Privacy Policy
Your reviews and customer data are sensitive. This policy describes what AI Review Sensor collects, why, how we keep it protected, and how you can delete it.
Last updated: July 1, 2026
Product: AIReviewSensor (https://www.aireviewsensor.com)
Operated by: VASUNDHARA SOLUTIONS LAB LLP
Effective date: 1 July 2026
Last updated: 1 July 2026
1. Introduction
This Privacy Policy explains how Vasundhara Solutions Lab LLP collects, uses, discloses, stores, and protects personal data when you use AIReviewSensor, a software-as-a-service platform that connects to your app-store, business-profile, and social-media accounts to read ratings, reviews, comments, and messages, and to generate and (optionally) publish reply content on your behalf.
By creating an account, connecting a platform, or otherwise using the Service, you acknowledge that you have read and understood this Privacy Policy. Where we act as a processor on behalf of a business customer, this Policy is read together with our Data Protection Agreement (DPA), which prevails on questions of processing roles and obligations.
This Policy should be read together with our Terms of Use, Cookie Policy, and, for business Customers, our Data Processing Agreement.
2. Who we are and how to contact us
For personal data we process about our own Customers, account holders, and website visitors, the controller (referred to as a "Data Fiduciary" under Indian law) is:
For personal data that flows through the Service about your own end users (for example, a customer who leaves a review on your app listing or comments on your social post), you are the controller and we act as your processor.That relationship is governed by our Data Processing Agreement, not by this Policy. See Section 5 below.
3. Who this Policy covers
We process personal data relating to:
Account users — people who register for and administer an AIReviewSensor account (typically business owners, agencies, and their team members).
Connected-platform data subjects — end users whose reviews, ratings, comments, or messages appear on your connected accounts (for example, a customer who left a Play Store review or sent an Instagram direct message). For this data we generally act as a processor on behalf of you, our business customer.
4. What data we collect
4.1 Data you provide directly
Name, email address, business name, and role.
Account credentials (passwords are stored only as salted hashes).
Support communications and correspondence.
Billing identifiers processed through our payment provider (see Section 8).
4.2 Data from connected platforms
When you connect a platform via OAuth, we access only the data needed to provide the Service. We do not receive your platform passwords.
Platform | Data we access |
Apple App Store | Your app list, app metadata, ratings, and customer reviews; reply content you or the Service submit. |
Google Play | Your app list, ratings, and reviews via the Google Play Developer Reviews API; reply content submitted to reviews. |
Google Business Profile | Business profile details (name, description, listing information), customer reviews and ratings, and reply content. |
Instagram Business | Post comments and direct messages on the connected business account, associated profile handles, and reply/response content. |
Facebook Business Page | Post comments and direct messages on the connected Page, associated profile identifiers, and reply/response content. |
Reviews, comments, and messages may contain personal data of third parties (names, handles, opinions, and any personal details those individuals chose to include). We process this data solely to provide the reply and automation features you request.
4.3 AI-generated content
Suggested and automated replies are generated by AI models. The review/comment/message text is sent to the AI provider(s) listed in our Sub-processor List to generate a response. We instruct our AI sub-processors not to train their foundation models on your content (see Section 9).
4.4 Data collected automatically
Log and usage data (IP address, device/browser type, timestamps, actions in the app).
Cookies and similar technologies (see Section 12).
5. Google API Limited Use disclosure
AIReviewSensor's use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
We access Google Play and Google Business Profile data only to display your ratings, reviews, and profile information inside AIReviewSensor and to generate and post reply content at your direction.
We do not use Google user data for advertising.
We do not sell Google user data.
We do not transfer Google user data to third parties except (a) sub-processors strictly necessary to provide the Service, (b) to comply with applicable law, or (c) as part of a merger/acquisition with prior notice.
We do not allow humans to read Google user data unless we have your consent for specific messages, it is necessary for security or to comply with law, or the data is aggregated and anonymized for internal operations.
We request the narrowest Google scopes needed to read your reviews and post replies. Where the connection flow surfaces broader account-management scopes, we only exercise the read-reviews and reply-to-reviews functions described in this Policy.
6. Meta (Facebook & Instagram) Platform data use
For data obtained through the Meta / Facebook Login and the Instagram and Facebook Graph APIs:
We use Page and Instagram Business data only to display comments and messages and to send the replies you compose or automate.
We comply with the Meta Platform Terms and Developer Policies, including their data-use, retention, and deletion requirements.
We do not use Meta data for advertising or sell it.
Data deletion: You can disconnect Meta at any time in the app, or request deletion via [email protected]. Instructions for our Meta data-deletion callback are published at https://www.aireviewsensor.com/data-deletion-policy.
7. How we use your data and our legal bases (GDPR)
Purpose | Legal basis |
Create and operate your account | Performance of a contract |
Read reviews/comments/messages and generate replies | Performance of a contract / processing on behalf of the controller |
Automate replies you have configured | Your consent and/or contract |
Billing and subscription management | Performance of a contract; legal obligation |
Security, fraud prevention, service integrity | Legitimate interests |
Product analytics and improvement (aggregated) | Legitimate interests |
Marketing communications to account users | Consent (opt-out anytime) |
Compliance with law and platform rules | Legal obligation |
Under the DPDP Act (India), we process personal data on the basis of your consent or for legitimate uses as defined by that Act.
8. Payments
Subscriptions are billed through Paddle, which acts as our Merchant of Record. Paddle collects and processes your payment information (card details, billing address, tax identifiers) under Paddle's own privacy policy. We receive limited billing metadata (plan, status, transaction identifiers, country for tax) but do not store your full card details. See https://www.paddle.com/legal/privacy.
9. Who we share data with
We share personal data only with:
Sub-processors who help us run the Service (cloud hosting, AI reply generation, email delivery, analytics, error monitoring). We use a limited number of trusted providers to run the Service -> For hosting (AWS), AI reply generation, payment processing (Paddle), email, and analytics.
Payment provider (Paddle) as described above.
The connected platforms themselves, when we post your replies back to Apple, Google, or Meta.
Authorities, where required by valid legal process.
A successor entity in the event of a merger, acquisition, or asset sale, with notice as required by law.
We do not sell personal data, and we do not share it for cross-context behavioral advertising (as those terms are defined under the CCPA/CPRA).
10. International data transfers
We operate globally and may process data in India and other countries. Where we transfer personal data out of the EEA, UK, or other regulated regions, we rely on appropriate safeguards such as the EU Standard Contractual Clauses, the UK IDTA/Addendum, adequacy decisions, or your explicit consent. A copy of the relevant safeguard is available on request.
11. Data retention
Account data is retained while your account is active and for a reasonable period afterward for legal, tax, and audit purposes.
Reviews, comments, and messages processed on your behalf are retained only as long as needed to provide the Service, then deleted or anonymized, subject to the retention terms in the DPA.
AI processing is transient; input content is not retained by our AI sub-processors beyond the period stated in the Sub-processor List.
Platform-specific limits (e.g., Meta and Google retention/deletion requirements) are honored and override longer periods.
12. Cookies and similar technologies
We use:
Strictly necessary cookies — authentication, security, and core functionality.
Functional cookies — remembering preferences.
Analytics cookies — understanding usage (only with consent where required).
You can manage non-essential cookies through our cookie banner or your browser settings. A dedicated Cookie Policy is available at https://www.aireviewsensor.com/cookie-policy.
13. Your rights
Depending on your location, you may have the right to:
Access the personal data we hold about you.
Correct inaccurate data.
Delete data ("right to be forgotten" / erasure).
Restrict or object to processing.
Data portability.
Withdraw consent at any time.
Nominate (DPDP Act) another person to exercise rights on your behalf in case of death or incapacity.
Non-discrimination and (CCPA/CPRA) to limit use of sensitive data and to opt out of sale/sharing (we do neither).
Lodge a complaint with a supervisory authority — the relevant EU authority, the UK ICO, or the Data Protection Board of India — or first raise it with our Grievance Officer.
To exercise any right, contact us using the details in Section 18. We will respond within the timeframes required by applicable law. We may need to verify your identity before acting on a request.
Where AIReviewSensor is a processor for a business customer, requests from connected-platform data subjects are forwarded to the relevant customer (controller), and we assist them in responding.
14. Security
We implement technical and organizational measures including encryption in transit (TLS), encryption at rest, hashed passwords, encrypted OAuth token storage, access controls, least-privilege permissions, logging, and regular review. No system is perfectly secure; we notify affected parties and authorities of any breach as required by law.
15. Children
The Service is intended for businesses and is not directed to individuals under the age of 18. We do not knowingly collect personal data from children. If you believe a child has provided us with personal data, please contact us and we will delete it.
16. Changes to this Policy
We may update this Policy from time to time. Material changes will be notified by email or in-app before they take effect. The "Last updated" date reflects the current version.
17. Governing law
This Policy is governed by the laws of India. Subject to the mandatory data-protection rights available to you in your own jurisdiction, the courts at Surat, Gujarat, India have jurisdiction over disputes relating to this Policy.
18. Contact us
For any questions, requests, or concerns about this Policy or your personal data:
Email: [email protected]

