Privacy Policy
Vouch helps local businesses ask their own customers for honest reviews. This policy explains what data we handle, why, how long we keep it, and how to make us delete it. It is written to be read, not to be survived.
In this policy, "business" means a business that uses Vouch. "Customer" means an individual who visited that business and may receive a review request from us on the business's behalf.
1. Who we are
Vouch is operated from Delhi NCR, India, at vouch4u.net. For any privacy question, data request, or complaint, contact ankush@rebal.tech or message us on WhatsApp at +91 98186 28694. We reply to every privacy request within seven days.
2. What we collect
| Data | Where it comes from | Why we have it |
|---|---|---|
| Business name, address, contact person, phone, email | The business, when signing up | To operate the account and contact them |
| Customer first name and phone number or email | Uploaded or connected by the business, or given to us by the customer when they scan a QR code or message us | To send the review request the business has asked us to send |
| Message and response data — sent, delivered, opened, clicked, replied, opted out | Generated as we operate | To avoid asking the same person twice, to honour opt-outs, and to report results to the business |
| Review draft text and the customer's edits | The customer, in our review helper | To show the customer their own draft, and to demonstrate that the published words were theirs |
| Google Business Profile data — location details, reviews, ratings, replies | Google's Business Profile APIs, only after the business connects their account | To show the business their reviews and to post replies they have approved |
We do not collect payment card details — payments are handled by our payment provider. We do not knowingly collect data about anyone under 18.
3. Consent, and who is responsible for it
When a business gives us customer contact details, that business confirms it has a lawful basis to share them with us and to have review requests sent. We act as a processor on the business's instructions for that data.
Under India's Digital Personal Data Protection Act, consent must be free, specific, informed, unconditional and unambiguous. Consent given for one purpose — completing a transaction, booking an appointment — does not automatically extend to marketing or review requests. We tell every business this plainly at sign-up, and we keep an auditable consent record so it can be produced if a customer or a regulator asks.
Where a customer contacts us first — by scanning a QR code or messaging our WhatsApp number — that customer has initiated contact directly, and we record that as the basis for replying to them.
4. Opting out
Any customer can stop hearing from us, at any time, by any reasonable means. Reply STOP, reply in plain words, tell the business, or email us. We do not require a form, an account, or a specific keyword.
We action opt-outs within one business day, and we apply them across every channel — WhatsApp, SMS and email — not only the one the request arrived on. An opt-out is permanent unless the customer asks us to reverse it.
5. Google user data — limited use
When a business connects its Google Business Profile, we access that data through Google's Business Profile APIs, and our use is limited to providing and improving the features that business asked for. Specifically:
- We access only Business Profiles the business owns or is authorised to manage, and only after they explicitly grant access.
- We do not cache or store Google Business Profile content for longer than 30 calendar days, in line with Google's API policies. Cached content is refreshed or deleted within that window.
- We never post a reply to a review without the business's explicit approval of that specific reply. There is no blanket auto-reply. Every published reply is approved by a named user, and we log who approved it and when.
- We notify the business of any change we make on their behalf within 48 hours.
- We do not sell Google user data, use it for advertising, or transfer it except to the sub-processors listed below, or where the law requires it.
- If a business ends their relationship with us, we remove our delegated permissions and give them at least seven business days to disassociate our account and regain full control of their profile.
- A business can revoke our access at any moment from their own Google account, without telling us first.
6. How we use AI
We use a large language model to draft suggested review text from the things a customer themselves selects or says. That draft is always shown to the customer, always editable, and only ever published by the customer's own action. We do not publish a review on anyone's behalf, and we do not generate reviews for people who did not visit the business. Customer content is not used to train third-party models.
7. Who else sees the data
We use a small number of service providers to run the product: cloud hosting, a database provider, messaging providers for WhatsApp, SMS and email, an AI model provider for drafting, and a payment provider. They process data only to deliver their service to us. We do not sell personal data to anyone, ever, and we do not share it for anyone else's advertising.
8. How long we keep things
- Google Business Profile content: maximum 30 calendar days, per Google's API policies.
- Customer contact details: for as long as the business remains a customer, and deleted within 30 days of their account closing.
- Message and consent records: retained for up to 24 months after the last message, because consent and opt-out evidence is exactly what a business needs if a complaint is ever raised. Opt-out records are kept indefinitely, so that we never message someone who has asked us not to.
9. Your rights
Any individual can ask us what data we hold about them, ask us to correct it, or ask us to delete it. Email ankush@rebal.tech and we will respond within seven days. If a request relates to data a business gave us, we will tell that business, since they may hold their own copy we cannot reach.
10. Security
Data is encrypted in transit and at rest. Access is limited to people who need it to run the service. We do not share account passwords or credentials with anyone, and we will tell affected businesses without delay if we ever become aware of unauthorised access.
11. Changes
If we change this policy in a way that materially affects how we handle personal data, we will tell current businesses by email before it takes effect, and update the date at the top.