SENTIREV

Privacy Policy

Last updated: 23 September 2026 · Applies to sentirev.com, app.sentirev.com, api.sentirev.com, the SENTIREV mobile app, the chat widget, and websites we host for businesses.

1. The short version

  • We collect what is needed to run bookings, shops, quotes and invoices, messaging and the AI tools between customers and businesses — and nothing for advertising.
  • We never sell personal data. We run no third-party advertising or tracking, on the website, in the app, or in the chat widget.
  • Card details go to Stripe. We never see or store full card numbers.
  • AI features send only the information needed for the task to our AI provider, which does not use it to train its models under our agreement. AI always says it is automated. No AI moves money or makes a decision about you on its own.
  • When a business uses SENTIREV to manage its clients, that business is the controller of its client data and we process it on its instructions (section 7).
  • You can see, export, correct or delete your data from your account, or by emailing support@sentirev.com.

2. Who we are and who this covers

SENTIREV ("SENTIREV", "we", "us") is a UK platform for local businesses and their customers: online bookings, an online shop, quotes and invoices (SENTIREV Trade), messaging, websites, and optional AI tools. Contact for anything in this policy: support@sentirev.com.

We are the data controller for the platform itself: your account, sign-in and security, the marketplace (Explore), your bookings and orders as a customer, platform messaging, billing between businesses and us, safety and moderation, and our own communications with you.

Where a business uses SENTIREV to hold and work with information about its own clients and staff — imported client lists, notes, consent records, staff schedules, invoices it sends — that business is the data controller and we are its data processor. Section 7 sets out the terms on which we do that. If you want to know why a business holds something about you, ask the business first; we will help either of you.

This policy covers

  • Customers who browse, book, buy, message, review, accept quotes or pay invoices — with an account or as a guest.
  • Business owners and the people who apply on a business's behalf.
  • Team members and staff, including self-employed workers hosted inside a business.
  • Visitors to sentirev.com, to business websites we host, and people who talk to a business's chat assistant.
  • People a business enters without an account: imported clients, walk-ins, the recipient of a quote or invoice.
  • Other businesses whose public listings are read by our competitor-intelligence feature (business-level facts only, section 3.11).

3. What we collect, feature by feature

Only the features you or the business you deal with actually use apply to you. Each item says what is collected and, where it matters, what we deliberately do not collect.

3.1 Account, sign-in and security

Name, email address, phone number (customers give one so a business can reach them about a booking), and a password stored only as a salted hash. If you sign in with Google or Apple we receive the identifier and email address they release; we never receive your Google or Apple password. Two-factor authentication: a hashed authenticator secret or the one-time codes we email you, plus a short list of hashed recovery data. Sessions: signed tokens, the time you signed in, and the device or browser type. For security we log the IP address and time of sign-in attempts, failed passwords (accounts lock for 15 minutes after 5 failures), password resets, email changes and two-factor changes. Every account holds exactly one role — customer, team member, business owner or SENTIREV team — and moving between roles happens only with your consent (for example, accepting a team invitation).

3.2 Explore, favourites and searching

The town or postcode you type to find businesses nearby. We do not read your device's location. Favourites, recently viewed businesses and search text are stored to your account so they follow you between devices.

3.3 Bookings

The service, staff member, branch, date and time, price and any deposit, notes you add, notes the business adds about the appointment, your attendance history (attended, cancelled, no-show, late cancellation) and reminders sent. For a visit to your home: the address you give. For a business that charges a travel fee: the distance we calculate between its branch and that address. Waiting-list requests, repeat bookings you set up, products you add to a booking, and any consent, patch-test or similar record the business asks for (see 3.14). Where a booking is moved between staff or edited by the business, we keep the history so both sides can see what changed.

3.4 Payments, deposits, gift cards, packages, memberships and tips

Payments are taken by Stripe on the business's own connected Stripe account. We store the amount, currency, what it was for, its status and the Stripe references — never the card number, expiry or security code, which go straight to Stripe from your device and are never sent to us. Gift cards: the code (hashed), balance and redemptions. Packages and memberships: what you bought, sessions used, renewal dates, and pauses or cancellations. Refunds, disputes and chargebacks: the outcome and the reason given. Business payout details (bank account) are held by Stripe; we hold only Stripe's account identifiers and payout status.

3.5 The shop and orders

Products you view, your basket, and each order: items, quantities, prices, discount codes used, the email address for the receipt, the delivery name and address for delivery orders, the handover code for collection orders, and the order's status. You can buy as a guest without an account; a guest order can be looked up only with the order reference and the email address used. If you ask to be told when a product is back in stock we keep your email address for that one product until we send that one email, then delete the request. If a shop has abandoned-basket reminders on and you gave your email address before paying, we keep it with the unfinished order to send a single reminder an hour later, then stop.

3.6 Quotes, jobs and invoices (SENTIREV Trade)

For a business that sends quotes and invoices: the customer's name and contact details, the job address, the description of work, line items and prices, photos the business attaches to a quote or job, acceptance (the time, IP address and name entered when a quote is accepted online — this is the record that the quote was agreed), invoices, payment status, reminder and final-notice letters sent, and job notes. The business decides what it writes in a quote; we store it on the business's behalf.

3.7 Messaging, team chat and reviews

Messages between a customer and a business, and between colleagues in team chat, with timestamps and any attachments. Reviews you write (text, star rating, photos), replies from the business, and reports about a review. Conversations a business's AI answers are logged so the business can see and correct what its assistant said. Blocks you place on a business, or a business places on a customer.

3.8 The chat assistant on business websites (the widget)

What a visitor types to a business's chat assistant, the assistant's replies, the page it was on, and — only if the visitor chooses to leave them — a name, email address or phone number for the business to follow up. The widget sets no cookies and does no tracking; it keeps the conversation in the visitor's browser session only so the thread survives a page change.

3.9 Websites and domains we host for businesses

A business can publish a website we build and connect its own domain. Visits to those sites reach our servers, which keep standard access logs (IP address, page, time, browser type) for security and to keep the site running; we run no analytics or advertising code on them. If a business buys a domain through us we pass the registrant details the registrar requires by law (name, address, email, phone) to the domain registrar.

3.10 Connected email and calendars

A business owner can connect a Gmail inbox so the email assistant can read incoming customer emails and send replies. That uses Google's Gmail permission for reading and for sending; the connection tokens are stored encrypted and the business can disconnect at any time from Settings, which removes them. We read and store only the messages the assistant works on; the assistant drafts or sends replies according to the level of autonomy the business chose. Our use of Google user data follows Google's API Services User Data Policy, including its Limited Use requirements: Gmail data is used only to provide the email-assistant feature, is never used for advertising, and is never read by a person at SENTIREV except with the business's permission to fix a problem, or for security or legal reasons. A business or worker can also connect an external calendar by its private subscription (ICS) address; we fetch that calendar's busy times to avoid clashes, store the address, and never show its contents to anyone else.

3.11 AI tools for businesses

The AI bundles read the business's own data — bookings, services, prices, products, reviews, messages, the material the business uploads (price lists, policies, FAQs) — to produce their output: booking suggestions and slot refills, operations and cost insights, commerce research and listing drafts, website text, email replies, quote drafts and materials lists. Where an AI works on a customer's message or booking, that customer's message and booking details are part of what is processed. Competitor intelligence reads publicly available information about other businesses — the business name, address, rating, review count, opening hours and prices shown on Google's listing and the competitor's own public website. We collect business-level facts only, do not build profiles of individuals from it, and a business can ask us to stop being tracked by emailing us. Google visibility reads the business's own public Google listing to report on it. Everything an AI changes on its own is recorded, shown to the business and reversible. See section 6 for the detail on providers and automated decisions.

3.12 Loyalty, referrals, promotions and win-back

Loyalty stamps and rewards on your account with a business. Referral codes and which business referred which. Promotion codes and paid promoted placement a business buys. Win-back nudges and review invitations a business chooses to send after a visit, with the record of what was sent to whom so nobody is contacted twice for the same thing.

3.13 Team members, staff and independent workers

Name, email address, phone, role, branch, permissions, working hours, time off, the schedule and the bookings assigned to you, sales you make, and — for a self-employed worker — your own prices, cancellation rules, connected Stripe account identifiers and payout status. Cost figures a business owner chooses to enter against services and staff — including how a staff member is paid (rate, basis, bonuses and deductions) — used only in that business's own reports; SENTIREV never moves wages and never shows those figures to the staff member. Team chat messages. If a business invites an existing SENTIREV account to its team, nothing changes until that person accepts.

3.14 Consent, patch-test and similar records (special category)

A business can record that you gave consent for a treatment or passed a patch test: the date, the type, and any note. For some treatments this implies something about your health, so it is special-category data. The business asks for it, decides what it needs, and is the controller; we store it under its instruction, show the business a reminder when a record is missing or out of date, never use it for anything else, and never show it to another business.

3.15 Business finances shown inside SENTIREV

Revenue, costs and margins we calculate from a business's own bookings and orders, and "save up for it" pots — virtual figures the business sets aside on paper. We hold no money for these pots; they are numbers in a report.

3.16 Platform billing

Which AI bundles or promotion a business subscribes to, its Stripe customer and subscription identifiers, invoices and payment status, grants or trials we apply, and usage of each AI allowance so we can enforce fair use.

3.17 Notifications and devices

Push-notification tokens for each phone the app is signed in on, your notification preferences, and a log of what we sent you (reminders, messages, security alerts, admin notices) so we never send the same thing twice.

3.18 Support, safety and technical data

Support conversations and reports you make. An append-only audit trail of security-relevant actions on your account (sign-ins, password and email changes, role changes, team invitations, admin actions on your account, AI actions taken on a business's behalf) which you can see under Account history. Server logs and error reports (which can include your IP address, the page or request that failed, and your account identifier) used to keep the service running and secure. Records of blocks, reports, suspensions and platform bans (section 16).

4. Where the data comes from

  • You — what you type, upload or choose.
  • The business you deal with — bookings it makes for you, notes, imported client details, a quote or invoice addressed to you, a team invitation.
  • Stripe — payment outcomes, disputes and payout status, by reference.
  • Google and Apple — sign-in identifiers when you use them; Google listing data about a business; Gmail data only where a business connects its inbox.
  • Your device — push token, app version and platform, browser type; IP address from the connection.
  • Public sources — public business listings and websites, for competitor intelligence and Google visibility (business facts only).

5. Why we use it and our lawful basis

PurposeExamplesLawful basis (UK GDPR Article 6)
Providing the service you asked forCreating and running bookings, orders, quotes, invoices, messaging; sending confirmations, reminders and receipts; team invitationsPerformance of a contract with you (Art 6(1)(b))
PaymentsTaking deposits and payments through Stripe, refunds, gift cards, membershipsContract; legal obligation for financial records (Art 6(1)(c))
Running a business’s tools on its behalfClient records, notes, consent records, staff schedules, AI drafts, connected emailThe business’s instructions as controller (we are processor, section 7)
Security and fraud preventionLogin lockouts, two-factor, session revocation, anomaly alerts, bans on repeat abusers, audit trailLegitimate interests (Art 6(1)(f)) in keeping the platform and its users safe; legal obligation where applicable
AI featuresBooking autopilot, insights, commerce research, website text, email replies, quote drafts, chat assistantsContract (a business subscribed and switched them on); legitimate interests in operating the marketplace features such as no-show estimates
Competitor and visibility intelligenceReading public listings and websites of other businessesLegitimate interests in providing market information; business-level facts only
Trust, moderation and disputesReviewing reported reviews, media and shops; handling blocks and disputes; keeping evidence of an online acceptanceLegitimate interests; legal obligation
Platform billingSubscriptions, invoices, fair-use allowancesContract; legal obligation
Service messagesSecurity alerts, admin notices about your account, changes to termsLegitimate interests; legal obligation
Improving the serviceFixing errors from error reports, understanding which features are used from our own logs — never third-party analyticsLegitimate interests
ComplianceResponding to lawful requests, tax and accounting records, rights requestsLegal obligation
Special-category recordsConsent and patch-test records a business keeps about youYour explicit consent given to the business (Art 9(2)(a)); the business is controller

Where we rely on legitimate interests we have weighed them against your rights and interests; you can object at any time (section 12). We do not use your data for third-party advertising, and we do not sell it.

6. Artificial intelligence and automated decisions

What the AI sees. For each task the AI is sent only the information that task needs: for a chat reply, the conversation and the business's public information and uploaded material; for a booking suggestion, the diary and the customer's booking history with that business; for a quote draft, the photos and notes the business supplies. It is not sent your password, card details, or data from a different business.

Providers. Our primary AI provider is Anthropic. We keep OpenAI configured as a fallback for when the primary provider is unavailable. Under our agreements with them, content we send is used only to produce the response and is not used to train their models. Providers may hold content briefly for abuse monitoring under their own terms. If both are unavailable, AI features stop rather than guess.

It always says it is automated. Every assistant identifies itself as automated and never claims to be a person.

No solely automated decisions with legal or similarly significant effects. The no-show estimate is a risk score shown to the business to help it decide its own deposit policy; the business decides. AI never moves money, never changes payout details, never changes stock on its own, and never suspends or bans an account. Anything an AI changes by itself is recorded, shown to the business, and can be undone.

Humans stay responsible. Businesses review AI-handled communications and remain responsible for what is said to their customers. If you believe an AI reply was wrong or unfair, tell the business or us and a person will look at it.

Your content and other people's. Material a business uploads for its AI is used to answer for that business only. Businesses must not upload anything they have no right to share, or anyone's personal data beyond what they need for the purpose.

7. Businesses as controllers: our processing terms

This section is the data processing agreement between SENTIREV (processor) and each business that uses SENTIREV to process personal data about its clients, staff and contacts (controller). It forms part of our Terms of Service and satisfies Article 28 UK GDPR.

  • Scope. We process client, staff and contact data on the business's documented instructions — which are the settings and actions the business takes in the product — for the duration of its account, for the purposes of the features it uses.
  • Confidentiality. People working for SENTIREV who can access personal data are bound by confidentiality and access only what is needed for support, security or a legal duty. Support access to a business's dashboard is logged and visible to the business in its Account history.
  • Security. We apply the measures in section 10 and will not lower them without notice.
  • Sub-processors. We use those listed in section 8 and will give notice of any addition or replacement by email or in-product at least 14 days before it takes effect; a business may object on reasonable grounds, and if we cannot resolve the objection it may close its account.
  • Assistance. We help the business respond to rights requests (its clients can also come to us; we will route the request), to security incidents, and to any assessment it must carry out, taking into account the nature of the processing.
  • Breach notice. We notify the business without undue delay after becoming aware of a personal data breach affecting its data, with the information we have.
  • Deletion and return. At the end of the account the business can export its data from the product (account export, order lists, client lists) or ask us for a copy. Terminated businesses have a 5-day reconsideration window, after which personal data is deleted or anonymised, except records we must keep by law (section 11).
  • Audit. We make available the information reasonably necessary to demonstrate compliance and allow audits by the business or an auditor it mandates, on reasonable notice and no more than once a year unless a regulator requires otherwise.

The business's responsibilities

  • Having a lawful basis for the client data it enters, imports or collects through SENTIREV, and telling its clients how it uses their data (its own privacy notice). Imported client lists must be ones the business had the right to bring.
  • Collecting explicit consent itself before recording any consent, patch-test or other health-related record, and recording only what it needs.
  • Sending marketing (win-back nudges, promotions, review invitations) only to people it may lawfully contact, and honouring anyone who asks it to stop.
  • Keeping its own and its staff's login details secure, giving staff only the permissions they need, and removing people who leave.
  • Reviewing AI output before it reaches customers where it has chosen a level of autonomy that allows the AI to act, and not uploading material it has no right to share.
  • Not using SENTIREV to collect or process data it has no right to, to profile people unfairly, or to contact people who have blocked it.

8. Who we share data with (sub-processors)

We share personal data only with the providers below, only for the purpose stated, and with the businesses and people you deal with as described in this policy. We do not sell data and we do not share it with data brokers or advertisers.

ProviderWhat forWhere
StripePayments, deposits, refunds, payouts, subscriptions and platform billing; identity and bank checks for businesses that connect an accountUK/EU and USA
HetznerHosting of our servers and databaseGermany (EU)
AnthropicAI responses for every AI feature (primary provider)USA
OpenAIAI responses only if the primary provider is unavailable (fallback)USA
CloudinaryStoring and resizing photos and images uploaded to profiles, galleries, products, reviews and quotesUSA/EU
GoogleSign in with Google; Places data about businesses for Explore, Google visibility and competitor intelligence; the Gmail API where a business connects its inbox; Firebase Cloud Messaging to deliver Android push notifications; Google Workspace to send our emailsUSA/EU
AppleSign in with Apple; Apple Push Notification service for iPhone notificationsUSA
ExpoRouting push notifications to the mobile appUSA
SentryError monitoring: reports of failures, which can include an IP address, request details and an account identifierUSA/EU
Domain registrarRegistering a custom domain a business buys through us (the registrant details the registrar requires by law)Depends on the domain

Businesses and people you deal with. A business you book with, buy from, message, or accept a quote from sees the details of that interaction: your name, contact details, the booking or order, the address you gave for a home visit or delivery, and your messages. Its staff see what their permissions allow. A self-employed worker you are booked with sees their own bookings with you. They are independent controllers of what they receive.

Other customers. Reviews you write are public under the name on your account. Nothing else about you is visible to other customers.

Legal. We disclose data where the law requires it, to a court or regulator, or where reasonably necessary to protect the safety of people or the integrity of the platform, including to prevent fraud.

Change of ownership. If SENTIREV is sold or merges, data transfers to the new owner under this policy and you will be told.

9. International transfers

Our servers are in the EU (Germany), which the UK recognises as providing adequate protection. Some providers above process data in the United States. Where they do, we rely on the UK Extension to the EU-US Data Privacy Framework where the provider is certified, and otherwise on the UK International Data Transfer Addendum to the EU Standard Contractual Clauses, together with the provider's own security commitments. You can ask us for a copy of the relevant safeguards.

10. Security

  • Everything travels over TLS 1.2 or higher, with HSTS on our domains. The chat widget and business websites are served the same way.
  • Passwords are stored as salted hashes. Two-factor authentication (authenticator app or emailed codes) is available on every account and required for SENTIREV administrators and for business owners.
  • Sign-in is rate-limited and locked for 15 minutes after 5 failed passwords. Sessions can be revoked everywhere at once when you change your password or email, or when we suspend an account.
  • Servers accept key-based administration only, with intrusion blocking and a firewall. Applications run as an unprivileged service account. Secrets are rotated when staff or systems change.
  • Connected-email credentials are stored encrypted with a key held separately from the database.
  • An append-only audit trail records security-relevant actions; anomaly detection alerts us to unusual login or export activity.
  • Encrypted backups are taken daily and stored off-site; restores are tested.
  • Access to personal data by SENTIREV staff is limited to what a task needs and, for business dashboards, is logged and visible to the business.

No system is perfectly secure. If you find a weakness, email support@sentirev.com (see our security.txt). If a breach is likely to put you at risk we will tell you and the ICO as the law requires.

11. How long we keep things

DataKept for
Your account and profileWhile the account is active. After you delete it: removed or anonymised within 30 days
Closed or terminated accounts and businessesA 5-day reconsideration window, then deleted or anonymised (except the records below)
Bookings, orders, quotes, invoices, payments, refunds6 years after the transaction, for tax, accounting and dispute purposes; anonymised where the account is gone
Online quote acceptance record (time, IP, name entered)For the life of the quote and invoice, then with the invoice (6 years)
Messages, team chat, AI conversation logsWhile the account or business they belong to exists
ReviewsWhile the business is listed; anonymised if you delete your account
Consent and patch-test recordsAs the business instructs, and no longer than the business’s account
Connected email tokens and processed emailsUntil the business disconnects the inbox or closes its account
Push tokensUntil you sign out on that device or the token stops working
Sign-in sessions, two-factor challenges, reset and verification linksUntil they expire (hours to days); expired ones are purged automatically
Waiting-list entries and back-in-stock requestsUntil fulfilled, then deleted (waiting-list entries within a week of the date)
Security audit trail and server logsOnly as long as needed for security monitoring, investigations and legal duties, then deleted
Platform ban records (email, phone, IP)For as long as the ban is in force and needed to keep it effective, including after the account is closed; lifted bans are marked as lifted
Error reports (Sentry)Per our retention setting with the provider, then deleted
BackupsRolling window; a deleted record leaves backups as they cycle out

12. Your rights

Under UK GDPR you can ask to access your data, have it corrected, deleted, or exported in a machine-readable form; to restrict or object to processing based on legitimate interests; and to withdraw consent where consent is the basis. You will not be discriminated against for using your rights.

  • In the app or on the web: Account (customers) or Settings (businesses) lets you edit your details, change your email address with confirmation, export your data, and delete your account.
  • By email: support@sentirev.com. We reply within one month. We may need to check it is really you before acting.
  • Data a business holds about you (its notes, consent records, its invoices to you): ask the business, or ask us and we will pass the request on and help.
  • Limits: we keep transaction records we must keep by law, and we may keep a minimal ban record about someone removed for abuse.

You can complain to the Information Commissioner's Office at ico.org.uk. We would appreciate the chance to help first.

13. Marketing and notifications

From us: service messages only — confirmations, reminders, receipts, security alerts, notices about your account, and changes to these terms. We do not send promotional email to customers and we run no advertising.

From businesses through SENTIREV: a business can send you a review invitation after a visit, a win-back nudge if you have not been back for a while, a waiting-list offer, or a promotion. The business chooses to send these and is responsible for having the right to. You can ask the business to stop, block the business from your account, or ask us and we will stop them for you.

Push notifications are controlled in your phone settings and in the app. Email reminders can be turned off in your account.

14. Cookies, local storage and the app

We use only what is needed to run the service. No advertising or cross-site tracking cookies, no third-party analytics, no fingerprinting.

NameWhat it doesLifetime
sv_accessSecure, HttpOnly cookie on api.sentirev.com holding your signed session15 minutes, refreshed while you are active
sv_refreshSecure, HttpOnly cookie used to renew the sessionUp to 7 days, revoked on sign-out
Local storage on app.sentirev.comA flag that you are signed in, your theme (light or dark), unsent drafts of forms such as a business application, dismissed tipsUntil you sign out or clear it
Mobile app secure storageYour session tokens in the device keychain; your theme and preferencesUntil you sign out or remove the app
Chat widgetKeeps the current conversation in the visitor’s browser session onlyCloses with the tab

Because these are strictly necessary, no consent banner is shown. Business websites we host carry no cookies of ours beyond the chat widget behaviour above; a business may not add tracking to a site we host.

15. Children

SENTIREV is not for people under 16. We do not knowingly collect data from under-16s. A business may record a booking for a child made by a parent or guardian; in that case the parent or guardian is our customer and the business is responsible for what it records. If you believe a child has created an account, email us and we will remove it.

16. Safety, moderation and bans

To keep the platform safe we review reported reviews, media and shops, and act on abuse, fraud, harassment, fake bookings and attempts to break security. We may block a customer from a business at the business's request, suspend an account, terminate an account or business, or place a platform ban. A ban record holds the minimum needed to keep it effective: the email address, phone number and IP address associated with the abuse, the reason, who applied it, and when it expires or was lifted. Suspensions end every active session at once. Terminated accounts have a 5-day reconsideration window before deletion. Decisions are made by people; you can ask us to review one by email.

17. Support access to your account

A SENTIREV administrator can open a business's dashboard or a customer's account to help with a problem. That access is time-limited (15 minutes), is recorded in the audit trail, and appears in the account's own Account history so you can see when it happened. Administrators cannot see your password and cannot make payments on your behalf. Administrators can also send you a notice that appears in the app and by email; those are recorded too.

18. Changes to this policy

We update this policy when the product changes. Material changes are announced in the app and by email before they take effect, and every change is listed on our Updates page. The date at the top tells you when it last changed.

19. Contact and complaints

Privacy questions, requests and security reports: support@sentirev.com. Regulator: Information Commissioner's Office, ico.org.uk.