Legal
Privacy Policy
What StarProof collects, who controls it, and the choices available to businesses and to the people they message.
Last updated: 24 July 2026
1. Who we are
StarProof is operated by OMNIAMUS S.R.L., Ploiești, Romania ("StarProof", "we", "us"). Contact us at contact@omniamus.com.
2. Two kinds of people, two different roles
StarProof serves businesses that use our app to collect reviews, and the customers of those businesses who receive a review request.
For a business's own account we are the data controller. For the contact details and feedback of that business's customers we act as a processor on the business's behalf — the business decides who is contacted and why. If you are a customer and want your data corrected or erased, contact the business that messaged you; we will assist them, but we act on their instructions.
3. What we collect from businesses
- Account details: email address, a hashed password, and your business name.
- Your public review link and chosen review platform.
- Subscription and billing status from Stripe. We never see or store your card number.
- Technical logs needed to operate and secure the service.
4. What we process about customers
We process this only to deliver the review request on behalf of the business and to show that business its own results. We do not build customer profiles across businesses.
- The name, email address and/or phone number the business gives us in order to send a review request.
- Whether the request was opened, and whether the recipient went on to leave a public review (we record that they clicked through — not what they wrote, which lives on the review platform).
- Any private feedback and star rating the recipient chooses to send back to the business.
5. How review requests are sent
Requests are sent by email (through Resend) and/or SMS (through Twilio). We send only to the contacts a business provides. The business is responsible for having the right to contact those people under the applicable law (such as GDPR and e-privacy/marketing rules). SMS messages include an opt-out instruction.
6. Payments
Business subscriptions are processed by Stripe under its own privacy policy. We receive the outcome and the card's brand or last digits where Stripe shows them; we never receive full card numbers.
7. What we never do
- We do not sell personal data.
- We do not use advertising SDKs or advertising identifiers.
- We do not use one business's customer list for our own marketing.
- We do not filter or hide negative reviews, and we do not divert unhappy customers away from the public review — the private-feedback option is offered alongside it, never as a gate.
8. Service providers
We share data only as necessary with the providers that run StarProof: Railway (hosting), Neon (database), Vercel (web pages), Stripe (payments), Resend (email) and Twilio (SMS). We may also disclose information when legally required, to protect rights and safety, or in a corporate transaction.
9. International transfers
Some providers may process information outside your country, including in the United States. Where required, we rely on safeguards such as the European Commission's Standard Contractual Clauses.
10. Retention
Business accounts and their data are kept until the account is deleted. Deleting a business erases its account and all its review requests, including the customer contact details attached to them. Records we must keep for accounting or tax, and Stripe's payment records, are retained for the period the law requires.
11. Security
Passwords are stored hashed. Data is encrypted in transit, access is restricted, and review links use unguessable tokens. No service can guarantee absolute security.
12. Your rights
Depending on where you live, you may request access, correction, deletion, portability or restriction of your personal data. Businesses can delete everything from the app. Customers should contact the business that messaged them; if you cannot reach them, write to us and we will help. You may also complain to your local data-protection authority.
13. Children
StarProof is a tool for businesses and is not directed to children. We do not knowingly collect personal data from children.
14. Changes and contact
We may update this policy as StarProof evolves; the current version is always published here. Privacy questions go to contact@omniamus.com or OMNIAMUS S.R.L., Ploiești, Romania.