Guests never log in.Staff see only their property.
A review page holds other people's opinions of your business and, in private feedback, things guests would rather not say in public. These are the controls behind that, as built, not as certified.
What is stored about a guest who scans or taps.
| Data | Why | How it is kept |
|---|---|---|
| Spot the code belongs to | Which campaign and property to credit | Stored |
| Scan or tap, and the platform chosen | Scans, clicks and the platform split | Stored |
| Time | Attribution windows, recency, idle-code alerts | Stored |
| Browser family (truncated user-agent) | Telling a phone from a bot; crawlers and link previews are not counted | Stored, truncated |
| IP address | Counting unique visitors | Stored only as a SHA-256 hash — never the address |
| Name, email, phone, device identifier, precise location | — | Never collected |
| Private feedback | Reaches the manager, never a listing | Rating, message, spot, time — no identity fields |
"Unique visitors" in the dashboard is counted from the hash. Crawlers and chat link-previewers are recognised and left out, so a shared link does not inflate scans or steal attribution.
Access is granted per property.
A Manager sees reviews, scans and printed codes for the properties they were invited to; an Admin can also invite and remove people; an Owner has full control. The bar manager can be invited to the bar alone.

Controls, as built.
| Control | What the code does |
|---|---|
| Guests never log in | No account, no app, no cookie and no tracking pixel on the guest page. The page is served by the product, not by a third party, and makes no AI call. |
| Access is granted per property | A Manager sees reviews, scans and printed codes for the properties they were invited to; an Admin can also invite and remove people; an Owner has full control. Every list passes through one scoping rule, and a property you cannot see is not confirmed to exist — the answer is "not found", never "forbidden". |
| Server-side sessions, not tokens | Signing someone out is immediate, because the thing being protected is every private complaint a guest ever left. The last owner of a property cannot be removed or demoted. |
| Keys stay on the server | The review-data provider key and the optional Anthropic key for the draft-helper wording never reach a browser. Uploaded logos are raster only; an SVG can carry script, so it is not accepted. |
| History cannot vanish | A spot with printed codes, or a code with scans, refuses deletion. A published address is never taken back: renaming publishes a new one and the old one keeps resolving. |
| Reports are stored snapshots | A report link is an unguessable token to a saved snapshot, so the numbers you sent in September are the numbers the reader sees in December. Public review pages carry no owner data. |
Security questions
Do you sell or share guest data?
There is no guest data to sell: no name, email or device identifier is collected, and the IP address is stored only as a hash. Scan counts and reviews are used to run your account and for nothing else. The public reviews shown in the dashboard are read from the platforms where they were already published.
Where do the reviews in the dashboard come from?
From a review-data provider that reads public reviews on Google, Tripadvisor and Yelp for each property. The product reads reviews; it cannot post, reply or edit anything on a platform. A direct Google Business Profile connection is not offered until Google approves the API access.
Is Review Systems certified?
No certification is claimed on this page because none has been obtained. What is listed here is what the code does; a security questionnaire from your procurement team is answered from the same source.
Who hosts it?
Review Systems runs as its own deployment with its own database; nothing is shared between customers. Email leaves through an SMTP provider; PDFs are rendered by a bundled service that never leaves the deployment.
Keep reading
Page
How Review Systems works — spot, code, guest page, attribution
Property, spot and printed code; one guest page for Google, Tripadvisor and a private note; and how a review is matched back to the scan with its confidence.
Page
FAQ
How the guest page works, what attribution means, what happens to private feedback, what is stored, and what Review Systems will never do with reviews.
Solution
Hotel review collection per spot — QR, NFC, links
Google and Tripadvisor reviews from the front desk, the bar and rooms, and which spot earned each one. Private feedback reaches the manager, not the listing.
Print one code today.
Add your property, print a code for one spot, and watch the first review land credited.