Security
Private feedback needs a locked door.
This is what we do today — not a certificate wall of logos we have not earned.
Transport encryption
All traffic uses HTTPS with TLS. Review text, voice files, and dashboard sessions are not sent in the clear.
Built for anonymity
Public pages do not show who left a review. We do not attach a Google or social profile to feedback.
Account access
Business dashboards require a signed-in owner. API routes check that token and only return that business’s data.
Database rules
Supabase row-level security is enabled on sensitive tables. The service role key stays on the server, never in the browser.
Payments
Cards are handled by Stripe. We do not store full card numbers on ReviewShroud servers.
GDPR
You can ask what we hold and ask us to delete it. Privacy requests go to privacy@reviewshroud.com.
Found a vulnerability? Email support@reviewshroud.com with “security” in the subject. Full legal terms live in Privacy and Terms.