Skip to main content

Privacy Policy

Last updated: July 27, 2026

Ghost Reviews ("we," "us," or "our") is the operating name of Devon Abernethy, a sole proprietor based in Ontario, Canada. We help businesses screen public Google reviews for unusual patterns and, when separately authorized, prepare and file policy-violation reports. This policy explains the information we handle when you visit the site, request a report, create an account, communicate with us, or become a client.

1. Information we collect

  • Information you provide. This may include your name, business email, phone number, messages, Google Business Profile URL or business name, and the email address used for passwordless sign-in. A new evidence- report request uses that verified account address rather than accepting a separate recipient typed into the request form.
  • Public business and review data. We may retrieve public business-profile details and, for a review, its public display name or account identifier, rating, date, text, direct link, and public account-activity count. We use only the fields needed to screen patterns, prepare evidence, or carry out an authorized filing. A public source does not make this information non-personal, so the limits below still apply.
  • Account and service records. For account holders and clients, we may store scan history, report requests, the exact service terms and consent accepted, consent time and technical evidence, Manager-access status, filing drafts and approvals, submissions, removal evidence, billing notices, charges, refunds, and support communications.
  • Scanner security data. We record the requesting IP address in a server-only rate-limit ledger to prevent automated abuse. Those IP records are deleted after 30 days by a scheduled cleanup, with a request-time cleanup backstop. Hosting providers may also keep short-lived security logs under their own retention practices.
  • Anonymous scan handling. An anonymous visitor's scan result is not saved to an account and the anonymous request does not create a stored scan report. To avoid repeating provider calls, the scanner may reuse a reviewer-detail-free business aggregate that was generated by an authenticated or administrative scan. It is served for no more than 24 hours and deleted after 24 hours.
  • Payment information. Stripe collects card details on its hosted page. We do not see or store your full card number. We retain Stripe customer and payment-method identifiers, card-on-file status, invoice or payment references, amounts, and refund status so we can operate and audit billing.
  • Outreach and opt-out records. For business outreach, we may record a publicly listed business contact, the source and relevance basis for contacting it, messages sent, replies, and suppression records. We keep an opt-out record so the address is not contacted again.

2. How we use information

  • Provide scans, accounts, and support. Before delivering an evidence report with reviewer names, full text, or account history, we separately confirm and record that the requester owns the business or is authorized to represent it. A verified email address alone is not enough.
  • Deliver authorized Manager and filing services, including recording per-filing approval and outcomes.
  • Compare text-free, keyed review and reviewer patterns across businesses to identify repeat activity worth human review. A pattern is a lead, not an identity finding or accusation.
  • Save a card through Stripe, send pre-charge notices, process authorized payments, provide hosted invoices and confirmations, and issue refunds.
  • Secure the service, limit abuse, and troubleshoot failures.
  • Respond to inquiries and send service communications or lawful business outreach, while enforcing opt-outs.
  • Meet legal, accounting, and dispute-resolution obligations.

3. Providers and disclosures

We do not sell personal information. We use service providers only as needed to operate Ghost Reviews:

  • Outscraper — retrieves public Google review data.
  • Anthropic — assists the operator with deeper review-content analysis for requested evidence reports. Candidate packets use ordinal labels instead of reviewer names, omit direct reviewer links, and limit excerpts; the preliminary heuristic scan itself does not use an AI model.
  • Google — provides public profile data and the official Manager and review-reporting systems used for authorized client work. Google Workspace, including restricted-access Docs and email, may hold working reports and service communications.
  • Supabase — database and passwordless authentication.
  • Cloudflare — supplies the Turnstile security check on account sign-in and may process browser and network signals needed to distinguish people from automated abuse.
  • Vercel — website hosting and infrastructure.
  • Stripe — hosted card setup, payments, hosted invoices, and refunds.
  • Resend — filing approvals, billing notices and confirmations, request alerts, and other transactional or requested service email. It is not used for cold outreach.
  • Twilio — business phone routing and voicemail when you call our published number.

Providers may process data in Canada, the United States, or other locations in which they operate. We may disclose information to the business whose reviews were analyzed, to an authorized client, or to Google when a client approves a filing. We may also disclose information when required by law, to enforce our terms, or to protect users, the public, or the service.

4. Card-on-file and billing records

The onboarding card step uses Stripe's hosted form. No payment is taken during card setup. If you authorize done-for-you filing, the saved payment method may later be used off-session only under the agreed success-fee terms. We send a notice with the review, evidence, and amount at least 24 hours before a charge. An objection or revocation pauses billing while it is reviewed. See our Terms of Service for the full payment rules.

5. Retention

  • Reviewer-detail-free business aggregates used by the scanner are reusable for no more than 24 hours and deleted after 24 hours.
  • Scanner rate-limit IP records are deleted after 30 days.
  • Candidate verification packets, review excerpts, and flagged review metadata are assigned a deletion date 14 days after the prospect scan. Database evidence is cleared by an automated retention job. We do not create governed local research copies unless the daily deletion task is enabled and verified. A missed or failed retention run is treated as a privacy incident. Reviewer names, raw account identifiers, raw review identifiers, and direct links are not stored in the prospect flag record.
  • Text-free prospect scoring series, aggregate prospect scans, and keyed review or reviewer pattern records are deleted no later than 12 months after capture. Keyed values are pseudonyms—not anonymous data—and remain protected accordingly.
  • Account data and saved scans remain while the account is active, unless deletion is requested or a longer period is required.
  • Report-request intake records and working copies of filled evidence reports stored in systems we control are reviewed monthly and deleted no later than 12 months after report delivery or the last related service communication, unless they become part of a client, outreach-consent, dispute, or other legally required record described below. This includes historical requests received before verified-account intake. This does not remove a copy already delivered to the recipient, and service-provider backups expire on the provider's own backup schedule.
  • Client consent, approvals, billing, refund, and transaction records are retained as reasonably necessary for accounting, legal compliance, fraud prevention, and dispute resolution.
  • Cold-outreach message, consent-evidence, and delivery records may be retained for up to seven years after the last outreach attempt, then deleted unless a longer period is legally required for a dispute, investigation, or preservation obligation.
  • Suppression records may be kept indefinitely because deleting them could cause us to contact someone who opted out.

6. Security

We use HTTPS, access controls, row-level database security, server-side secrets, restricted administrative access, signed Stripe webhooks, and billing audit records. No system is perfectly secure, but we use reasonable safeguards appropriate to the information and the service.

7. Your choices and rights

You may ask to access or correct personal information, delete an account, withdraw optional communications consent, revoke our service authorization, or raise a privacy concern. Some records may be retained when legally required or needed to document a transaction, opt-out, or dispute. Every outreach email includes a direct opt-out; we suppress those requests promptly and no later than the legally required period.

This includes a reviewer who reasonably believes our records refer to them. We verify requests proportionately, acknowledge them, and normally respond within 30 days, subject to lawful extensions or exceptions. If you make a complaint, our Privacy Officer will investigate and explain the outcome and any corrective action.

8. Cookies and local browser storage

We use essential cookies for passwordless authentication and security. If you choose to unlock a scan or verify an evidence-report request by signing in, we keep only that public Google Business Profile URL in your browser for up to two hours so the one-time sign-in link can return to the matching scan or finish the verified request. The anonymous report, reviewer-level result, and email address are not placed in this browser handoff, and the pending URL is removed when used or when it expires. We do not use third-party advertising cookies or sell browsing profiles.

9. Children

Ghost Reviews is a business service and is not directed to children. We do not knowingly collect personal information from anyone under 16.

10. Canadian privacy law

We operate from Ontario and handle personal information in line with the Personal Information Protection and Electronic Documents Act (PIPEDA) where it applies. Information may be subject to lawful access rules in a provider's processing jurisdiction.

11. Changes

We may update this policy as the service changes. We will revise the date above and provide additional notice where a material change requires it.

12. Contact

Privacy questions or requests can be sent to:

Ghost Reviews
Devon Abernethy, Privacy Officer
Suite 1022, 1737 Richmond Street Unit #9, London, ON N5X 3Y2, Canada
devon@ghostreviews.app
(548) 800-0156

If we do not resolve a privacy concern, you may contact the Office of the Privacy Commissioner of Canada.