Privacy Policy
Last updated: June 2026
1. Who we are
ReviewNest is a Google Reviews widget platform operated by EBI Consulting, a digital agency based in South Africa. We help businesses display their Google Business Profile reviews on their websites.
Contact: info@ebiconsulting.co.za · ebiconsulting.co.za
2. What data we collect and why
Google account data (via OAuth 2.0)
When you connect your Google account, we request access using thehttps://www.googleapis.com/auth/business.managescope. This allows us to:
- Read the list of Google Business Profile locations your account manages
- Read the reviews posted on those locations
We do not post, edit, delete, or respond to reviews on your behalf. We do not access any other Google services, Gmail, Google Drive, or personal account information beyond what is listed above.
OAuth tokens
We store an OAuth refresh token in our secure database (Supabase) to allow us to periodically refresh your review data without requiring you to reconnect. This token is used solely to fetch your Business Profile reviews. It is never sold, shared with third parties, or used for advertising.
Review data
We store a cached copy of your Google reviews (reviewer name, photo, star rating, review text, and date) in our database. This cached data is served to your website visitors via the ReviewNest widget. It is refreshed automatically once per day.
Account information
If you create a ReviewNest account, we store your name, email address, and encrypted password. This information is used only to authenticate you and provide access to the dashboard.
3. How we use your data
- To display your Google reviews on your website via the embeddable widget
- To refresh your review data daily using the stored OAuth token
- To authenticate you when you log in to the dashboard
- To communicate with you about your account (if necessary)
We do not use your data for advertising, profiling, or any purpose beyond operating the ReviewNest service.
4. Data sharing
We do not sell or share your personal data with third parties. We use the following sub-processors to operate the service:
- Supabase — database and authentication (supabase.com)
- Vercel — hosting and infrastructure (vercel.com)
- Google APIs — for reading your Business Profile reviews
Each of these providers operates under their own privacy policies and GDPR-compliant data processing agreements.
5. Data retention and deletion
We retain your data for as long as your account is active. You may request deletion of your account and all associated data at any time by emailing info@ebiconsulting.co.za. We will action deletion requests within 30 days.
You may also revoke ReviewNest's access to your Google account at any time by visiting myaccount.google.com/permissions and removing ReviewNest. Revoking access will stop review syncing but will not automatically delete your cached review data — email us to request that as well.
6. Security
All data is stored in an encrypted database with row-level security. OAuth tokens are never exposed to the public. Our infrastructure uses HTTPS exclusively. Access to the admin dashboard is restricted to approved users only.
7. Your rights
You have the right to:
- Access the personal data we hold about you
- Request correction of inaccurate data
- Request deletion of your data
- Revoke Google OAuth access at any time
- Object to processing of your data
To exercise any of these rights, email us at info@ebiconsulting.co.za.
8. Changes to this policy
We may update this privacy policy from time to time. The date at the top of this page will reflect the most recent update. Continued use of the service after changes constitutes acceptance of the updated policy.
9. Contact
For any privacy-related questions or requests, contact EBI Consulting at info@ebiconsulting.co.za or visit ebiconsulting.co.za.