Privacy Policy
BrandTrust.reviews — operated by Brand Lew LLC
Last updated: August 14, 2026
1. Who We Are
BrandTrust.reviews is a review-display service operated by Brand Lew LLC ("BrandTrust," "we," "us," "our"), a limited liability company based in Tempe, Arizona, USA.
We provide a platform that lets a business connect its own accounts on third-party review platforms and display its existing reviews on its website through embeddable widgets and a WordPress plugin (the "Services"). BrandTrust is primarily an aggregator and display tool — the reviews we show are retrieved from the third-party platforms described below. We do not solicit or publish new reviews from the public on our platform.
Contact: Brand Lew LLC, 1110 W Elliot Rd #1049. Tempe, AZ 85284. United States.
2. Who This Policy Covers
This Policy applies to four groups:
- Business customers — account holders who subscribe to BrandTrust and connect their review-platform accounts.
- Team members — additional users an account owner invites to help manage the account, each with their own login and role-based access.
- Reviewers — individuals whose reviews (originally posted on Google, Facebook, Etsy, eBay, or a business's WooCommerce store) are retrieved and displayed through our Services.
- Site visitors — people who view a page on a business's website where a BrandTrust widget or plugin is displayed.
3. What We Do and How Reviews Flow
A business customer connects its own account on a supported platform — currently Google (Business Profile), Facebook/Meta, Etsy, eBay, and WooCommerce (the business's own online store) — using that platform's official authorization (OAuth) or API access. We then retrieve that business's existing reviews from the platform and display them in the customer's chosen widget or WordPress plugin.
Business customers can configure how their reviews display, including a minimum star-rating filter, keyword filters, tags, and the ability to exclude specific reviews from the displayed cards. These display controls do not change the overall star rating or total review count shown, which reflect all reviews retrieved from the source platform. Business customers are responsible for using these controls lawfully and honestly. We do not create, write, or alter the content of reviews; we display them as provided by the source platform.
At a business customer's direction, we can also submit the customer's own reply to one of their reviews back to the source platform (for example, replying to a Google review). In that case we transmit only the reply text the customer writes; we do not otherwise write to the platform.
4. Information We Collect
A. Business customer account data
- Email address and name, managed through our authentication provider (Supabase Auth).
- Subscription and billing identifiers (e.g., Stripe customer and subscription IDs, trial/period dates). We do not receive or store full payment-card numbers — card entry occurs on Stripe-hosted pages.
- Business/location identifiers you connect (e.g., place ID, account/location IDs, business name and address), and the connected business's profile photo where the platform provides one.
- Access credentials for the platforms you connect (OAuth access and refresh tokens, API keys, or store credentials such as a WooCommerce store URL and keys), used solely to retrieve your reviews and, where applicable, post your replies. See §12 on how these are protected.
B. Review content we retrieve and cache
For each displayed review we store: reviewer display name (where the platform provides one), reviewer photo URL, star rating or recommendation, review text, review timestamp, the source platform, a verified-purchase indicator where the platform supplies one, the related product name and link (for product reviews from Etsy or WooCommerce), and any business-owner reply and its timestamp. Cached reviews are refreshed and pruned on a schedule (see §9).
Some platforms limit the reviewer information available to us, and we display a neutral label where a name or photo is withheld — for example, Facebook reviews may appear without a reviewer name or photo, and Etsy product reviews are shown as "Etsy Buyer." eBay reviews display the reviewer's eBay username, and WooCommerce reviews may use the reviewer's Gravatar image. We do not store reviewer profile URLs.
When reviews are displayed through our WordPress plugin, the plugin may download reviewer photos and review images into your own WordPress site's media storage so they load from your site. In that case those images are stored on your server rather than loaded from the source platform each time.
C. Widget usage data
When a widget loads on a business's site, our server records a view event containing the referring site (the page's origin), the browser user-agent, and a timestamp, and maintains monthly view counts (used for plan limits and analytics). We do not store the visitor's IP address in our application, though our hosting/edge provider may process it transiently to deliver the response.
We also record aggregate interaction events when a visitor uses a widget's interactive controls — specifically clicking the "Leave a review" link, a "Load more" button, or carousel navigation. Each interaction event stores only the widget identifier, the type of interaction, and a timestamp — no IP address, user-agent, referrer, cookie, or any visitor identifier — so these events cannot be linked to an individual. We use them solely to produce anonymous engagement statistics for the business customer (for example, how many visitors clicked through to leave a review). Business customers can disable interaction-event collection entirely from their account settings or the Analytics page; when disabled, the widget sends no interaction signal and we record nothing.
D. Data collected on our own website and app
- Strictly necessary authentication cookies for logged-in business customers (Supabase session cookies).
- Cookieless product analytics on our own marketing/app pages (Vercel Web Analytics).
- Server logs, which may include account identifiers (UUIDs) and technical error details. We do not log reviewer emails or visitor IP addresses in our application code.
E. Team members and access
An account owner can invite additional users ("team members") and organize widgets into projects with role-based access. For each team member we store their name, email, assigned role, and which projects they can access. The account owner controls these invitations and permissions.
We do not intentionally collect special-category/sensitive personal data.
5. Third-Party Content Loaded by the Widget
When our widget displays reviews on a business's site, the visitor's browser loads certain content directly from third parties:
- Reviewer avatars and review images are loaded from the source platforms' content networks (e.g., Google, Facebook, Etsy, eBay). As a result, those platforms may receive the visitor's IP address and browser information. (When the WordPress plugin is used, these images may instead be served from the business's own WordPress site — see §4B.)
- Google Fonts are loaded from Google only if the business selects a Google font for the widget.
The widget itself does not set cookies or use local/session storage on the visitor's device. To produce the aggregate interaction statistics described in §4(C), the widget sends a lightweight, non-identifying signal (the widget id and interaction type only) to our own servers; this likewise sets no cookies and stores nothing on the visitor's device. These third-party requests are governed by the third parties' own privacy policies.
6. How We Use Information
We use information to: provide and operate the Services; retrieve, cache, refresh, and display your reviews; transmit replies you choose to post back to a source platform; authenticate accounts and manage team-member access; process subscriptions; enforce plan limits and prevent abuse; provide support; maintain security and integrity; analyze and improve the Services; and comply with law and enforce our Terms.
7. Legal Bases (EEA/UK)
Where the EU or UK GDPR applies we rely on: contract (to provide the Services you request); legitimate interests (to operate, secure, analyze, and improve the Services, and to display publicly-available reviews of a business that authorized their retrieval), balanced against individuals' rights; consent (where required, e.g., certain analytics); and legal obligation.
8. How We Share Information
- Displayed publicly — review content appears in widgets on the business customer's own website(s), which may be indexed by search engines.
- Service providers (sub-processors) — hosting/edge/CDN (Vercel), database and authentication (Supabase, hosted on AWS), payments (Stripe), and the review-source platforms whose APIs we call (Google, Meta, Etsy, eBay, and each business's own WooCommerce store). Google Fonts may be loaded at display time as described in §5.
- Legal and safety — to comply with law or lawful requests, enforce our Terms, or protect rights, safety, and property.
- Business transfers — in a merger, acquisition, financing, or asset sale, subject to this Policy.
We do not sell personal information, and we do not use it for cross-context behavioral advertising.
9. Data Retention
- Cached reviews: refreshed on a recurring schedule that varies by platform and is consistent with each platform's terms. Reviews removed at the source, or excluded by the business, are deleted from our cache on the next sync; all cached reviews for a widget are deleted when the widget is deleted.
- Widget view records (referrer origin, user-agent, timestamp) and widget interaction events (widget id, interaction type, timestamp): retained on a rolling basis and automatically purged after approximately 24 months. Aggregate monthly view counts (which contain no visitor-level data) are retained for billing.
- Account and billing data: kept for the life of the account and as required by tax/accounting law thereafter.
- Connected-platform credentials: retained while the connection is active; revoked/deleted when you disconnect a platform or close your account.
Platform-initiated deletion. If you remove BrandTrust from your Facebook settings, Facebook notifies us and we delete the Facebook data associated with that connection. You can also request deletion of your Facebook data and check the status of that request at `https://brandtrust.reviews/facebook-data-deletion`. Similarly, when eBay notifies us that a user has closed their account, we delete the eBay data associated with that connection. Disconnecting a source or using "Disconnect & delete all data" in your account removes the stored reviews and credentials for that connection.
10. International Transfers
We are based in the United States and process data in the U.S. and in our providers' regions (e.g., Supabase on AWS). Where we process personal data of individuals in the EEA or UK, we rely on appropriate safeguards such as the EU Standard Contractual Clauses and the UK International Data Transfer Addendum.
11. Your Rights
Depending on where you live, you may have rights to access, correct, delete, port, restrict, or object to processing, and to withdraw consent. Contact hello@brandtrust.reviews to exercise them; we will verify your identity and respond within the timeframes required by law.
- EEA/UK (GDPR/UK GDPR): access, rectification, erasure, restriction, portability, objection, and complaint to a supervisory authority.
- California (CCPA/CPRA): rights to know, delete, correct, and opt out of "sale"/"sharing," and non-discrimination. We do not sell or share personal information as those terms are defined.
- Other U.S. state laws (e.g., Virginia, Colorado, Connecticut, and others): comparable rights where applicable.
Reviewers: because we display reviews sourced from third-party platforms, the most complete way to change or remove a review is at its source (the change flows to us at the next sync). You may also contact hello@brandtrust.reviews to request that a specific review about you be excluded from display through our Services, and we will act in accordance with applicable law.
12. Security
- Business-customer passwords are handled by our authentication provider (Supabase Auth); we do not store or process raw passwords.
- Payments are handled by Stripe; card data does not touch our servers.
- Traffic to the Services is served over HTTPS by our hosting platform.
- Connected-platform credentials (OAuth access/refresh tokens and API secrets) are encrypted at the application level (AES-256-GCM) before being stored, in addition to our infrastructure providers' access controls and encryption at rest.
- No system is perfectly secure. Use a strong, unique password and report any suspected issue to hello@brandtrust.reviews.
13. Children
The Services are intended for businesses and are not directed to children under 16. We do not knowingly collect their personal information; contact us to request deletion.
14. Changes; Contact
We may update this Policy and will post the new version with an updated date, providing additional notice for material changes where required.
Brand Lew LLC
1110 W Elliot Rd #1049
Tempe, AZ 85284
United States