Legal
Last updated 13 August 2026
You are trusting us with information about your restaurant, your team and your guests, so you deserve a clear account of what we hold, why we hold it, and who else touches it. This policy names every outside service we use rather than hiding them behind a general phrase.
On this page
Reviews to Revenue is operated by [Your registered company name], company number [Company number], registered at [Registered office address]. We are the data controller for the information described in this policy, except where you are the controller and we act for you, which is covered in our data processing addendum.
Write to us about anything in this policy at [your@email address].
| What for | Legal basis |
|---|---|
| Running your account and delivering the course and tools | Performance of our contract with you |
| Taking payment and preventing fraud | Performance of our contract, and our legitimate interest in being paid |
| Sending service emails, including floor notes digests and reminders | Performance of our contract |
| Support, and answering your questions | Performance of our contract |
| Improving the product and understanding how it is used | Our legitimate interest in building something that works |
| Marketing emails to people who are not yet members | Consent, or legitimate interest in business to business contact where the law allows it |
| Meeting our tax and accounting duties | Legal obligation |
The daily floor notes email is opt in, so you receive it only if you switch it on. The weekly one is on by default and you can turn it off from your account page at any time.
You can unsubscribe from marketing email at any point using the link in the message or by writing to us. Service emails about your own account carry on, because they are part of what you are paying for.
We keep the list of outside services deliberately short, and here is every one of them along with what it does and where it holds data.
| Service | What it does | Where |
|---|---|---|
| Supabase | Database, login and back end functions. This is where your data lives. | United States |
| Netlify | Serves the website and portal. | Global network |
| Stripe | Takes payments and manages subscriptions. | United States and Ireland |
| Resend | Sends and receives our email. | United States |
| Apify | Gathers public review and ranking data. | European Union |
| Vimeo | Hosts the course videos. | United States |
| YouTube | Hosts one introductory video shown after signup. | United States |
| OpenAI | Drafts review replies and helps read menus and floor notes. | United States |
| Anthropic | Drafts review replies and helps read menus and floor notes. | United States |
| Plausible | Website analytics on public pages only, never inside the portal. | European Union |
| Google Fonts | Serves the typefaces. Receives your IP address when a page loads. | United States |
We do not sell your data, and we do not pass it to advertisers. We share it only with the services above, with professional advisers such as our accountant where they need it, and with authorities where the law requires it.
If the business is ever sold or merged, your data may transfer to the buyer, who would be bound by this policy or something at least as protective.
Some features send your content to OpenAI or Anthropic to do their job. That includes drafting suggested replies to reviews, reading a menu you upload, and grouping floor notes into findings.
When that happens, the relevant content goes to the provider, is processed, and comes back. Both providers commit not to use business API content to train their models. We do not send them your payment details, your password, or your team's contact details.
Everything AI produces is a draft for you to check. Nothing is published to a review platform on your behalf without you approving it.
To show your rankings and reviews we collect what is already published publicly on TripAdvisor, Google and OpenTable about your venue. That includes review text, ratings, dates and the display name the reviewer chose to show.
We collect this because you have asked us to track your reputation, and our basis for it is our legitimate interest in delivering the service you signed up for. We use it only to show you your own reputation and to teach from it. Guest names are shown as the platform displays them and are never used for marketing.
This is the part worth reading carefully, because it involves other people rather than you.
Floor notes can record observations about service and about named team members, and the team tools hold manager names and email addresses. That information is about your staff, and you are the one who decides to collect it, so for that data you are the controller and we act on your instructions. The terms of that arrangement are in our data processing addendum.
What this means practically is that you should tell your team that observations are being logged and what they are used for. It is fairer, it is what data protection law expects, and in our experience it makes the notes better anyway, because people log honestly when nothing is hidden.
Ask us to delete something sooner and we will, unless we are legally required to keep it.
Several of the services above are based in the United States, so your data is transferred outside the United Kingdom and the European Economic Area. Those transfers are covered by the UK International Data Transfer Addendum and the European Commission's Standard Contractual Clauses, which are the safeguards the law provides for exactly this situation.
Depending on where you live you have rights over your personal data, and under UK and EU law those are to ask for a copy, to have mistakes corrected, to have data deleted, to restrict or object to how we use it, to receive it in a portable form, and to withdraw consent where consent is what we relied on.
Email [your@email address] to use any of these and we will respond within one month. There is no charge.
If you are unhappy with how we have handled it, you can complain to the Information Commissioner's Office at ico.org.uk, or to the data protection authority where you live. We would appreciate the chance to put it right first.
We use very few cookies, and none of them are for advertising.
The portal sets a cookie to keep you signed in, which is strictly necessary for the service to work at all. Your browser also stores small preferences such as whether you have dismissed a tip.
Our public pages use Plausible for analytics, which is cookieless, does not track people across sites, and collects no personal data. That is why you are not being asked to click through a cookie banner.
One introductory video after signup is embedded from YouTube, and YouTube may set its own cookies when that video loads. If you would rather it did not, do not play the video.
Data is encrypted in transit and at rest. Access to the database is controlled by row level security, which means the system itself enforces that each restaurant can only read its own data rather than relying on the interface to hide things. Administrative access is limited to those who need it.
No system is perfect. If a breach ever affects your data and creates a real risk to you, we will tell you and the regulator within 72 hours of finding out.
Write to [your@email address] or to [Your registered company name], [Registered office address].
We may update this policy. The date at the top always shows when it last changed, and if a change matters to you we will email rather than leaving you to notice.