RatingMinder/Privacy

Privacy policy What we collect, why we use it, and how to ask for deletion.

Reviewed by Doug Baker, founder · Updated September 24, 2026

The short version. There is no email wall in front of the answer: the free check asks for the business, not for you. We store the reviews rated 2 stars or below and our assessment of the ones we can assess; reviews above 2 stars are counted, and only their identifiers are kept so Monitoring can tell a new review from an old one; their text and reviewer details are never stored. We ask for your email only when you ask to be emailed something, or at checkout, where it becomes your account. Stripe handles payment. Your card is entered on Stripe's own page and never reaches our systems. Our analytics run through our own domain, with page addresses scrubbed before they leave your browser. We don't sell data and we don't build advertising audiences.

1. Who we are and what this covers

RatingMinder is operated by The Leads Foundry LLC, a Minnesota limited liability company, at 14040 Delwood Dr, Elbert, CO 80106. This policy covers ratingminder.com, the free check, paid cases, Monitoring, and the emails we send. Effective 2026-09-24.

2. What we collect and when

The free check. You type a business name and city and Google Places autocomplete suggests matches, or you paste a Google Maps URL. From the profile you confirm, we keep the facts shown on the confirm card: name, address, rating, review count, and Google's identifier for that place. Our review-data provider then retrieves the profile's reviews. We store every review rated 2 stars or below: the review text, its rating and date, the reviewer's display name, the reviewer's review count and profile link, and any owner reply. Rating-only reviews at 2 stars or below, meaning no text or fewer than ten characters of it, are stored the same way, and they are counted rather than assessed, because there is nothing to read. Reviews above 2 stars are counted, and only their identifiers are kept so Monitoring can tell a new review from an old one; their text and reviewer details are never stored. We also store the assessment we produce for each review we assess: the tier, the policy it may fall under, its category, a confidence level, its class, our reasoning, and the evidence a case would need.

Anyone can run the check on any business. The reviews are public. A check run on a profile within 24 hours of a completed one returns that same result instead of fetching again.

Your email. We ask for it only if you want a result or a reply playbook emailed to you, or at checkout. The email you use at checkout is your account. You sign in with Google, with a password, or with a code we email to that address.

Purchases and cases. Stripe processes payment. Your card is entered on Stripe's own page and never reaches our systems; we receive confirmation of the charge Pending · operator fact Stripe identifiers stored on case and subscription records. Your statement reads RATINGMINDER. For each case we hold the case packet, the filings you confirm to us, and the Case ID you save from Google's appeal form. At purchase we freeze an evidence snapshot: a copy of the review, the reviewer fields, and the profile facts as they stood that day. Screenshots stay with you; we don't upload them Pending · operator fact Confirmation that no screenshot upload exists.

Monitoring. If you subscribe, we check your reviews daily and analyze new negative reviews when we find them. We store the record of each daily check, each new negative review and its assessment, and your digest history.

Technical data. We keep a hashed form of your IP address (SHA-256) to limit how many checks one connection can run per day. Raw IP addresses are never stored. Pending · operator fact Vendor IP-log retention (hosting and analytics) Our analytics collect device and browser data, described in section 5.

3. Why we use it

  • To run the check: fetch, store, and assess the negative reviews on the profile you confirmed.
  • To build and track your case: the packet, the evidence snapshot, your filing confirmations, and the Case ID.
  • To email you what you asked for: a result, a playbook, case reminders, outcome notices, and monitoring digests.
  • To bill you, and to refund you when the guarantee applies. The guarantee covers the appeal fee only, never subscriptions. Terms on the guarantee page.
  • To keep the free check free: a limit of three checks per connection per day, by hashed IP, and a daily capacity cap.
  • To see how the site is used and fix what breaks, through the analytics in section 5.

We don't sell personal data. We don't build advertising audiences. We don't share reviewer data with anyone beyond the processors needed to prepare your appeal.

4. Who processes it for us

Each name links to that company's own privacy policy.

  • Convex. Our database and backend. The scans, reviews, assessments, cases, and evidence snapshots in section 2 are stored here.
  • Vercel. Hosts the website.
  • Clerk. Sign-in. Holds your account email, your password if you set one, and the link to your Google account if you sign in with Google. It also issues your sign-in session and emails your sign-in and password-reset codes.
  • Stripe. Payment and subscription billing, and the billing portal where you manage your card and invoices.
  • Resend. Delivers every email we send you, including the ones that quote your review text.
  • DataForSEO. Our review-data provider. Receives the business identifier and returns the reviews.
  • Google Places Autocomplete. The business-name typeahead. What you type in the search box goes to Google to produce suggestions. Reviews never come from Google's APIs.
  • OpenRouter. Our language-model provider. To produce the policy assessment, we send a language model, through OpenRouter, the business's name, rating and review count, and for each review we assess: the review text (its first 1,200 characters), the star rating and date, the reviewer's display name and review count, and the owner's reply (its first 200 characters). The reviewer's profile link is not sent, and neither is your email or any account data. OpenRouter's published terms (2026) state that it does not use the text to train models and that it passes the text to the model's provider, Google. Google's terms for paid API use (2026) state that it does not use the text to improve its products and that it keeps a log for a limited period, only to detect abuse. Google's Gemini API terms.
  • PostHog. Analytics, session replay, and feature flags, described next.
Pending · operator factData-processing terms and hosting regions for each vendor

5. Analytics, session replay, and cookies

We use PostHog to see which pages get used and where the product breaks. That includes session replay: a replay of the pages you saw and what you clicked, including the results shown to you. Before anything leaves your browser, page addresses and referrers are scrubbed to an allow-list of query keys (intent, source, src, and utm_ parameters); the query string is reduced to those keys and the fragment is dropped; the page path itself, including your scan's identifier, is sent as-is. Replay recordings, console output, and error reports get the same scrub, which covers addresses, links, and logged text rather than the page content a recording reproduces. Analytics traffic goes through our own domain, and each request is rebuilt without your cookies, the referring page, or any authorization header before it reaches PostHog. We use PostHog feature flags to switch parts of the product on and off. A browser that sends the Global Privacy Control signal is treated as declined unless analytics are turned back on here.

Cookies, in plain words:

  • Sign-in cookies, set by Clerk. A short-lived session token (__session), a timestamp (__client_uat), a refresh token (__refresh_ plus a suffix), and three handshake cookies used during sign-in (__clerk_handshake, __clerk_handshake_nonce, __clerk_redirect_count). Clerk's long-lived __client cookie is set on Clerk's own domain and never reaches ratingminder.com. On our development and preview instances only, Clerk adds one more, __clerk_db_jwt.
  • Analytics cookies, set by PostHog. Names begin with ph_ or __ph_.
  • One cookie of our own. Set only on the monitoring cancel page and readable only by that page, so your cancel token never ends up in the address of a page you are looking at, where analytics and referrers would pick it up.
  • On preview deployments only, a Vercel deployment-protection cookie.

No third-party advertising cookies. Stripe's checkout runs on Stripe's pages under Stripe's own policy.

6. How long we keep it

  • Free-check results, the reviews stored with them, and their assessments: 12 months after the last check on that profile, then deleted, unless a review is attached to a case.
  • Case records, including the evidence snapshot, the packet, your filing confirmations, and the Case ID: for the life of the case and 3 years after it closes, then deleted. Billing records: 7 years.
  • Your email address: for as long as you hold an account or have an open request with us, then deleted, or sooner if you ask.
  • Monitoring records, alerts, and digest history: for the life of the subscription and 12 months after it ends, then deleted.
  • Session replays: kept 30 days, then deleted. Analytics events: 12 months, then deleted.

A deletion request overrides every period above except the billing records we are required to keep.

One rule is already fixed. The evidence snapshot frozen at purchase is kept unchanged for the life of the case. Google can remove parts of a reviewer's profile or restrict the account. The snapshot keeps the record your filing rests on.

7. Your choices and rights

  • You can run the check without giving us an email. The verdict is on the page.
  • You can cancel Monitoring from your dashboard. Month-to-month; we don't do retention calls.
  • You can manage your card and invoices in the Stripe billing portal from your dashboard.
  • You can ask what we hold about you or your business, or ask for deletion, by emailing support@ratingminder.com. We answer within one business day.
  • You can turn off analytics and session replay in this browser. A browser that sends the Global Privacy Control signal is treated as declined without it.
Pending · operator factAttorney review: CCPA and state privacy rights, including a do-not-sell-or-share statement and request verification

8. If you wrote a review

If you left a review on a business whose owner ran it through RatingMinder, we hold the public content of that review as it appeared on Google, the public reviewer fields shown beside it, and our assessment of whether it has a basis for challenge under Google's policies. That assessment is produced by a language model reading the review against Google's written policies. That assessment is about policy basis, not about you. We submit nothing to Google; the owner files, and Google decides. To ask what we hold or request deletion, email support@ratingminder.com. We won't tell you anything about the business's case. A snapshot attached to an open case is kept for the life of that case (section 6).

9. Children, security, transfers, changes, contact

Children. RatingMinder is a tool for business owners and isn't directed at children. Pending · operator fact Attorney review: children's privacy age threshold and statement

Security. Data moves over encrypted connections. IP addresses are stored only as hashes. Our own cookie is HttpOnly and scoped to the single page that reads it. Clerk's session cookie is not HttpOnly, by Clerk's design, because Clerk's own browser code reads it. Pending · operator fact Encryption-at-rest or access-control statement

International transfers. Pending · operator fact Attorney review: international transfers clause

Changes. When this policy changes, we update the date at the top and email account holders about material changes.

Contact. support@ratingminder.com, or through our contact page.

RatingMinder