Data Protection Policy
Adapt Progress Evolve Limited, trading as ReviewNudge, protects the personal data of its users and their customers under the UK GDPR and the Data Protection Act 2018. This page summarises the policy; the full text is rendered at reviewnudge.app/data-protection.
Controller
Adapt Progress Evolve Limited, registered in England and Wales, is the controller for data processed through ReviewNudge. Where a business owner uses ReviewNudge to process their own customers' data, that owner is the controller and ReviewNudge is the processor acting on their instructions.
Data protection principles
Personal data is processed lawfully, fairly and transparently; collected for specified and legitimate purposes only, never repurposed for marketing or sold; limited to what is necessary, which for SMS delivery is a name and a phone number; kept accurate, with owners able to update their own and their customers' records from the dashboard; retained for the subscription term plus 12 months and then deleted, with rate-limiting IP records purged on a rolling basis; and protected by appropriate technical and organisational measures.
Technical and organisational measures
- All data in transit encrypted with TLS
- Row-level security policies, so each business owner can reach only their own data
- API keys stored as SHA-256 hashes — plaintext keys are never persisted
- Twilio webhook signatures verified to prevent spoofed inbound messages
- Rate limiting on public endpoints: 100 requests per hour per IP per business
- Card data handled entirely by Stripe and never stored on our systems
- Production access restricted to authorised personnel; sessions use secure httpOnly tokens
Sub-processors and international transfers
We do not sell, rent or trade personal data, and do not share it for marketing. Sub-processors are Supabase (database and authentication), Twilio (SMS delivery), Vonage (back-up SMS), Stripe (payments), Resend (transactional and contact-form email) and Google (Place ID lookup at onboarding). Where data reaches the United States we rely on UK adequacy regulations, ICO-approved Standard Contractual Clauses, or a UK International Data Transfer Agreement under Chapter V of the UK GDPR.
Rights, breaches and complaints
Individuals may exercise their UK GDPR rights through support. Reportable breaches are notified to the ICO within 72 hours and to affected individuals where the risk is high. Complaints can be raised with us and then with the ICO. See also the privacy policy.
ReviewNudge · Pricing · Free trial · ROI calculator · Blog · Support · Stop SMS · Privacy · Terms
ReviewNudge is an operating name of Adapt Progress Evolve Limited, registered in England and Wales. Built by Jack Stovell.