Privacy Policy
Effective 30 August 2026. This explains what VouchRate Ltd does with personal data when you use VouchRate. A review platform necessarily collects more than it displays, so this policy is explicit about the difference.
1. Who we are
VouchRate Ltd, is the controller of personal data described in this policy.
Privacy enquiries and rights requests: privacy@vouchrate.co.uk.
2. What we collect
2.1 Information you give us
- Account — name, email address, password (stored only as a scrypt hash), and optionally an avatar.
- Profile — display name, handle, town or city, and your visibility choices.
- Reviews — rating, title, body, criteria ratings, the date of your experience, and any photographs you attach.
- Correspondence — reports, disputes, appeals and support messages.
2.2 Information businesses give us about you
Where a Business uses our collection tools it may upload a transaction record containing your email address, name and an order reference. We store the email address as a salted hash for matching. Plaintext is retained only while an invitation is outstanding and is then purged.
2.3 Information we generate
- Fraud signals — IP address, a device fingerprint derived from your browser and network, referral source and submission timing. These are stored as SHA-256 hashes with a server-side secret, never in plaintext.
- Authenticity scores — a score and classification for each review, and the individual signals that produced it.
- Analysis — detected sentiment, topics and language of your review.
- Reviewer standing — a score derived from account age, verified experiences, helpful votes and reports.
3. Lawful bases
| Purpose | Lawful basis |
|---|---|
| Creating and operating your account | Contract |
| Publishing your review | Contract |
| Verifying that an experience was real | Legitimate interests — the integrity of the Review Network, which is the entire value of the service to consumers |
| Detecting and preventing review fraud | Legitimate interests — preventing deception of consumers; and legal obligation where consumer protection law applies |
| Moderating content | Legitimate interests; legal obligation where content is unlawful |
| Sending review invitations on behalf of a business | Legitimate interests of the business, subject to your right to object and to our global suppression list |
| Service emails (verification, password reset, decisions about your content) | Contract |
| Marketing email from us | Consent |
| Keeping an audit trail of moderation decisions | Legitimate interests — accountability; legal obligation for records of complaints |
Where we rely on legitimate interests we have assessed that our interest in operating a trustworthy review network does not override your rights, principally because the data used for fraud detection is pseudonymised, is never published, and is not used to make decisions about you outside the Platform.
4. What is published
Your display name, your reviews and your responses are public. Your avatar and town are public only if you choose. If you review anonymously, none of your identifying details are shown.
Your email address is never published, is never disclosed to a Business, and is not available through our API. A Business cannot use a review to determine which of its customers wrote it beyond what you chose to display.
Fraud signals, authenticity scores, individual trust signals and business dispute evidence are never published and are not selectable through any public endpoint.
5. Automated decision-making
We score every review for authenticity automatically. This is profiling within the meaning of UK GDPR. It does not produce a legal or similarly significant effect on you, because:
- no review is removed by an automated process alone;
- a low score routes the review to a human, who decides and records a written rationale;
- a review awaiting that decision remains visible, labelled “Under review”, rather than being hidden;
- you may contest the outcome and obtain human review through our appeals process.
The categories of signal we use are published. The weights are not, because publishing them would tell those attempting to manipulate the system precisely what to avoid.
6. Who we share with
We do not sell personal data. We share it with:
- Hosting and database providers — to run the service.
- Email delivery providers — to send service emails and invitations.
- Payment providers — for business subscriptions. We do not store card details.
- Commerce platforms you or a business connect — to confirm that an order occurred.
- Professional advisers, regulators and law enforcement — where legally required or to establish or defend legal claims.
All processors act under written contracts requiring appropriate security and permitting processing only on our instructions. A current list is available on request.
7. International transfers
Where personal data is transferred outside the UK, we rely on UK adequacy regulations or on the International Data Transfer Addendum to the EU Standard Contractual Clauses, together with a transfer risk assessment.
8. Retention
| Data | Retained for |
|---|---|
| Published reviews and responses | While your account exists, because they form a public record others rely on |
| Review version history | As long as the review, so edits remain auditable |
| Account data | Until you delete your account, then removed within 30 days |
| Fraud signals and device hashes | 13 months from collection |
| Invitation records and plaintext recipient emails | Until the invitation completes or expires, then the plaintext is purged |
| Transaction records supplied by businesses | 24 months, or until the business deletes them |
| Moderation decisions and audit log | 6 years, for accountability and to defend legal claims |
| Suppression list (unsubscribes) | Indefinitely, as a hashed value, so we can keep honouring your opt-out |
9. Your rights
You have the rights of access, rectification, erasure, restriction, portability and objection, and the right not to be subject to solely automated decisions with significant effects. These are described in detail at your data rights, along with how to exercise them.
Signed-in users can export or delete their data from account settings. Otherwise write to privacy@vouchrate.co.uk. We respond within one month, extendable by two months for complex requests, and will tell you if we extend.
10. Cookies
We use strictly necessary cookies for authentication and security. We do not use advertising cookies. See our cookie policy.
11. Security
- Passwords are stored as scrypt hashes and are never recoverable.
- Identifiers used for fraud clustering are hashed with a server-side secret, so a database breach does not disclose reviewers’ IP addresses.
- All traffic is encrypted in transit with certificate verification enforced.
- Administrative actions are logged to an append-only audit trail.
12. Children
The Platform is not intended for under-16s and we do not knowingly collect their data. If you believe a child has given us personal data, contact us and we will delete it.
13. Changes
We will post any changes here and update the effective date. Material changes will be notified by email or a prominent notice at least 30 days in advance.
14. Complaints
If you are unhappy with how we have handled your data, contact privacy@vouchrate.co.uk. You also have the right to complain to the Information Commissioner’s Office at ico.org.uk, or by telephone on 0303 123 1113.