Privacy Policy
Last updated: 30/05/2026
This Privacy Policy explains how Reviso (“we”, “us”) collects, uses, and protects information in connection with the getreviso.io website (“Site”) and the Reviso for Bricks plugin (“Plugin”). By using the Site or Plugin you agree to this Policy.
1. Two data contexts
Our role differs depending on context:
- Our website & sales (we are the controller). When you visit getreviso.io, sign up, purchase, or contact support, we control that data.
- The Plugin on your WordPress site (you are the controller). Comments, reviewer names, reviewer emails, screenshots, and attachments created through the Plugin are stored in your own WordPress database on your own hosting. We do not receive or store that data on our servers in normal operation. As the site operator, you are the controller of it and are responsible for your own privacy compliance and for obtaining any consents from your reviewers. We are a tool provider; where we process such data on your behalf (e.g. support access or optional AI features) we act as your processor.
2. Information we collect (Site & sales)
- Account & contact data — name, email, company, and details you submit via forms, support, or feedback.
- Billing data — processed by our payment provider, Lemon Squeezy (Merchant of Record). We receive limited order/license metadata, not full card details.
- Pro trial data — if you start a free trial of the Pro add-on, the email address you provide. We use it to operate and protect the trial (including a one-trial-per-email check) and, with your consent, to send occasional product updates. For the abuse check it is stored as a one-way hash; the plain-text address is held only on our conversion list with our email provider (see Section 6). We also store a one-way hashed, non-identifying site identifier — we do not receive your site’s URL.
- Usage & device data — IP address, browser, pages viewed, and analytics events on the Site.
- Support communications — the content of messages you send us.
- Free trial emails — When you start a Reviso Pro free trial, we collect the email address you provide. We use it to operate your trial (activation, expiry) and to send you a short series of onboarding emails about using Reviso during and shortly after your trial, which you can unsubscribe from at any time via the link in any email. Trial emails are stored on our own server for up to 365 days and are shared with MailerLite (our email service provider) solely to deliver these emails. We never sell or share your address for any other purpose. To have your address removed entirely, email ben@getreviso.io.
3. Information the Plugin handles (on your site)
- Reviewer name and email entered in review mode (or, for logged-in WordPress users, their account name and email);
- Comment text, replies, screenshots, and file attachments;
- Page/element metadata (which element a comment is anchored to, position, screenshot annotations, and review round);
- Technical context captured with a comment — the reviewer’s browser, operating system, viewport/breakpoint, page URL, and any JavaScript errors present on the page, to help reproduce reported issues;
- Approval records — when a reviewer marks a page as approved, the Plugin stores their name, email, the page, a timestamp, and the reviewer’s IP address and browser user-agent as evidence of the approval;
- A review-session cookie (
reviso_reviewing) so a reviewer can act within a review session.
This data stays on your infrastructure unless you enable a feature that sends it elsewhere — for example AI audits (Section 9), notifications/integrations (Section 9a), or the optional anonymous diagnostics (Section 9b).
4. How we use information
- Provide, operate, secure, and improve the Site and Plugin;
- Process purchases, deliver license keys, and provide updates and support;
- Operate and protect free trials of the Pro add-on, including preventing repeat or abusive trials;
- Send transactional messages (receipts, license, security/update notices);
- With consent where required, send product and marketing emails (opt out anytime);
- Comply with legal, tax, and accounting obligations.
5. Legal bases (EEA/UK users)
We rely on performance of a contract, legitimate interests (securing and improving our products, basic analytics, preventing trial abuse), consent (marketing, non-essential cookies), and legal obligation (tax/accounting).
6. Sharing & subprocessors
We do not sell personal data. We share data with service providers under appropriate agreements, including:
- Lemon Squeezy — payments, licensing, invoicing;
- ActiveCampaign Postmark — transactional and marketing email;
- Vultr — Site hosting;
- Google Analytics — Site analytics;
- Anthropic, OpenAI — only if you enable AI audit features (Section 9).
7. Cookies
On the Site: essential cookies plus, with consent where required, analytics cookies. In the Plugin: the reviso_reviewing session cookie is strictly necessary to run a review session. You can control cookies via your browser; blocking essential cookies may break functionality.
8. Data retention
Sales/account data is retained for the life of your account and as required by law. Trial email records are kept while relevant to operating the trial programme and, for marketing, until you unsubscribe or request deletion. Plugin data is retained in your database under your control; you decide retention and deletion.
9. AI features & data processing (when enabled)
If you enable optional AI audit features, the Plugin may transmit page content and comment text to a third-party AI provider (Anthropic, OpenAI) using your own API key to generate results. For that processing we act as your processor and the AI provider as a subprocessor. A Data Processing Agreement is available on request at ben@getreviso.io. Do not enable these features for content you are not permitted to share.
9a. Notifications & integrations (when enabled)
By default the Plugin sends email notifications (and optional weekly digests) about new comments and approvals to the address you configure. If you connect an integration (Slack, Discord, or a generic/Zapier-style webhook), the Plugin sends comment and approval data to that destination you choose and control. You decide whether reviewer email addresses are included in webhook payloads (off by default for privacy). These destinations are third parties controlled by you, not our subprocessors, and you are responsible for your use of them. A per-site toggle lets you disable outbound notification emails entirely for GDPR/data-minimisation purposes.
9b. Anonymous usage diagnostics (when enabled)
The free Plugin can send optional, opt-in anonymous diagnostics to us — plugin/WordPress/PHP/Bricks versions, locale, timezone, license tier, which features are enabled, and bucketed comment counts — with a random install ID so we can de-duplicate. This is off by default, contains no site URL, comment content, reviewer details, or other personal data, and can be turned off at any time in the Plugin settings.
10. Security
We use reasonable technical and organizational measures to protect data we control. No method is 100% secure. You are responsible for securing your own WordPress installation, hosting, and review links.
11. International transfers
Data may be processed in countries other than yours, including by our providers. Where required, transfers are protected by appropriate safeguards (e.g. Standard Contractual Clauses).
12. Your rights
Depending on your location (e.g. GDPR/UK GDPR, CCPA/CPRA), you may have rights to access, correct, delete, port, or object to processing, and to withdraw consent. For data we control, contact ben@getreviso.io. For data held in a customer’s WordPress site, contact that site’s operator.
13. Children
The Site and Plugin are not directed to children under 16, and we do not knowingly collect their data.
14. Changes
We may update this Policy. Material changes will be posted here with a new “Last updated” date, and where the change materially affects how we handle personal data we control, we will make reasonable efforts to notify registered customers by email before the change takes effect.
15. Contact
Reviso, 182 Vivian Street, Wellington, New Zealand
Email: ben@getreviso.io