Privacy Policy
We're committed to protecting your privacy and being transparent about how we handle your data, especially regarding Google Business Profile API integration
Contents
1. Company Details
TrueStars.ai is a service provided by Nuvem Catita Unipessoal Lda, headquartered in Portugal. This Privacy Policy explains how we collect, use, and protect your personal data under the EU General Data Protection Regulation (GDPR), with special attention to our Google Business Profile API integration.
2. What Data We Collect
We may collect the following types of data:
- Business identity and contact information
- Google Business review data (with your permission)
- NFC interaction logs (e.g., timestamp, browser info)
- IP address, cookies, and usage data from website interactions
- Consent timestamps for compliance purposes (without storing personal data)
3. Google Services Integration
Google Business Profile API Usage
- ✅We facilitate customer reviews through Google Business Profile APIs
- ✅We do NOT store, cache, or modify your review content
- ✅We do NOT access your existing Google reviews
- ✅We only redirect customers to Google's official review interface
User Consent for Automated Actions
- 🔒Every automated action requires your explicit prior consent
- 📱NFC card interaction triggers a consent request before any redirect
- ⏰You can withdraw consent at any time
- 📊We log consent timestamps for compliance purposes (without storing personal data)
Third-Party Authentication
- 🔑Restaurant partners must authenticate with their own Google Business accounts
- 🚫We do NOT share API credentials between different restaurant locations
- 🔐Each location maintains independent access to their Google Business Profile
4. How We Process Your Data
We process your data to:
- Provide NFC review facilitation service
- Redirect customers to Google Reviews with consent
- Analytics and service improvement
- Customer support and communication
- Legal compliance and fraud prevention
Specifically for Review Services:
- ❌We do NOT create, edit, or delete reviews on your behalf
- ❌We do NOT automatically post content without user action
- ❌We do NOT interfere with Google's review monitoring systems
- ✅We maintain transparent audit trails for all API interactions
5. Review Authenticity and Google Policy Compliance
Our Commitment to Authentic Reviews
- ✅We only facilitate reviews from genuine customers who visited your establishment
- ✅We prohibit and actively prevent fake review generation
- ✅Staff must verify customer authenticity before providing NFC cards
- ✅We do not incentivize specific rating levels (1-5 stars)
Prohibited Activities
We strictly prohibit:
- ❌Creating fake or automated reviews
- ❌Paying customers for specific ratings
- ❌Reviewing businesses you haven't visited
- ❌Using our service to manipulate Google rankings artificially
Google Policy Compliance
- 🔒All activities comply with Google Business Profile API policies
- 👀We do not interfere with Google's monitoring or auditing
- 📊We maintain full transparency with Google regarding our API usage
- 🚨We immediately report any suspicious activity to relevant authorities
6. Legal Basis for Processing
We rely on:
Performance of a contract
To provide the service
Legitimate interest
Improving service and security
User consent
Newsletter, review reply automation
7. Data Sharing & Third-Party Access
We share data with:
✅ Google (via official APIs)
Customer redirect data for review facilitation
✅ Essential service providers
Payment processing, hosting, analytics
✅ Legal authorities
When required by law or to prevent fraud
Google-Specific Sharing:
- •We share minimal necessary data with Google through official Business Profile APIs
- •We do NOT provide Google with customer personal information
- •Redirects to Google Reviews are direct and transparent
- •Google processes review data according to their own privacy policies
We NEVER share data with:
- ❌ Review farms or fake review services
- ❌ Competitors or unauthorized third parties
- ❌ Marketing agencies (without explicit consent)
- ❌ Any party that violates Google's content policies
8. Your Rights
You may request at any time:
Access Rights
- • Access to your personal data
- • Data portability
Control Rights
- • Rectification or erasure
- • Restriction or objection to processing
Submit requests via:sa@truestars.ai
9. Your Rights Regarding Review Services
As a Customer:
- ✅Right to withdraw consent before completing a review
- ✅Right to edit or delete your review directly on Google
- ✅Right to report inappropriate use of our service
- ✅Right to opt-out of future review requests
As a Restaurant Partner:
- ✅Right to disconnect Google Business Profile integration
- ✅Right to audit all review facilitation activity
- ✅Right to receive transparency reports on service usage
- ✅Right to terminate service with immediate effect
Complaint Process:
- 1. Contact us at: sa@truestars.ai
- 2. Google Business Profile support (for review-related issues)
- 3. CNPD Portugal (for privacy-related complaints)
- 4. Google API compliance team (for policy violations)
11. Data Retention
Business Data
- 📅Restaurant profiles: Duration of service agreement + 3 years
- 🔑API authentication data: Duration of service agreement
- 📊Usage analytics: 2 years for service improvement
Customer Data
- ⏰NFC interaction logs: 30 days maximum
- ✅Consent records: 3 years for compliance
- 🚫Review content: We do NOT retain any review content
Legal and Compliance Data
- ⚖️Legal compliance records: 7 years
- 🛡️Security incident logs: 3 years
- 📋Audit trails: 5 years for Google API compliance
12. Contact & Complaints
General Privacy Inquiries
Google API Compliance Issues
Review Authenticity Reports
Data Controller
Nuvem Catita Unipessoal Lda
Avenida Aida 411
Centro Comercial Estoril Garden
2765-187 Estoril, Portugal
Data Protection Authority
CNPD (Comissão Nacional de Proteção de Dados), Portugal
If you are not satisfied with our response to your privacy concerns, you may lodge a complaint with the Portuguese Data Protection Authority.
13. Policy Updates & Compliance
Regular Reviews
- 📅This policy is reviewed quarterly for Google API compliance
- 🔄Updates reflect changes in Google Business Profile policies
- 📧We notify partners of material changes via email (48 hours advance notice)
Google Policy Changes
- 👀We monitor Google Business Profile API policy updates
- ⚡Service modifications implement new Google requirements immediately
- 🛑Non-compliant features are disabled until compliance is achieved
Version History
- 📝Last Updated: June 2025
- 🔜Next Review: September 2025
- ✨Major Changes: Added Google Business Profile API compliance sections
Important Notice
This policy must be read in conjunction with Google's Business Profile API policies and terms of service. In case of conflicts between our policy and Google's requirements, Google's policies take precedence for API-related activities.