Full Service Review LLC
Effective date: September 18, 2026 Last updated: September 25, 2026 Version: 2.1
This policy is long because we would rather be thorough. The short version is the following:
We collect what we need to run the service and nothing else. We do not sell your personal information. We have never sold it, we do not have a business model that depends on selling it, and we will not start. We do not share it with advertisers, data brokers, or list vendors. Where we can do a job with anonymous or aggregated data instead of data about you, we do the job that way. Where we hold something about you, you can ask us what it is, ask us to correct it, and ask us to delete it, and we will answer.
Everything below is the detail behind those sentences, section by section. Each section is written to tell you five things: who is involved, what is collected or done, how it happens, why we do it, and what remedy is available to you if you are unhappy about it.
A note on scope. This policy covers everything Full Service Review LLC operates: fullservicereview.com, the free visibility check, the business directory, the account dashboard, the Visible plugin, the FSR badge, and the emails and (if activated) text messages we send. Where a section applies to only part of that, it says so.
Who. The data controller for the processing described in this policy is:
Full Service Review LLC 110 North Hillside Street Wichita, Kansas 67214 United States
Contact for privacy matters.
The address above is a real, monitored channel staffed by a person who can answer substantive questions and act on requests, not a ticket queue that closes without reply.
Where we operate. Full Service Review is offered only in the United States. We do not market the service to, or knowingly collect personal information from, people outside the United States. If that changes, this policy will be updated before the service is offered anywhere else.
Why this matters. Under the California, Colorado, Connecticut, Virginia, Texas, Oregon and similar state privacy statutes, you are entitled to know the identity of the entity making decisions about your data and to have a working way to contact it.
Remedy. If you contact us at the address above and do not receive a substantive human response within thirty days, you may escalate directly to a supervisory authority (Section 16) or to your state Attorney General, and we will not treat having done so as a reason to deprioritize your request.
We use these terms throughout. They are defined here rather than assumed.
| Term | What we mean by it |
|---|---|
| Personal information / personal data | Information that identifies, relates to, or could reasonably be linked with a particular individual or household. We use the two phrases interchangeably. |
| Processing | Anything done with data: collecting, storing, organizing, consulting, transmitting, combining, restricting, erasing. |
| Controller | The party that decides why and how data is processed. |
| Processor | A party that processes data on a controller's instructions and for no purpose of its own. |
| Sub-processor | A vendor engaged by a processor to help perform the processing. |
| Visitor | Someone who browses a public page — fullservicereview.com, an FSR directory listing, or a website that runs the Visible plugin or displays the FSR badge. |
| Account holder | Someone who has registered for an FSR account, whether free or paid. |
| Listed business | A business that appears in the FSR directory, whether or not it has claimed its listing. |
| Agent traffic | Requests made by automated software rather than a person: search crawlers, AI crawlers, link previewers, monitoring tools, security scanners. |
| Aggregate data | Information about a group, from which individual records cannot be singled out or reconstructed. |
| De-identified data | Information we have processed so that it cannot reasonably be linked back to an individual, and which we commit not to attempt to re-identify. |
This is a summary. Sections 4 through 9 give the full detail, including lawful basis and retention.
| Category | Examples | Source | Do we sell it? | Do we share it for advertising? |
|---|---|---|---|---|
| Identifiers | Name, email, business name, phone | You | No | No |
| Account data | Login credentials (hashed), account tier, locations | You | No | No |
| Billing data | Last four digits of card, billing address, invoice history | You, via Stripe | No | No |
| Business listing data | Address, hours, categories, website, social links | You, or public sources | No | No |
| Usage data | Pages viewed in the dashboard, features used | Automatic | No | No |
| Traffic data | Salted daily-rotating visitor hash, referrer origin, coarse timestamp | Automatic | No | No |
| Agent data | User-agent string, bot classification, verification status | Automatic | No | No |
| Communications | Emails you send us, support tickets, form submissions | You | No | No |
| SMS data (if enabled) | Mobile number, consent record, message log | You | Never, under any circumstances | Never, under any circumstances |
One qualification to the last column: the advertising tags on our public marketing pages (Section 10) tell Google and Meta that a visit happened. That is not any of the categories above being handed over, but California law may call it "sharing", so Section 11 treats it as such and gives you the opt-out.
We do not collect and do not want: government identification numbers, payment card numbers (Stripe holds those, we never see them), health information, biometric data, precise geolocation, information about religion, race, ethnicity, sexual orientation, political affiliation, union membership, or immigration status. If you send us any of this unsolicited, we will delete it rather than file it.
Who. Account holders, people who request a free visibility check, people who fill in a contact form, people who email us.
What.
How. Through forms on our site, through Stripe's hosted checkout, and by email.
Why. To create and operate your account, to publish the listing you asked us to publish, to bill you for a service you bought, and to answer you when you write to us. Account, listing and billing data are needed to provide the service you asked for; support correspondence is kept so we can answer you.
Remedy. You can view and edit most of this yourself in your dashboard at any time. Anything you cannot edit yourself, we will correct on request under Section 15. If you believe we hold information you never gave us, tell us and we will trace its origin and tell you what we find.
Who. Anyone who visits fullservicereview.com, including directory listing pages.
What.
How. Server-side, in PHP, at the moment of the request. Our own analytics do not use cookies for this purpose. See Section 10 for cookies generally.
Why. To know whether pages work, to detect abuse and attacks, to report to a listed business how many people clicked from their listing to their site, and to understand which parts of the product are used. This is our legitimate business interest in operating a functioning and secure service, balanced against your interests by the design choices described here — specifically that we do not store raw IP addresses in our application database, do not use persistent identifiers, and do not build profiles.
What we deliberately do not do. We do not fingerprint browsers. We do not use persistent cookies or localStorage for analytics. We do not buy or append third-party data to enrich what we know about you. We do not track you across other websites.
Remedy. If your browser sends a Global Privacy Control signal or a Do Not Track header, our application records nothing about the visit: no visitor hash, no listing view, no click record, no badge impression. The web server's standard access log still receives the request, as it does on every website, and is deleted on the schedule in Section 9. You can also block our analytics entirely with any standard content blocker without degrading the site.
The badge is the small graphic a listed business can display on its own website. It is delivered by a short script loaded from fullservicereview.com, and it links back to the business's listing here.
Who. Visitors to a business's own website where the badge is installed.
What. Each time a page carrying the badge loads, the visitor's browser fetches the badge script from our server. From that request we keep two things: a page-load count for that listing, split between people and known automated crawlers by the browser identification string, and the address of the page the badge sits on, so we can confirm the badge is installed and working. The badge sets no cookie, does not record the visitor's IP address, loads no third-party scripts, and shares nothing with us about the visitor beyond that page-load count. We cannot tell who saw it or link one page load to another.
Reciprocal link disclosure. The badge includes a small link back to fullservicereview.com. This is a reciprocal link: it identifies the badge as ours and lets a visitor verify the listing it represents. The link carries a "sponsored" attribute on paid listings and a "nofollow" attribute on free ones, so it passes no search-engine ranking credit in either direction.
If someone clicks the badge, they arrive at fullservicereview.com, and at that point Section 5.1 applies: a daily-rotating hash, the referring domain, a timestamp.
Why. Because a business that displays the badge deserves to know it is working, and a page-load count is how we show them it is.
Remedy. Remove the badge and the requests stop immediately. The counts already recorded are per-listing totals that contain nothing about any individual.
Who. The Visible plugin is proprietary and only in use on Full Service Review and top-tier retained sites where additional work is requested.
What the plugin does. It emits structured data (schema.org markup) describing the business, and it inspects the user-agent string of incoming requests to classify automated traffic — distinguishing AI training crawlers, retrieval crawlers, and user-triggered agents from ordinary search engines and from human visitors.
What it records. Agent classification, the user-agent string, whether the agent's identity could be verified against its operator's published IP ranges, the URL requested, the HTTP status returned, and a timestamp. Where the plugin records anything about a human visitor, it records the same daily-salted hash construction described in Section 5.1 and never a raw IP address.
Who is the controller here. The website owner is the controller for their own visitors. Full Service Review LLC acts as a processor, handling that data on the owner's instructions and for no purpose of our own. The terms of that relationship are set out in our Data Processing Addendum, which forms part of the FSR agreement and which we will sign as a standalone document on request.
Why. Because knowing which AI systems read your website, and whether they got a working page or an error, is the core thing FSR exists to tell you. It is invisible in every other analytics product.
Remedy. Deactivate the plugin and collection stops immediately. Website owners may also request deletion of their site's collected data at any time, and we will complete it within thirty days. Visitors to a client site who wish to exercise rights should contact that site's owner, who is the controller; if they contact us instead, we will forward the request to the owner within five business days and tell the individual we have done so.
Who. Listed businesses, including those who have not claimed their listing.
What and from where.
How. Automated API calls and ordinary HTTP requests that respect robots.txt.
Why. To build and score directory listings, including unclaimed ones, so that the directory is useful from day one rather than empty. This is our legitimate business interest in operating a directory, which is a long-established and expected activity.
A specific commitment about unclaimed listings. Business contact information is not the same as personal information, but for sole proprietors and very small businesses the two can be the same thing — the "business phone" is a personal mobile, the "business address" is a house. We therefore treat these as follows:
Remedy. Email [email protected] with the listing URL and the word "remove." That is the whole process. A publicly visible listing with a visible removal link is how we tell you we hold this data; if you would prefer direct notice, tell us.
Who. Account holders whose content we generate, and any business we score.
How, and what leaves our systems. For content generation, we send the API the source material and the business's public listing details. We do not send account credentials, billing information, personal information about your customers, or anything from the Visible plugin's traffic logs. Our API provider does not train models on data submitted through the business API.
Why. Because the flagship paid feature is content production.
A commitment about your data and model training. We do not use your data to train AI models. We do not permit our vendors to use data we send them to train their models. If that ever changes, it will require an opt-in from you that is separate from accepting this policy.
Remedy. No automated decision we make produces legal or similarly significant effects on an individual. Regardless: if you believe your score is wrong, you can request a human review at [email protected] or [email protected], we will have a person look at the inputs, and we will tell you what we found and correct it if it is wrong. You may decline AI-generated content entirely and remain a customer.
| Activity | Why | Notes |
|---|---|---|
| Creating and operating an account | To provide the service you asked for | Cannot provide the service without it |
| Processing payment | To provide the service you asked for | Card data handled by Stripe, not us |
| Publishing a claimed listing | To provide the service you asked for | You asked us to publish it |
| Publishing an unclaimed listing | Our legitimate business interest | Directory operation; balanced by no-questions removal |
| Scoring a business | Our legitimate business interest | Assessment of a business, from public signals |
| Site analytics and traffic counts | Our legitimate business interest | Balanced by salted rotating hashes and no raw IP retention |
| Agent/bot classification | Our legitimate business interest | Bots are not people; little to no personal data involved |
| Security, fraud prevention, abuse blocking | Our legitimate business interest | Also a legal obligation in some contexts |
| Transactional email (receipts, alerts) | To provide the service you asked for | Not marketing; cannot be unsubscribed from while you hold an account |
| Marketing email | Your consent where the law requires it; existing customers may hear from us about the service they use | One-click unsubscribe in every message |
| SMS messaging | Your express written consent only | Express written consent; see Section 12 |
| Cookies that are not strictly necessary | Our interest in understanding how the public site is used and which of our own advertising works, with an opt-out you can use at any time | See Section 10 |
| Responding to legal process | Legal obligation | See Section 14 |
Our business-interest assessment, summarized. Where we rely on a business interest, we have asked in each case whether the processing is necessary, whether a less intrusive method would achieve the same result, and whether a reasonable person in your position would find it unexpected. The design choices in this policy — daily-rotating salts, no raw IP retention, no cross-site tracking, no data enrichment, no-questions listing removal — are the output of that assessment, not decoration. You may request our written balancing test.
Remedy. You have an absolute right to object to the use of your information for direct marketing, and we will stop immediately. For other uses based on our business interests you may object, and we will stop unless we can show compelling grounds that override your interests, which we will explain to you in writing rather than assert.
We do not keep data indefinitely by default. Every category has an end date.
| Data | Retention | What happens then |
|---|---|---|
| Raw IP address | Not stored in our application database, with two exceptions: SMS consent records (Section 12) and listing reports (Section 4), each kept only as long as stated in its own row | Discarded at the moment of hashing |
| Web server logs | 30 days | Automatically rotated and deleted |
| Daily visitor hashes | 90 days | Rolled into aggregate counts; hashes deleted |
| Aggregate traffic counts | Indefinitely | Contains no individual records and cannot be reversed |
| Agent/bot logs | 90 days raw, then aggregated | Same rollup treatment |
| Account data | Life of account + 30 days | Deleted after a 30-day grace period following closure |
| Listing content | Life of listing + 30 days | Removed from the public directory immediately on request |
| Billing and invoice records | 7 years | Retained because tax and accounting law requires it; this survives an account deletion request and we will tell you so |
| Support correspondence | 3 years | Deleted |
| Listing reports | 3 years; the IP address and browser string are blanked after 12 months | Deleted; the reference number and decision may be kept in aggregate |
| Marketing email list | Until you unsubscribe + 30 days | Then a suppression record only: your email in hashed form so we do not re-add you |
| SMS consent records | 4 years after opt-out | Required to evidence consent under TCPA; see Section 12 |
| Suppression / do-not-contact lists | Indefinitely | Deleting these would defeat their purpose; they contain only what is needed to keep you off a list |
| Backups | 35 days | Deletion requests are applied to live systems immediately and to backups as they age out; we do not restore a backup to defeat a deletion request |
Why we retain some things after you ask us to delete. Billing records, consent evidence, and suppression lists are the three cases where deletion would either break the law or harm you. Each is listed above with its reason. There is no fourth case, and we will not invent one.
What we set.
| Cookie / storage | Type | Purpose | Duration | Consent needed? |
|---|---|---|---|---|
| Session and auth cookies | Strictly necessary | Keep you logged in | Session to 14 days | No |
| CSRF / nonce tokens | Strictly necessary | Prevent forged requests | Session | No |
| Cookie consent record | Strictly necessary | Remember your choice | 12 months | No |
| Checkout cookies | Strictly necessary | Fraud prevention during payment | Per Stripe | No |
| Google Analytics 4 | Analytics | Understand how visitors use the public site, in aggregate | Up to 2 years | No. On by default; you can turn it off in the cookie banner |
| Google Ads conversion tag | Advertising measurement | Tell Google Ads when a visit led to a free check or a signup, so we can see which ads work | Up to 90 days | No. On by default; you can turn it off in the cookie banner, and a Global Privacy Control signal turns it off for you |
| Meta Pixel | Advertising measurement | Tell Meta when a visit led to a free check or a signup | Up to 90 days | No. On by default; you can turn it off in the cookie banner, and a Global Privacy Control signal turns it off for you |
| Home page delivery | Functional | Remember which version of our home page you saw so it stays the same on your next visit; nothing about you | 90 days | No |
A note about the marketing tags. Our own product analytics are server-side and hash-based (Section 5.1) and set no cookies. The three marketing tags above are different: they are operated by independent controllers, they run only on the public marketing pages of fullservicereview.com, never inside the account dashboard, and under California law the Meta Pixel and the Google Ads tag may count as "sharing" personal information for cross-context behavioral advertising. Section 11 explains what that means and how to opt out.
Who. All visitors.
How you control it. The analytics and advertising tags run by default on our public marketing pages, the way they do on most United States websites. The cookie banner lets you turn either category off; once you do, those tags stay off on every later visit until you change your choice. If your browser sends a Global Privacy Control signal, we treat it as turning the advertising category off, with nothing for you to click. Browser controls also work; nothing on our site breaks if you refuse cookies except staying logged in.
Remedy. Change your choice at any time via the cookie preferences link in the site footer, or clear cookies in your browser.
We do not sell personal information. We have not sold personal information in the preceding twelve months, and we have no plans to.
On "sharing" for advertising. The California Consumer Privacy Act as amended by the CPRA defines "sharing" as disclosing personal information for cross-context behavioral advertising, whether or not money changes hands. Our public marketing pages run a Google Ads conversion tag and a Meta Pixel (Section 10) so we can tell which of our own advertising brought in a visitor. Those tags send Google and Meta an identifier and the fact of your visit, which may meet that definition. We do not send them your name, email, or anything you type. These tags run by default, as they do on most United States websites. You can stop them at any time through the cookie banner or by sending a Global Privacy Control signal, and we treat either as a "Do Not Sell or Share" request. We do not participate in data cooperatives, identity graphs, or clean rooms, and no advertising tag runs inside the account dashboard.
We do not sell or rent our mailing list. We do not sell or rent SMS opt-in data — see Section 12 for the specific carrier-required language.
We do not knowingly collect data about minors. Our service is a business tool sold to businesses. We do not have actual knowledge of selling or sharing the personal information of consumers under sixteen, because we do not sell or share personal information about anyone.
What "sell" means, so this is not a word game. Under the CPRA, "sell" covers disclosing personal information to a third party for monetary or other valuable consideration — which is broad enough to capture arrangements that do not involve money changing hands. We mean the broad version. We do not trade access to information about you for anything of value, in any form, including reciprocal data access, discounted vendor pricing, or co-marketing arrangements.
What we do instead, which is not selling. We disclose data to service providers who process it on our behalf under written contract, for our purposes only, with no right to use it for their own (Section 13). Under CPRA that is a service provider relationship and is expressly not a sale. We also publish aggregate, non-identifying statistics — for example, "AI systems retrieved Full Service Review listings 4,200 times last month." That figure describes a group and cannot be reversed into an individual.
Remedy. Reject the advertising category in the cookie banner, send a Global Privacy Control signal, or email [email protected] with "Do Not Sell or Share My Personal Information." We will confirm in writing. We never sell, so the "sell" half of that request always has nothing to stop; the "share" half switches the advertising tags off for you.
Status: not currently active. This section is written in advance so that the disclosures are in place before any messaging program launches, as carrier registration requires the policy to exist first.
Who. Account holders who explicitly opt in to receive text messages.
What. Your mobile telephone number, a record of your consent including timestamp and the exact language you agreed to, the messages sent and their delivery status, and any STOP or HELP replies.
How consent is obtained. By express written consent, given by you, through an affirmative act — checking an unchecked box or replying to a confirmation message. Consent to receive text messages is never a condition of purchasing any service. Consent is never bundled into acceptance of these terms or of any other agreement. There is no pre-checked box anywhere in our signup flow.
The disclosures carriers require the following information:
The specific commitment required by mobile carriers and The Campaign Registry, stated without qualification:
No mobile information will be sold or shared with third parties or affiliates for marketing or promotional purposes. All of the categories of exclusions listed above exclude text messaging originator opt-in data and consent; this information will not be shared with any third parties.
We share mobile numbers only with the messaging service provider that transmits the message on our behalf, which is a service provider acting on our instructions and which may not use the number for any purpose of its own. That is the only disclosure of your mobile number that occurs.
Why we retain the consent record. The Telephone Consumer Protection Act places the burden of proving consent on the sender. We keep the record for four years after you opt out so that we can demonstrate we had permission, which protects you as much as it protects us.
Remedy. Reply STOP. It takes effect immediately and permanently. If you receive a message after replying STOP, that is a failure on our part — report it to [email protected] and we will investigate and tell you what went wrong.
We disclose personal information to the following categories of recipient and to no others.
We use service providers in these categories. Each is bound by a written contract requiring it to process data only on our instructions, to maintain appropriate security, to assist us with requests about your data, and to delete or return data at the end of the engagement.
Advertisers. Data brokers. List vendors. Marketing cooperatives.
Who. Law enforcement, courts, regulators.
What we do. We require valid legal process. A subpoena, court order, or warrant — appropriate to what is being sought — not an informal request on letterhead. We assess whether the process is facially valid and whether its scope is proportionate, and we push back on requests that are overbroad.
Notice to you. Unless we are legally prohibited from doing so, or unless there is a genuine emergency involving risk of death or serious physical injury, we will notify you before disclosing your data, in time for you to seek to quash it. Being asked not to tell you is not the same as being prohibited, and we treat only the latter as binding.
Transparency. We will publish an annual report of the number of legal requests received and the number complied with, beginning 2027 if the quantity is above zero.
Remedy. If we disclose your data under legal process and later become permitted to tell you, we will.
Your rights depend on where you live. We extend the substance of the strongest set to everyone, because operating two tiers of respect for the same data is not a position we want to be in.
What you can ask for.
| Right | What it means | Available to |
|---|---|---|
| Access / know | A copy of what we hold and an explanation of what we do with it | Everyone |
| Correction | Fix anything inaccurate | Everyone |
| Deletion | Remove your data, subject to the exceptions in Section 9 | Everyone |
| Portability | Receive your data in a structured, machine-readable format (we provide JSON and CSV) | Everyone |
| Object | Stop processing based on legitimate interests | Everyone |
| Restrict | Freeze processing while a dispute is resolved | Everyone |
| Withdraw consent | Where processing rests on consent, take it back; this does not undo what was lawful before | Everyone |
| Opt out of sale/share | Nothing to opt out of, but see Section 11 | Everyone |
| Non-discrimination | We will not degrade your service, raise your price, or treat you worse for exercising a right | Everyone |
| Appeal | If we refuse a request, ask us to reconsider | Everyone |
How to make a request. Email [email protected]. Say what you want. You do not need to cite a statute, use particular wording, or fill in a form.
Verification. We will verify that you are who you say you are, proportionate to the sensitivity of what is being asked. For an account holder, replying from the email address on the account is usually enough. For a deletion of listing data, we do not require verification at all, because the cost of wrongly deleting a listing is low and the cost of making someone prove themselves to be left alone is high. We will never ask you to create an account in order to exercise a right.
Authorized agents. You may use an agent. We will ask for written authorization from you, or a power of attorney.
How long we take.
If we say no. We will tell you which exemption we are relying on, in plain language, and how to appeal. Appeals go to a different person than the one who made the original decision, and we will respond to an appeal within 45 days. If we deny an appeal, we will give you the contact details of your state Attorney General or supervisory authority in the same message.
To us, first, if you are willing. [email protected].
To a regulator, at any time, whether or not you contacted us. You do not need our permission and you do not need to exhaust our process first.
What we do.
What we cannot promise. No system is perfectly secure, and anyone who tells you otherwise is selling something. What we can promise is that we will not quietly absorb a breach.
Breach notification. If a breach affects your personal data and is likely to result in a risk to your rights and freedoms, we will notify you, and any regulator that state breach-notification law requires us to notify, without unreasonable delay and within the timeframes those laws set. Our notice will say what happened, what data was involved, what we have done, and what you should do. We will not wait for a complete investigation before telling you something is wrong.
Reporting a vulnerability. Email [email protected]. We will not pursue legal action against anyone who reports a vulnerability to us in good faith, does not access more data than necessary to demonstrate it, and gives us reasonable time to fix it before disclosing.
The service is a business product sold to businesses and is not directed at children. We do not knowingly collect personal information from anyone under 16. If you believe a child has given us information, write to [email protected] and we will delete it promptly.
How we change it. We will post the updated policy with a new version number and effective date, and keep prior versions available on request so you can see what changed and when.
When we will tell you first. For any change that materially reduces your rights, expands what we collect, or introduces a new purpose, we will give at least 30 days' notice by email before it takes effect. For a change that would require your consent — for example, any use of your data for AI training, or any disclosure that would constitute a sale — we will ask you, and we will treat silence as a no.
Remedy. If you disagree with a change, you may close your account before it takes effect and request deletion, and we will not charge you for the remainder of a prepaid term. That is a real exit, not a formality.
California residents. Sections 3, 9, 10, 11, 13 and 15 together satisfy the CCPA/CPRA notice-at-collection, categories, purposes, disclosure, retention, and rights requirements. We collect the categories of personal information identified in Section 3 and have disclosed the same categories to service providers in the preceding twelve months for the business purposes described. We have sold none. Identifiers and internet activity from our public marketing pages may have been "shared" with Google and Meta through advertising tags, as described in Sections 10 and 11; you may opt out there or through Global Privacy Control. We do not process sensitive personal information for purposes requiring a right-to-limit disclosure. You have the right to know, delete, correct, opt out, and not be retaliated against.
Colorado, Connecticut, Virginia, Texas, Oregon, Montana, and other state privacy law residents. You have rights of access, correction, deletion, portability, and opt-out of targeted advertising, sale, and profiling in furtherance of decisions producing legal or similarly significant effects. We conduct none of those three activities. You have a right to appeal a denied request, described in Section 15. We recognize universal opt-out mechanisms including Global Privacy Control.
Nevada residents. We do not sell covered information as defined by NRS 603A and have no such sales to opt out of.
Privacy: [email protected] Support: [email protected] Security: [email protected] Accessibility: [email protected]
Full Service Review LLC 110 North Hillside Street, Wichita, Kansas 67214, United States