Guests never log in.Staff see only their property.

A review page holds other people's opinions of your business and, in private feedback, things guests would rather not say in public. These are the controls behind that, as built, not as certified.

What is stored about a guest who scans or taps.

DataWhyHow it is kept
Spot the code belongs toWhich campaign and property to creditStored
Scan or tap, and the platform chosenScans, clicks and the platform splitStored
TimeAttribution windows, recency, idle-code alertsStored
Browser family (truncated user-agent)Telling a phone from a bot; crawlers and link previews are not countedStored, truncated
IP addressCounting unique visitorsStored only as a SHA-256 hash — never the address
Name, email, phone, device identifier, precise locationNever collected
Private feedbackReaches the manager, never a listingRating, message, spot, time — no identity fields

"Unique visitors" in the dashboard is counted from the hash. Crawlers and chat link-previewers are recognised and left out, so a shared link does not inflate scans or steal attribution.

Access is granted per property.

A Manager sees reviews, scans and printed codes for the properties they were invited to; an Admin can also invite and remove people; an Owner has full control. The bar manager can be invited to the bar alone.

Team roles per property: Manager, Admin, Owner
Sample data

Controls, as built.

ControlWhat the code does
Guests never log inNo account, no app, no cookie and no tracking pixel on the guest page. The page is served by the product, not by a third party, and makes no AI call.
Access is granted per propertyA Manager sees reviews, scans and printed codes for the properties they were invited to; an Admin can also invite and remove people; an Owner has full control. Every list passes through one scoping rule, and a property you cannot see is not confirmed to exist — the answer is "not found", never "forbidden".
Server-side sessions, not tokensSigning someone out is immediate, because the thing being protected is every private complaint a guest ever left. The last owner of a property cannot be removed or demoted.
Keys stay on the serverThe review-data provider key and the optional Anthropic key for the draft-helper wording never reach a browser. Uploaded logos are raster only; an SVG can carry script, so it is not accepted.
History cannot vanishA spot with printed codes, or a code with scans, refuses deletion. A published address is never taken back: renaming publishes a new one and the old one keeps resolving.
Reports are stored snapshotsA report link is an unguessable token to a saved snapshot, so the numbers you sent in September are the numbers the reader sees in December. Public review pages carry no owner data.

Security questions

Do you sell or share guest data?

There is no guest data to sell: no name, email or device identifier is collected, and the IP address is stored only as a hash. Scan counts and reviews are used to run your account and for nothing else. The public reviews shown in the dashboard are read from the platforms where they were already published.

Where do the reviews in the dashboard come from?

From a review-data provider that reads public reviews on Google, Tripadvisor and Yelp for each property. The product reads reviews; it cannot post, reply or edit anything on a platform. A direct Google Business Profile connection is not offered until Google approves the API access.

Is Review Systems certified?

No certification is claimed on this page because none has been obtained. What is listed here is what the code does; a security questionnaire from your procurement team is answered from the same source.

Who hosts it?

Review Systems runs as its own deployment with its own database; nothing is shared between customers. Email leaves through an SMTP provider; PDFs are rendered by a bundled service that never leaves the deployment.

Read the full FAQ → or contact us

Print one code today.

Add your property, print a code for one spot, and watch the first review land credited.