Data and privacy

Your customers' data, barely touched.

We collect three things per order, keep them only as long as an invitation needs them, and delete them on a fixed schedule. Or send the invitation yourself and we never see your customer's email at all.

What we collect
Customer emailOnly to send one invitation and one reminder. Encrypted while held, deleted when the invite is used or expires, and never kept more than 45 days.
Order numberStored only as a one-way hash, so we can stop the same order being reviewed twice. Nobody, including us, can read it back.
Order dateTo time the invitation and check the order is recent.
What we never collect or doNames, addresses or phone numbersProducts, quantities or order totalsPayment details of any kindSelling or renting data, or using it for marketingSharing a vendor's customers with any other vendorKeeping wording our screen removed from a review or reply. It's deleted once the text is finalOpen or click tracking in invitation emails

If you BCC us on your order emails, we read the customer's address, the order number and the date from each email and discard the rest of it immediately. Names, addresses and products in those emails are never stored, and the email never goes to our AI screening provider.

Rather not share emails at all? Send the invite yourself.

Send us just the order number and date. We give you back a one-time review link, and you email it through your own store or email platform. The buyer confirms their own email when they open it. We never receive your customer list.

Available on every plan. The only trade-off: we can't send the reminder, so you'll get somewhat fewer reviews.

POST /api/v1/orders
{ "order_number": "10482", "order_date": "2026-09-14" }

→ { "results": [{ "order_number": "10482",
    "result": "link",
    "review_url": "https://ruoreviews.com/review/…" }] }

How long we keep it

Customer email (encrypted)Deleted when the invite is used, expires (30 days after sending) or is skipped. Hard limit: 45 days.
Order record (hashes and date)Deleted after 2 years.
Vendor's order data after they leaveDeleted 30 days after the subscription ends. Published reviews stay.
Email delivery log (hashed email)Deleted after 1 year.
Unsubscribes (hashed email)Kept, so we never email that person again.

These deadlines run automatically every 15 minutes. They're enforced by code, not by someone remembering.

Who handles it

Hosting provider (United States)Runs the site and the databaseSees: Everything we store
Network and security providerProtects the site and receives BCC order emailsSees: Website traffic, and BCC'd order emails in transit (not stored)
Email delivery providerDelivers invitation and sign-in emailsSees: Email address and the email we send
AI screening providerScreens review and reply wording for complianceSees: Review and reply text only. Never emails or order numbers
Encrypted emails

Customer emails are encrypted with a key kept outside the database. A database leak alone wouldn't expose them.

Hashed order numbers

Order numbers and unsubscribes are stored as one-way hashes that can't be turned back into the original.

You stay in control

Erase a customer's email and order details on request, download everything we hold for you, or revoke API keys, any time. Reviews are never affected.

Data processing terms

Version 1, October 2, 2026. Vendors accept these in their dashboard before sending us any orders.

  1. 1The vendor decides which customers' data is sent. RUO Reviews processes it only on the vendor's behalf, only to invite those customers to review their order, and only as described in these terms.
  2. 2We collect only an email address, order number and order date per order. We don't ask for or keep anything else.
  3. 3We keep data only for the periods in the retention table and delete it automatically after that.
  4. 4We never sell, rent or share a vendor's customer data, never use it for marketing, and never show it to other vendors.
  5. 5We use only the subprocessors named in the vendor dashboard's copy of these terms. We'll notify vendors by email at least 30 days before adding a new one.
  6. 6Customer emails are encrypted at rest with a key held separately from the database, order numbers are stored only as one-way hashes, and all traffic is encrypted in transit. Access to production systems is limited to RUO Reviews administrators.
  7. 7If we discover unauthorized access to a vendor's customer data, we'll notify the vendor within 72 hours with what we know.
  8. 8Vendors can delete any customer's data at any time from their dashboard, and can download everything we hold for them.
  9. 9When a vendor leaves, their order data is deleted within 30 days. Reviews that buyers published are the buyers' own and remain public.

Buyers: your review shows a handle, never your name or email. You can delete your reviews and stop all review emails at any time. Questions about data? Reply to any email from us. See also how verification works.