StarvoStarvo
Pricing
Back to home

Privacy Policy

What we collect, how we use it, and the rights you have over your data.

Last updated: May 23, 2026

The short version
We collect account, business, and review data to run Starvo. We do not sell it. We do not train AI models on it. Customers' reviews are processed on your behalf (you are the controller; we are the processor — see theDPA). Cookies: essential auth only — see theCookie Policy.

1. Who We Are & Our Role

Starvo ("Starvo", "we", "us") operates the review-management platform atstarvo.app. Starvo is operated as a sole proprietorship byShiva Kumar Esakki Pandiyan, based in Hyderabad, Telangana, India. See theTerms of Service, Section 0, for full legal-identity details.

Roles for the data we handle:

  • For an account-holder (a business owner using Starvo), we are thedata controller / Data Fiduciaryof your account data.
  • For the customer reviews your QR codes collect, the business owner is thecontroller / Data Fiduciary, and Starvo acts as aprocessor / Data Processoron the owner's behalf. This relationship is governed by ourData Processing Agreement, which forms part of these terms for every business owner subject to the GDPR, the UK GDPR, or the Indian Digital Personal Data Protection Act 2023.
Grievance Officer
In accordance with Rule 3(1)(a) of the IT Rules 2021 and the DPDPA 2023, our Grievance Officer isShiva Kumar Esakki Pandiyan, contactable atgrievance@starvo.app. General privacy enquiries:privacy@starvo.app. Complaints are acknowledged within 48 hours and resolved within 15 days under the IT Rules (30 days for data-principal requests under the DPDPA).

2. What Data We Collect

We only collect what is necessary to run the service. Specifically:

CategoryExamplesWho can see it
Account dataEmail, hashed password (Supabase Auth), optional profile name; Google OAuth id + email if you use Google sign-inYou + Starvo (account ops)
Business dataName, type, Google review URL, logo, locations, team emails/roles, templates, country/timezone/currencyYour Owner / Manager / Staff per role
Customer review dataRating, optional feedback, optional email, salted IP hash (rate-limit only), timestampsYour team; Starvo as processor
Synced Google reviewsPublic review text, rating, author display name; OAuth access/refresh tokens for your GBPYour team; tokens locked from staff SELECT
Payment metadataBilling email, country, subscription status, Dodo IDs (never card numbers)Dodo (MoR) + Starvo entitlement records
Consent & ops logsTerms acceptances; request/error/cron logs; optional WhatsApp message rowsStarvo ops; WhatsApp visible to Owner/Manager
  • Submitters can review anonymously by leaving the email field blank.
  • Cookies — strictly necessary auth/session cookies only (Supabase). No advertising or third-party tracking cookies.
  • Starvo never sees, processes, or stores card numbers, CVV, or other payment instrument data.

3. Legal Basis for Processing (EU / UK / EEA)

If GDPR or UK GDPR applies to you, the legal bases we rely on are:

  • Contract (Art. 6(1)(b))— to provide the Service you signed up for: hosting your account, displaying your dashboard, processing your subscription.
  • Legitimate interests (Art. 6(1)(f))— for security, abuse prevention, rate limiting, IP-hash duplicate detection, and basic operational logging. We balance these interests against your rights.
  • Legal obligation (Art. 6(1)(c))— to retain limited records required by tax, accounting, or anti-fraud law.
  • Consent (Art. 6(1)(a))— for the optional Google Business Profile integration (you explicitly authorise via OAuth), the optional WhatsApp channel (you set up the number), and any future marketing emails (we will ask separately before sending any).

3A. Legal Basis for Processing (India — DPDPA 2023)

Starvo is operated from India and is aData Fiduciaryunder India's Digital Personal Data Protection Act, 2023 ("DPDPA") for the personal data of Indian Data Principals. Section 4 of the DPDPA permits processing for a lawful purpose for which the Data Principal has either given consent or for which consent is implied under one of the "certain legitimate uses" (Section 7).

For Indian Data Principals, our lawful bases are:

  • Consent (DPDPA Section 6)— for account creation, the optional Google Business Profile integration, the optional WhatsApp channel, and any future marketing emails. Consent is captured at the relevant opt-in point and can be withdrawn at any time, with the same effort as it was given.
  • Certain legitimate uses (DPDPA Section 7)— for processing necessary to perform the Service you signed up for, for compliance with law, and for prevention and investigation of fraud and abuse of the Service.

Rights of Indian Data Principals. Under the DPDPA you have the right to: access a summary of the personal data we process about you and the processing activities; correct, complete, or update inaccurate or incomplete personal data; erase personal data that is no longer necessary for the purpose for which it was collected; nominate another person to exercise your rights in the event of your death or incapacity; and grievance redressal. To exercise any of these rights, email our Grievance Officer atgrievance@starvo.app. We respond within the time prescribed by the DPDPA (currently 30 days) and never within fewer than the timeframes prescribed by the IT Rules 2021 for related grievances (15 days).

Grievance escalation. If you are not satisfied with our response, you may approach the Data Protection Board of India once it is constituted, or any other competent authority under Indian law.

4. How We Use Your Data

We use the data above only to:

  • Provide the Service: serve QR codes, run your dashboard, run reviews through analysis, generate AI reply drafts when you click Generate, sync Google reviews when you connect Google.
  • Notify you about activity (new reviews, weekly digest, monthly report) and operational matters (account, billing, security).
  • Send customer-facing emails on your behalf when you choose to (apology, discount, thank-you).
  • Process subscription payments through Dodo Payments.
  • Detect, investigate, and prevent abuse — rate limiting, duplicate detection, sanctions checks.
  • Comply with legal obligations and respond to lawful requests from authorities.

We do not sell, rent, or share your datawith anyone for marketing or advertising.We do not train any AI model on your data.Our business model is your subscription — that's it.

5. Automated Decision-Making & AI

Starvo uses AI (via Groq) for two things, both of which require your explicit click:

  • Reply drafts. When you click "Generate reply", we send the review text, your business name, business type, and any active templates to the AI provider to produce a draft. You always edit and send manually — there is no auto-publication.
  • Sentiment & topic analysis. Reviews are run through a lightweight tagging step (positive/negative, topic categories) so you can sort and filter them.

No solely-automated decisions with legal or similarly significant effects are made about any individual. AI is a drafting and labelling aid; humans make every send/publish/resolve decision. Our current AI provider, Groq, processes Starvo's requests under its enterprise terms which, as of the date of this Policy, include a commitment not to retain request content for training. We do not use the content to train third-party models. If we change AI provider or those underlying terms change materially, we will update this Policy. For Groq's current terms seegroq.com/privacy-policy.

6. Sharing Data with Third Parties (Sub-processors)

We rely on a small set of carefully chosen providers to run the Service. They each receive only the data they need to perform their function and are bound by their own privacy commitments.

  • Supabase— managed PostgreSQL, authentication, file storage. Receives: account, business, and review data.
  • Vercel— application hosting and CDN. Receives: HTTP requests; no direct database access.
  • Dodo Payments— Merchant of Record. Receives: billing email, country, subscription details. Card data stays with Dodo under PCI-DSS.
  • Groq— AI inference. Receives: review text and business metadata only when you click Generate or when a review is analysed.
  • Resend— transactional email. Receives: recipient email and message content for outbound mail.
  • Google— Business Profile API, only if you connect via OAuth.
  • Meta (WhatsApp Cloud API)— optional; only if you provide WhatsApp credentials.

Changes to our sub-processor list. We may add or replace sub-processors as the Service evolves. For business owners covered by ourData Processing Agreement, we will give at least 30 days' advance notice by email before a new sub-processor begins processing your personal data, and you may object during that window (see the DPA for the objection mechanism). For all other users, material changes are reflected on this page.

7. International Data Transfers

Starvo is operated from India. Several of our sub-processors are based in the United States or operate globally. This means your data may be transferred to and processed outside your country of residence, including outside the European Economic Area.

Where personal data of EEA / UK individuals is transferred to a country without an EU/UK adequacy decision, the transfer is protected by the relevant provider's Standard Contractual Clauses (SCCs) and supplementary measures, in line with the GDPR Chapter V requirements. The major sub-processors named above publish their SCCs and Data Processing Addenda on their websites.

8. Data Retention

We keep your data only as long as we need it:

  • Active account data— kept while your account is active.
  • Soft-deleted account data— kept for 48 hours after you (or an admin) initiate deletion, to allow recovery, then permanently deleted by a scheduled job.
  • Customer review data— kept while the owning business's account is active. Permanently deleted when the account is hard-deleted.
  • Billing records— retained by Dodo under their policy and tax law; Starvo keeps subscription metadata while the account exists.
  • Consent records— kept for at least three years after the account closes.
  • Operational logs— typically rotated within 30 days; security logs may be kept longer to investigate abuse.

9. Data Storage & Security

  • Encryption in transit. HTTPS / TLS on every connection, HSTS preloaded.
  • Encryption at rest. Provided by our database and storage providers (Supabase, Vercel) at the infrastructure level.
  • Row-level security. Every table has database-level access policies. OAuth token columns are additionally locked at the column level.
  • Server-enforced authorisation. Every API route verifies ownership; UI gating is defence in depth, not the gate.
  • Secrets. API keys and credentials are environment variables — never in code or client bundles.
  • Webhooks. All incoming webhooks (Dodo, WhatsApp) are signature-verified before processing.
  • Account take-over protection. Email confirmation is required before an invite can be claimed.

10. Data Breach Notification

If we become aware of a personal-data breach that is likely to result in a risk to your rights and freedoms, we will notify you and the relevant supervisory authority without undue delay, and where feasible within 72 hours of becoming aware (in line with GDPR Article 33).

Notice to you will be sent to the email address on your account and will include the nature of the breach, the categories of data affected, the measures we have taken, and any steps you can take to protect yourself.

10A. California Residents (CCPA / CPRA)

This section applies if you are a California resident and the California Consumer Privacy Act, as amended by the California Privacy Rights Act (together, the "CCPA/CPRA"), applies to you. Starvo does not meet the CCPA's applicability thresholds today, but we honour these rights regardless for any California user.

  • Categories of personal information we collect — identifiers (email, account ID), commercial information (subscription / payment metadata via Dodo), internet activity (login, scan, reply events), and inferences (sentiment / topic tags on reviews). See Section 2 for the full inventory.
  • Sources — directly from you, automatically from your interactions with the Service, and from Google when you authorise the Google Business Profile integration.
  • Business purposes — providing and improving the Service, communicating with you, processing payments via our Merchant of Record, securing the Service, and complying with the law (the same purposes described in Section 4).
  • Sale of personal information. We do not sell your personal information as "sale" is defined under the CCPA/CPRA, and we have not sold personal information in the preceding 12 months.
  • Sharing for cross-context behavioural advertising. We do not share personal information for cross-context behavioural advertising. We do not have a "Do Not Sell or Share My Personal Information" link because there is nothing to opt out of.
  • Sensitive personal information — used solely to run the Service (account credentials); no CPRA "limit" trigger applies.
  • California "Shine the Light" (Cal. Civ. Code § 1798.83) — we do not share personal information with third parties for those third parties' own direct marketing purposes.
  • Your CCPA/CPRA rights — to know, access, delete, correct, opt out of sale/sharing (N/A), limit sensitive PI (N/A), and non-discrimination. Exercise any of these by emailingprivacy@starvo.appfrom the email on your account.
  • Authorised agents — written, signed authorisation required; we may verify directly with you.

11. Your Rights

If you are located in the European Economic Area, the United Kingdom, India, or any other region with equivalent data-protection law, you have the rights below. We honour them globally where the underlying processing makes them applicable.

  • Access— Request a copy of the personal data we hold about you.
  • Portability— Customer list exportable as CSV from your dashboard; full machine-readable export on request.
  • Rectification— Most fields editable in Dashboard → Settings; otherwise email us.
  • Erasure— Delete from Dashboard → Settings → Delete account (48-hour soft-delete), or request by email.
  • Objection / Restriction— Email us; some processing must continue for legal obligations (e.g. invoices).
  • Withdraw consent— Where processing is consent-based (Google, WhatsApp, future marketing), withdraw anytime.
  • Complain to a supervisory authority— Always available; we prefer you tell us first so we can fix it.

For any request you cannot self-serve, emailprivacy@starvo.appfrom your account email address. We verify the request comes from you and respond within 30 days — usually much sooner.

Data Protection Officer. Starvo does not engage in large-scale systematic monitoring of individuals, nor process special categories of data as a core activity, and is therefore not required to appoint a Data Protection Officer under Article 37 of the GDPR. The named Grievance Officer (grievance@starvo.app) and the privacy contact (privacy@starvo.app) handle all data-protection enquiries. We will appoint a DPO if the scope of processing later triggers that requirement.

12. Children & Age Thresholds

Starvo is not directed to children. The applicable minimum ages differ by context:

  • Account holdersmust be at least18(or the age of majority in their jurisdiction if higher). SeeTermsSection 1.
  • Customers submitting a review through a QR code are the business owner's end customers; Starvo does not knowingly collect personal data through this surface from anyone under 16 (EEA/UK) or 13 (United States, COPPA). Review submission is optional and can be anonymous.

If you believe a child below the relevant threshold has provided personal data to us, emailprivacy@starvo.appand we will delete it without delay.

13. Cookies

Starvo uses only strictly necessary cookies — the session cookies that keep you logged in (issued by Supabase Auth). These are essential for the Service to function and do not require consent under GDPR / ePrivacy.

We do not use advertising cookies, marketing pixels, third-party analytics (such as Google Analytics), or cross-site tracking. If we ever add optional analytics, it will be opt-in. Full detail — including cookie names, durations, third-party redirects, and how to delete cookies — is in our dedicatedCookie Policy.

14. Customer Reviews Submitted Through Your QR

When a customer of a Starvo user submits a review through a QR code, Starvo processes that data on behalf of the business owner, who is thecontrollerof the review data. Starvo's role isprocessor.

Business owners are responsible for: providing their own privacy notice to their customers; responding to data-subject requests from their customers; and complying with applicable law for the collection and storage of customer feedback. Starvo will reasonably assist owners when notified atprivacy@starvo.app.

15. Changes to This Policy

We may update this Policy. For material changes, we will notify you by email and post a banner in the dashboard at least 30 days before they take effect. The most recent update date is shown at the top of this page.

16. Contact

Questions, requests, or concerns about this policy or your personal data:privacy@starvo.app— read directly by the founder.

Related:Terms·DPA·Cookie Policy·Security·Acceptable Use·Refund.

Disclaimer & Updates

These pages describe how Starvo operates as a product. They are not legal advice. We may update them; for material changes we notify signed-in users by email and/or post a notice on the site or in the dashboard. The date at the top of each page is authoritative.

Related:Privacy·Terms·Refund·Cookies·DPA.

StarvoStarvo

Review management for local businesses. Turn every customer into a 5-star Google review.

Founder: Shiva Kumar Esakki Pandiyan

  • GitHub · github.com/shivae372
  • X · x.com/shivae372
  • Instagram · instagram.com/shivae372
Starvo - Smart QR codes to get more 5-star Google reviews | Product Hunt
Listed on BacklinkLog
Product
  • Features
  • AI Replies
  • Google Reviews
  • Review Management
  • Negative Review Recovery
  • Staff Management
  • Pricing
Industries
  • Restaurants
  • Cafés
  • Hotels
  • Salons
  • Gyms
  • Clinics
  • All industries
Guides
  • All guides
  • Get more Google reviews
  • Respond to bad reviews
  • QR review system setup
  • GBP optimization
  • The review funnel
Compare
  • Compare matrix
  • All alternatives
  • Starvo vs Podium
  • Starvo vs Birdeye
  • Starvo vs NiceJob
  • vs Reputation.com
  • Review management software
  • Google review management
Resources
  • Blog
  • Changelog
  • About
  • Founder
  • Documentation
  • Help Center
  • FAQ
  • Security
  • Billing
  • Refund
  • Contact
  • X · @starvo_app
  • Product Hunt
  • Capterra
  • Privacy
  • Cookie Policy
  • Terms
  • Acceptable Use
  • Data Processing Agreement
© 2026 Starvo™. All rights reserved. · Shiva Kumar Esakki Pandiyan, founderCancel anytime · No lock-in
Starvo - Smart QR codes to get more 5-star Google reviews | Product HuntListed on BacklinkLog
© 2026 Starvo™. All rights reserved.Privacy PolicyTerms of ServiceSupportShiva Kumar Esakki Pandiyangithub.com/shivae372x.com/shivae372instagram.com/shivae372@starvo_app