KeepReviews Privacy Policy
Last updated: August 29, 2026
KeepReviews ("the app") is a product review app for Shopify stores. This page explains what data the app collects, why, and how it's handled — for merchants who install the app and for their customers who submit reviews.
Data collected from your store
When you install KeepReviews, Shopify grants the app access to your store's product and order data through the following API scopes:
- read_products — to show the correct product title alongside each review.
- read_orders — only used if you turn on post-purchase review request emails (off by default). If enabled, the app reads paid order data to know when to send a "please review your purchase" email, using the customer's email and the products they bought.
Data collected from your customers
When a customer submits a review through the storefront widget, the app stores:
- The name and (optional) email address they typed into the review form.
- The rating and review text.
- Photos attached to the review, if your plan includes that feature.
None of this is collected silently — it's only ever what the customer typed into the visible review form on your storefront.
How data is used
- Displaying approved reviews on your storefront.
- Giving you a moderation panel to approve, reject, or export reviews.
- Sending a post-purchase review request email, but only if you've explicitly turned that on in the app's settings, and only for orders that haven't been cancelled.
A review is never published automatically — every review is held for your approval before it appears on your storefront.
Where data is stored
KeepReviews uses a small number of infrastructure providers to run the app:
- Supabase — hosts the app's database and any review photos.
- Resend — delivers the post-purchase review request emails, if you've enabled that feature.
- Render — hosts the app's server.
None of these providers use your store's or your customers' data for anything other than running KeepReviews on your behalf.
Data retention and deletion
KeepReviews' retention rule is tied to purpose, not a fixed calendar deadline: a reviewer's name and email are kept for exactly as long as their review exists and is being displayed to shoppers — no longer, and never for a secondary purpose like marketing. Concretely:
- Reviews (and the reviewer's name/email attached to them) are kept for as long as you use the app, regardless of which plan you're on — a plan change or a failed payment never deletes or hides review history, it only affects how many reviews are displayed on the storefront widget.
- If a customer asks you to delete their personal data, KeepReviews supports Shopify's standard data erasure request: the customer's name and email are removed from their review immediately, while the review text and rating remain (a product opinion isn't itself personal data).
- If you uninstall the app, all of your store's data — reviews, reviewer names and emails, everything — is permanently deleted after Shopify's standard compliance waiting period. Nothing is retained "just in case" past that point.
Data loss prevention
KeepReviews' data loss prevention approach is a set of concrete technical controls rather than a single tool, applied at every layer data passes through:
- In transit: every connection — storefront to app, app to database, app to email/storage providers — is HTTPS/TLS only.
- At rest: the database and file storage are encrypted at rest by the underlying provider (Supabase), including automated backups.
- Access control: the credentials that can write to storage or bypass row-level restrictions are used only in server-side code and are never exposed to the browser or to any third party.
- Abuse prevention: the public endpoints that accept data from shoppers (submitting a review, reading the widget) are rate-limited per IP and reject oversized requests, so a single bad actor can't extract or flood data at scale.
- Monitoring: the actions described under "Access log" below are recorded and reviewable.
- Response: the incident response process below governs what happens if a control fails.
Access log
Every action that touches a merchant's reviews or settings — approving or rejecting a review, exporting the CSV, or changing widget/email settings — is recorded with who performed it and when, so access to personal data is auditable after the fact.
Your rights
You can export every review you've ever collected, on any plan, at any time, from the app's Reviews page — no restrictions, no deleted history.
Data processing terms
KeepReviews acts as a data processor for the personal data described above (reviewer name, email, and photos), and you — the merchant — remain the data controller for your store and its customers. In that capacity, KeepReviews:
- Only processes this data to provide the app's features described in this policy — never for its own marketing, resale, or any other purpose.
- Does not share this data with any third party except the infrastructure providers listed above, solely to run the app.
- Will assist you in responding to a data subject's access or deletion request, as described under "Data retention and deletion" above.
- Will notify you without undue delay if it becomes aware of a security incident affecting your store's data — see the incident response section below.
Security incident response
If KeepReviews becomes aware of a security incident that may have exposed merchant or customer data, we will:
- Contain the issue and, where possible, stop it from continuing.
- Assess what data and which shops were affected.
- Notify affected merchants by email within 72 hours of confirming the incident, describing what happened, what data was involved, and what we're doing about it.
- Where the incident involves personal data of a merchant's customers, provide the merchant with what they need to meet their own legal notification obligations.
- Fix the underlying cause before considering the incident closed.
To report a suspected security issue, email soporte@keepreviews.c3lect.com with as much detail as you can provide.
Contact
Questions about this policy, or a data request from one of your customers, can be sent to soporte@keepreviews.c3lect.com.