or rent your personal information. We share limited data with vetted service providers acting as our processors, strictly to run the Services:

  • Stripe, Inc. - payment processing, card authorization, chargeback handling.
  • Cloud hosting & database provider - encrypted storage of account, order and log data.
  • Transactional email provider - sending order, account and support emails.
  • Push notification service - routing browser push messages via the Web Push protocol.
  • Product analytics - aggregate usage analytics for the website and dashboards.
  • Google (Sign-In) - where you choose to sign in with Google.
  • Fulfillment team members - internal agents with need-to-know access to complete your order.

We may also disclose information when we believe in good faith it is necessary to:

  • Comply with law, legal process, or a valid governmental request.
  • Enforce our Terms, including investigating potential violations or chargeback fraud.
  • Protect the rights, property, or safety of BGR Review, our users, or the public.
  • Complete a merger, acquisition, financing, or sale of assets, with appropriate confidentiality safeguards.

Payments & Stripe

All card payments are processed by Stripe. When you enter card details, they are submitted directly to Stripe from your browser and tokenized; BGR Review never sees or stores the raw card number or CVC.

For removal orders, you also authorize us to:

  • Place a small verification hold (typically $1.00) at order creation to confirm the payment method.
  • Store the tokenized card as a saved credential.
  • Charge the saved card on an off-session, merchant-initiated basis for each successfully removed review, per our Refund & Dispute Policy.

Stripe processes payment data as an independent controller for its own compliance and fraud purposes. See Stripe's privacy policy for details.

Cookies & tracking

We use strictly necessary cookies to keep you signed in and secure, functional cookies to remember preferences, and limited analytics to understand how the Services are used. You can control cookies through your browser and through the choices described in our Cookies Policy.

Marketing & communications

No marketing spam

We only email you about your account and orders unless you explicitly opt in to product updates or promotional broadcasts. You can unsubscribe from any optional email at any time using the link in the footer of the message or from your dashboard notification settings.

Transactional messages (order confirmation, delivery, replacement, refund status, password reset, security alerts, ticket replies) are required to operate the Services and cannot be opted out of while your account is active.

Security

We use a defense-in-depth approach that includes:

  • HTTPS/TLS 1.2+ encryption for all data in transit.
  • Encryption at rest for our managed database and file storage.
  • Row-level access control so users only see rows they are entitled to.
  • Scoped service roles for admin, team and client dashboards.
  • Hashed and salted password storage; industry-standard session tokens.
  • Audit logging of sensitive administrative actions.
  • Card data isolation via Stripe's PCI-DSS Level 1 environment.
  • Least-privilege access limited to team members who need it to deliver your order.

No online service can guarantee absolute security. You are responsible for keeping your account credentials confidential and for enabling any additional protections we make available.

Data retention

We keep personal information only for as long as we need it for the purposes described in this policy:

  • Account data - while your account is active, plus a reasonable period afterward for legal and audit purposes.
  • Order and delivery records - at least the duration of the 30-day replacement guarantee and any longer period required for accounting, tax, and chargeback representment.
  • Payment records and tax records - for the period required by applicable tax and financial-reporting laws (typically up to 7 years).
  • Support communications - up to 3 years after last contact.
  • Security and log data - typically up to 12 months for detection, investigation and audit.
  • Cookies - as described in the Cookies Policy.

When retention periods expire, we delete or irreversibly anonymize the data. Backups may contain data for a limited additional period before being overwritten.

Your rights

Depending on where you live, you have some or all of the following rights over your personal information:

  • Access - request a copy of the personal information we hold about you.
  • Correction - ask us to correct inaccurate or incomplete data.
  • Deletion - ask us to delete your account and personal information, subject to legal retention requirements.
  • Restriction - ask us to limit how we process your data in certain circumstances.
  • Objection - object to processing based on our legitimate interests, including profiling.
  • Portability - receive your data in a structured, machine-readable format.
  • Withdraw consent - where processing is based on consent, withdraw it at any time.
  • Complaint - lodge a complaint with your local data protection authority.

To exercise these rights, email team@bgrreview.com from the email address on your account. We may need to verify your identity before acting. We respond within 30 days, or sooner where required by law. Exercising these rights is free unless the request is manifestly unfounded or excessive.

US state privacy rights (California, and similar states)

If you are a California resident, you have the right to know what personal information we collect, to request access and deletion, to correct inaccurate information, and to opt out of the "sale" or "sharing" of personal information for cross-context behavioral advertising. BGR Review does not sell personal information and does not share it for cross-context behavioral advertising as those terms are defined by the CCPA/CPRA.

Similar rights are available to residents of Colorado, Connecticut, Virginia, Utah, and other states with comprehensive privacy laws. To exercise them, email team@bgrreview.com. You may designate an authorized agent to submit a request on your behalf; we may require verification. We will not discriminate against you for exercising any of these rights.

International transfers

BGR Review operates in the United States, United Kingdom, and Canada, and we use service providers located in these and other jurisdictions. When we transfer personal information across borders, we rely on lawful transfer mechanisms such as the European Commission's Standard Contractual Clauses, the UK International Data Transfer Addendum, adequacy decisions where available, or your explicit consent.

Children

Our Services are intended for businesses and adults. We do not knowingly collect personal information from anyone under 16. If you believe a child has provided us with personal information, contact us and we will delete it.

Automated decisions

We use automated systems to detect fraud, abuse, and chargeback risk, and to route work to fulfillment agents. These systems do not make decisions that produce legal or similarly significant effects on you without meaningful human review. You may request human review of any automated decision that affects your account by contacting support.

Third-party sites & review platforms

The Services may link to third-party websites (including the review platforms we service). Those sites operate under their own privacy policies, and BGR Review is not responsible for their practices. We recommend you review their policies before providing personal information.

Breach notification

In the unlikely event of a personal-data breach that is likely to result in a risk to your rights and freedoms, we will notify affected users and the relevant supervisory authorities within the timeframes required by applicable law (for example, without undue delay and, where feasible, within 72 hours under GDPR/UK GDPR).

Changes to this policy

We may update this policy from time to time. The version in force when you use the Services governs that use. Material changes will be posted on this page with a new "Last updated" date and, where appropriate, notified to you by email or in-app notice.

Contact & complaints

Privacy questions, data requests, or complaints: team@bgrreview.com · US +1 561 461 0399 · UK +44 7761 248539. Offices in New York, London, and Thornhill.

UK/EU residents have the right to lodge a complaint with their local data protection authority (in the UK, the Information Commissioner's Office at ico.org.uk). Canadian residents may contact the Office of the Privacy Commissioner of Canada at priv.gc.ca.