Privacy Policy

Last Updated: September 18, 2026

Review Mechanic (operated by Bankat Technologies) is committed to data transparency, user security, strict adherence to Google API Services User Data Policies, and global data privacy standards (GDPR / CCPA).

Data We Collect & Access

1. Google OAuth & Identity Credentials

We use Google OAuth for secure merchant sign-in with basic identity scopes (openid email profile). Authorized OAuth access and refresh tokens are encrypted in our database (account_credentials) solely to maintain active sessions and interact with authorized Google APIs on your behalf. We strictly do not request, store, or log customer Google passwords or sensitive private keys.

2. Google Business Profile & Places Data

When authorized (https://www.googleapis.com/auth/business.manage), Review Mechanic accesses authorized location identifiers, public review comments, reviewer display names, star ratings, and review timestamps. This data is accessed solely to display incoming reviews within your dashboard and assist you in drafting responses. We do not modify business profile metadata without your explicit action.

3. Merchant-Initiated Feedback Invitations

We store business profile details and recipient contact details provided directly by the merchant solely to deliver feedback invitations via SMS or WhatsApp. Invitations are dispatched on-demand by the merchant, preventing unsolicited spam or background message blasting. Shortlinks (/r/:shortCode) track link open metrics without tracking personal user browsing histories.

4. Payment & Billing Processing

All multi-currency subscription checkouts (USD and INR) are processed directly by our Merchant of Record, Lemon Squeezy. Review Mechanic only retains customer email references, subscription identifiers, and billing plan status; we never capture, process, or store raw credit card numbers or CVVs.

5. Anti-Abuse SHA-256 Trial Ledger

To prevent trial abuse while protecting merchant privacy, we store one-way cryptographic SHA-256 hashes of Google Place IDs and merchant identifiers in a dedicated ledger (trial_registry). Raw personal data cannot be reverse-engineered from these hashes.

6. POS & Invoicing Webhook Ingestion (Optional Automation)

When merchants optionally connect payment gateways (Stripe, Square, Shopify, or Clover), Review Mechanic ingests completed transaction notifications via read-only webhooks. Ingested data is strictly limited to customer contact info (name, phone, email), order total, and transaction timestamps (pos_transactions) solely to facilitate review invitations. We never access, transmit, or store credit card numbers, CVVs, or financial credentials.

Google API User Data Policy Compliance & AI Use

Review Mechanic's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements:

  • No General AI/ML Model Training: Data obtained through Google APIs is never used to train, retrain, or fine-tune generalized artificial intelligence (AI) or machine learning (ML) models. AI review reply suggestions are generated transiently per user session.
  • No Third-Party Advertising: We do not sell, rent, or transfer Google user data to data brokers, advertising networks, or third-party marketplaces.
  • Limited Human Access: Human employees or contractors do not read your Google user data unless you provide explicit consent to investigate a specific technical support issue, or where required by law.

POS & Invoicing Integrations (Stripe, Square, Shopify, Clover)

Review Mechanic offers optional integrations with point-of-sale (POS) and invoicing platforms to automate customer review invitations. We adhere to strict data minimization principles:

  • Zero Financial Access: Review Mechanic is not a payment gateway. We never process, store, intercept, or request card numbers (PAN), CVVs, expiration dates, PINs, or banking passwords.
  • Read-Only Webhooks: Integrations rely solely on event postbacks (payment_intent.succeeded, orders/paid, payment.updated). Our systems have zero authorization to initiate charges, issue refunds, or modify customer invoices.
  • Purpose-Bound Use: Customer names and phone numbers ingested through POS checkouts are used exclusively to prepare 1-tap review invitations. Ingested contact data is never shared with third parties, sold, or used for behavioral advertising.
  • Merchant Ownership & Purge: Merchants can disconnect POS gateways or purge ingested transaction feeds at any time directly from the dashboard.

Anti-Gating Policy

Review Mechanic strictly forbids and prevents review gating. Customer landing pages present unfiltered, simultaneous choices to leave a public Google review or contact management directly. We do not filter customers by prior sentiment.

Security & Encryption

All network transmissions enforce TLS 1.3 encryption in transit. Databases utilize industry-standard encryption at rest and strict Row-Level Security (RLS) policies, guaranteeing that each business tenant can only access its own authorized records.

GDPR Article 17 (Right to Erasure)

Every merchant maintains full sovereignty over their data. You can trigger an atomic, permanent cascade deletion of your entire account—including Google credentials, connected business profiles, review logs, message templates, and audit logs—directly from your settings panel at any time.

Contact Support & Data Inquiries

For privacy inquiries, manual data deletion requests, or questions regarding Google API compliance, contact us at: bankattechnologies@gmail.com.