DiscoverFor businessPricingLog in
Legal

Privacy Policy

Last updated: May 22, 2026

This Privacy Policy explains how Reviews by MGS, operated by MGS Hosting (Riga, Latvia), collects, uses, and protects your personal data. We are GDPR-compliant and store data within the EU.

1. Data we collect

Account data

  • Email address, name, hashed password.
  • Subscription state (free/pro/business), payment metadata from Paddle (no card details).
  • Timestamps for sign-up, login, and account changes.

Business profile data

  • Business name, slug, description, category, website URL, logo.
  • Claim and verification status.

Review data

  • Rating, title, body, optional reviewer name and email.
  • Verification token (until used or expired).
  • Moderation state and history.

Usage data

  • IP address (used only for rate limiting; not retained beyond 30 days).
  • User agent string for security analysis.
  • Review-helpful clicks and report submissions.

2. How we use your data

  • To provide and operate the Service.
  • To verify reviews and prevent fraud.
  • To moderate content for compliance with our Terms.
  • To send transactional emails (review verification, claim verification, billing receipts).
  • To detect and prevent abuse, spam, and security incidents.
  • To comply with legal obligations.

3. Legal basis (GDPR)

  • Contract: to deliver the Service you signed up for.
  • Legitimate interest: for security, fraud prevention, and analytics.
  • Consent: for optional features such as marketing emails (you can opt out anytime).
  • Legal obligation: for tax and accounting records.

4. Data sharing

We share data only with:

  • Paddle — our merchant of record, processes payments and handles VAT.
  • Email service provider — to send transactional emails.
  • Database & hosting providers — EU-based infrastructure.
  • Law enforcement — only when compelled by valid legal process.

We do not sell personal data. We do not run third-party advertising trackers.

5. Public reviews

Reviews you submit are public. They include your rating, title, body, the name you provide (or "Anonymous"), and the publication date. Email addresses are never displayed publicly. If your review is verified by email, a "Verified review" badge is shown next to it.

6. Cookies

We use the minimum cookies required to operate the Service:

  • session — signed JWT cookie for keeping you logged in (HttpOnly, Secure, SameSite=Lax).

We do not use tracking, advertising, or third-party analytics cookies.

7. Your rights

Under GDPR you have the right to:

  • Access your personal data.
  • Correct inaccurate data.
  • Request erasure ("right to be forgotten").
  • Object to processing or restrict it.
  • Receive your data in a portable format.
  • Withdraw consent at any time.
  • Lodge a complaint with the Latvian data protection authority (Datu valsts inspekcija).

To exercise these rights, email privacy@reviews.mgshosting.com.

8. Data retention

  • Account data: retained while your account is active. Deleted within 30 days of account closure.
  • Reviews: retained as part of the public review record. May be anonymized on request.
  • IP logs and rate-limit data: 30 days.
  • Billing records: 7 years (legal requirement under Latvian and EU tax law).

9. International transfers

Data is stored within the EU. If we use sub-processors outside the EU, we rely on Standard Contractual Clauses or other approved transfer mechanisms.

10. Children

Reviews by MGS is not intended for users under 16. We do not knowingly collect data from children. If you become aware that a child has provided us with personal data, contact us and we will remove it.

11. Security

We protect your data with encryption in transit (TLS 1.3) and at rest, hashed passwords, principle-of-least-privilege access controls, and regular security reviews. Despite our efforts, no system is perfectly secure. Report security issues to security@reviews.mgshosting.com.

12. Changes

We will notify you of material changes via email or in-product notice. The "Last updated" date at the top reflects the latest revision.

13. Contact

For privacy questions: privacy@reviews.mgshosting.com.

Data controller: MGS Hosting · Riga, Latvia