Privacy Policy

Full Service Review LLC

Effective date: September 18, 2026 Last updated: September 25, 2026 Version: 2.1


How to read this document

This policy is long because we would rather be thorough. The short version is the following:

We collect what we need to run the service and nothing else. We do not sell your personal information. We have never sold it, we do not have a business model that depends on selling it, and we will not start. We do not share it with advertisers, data brokers, or list vendors. Where we can do a job with anonymous or aggregated data instead of data about you, we do the job that way. Where we hold something about you, you can ask us what it is, ask us to correct it, and ask us to delete it, and we will answer.

Everything below is the detail behind those sentences, section by section. Each section is written to tell you five things: who is involved, what is collected or done, how it happens, why we do it, and what remedy is available to you if you are unhappy about it.

A note on scope. This policy covers everything Full Service Review LLC operates: fullservicereview.com, the free visibility check, the business directory, the account dashboard, the Visible plugin, the FSR badge, and the emails and (if activated) text messages we send. Where a section applies to only part of that, it says so.


1. Who we are and how to reach us

Who. The data controller for the processing described in this policy is:

Full Service Review LLC 110 North Hillside Street Wichita, Kansas 67214 United States

Contact for privacy matters.

The address above is a real, monitored channel staffed by a person who can answer substantive questions and act on requests, not a ticket queue that closes without reply.

Where we operate. Full Service Review is offered only in the United States. We do not market the service to, or knowingly collect personal information from, people outside the United States. If that changes, this policy will be updated before the service is offered anywhere else.

Why this matters. Under the California, Colorado, Connecticut, Virginia, Texas, Oregon and similar state privacy statutes, you are entitled to know the identity of the entity making decisions about your data and to have a working way to contact it.

Remedy. If you contact us at the address above and do not receive a substantive human response within thirty days, you may escalate directly to a supervisory authority (Section 16) or to your state Attorney General, and we will not treat having done so as a reason to deprioritize your request.


2. Definitions

We use these terms throughout. They are defined here rather than assumed.

Term What we mean by it
Personal information / personal data Information that identifies, relates to, or could reasonably be linked with a particular individual or household. We use the two phrases interchangeably.
Processing Anything done with data: collecting, storing, organizing, consulting, transmitting, combining, restricting, erasing.
Controller The party that decides why and how data is processed.
Processor A party that processes data on a controller's instructions and for no purpose of its own.
Sub-processor A vendor engaged by a processor to help perform the processing.
Visitor Someone who browses a public page — fullservicereview.com, an FSR directory listing, or a website that runs the Visible plugin or displays the FSR badge.
Account holder Someone who has registered for an FSR account, whether free or paid.
Listed business A business that appears in the FSR directory, whether or not it has claimed its listing.
Agent traffic Requests made by automated software rather than a person: search crawlers, AI crawlers, link previewers, monitoring tools, security scanners.
Aggregate data Information about a group, from which individual records cannot be singled out or reconstructed.
De-identified data Information we have processed so that it cannot reasonably be linked back to an individual, and which we commit not to attempt to re-identify.

3. The short version of what we collect, in one table

This is a summary. Sections 4 through 9 give the full detail, including lawful basis and retention.

Category Examples Source Do we sell it? Do we share it for advertising?
Identifiers Name, email, business name, phone You No No
Account data Login credentials (hashed), account tier, locations You No No
Billing data Last four digits of card, billing address, invoice history You, via Stripe No No
Business listing data Address, hours, categories, website, social links You, or public sources No No
Usage data Pages viewed in the dashboard, features used Automatic No No
Traffic data Salted daily-rotating visitor hash, referrer origin, coarse timestamp Automatic No No
Agent data User-agent string, bot classification, verification status Automatic No No
Communications Emails you send us, support tickets, form submissions You No No
SMS data (if enabled) Mobile number, consent record, message log You Never, under any circumstances Never, under any circumstances

One qualification to the last column: the advertising tags on our public marketing pages (Section 10) tell Google and Meta that a visit happened. That is not any of the categories above being handed over, but California law may call it "sharing", so Section 11 treats it as such and gives you the opt-out.

We do not collect and do not want: government identification numbers, payment card numbers (Stripe holds those, we never see them), health information, biometric data, precise geolocation, information about religion, race, ethnicity, sexual orientation, political affiliation, union membership, or immigration status. If you send us any of this unsolicited, we will delete it rather than file it.


4. Information you give us directly

Who. Account holders, people who request a free visibility check, people who fill in a contact form, people who email us.

What.

  • Account registration: name, email address, business name, business address, phone number, website URL, and a password.
  • Business listing details: hours of operation, service categories, description text, social media profile links, calendar or RSS feed URLs you choose to connect.
  • Billing: your billing address, your business tax status, and the last four digits and card brand of your payment method. We never receive or store your full card number, expiry, or security code. Those go directly from your browser to Stripe.
  • Support and contact: whatever you choose to write to us, plus your email address and any attachments.
  • Free visibility check: the website address you ask us to check and the email address you give us to send the result to.
  • Listing reports: if you use the "Report this listing" button on a directory profile, the problem type you choose, your description, your email address, the page you reported from, and the IP address and browser identification of the connection you sent it from. This is one of two places we keep a raw IP address (the other is SMS consent, Section 12). A public form that can take a listing down needs a way to tell a genuine report from a campaign of false ones, and the IP address is that evidence. We blank it after twelve months; the report itself stays so the decision can be explained later.

How. Through forms on our site, through Stripe's hosted checkout, and by email.

Why. To create and operate your account, to publish the listing you asked us to publish, to bill you for a service you bought, and to answer you when you write to us. Account, listing and billing data are needed to provide the service you asked for; support correspondence is kept so we can answer you.

Remedy. You can view and edit most of this yourself in your dashboard at any time. Anything you cannot edit yourself, we will correct on request under Section 15. If you believe we hold information you never gave us, tell us and we will trace its origin and tell you what we find.


5. Information we collect automatically

5.1 On our own websites

Who. Anyone who visits fullservicereview.com, including directory listing pages.

What.

  • A visitor hash, generated from your IP address and user-agent string combined with a secret salt that rotates every twenty-four hours. This lets us count a person once per day without knowing who they are and without being able to link today's visit to yesterday's.
  • The origin of your referrer — the domain you came from, not the full URL of the page you were on.
  • Coarse timestamp, page requested, HTTP status code, and approximate region derived from IP at the point of request.
  • Standard web server logs.

How. Server-side, in PHP, at the moment of the request. Our own analytics do not use cookies for this purpose. See Section 10 for cookies generally.

Why. To know whether pages work, to detect abuse and attacks, to report to a listed business how many people clicked from their listing to their site, and to understand which parts of the product are used. This is our legitimate business interest in operating a functioning and secure service, balanced against your interests by the design choices described here — specifically that we do not store raw IP addresses in our application database, do not use persistent identifiers, and do not build profiles.

What we deliberately do not do. We do not fingerprint browsers. We do not use persistent cookies or localStorage for analytics. We do not buy or append third-party data to enrich what we know about you. We do not track you across other websites.

Remedy. If your browser sends a Global Privacy Control signal or a Do Not Track header, our application records nothing about the visit: no visitor hash, no listing view, no click record, no badge impression. The web server's standard access log still receives the request, as it does on every website, and is deleted on the schedule in Section 9. You can also block our analytics entirely with any standard content blocker without degrading the site.

5.2 The FSR badge and its reciprocal link

The badge is the small graphic a listed business can display on its own website. It is delivered by a short script loaded from fullservicereview.com, and it links back to the business's listing here.

Who. Visitors to a business's own website where the badge is installed.

What. Each time a page carrying the badge loads, the visitor's browser fetches the badge script from our server. From that request we keep two things: a page-load count for that listing, split between people and known automated crawlers by the browser identification string, and the address of the page the badge sits on, so we can confirm the badge is installed and working. The badge sets no cookie, does not record the visitor's IP address, loads no third-party scripts, and shares nothing with us about the visitor beyond that page-load count. We cannot tell who saw it or link one page load to another.

Reciprocal link disclosure. The badge includes a small link back to fullservicereview.com. This is a reciprocal link: it identifies the badge as ours and lets a visitor verify the listing it represents. The link carries a "sponsored" attribute on paid listings and a "nofollow" attribute on free ones, so it passes no search-engine ranking credit in either direction.

If someone clicks the badge, they arrive at fullservicereview.com, and at that point Section 5.1 applies: a daily-rotating hash, the referring domain, a timestamp.

Why. Because a business that displays the badge deserves to know it is working, and a page-load count is how we show them it is.

Remedy. Remove the badge and the requests stop immediately. The counts already recorded are per-listing totals that contain nothing about any individual.

5.3 The Visible plugin

Who. The Visible plugin is proprietary and only in use on Full Service Review and top-tier retained sites where additional work is requested.

What the plugin does. It emits structured data (schema.org markup) describing the business, and it inspects the user-agent string of incoming requests to classify automated traffic — distinguishing AI training crawlers, retrieval crawlers, and user-triggered agents from ordinary search engines and from human visitors.

What it records. Agent classification, the user-agent string, whether the agent's identity could be verified against its operator's published IP ranges, the URL requested, the HTTP status returned, and a timestamp. Where the plugin records anything about a human visitor, it records the same daily-salted hash construction described in Section 5.1 and never a raw IP address.

Who is the controller here. The website owner is the controller for their own visitors. Full Service Review LLC acts as a processor, handling that data on the owner's instructions and for no purpose of our own. The terms of that relationship are set out in our Data Processing Addendum, which forms part of the FSR agreement and which we will sign as a standalone document on request.

Why. Because knowing which AI systems read your website, and whether they got a working page or an error, is the core thing FSR exists to tell you. It is invisible in every other analytics product.

Remedy. Deactivate the plugin and collection stops immediately. Website owners may also request deletion of their site's collected data at any time, and we will complete it within thirty days. Visitors to a client site who wish to exercise rights should contact that site's owner, who is the controller; if they contact us instead, we will forward the request to the owner within five business days and tell the individual we have done so.


6. Information we get from other sources

Who. Listed businesses, including those who have not claimed their listing.

What and from where.

  • Google Business Profile and similar services: business name, address, phone, hours, categories, aggregate rating and review count. This is business information published by the business itself to Google.
  • Public web pages: we read an organization's own website to find social profile links, aggregated content, and to check whether the site is reachable by AI crawlers.
  • Trend Analysis Tools: search trend and result data at the query level.
  • Domain registration records and similar services: domain registration age, for assessing how established a web presence is.
  • Phone verification tools and similar services: validation that a phone number is a real, correctly formatted line — not who owns it.

How. Automated API calls and ordinary HTTP requests that respect robots.txt.

Why. To build and score directory listings, including unclaimed ones, so that the directory is useful from day one rather than empty. This is our legitimate business interest in operating a directory, which is a long-established and expected activity.

A specific commitment about unclaimed listings. Business contact information is not the same as personal information, but for sole proprietors and very small businesses the two can be the same thing — the "business phone" is a personal mobile, the "business address" is a house. We therefore treat these as follows:

  • We publish only what the business has already published about itself elsewhere.
  • We accept a removal request from a business at face value and do not require proof of identity to remove a listing, only to claim one.
  • We honor removal within seven days and do not re-create the listing from the same source afterward, because we maintain a suppression list keyed to the domain.
  • Where an address appears to be residential, we will display the city and region rather than the street address on request, without argument.

Remedy. Email [email protected] with the listing URL and the word "remove." That is the whole process. A publicly visible listing with a visible removal link is how we tell you we hold this data; if you would prefer direct notice, tell us.


7. Artificial intelligence and automated processing

Who. Account holders whose content we generate, and any business we score.

  1. The AI visibility score. A weighted assessment of publicly observable signals about a business's web presence, how consistently the business is described across the sources AI systems rely on, and how AI systems respond when asked about businesses like it. The score is computed by our own software from those inputs; the specific signals, their weighting, and how they are combined are proprietary and change over time. The score does not produce legal or similarly significant effects about a person. It is an assessment of a business's web presence, not of any individual.
  2. Content generation. For account holders on tiers that include it, we use third-party large language models to sample what AI assistants say about a business and, on tiers that include it, to draft news summaries and content about a business's industry.

How, and what leaves our systems. For content generation, we send the API the source material and the business's public listing details. We do not send account credentials, billing information, personal information about your customers, or anything from the Visible plugin's traffic logs. Our API provider does not train models on data submitted through the business API.

Why. Because the flagship paid feature is content production.

A commitment about your data and model training. We do not use your data to train AI models. We do not permit our vendors to use data we send them to train their models. If that ever changes, it will require an opt-in from you that is separate from accepting this policy.

Remedy. No automated decision we make produces legal or similarly significant effects on an individual. Regardless: if you believe your score is wrong, you can request a human review at [email protected] or [email protected], we will have a person look at the inputs, and we will tell you what we found and correct it if it is wrong. You may decline AI-generated content entirely and remain a customer.


8. Why we use each category of information

Activity Why Notes
Creating and operating an account To provide the service you asked for Cannot provide the service without it
Processing payment To provide the service you asked for Card data handled by Stripe, not us
Publishing a claimed listing To provide the service you asked for You asked us to publish it
Publishing an unclaimed listing Our legitimate business interest Directory operation; balanced by no-questions removal
Scoring a business Our legitimate business interest Assessment of a business, from public signals
Site analytics and traffic counts Our legitimate business interest Balanced by salted rotating hashes and no raw IP retention
Agent/bot classification Our legitimate business interest Bots are not people; little to no personal data involved
Security, fraud prevention, abuse blocking Our legitimate business interest Also a legal obligation in some contexts
Transactional email (receipts, alerts) To provide the service you asked for Not marketing; cannot be unsubscribed from while you hold an account
Marketing email Your consent where the law requires it; existing customers may hear from us about the service they use One-click unsubscribe in every message
SMS messaging Your express written consent only Express written consent; see Section 12
Cookies that are not strictly necessary Our interest in understanding how the public site is used and which of our own advertising works, with an opt-out you can use at any time See Section 10
Responding to legal process Legal obligation See Section 14

Our business-interest assessment, summarized. Where we rely on a business interest, we have asked in each case whether the processing is necessary, whether a less intrusive method would achieve the same result, and whether a reasonable person in your position would find it unexpected. The design choices in this policy — daily-rotating salts, no raw IP retention, no cross-site tracking, no data enrichment, no-questions listing removal — are the output of that assessment, not decoration. You may request our written balancing test.

Remedy. You have an absolute right to object to the use of your information for direct marketing, and we will stop immediately. For other uses based on our business interests you may object, and we will stop unless we can show compelling grounds that override your interests, which we will explain to you in writing rather than assert.


9. Retention: how long we keep things

We do not keep data indefinitely by default. Every category has an end date.

Data Retention What happens then
Raw IP address Not stored in our application database, with two exceptions: SMS consent records (Section 12) and listing reports (Section 4), each kept only as long as stated in its own row Discarded at the moment of hashing
Web server logs 30 days Automatically rotated and deleted
Daily visitor hashes 90 days Rolled into aggregate counts; hashes deleted
Aggregate traffic counts Indefinitely Contains no individual records and cannot be reversed
Agent/bot logs 90 days raw, then aggregated Same rollup treatment
Account data Life of account + 30 days Deleted after a 30-day grace period following closure
Listing content Life of listing + 30 days Removed from the public directory immediately on request
Billing and invoice records 7 years Retained because tax and accounting law requires it; this survives an account deletion request and we will tell you so
Support correspondence 3 years Deleted
Listing reports 3 years; the IP address and browser string are blanked after 12 months Deleted; the reference number and decision may be kept in aggregate
Marketing email list Until you unsubscribe + 30 days Then a suppression record only: your email in hashed form so we do not re-add you
SMS consent records 4 years after opt-out Required to evidence consent under TCPA; see Section 12
Suppression / do-not-contact lists Indefinitely Deleting these would defeat their purpose; they contain only what is needed to keep you off a list
Backups 35 days Deletion requests are applied to live systems immediately and to backups as they age out; we do not restore a backup to defeat a deletion request

Why we retain some things after you ask us to delete. Billing records, consent evidence, and suppression lists are the three cases where deletion would either break the law or harm you. Each is listed above with its reason. There is no fourth case, and we will not invent one.


10. Cookies and similar technologies

What we set.

Cookie / storage Type Purpose Duration Consent needed?
Session and auth cookies Strictly necessary Keep you logged in Session to 14 days No
CSRF / nonce tokens Strictly necessary Prevent forged requests Session No
Cookie consent record Strictly necessary Remember your choice 12 months No
Checkout cookies Strictly necessary Fraud prevention during payment Per Stripe No
Google Analytics 4 Analytics Understand how visitors use the public site, in aggregate Up to 2 years No. On by default; you can turn it off in the cookie banner
Google Ads conversion tag Advertising measurement Tell Google Ads when a visit led to a free check or a signup, so we can see which ads work Up to 90 days No. On by default; you can turn it off in the cookie banner, and a Global Privacy Control signal turns it off for you
Meta Pixel Advertising measurement Tell Meta when a visit led to a free check or a signup Up to 90 days No. On by default; you can turn it off in the cookie banner, and a Global Privacy Control signal turns it off for you
Home page delivery Functional Remember which version of our home page you saw so it stays the same on your next visit; nothing about you 90 days No

A note about the marketing tags. Our own product analytics are server-side and hash-based (Section 5.1) and set no cookies. The three marketing tags above are different: they are operated by independent controllers, they run only on the public marketing pages of fullservicereview.com, never inside the account dashboard, and under California law the Meta Pixel and the Google Ads tag may count as "sharing" personal information for cross-context behavioral advertising. Section 11 explains what that means and how to opt out.

Who. All visitors.

How you control it. The analytics and advertising tags run by default on our public marketing pages, the way they do on most United States websites. The cookie banner lets you turn either category off; once you do, those tags stay off on every later visit until you change your choice. If your browser sends a Global Privacy Control signal, we treat it as turning the advertising category off, with nothing for you to click. Browser controls also work; nothing on our site breaks if you refuse cookies except staying logged in.

Remedy. Change your choice at any time via the cookie preferences link in the site footer, or clear cookies in your browser.


11. We do not sell your data

We do not sell personal information. We have not sold personal information in the preceding twelve months, and we have no plans to.

On "sharing" for advertising. The California Consumer Privacy Act as amended by the CPRA defines "sharing" as disclosing personal information for cross-context behavioral advertising, whether or not money changes hands. Our public marketing pages run a Google Ads conversion tag and a Meta Pixel (Section 10) so we can tell which of our own advertising brought in a visitor. Those tags send Google and Meta an identifier and the fact of your visit, which may meet that definition. We do not send them your name, email, or anything you type. These tags run by default, as they do on most United States websites. You can stop them at any time through the cookie banner or by sending a Global Privacy Control signal, and we treat either as a "Do Not Sell or Share" request. We do not participate in data cooperatives, identity graphs, or clean rooms, and no advertising tag runs inside the account dashboard.

We do not sell or rent our mailing list. We do not sell or rent SMS opt-in data — see Section 12 for the specific carrier-required language.

We do not knowingly collect data about minors. Our service is a business tool sold to businesses. We do not have actual knowledge of selling or sharing the personal information of consumers under sixteen, because we do not sell or share personal information about anyone.

What "sell" means, so this is not a word game. Under the CPRA, "sell" covers disclosing personal information to a third party for monetary or other valuable consideration — which is broad enough to capture arrangements that do not involve money changing hands. We mean the broad version. We do not trade access to information about you for anything of value, in any form, including reciprocal data access, discounted vendor pricing, or co-marketing arrangements.

What we do instead, which is not selling. We disclose data to service providers who process it on our behalf under written contract, for our purposes only, with no right to use it for their own (Section 13). Under CPRA that is a service provider relationship and is expressly not a sale. We also publish aggregate, non-identifying statistics — for example, "AI systems retrieved Full Service Review listings 4,200 times last month." That figure describes a group and cannot be reversed into an individual.

Remedy. Reject the advertising category in the cookie banner, send a Global Privacy Control signal, or email [email protected] with "Do Not Sell or Share My Personal Information." We will confirm in writing. We never sell, so the "sell" half of that request always has nothing to stop; the "share" half switches the advertising tags off for you.


12. SMS and text messaging

Status: not currently active. This section is written in advance so that the disclosures are in place before any messaging program launches, as carrier registration requires the policy to exist first.

Who. Account holders who explicitly opt in to receive text messages.

What. Your mobile telephone number, a record of your consent including timestamp and the exact language you agreed to, the messages sent and their delivery status, and any STOP or HELP replies.

How consent is obtained. By express written consent, given by you, through an affirmative act — checking an unchecked box or replying to a confirmation message. Consent to receive text messages is never a condition of purchasing any service. Consent is never bundled into acceptance of these terms or of any other agreement. There is no pre-checked box anywhere in our signup flow.

The disclosures carriers require the following information:

  • Message frequency varies. You will typically receive one or fewer messages per day.
  • Message and data rates may apply. Your mobile carrier may charge you for messages sent to or from you. We do not control those charges.
  • To stop receiving messages, reply STOP to any message. You will receive one final confirmation and then no further messages.
  • For help, reply HELP or contact [email protected] or 316-519-9900.
  • Carriers are not liable for delayed or undelivered messages.
  • Supported carriers: Pending Activation.

The specific commitment required by mobile carriers and The Campaign Registry, stated without qualification:

No mobile information will be sold or shared with third parties or affiliates for marketing or promotional purposes. All of the categories of exclusions listed above exclude text messaging originator opt-in data and consent; this information will not be shared with any third parties.

We share mobile numbers only with the messaging service provider that transmits the message on our behalf, which is a service provider acting on our instructions and which may not use the number for any purpose of its own. That is the only disclosure of your mobile number that occurs.

Why we retain the consent record. The Telephone Consumer Protection Act places the burden of proving consent on the sender. We keep the record for four years after you opt out so that we can demonstrate we had permission, which protects you as much as it protects us.

Remedy. Reply STOP. It takes effect immediately and permanently. If you receive a message after replying STOP, that is a failure on our part — report it to [email protected] and we will investigate and tell you what went wrong.


13. Who we share data with

We disclose personal information to the following categories of recipient and to no others.

13.1 Service providers and sub-processors

We use service providers in these categories. Each is bound by a written contract requiring it to process data only on our instructions, to maintain appropriate security, to assist us with requests about your data, and to delete or return data at the end of the engagement.

  • Payment processing and subscription billing: name, email, billing address. Card details go directly from you to the payment processor and never touch our servers.
  • Email delivery: name, email address, message content.
  • Business-listing, search and domain data providers: business names, addresses and website queries; no account-holder identifiers.
  • AI providers used to sample what assistants say about a business and, on tiers that include it, to draft content: public listing details and source material only. They may not train on what we send.
  • Content delivery, DNS and security: request metadata and the IP address at the network edge.
  • Application and database hosting: all account and application data.
  • Text-message transmission, only if messaging is activated: mobile number and message body.

13.2 Other disclosures

  • To the public, but only what you chose to publish: your directory listing. Your AI visibility score and your content-source panel are never shown publicly; they are visible only to you and to our administrators.
  • To account holders who run the Visible plugin, where we act as their processor — the data about their own website's traffic.
  • In a business transfer, if Full Service Review LLC is acquired, merges, or reorganizes. If that happens we will give notice before your data becomes subject to a different policy, and the acquirer will be bound by commitments no weaker than these.
  • For legal reasons — see Section 14.

13.3 Who we never share with

Advertisers. Data brokers. List vendors. Marketing cooperatives.


14. Legal process and government requests

Who. Law enforcement, courts, regulators.

What we do. We require valid legal process. A subpoena, court order, or warrant — appropriate to what is being sought — not an informal request on letterhead. We assess whether the process is facially valid and whether its scope is proportionate, and we push back on requests that are overbroad.

Notice to you. Unless we are legally prohibited from doing so, or unless there is a genuine emergency involving risk of death or serious physical injury, we will notify you before disclosing your data, in time for you to seek to quash it. Being asked not to tell you is not the same as being prohibited, and we treat only the latter as binding.

Transparency. We will publish an annual report of the number of legal requests received and the number complied with, beginning 2027 if the quantity is above zero.

Remedy. If we disclose your data under legal process and later become permitted to tell you, we will.


15. Your rights and how to exercise them

Your rights depend on where you live. We extend the substance of the strongest set to everyone, because operating two tiers of respect for the same data is not a position we want to be in.

What you can ask for.

Right What it means Available to
Access / know A copy of what we hold and an explanation of what we do with it Everyone
Correction Fix anything inaccurate Everyone
Deletion Remove your data, subject to the exceptions in Section 9 Everyone
Portability Receive your data in a structured, machine-readable format (we provide JSON and CSV) Everyone
Object Stop processing based on legitimate interests Everyone
Restrict Freeze processing while a dispute is resolved Everyone
Withdraw consent Where processing rests on consent, take it back; this does not undo what was lawful before Everyone
Opt out of sale/share Nothing to opt out of, but see Section 11 Everyone
Non-discrimination We will not degrade your service, raise your price, or treat you worse for exercising a right Everyone
Appeal If we refuse a request, ask us to reconsider Everyone

How to make a request. Email [email protected]. Say what you want. You do not need to cite a statute, use particular wording, or fill in a form.

Verification. We will verify that you are who you say you are, proportionate to the sensitivity of what is being asked. For an account holder, replying from the email address on the account is usually enough. For a deletion of listing data, we do not require verification at all, because the cost of wrongly deleting a listing is low and the cost of making someone prove themselves to be left alone is high. We will never ask you to create an account in order to exercise a right.

Authorized agents. You may use an agent. We will ask for written authorization from you, or a power of attorney.

How long we take.

  • Acknowledgment: within 5 business days.
  • Substantive response: within 30 days, extendable once by a further 60 days for genuinely complex requests, in which case we will tell you why within the first 30.
  • No charge, unless a request is manifestly unfounded or repetitive, in which case we will tell you the fee before doing the work rather than after.

If we say no. We will tell you which exemption we are relying on, in plain language, and how to appeal. Appeals go to a different person than the one who made the original decision, and we will respond to an appeal within 45 days. If we deny an appeal, we will give you the contact details of your state Attorney General or supervisory authority in the same message.


16. Complaints

To us, first, if you are willing. [email protected]. 

To a regulator, at any time, whether or not you contacted us. You do not need our permission and you do not need to exhaust our process first.

  • California: the California Privacy Protection Agency, cppa.ca.gov, or the Attorney General at oag.ca.gov.
  • Other US states: your state Attorney General.

17. Security

What we do.

  • TLS on every connection; HSTS enabled; legacy protocols (TLS 1.0 and 1.1) and weak cipher suites disabled.
  • Passwords stored using a modern one-way hash. We cannot read your password and will never ask you for it.
  • Card data never touches our servers.
  • Least-privilege access. Administrative access is limited to staff who need it and is reviewed periodically.
  • Webhook signature verification and idempotency on all payment events.
  • Automated dependency and malware scanning across our infrastructure.
  • Encrypted backups with a defined retention window.

What we cannot promise. No system is perfectly secure, and anyone who tells you otherwise is selling something. What we can promise is that we will not quietly absorb a breach.

Breach notification. If a breach affects your personal data and is likely to result in a risk to your rights and freedoms, we will notify you, and any regulator that state breach-notification law requires us to notify, without unreasonable delay and within the timeframes those laws set. Our notice will say what happened, what data was involved, what we have done, and what you should do. We will not wait for a complete investigation before telling you something is wrong.

Reporting a vulnerability. Email [email protected]. We will not pursue legal action against anyone who reports a vulnerability to us in good faith, does not access more data than necessary to demonstrate it, and gives us reasonable time to fix it before disclosing.


18. Children

The service is a business product sold to businesses and is not directed at children. We do not knowingly collect personal information from anyone under 16. If you believe a child has given us information, write to [email protected] and we will delete it promptly.


19. Changes to this policy

How we change it. We will post the updated policy with a new version number and effective date, and keep prior versions available on request so you can see what changed and when.

When we will tell you first. For any change that materially reduces your rights, expands what we collect, or introduces a new purpose, we will give at least 30 days' notice by email before it takes effect. For a change that would require your consent — for example, any use of your data for AI training, or any disclosure that would constitute a sale — we will ask you, and we will treat silence as a no.

Remedy. If you disagree with a change, you may close your account before it takes effect and request deletion, and we will not charge you for the remainder of a prepaid term. That is a real exit, not a formality.


20. Jurisdiction-specific disclosures

California residents. Sections 3, 9, 10, 11, 13 and 15 together satisfy the CCPA/CPRA notice-at-collection, categories, purposes, disclosure, retention, and rights requirements. We collect the categories of personal information identified in Section 3 and have disclosed the same categories to service providers in the preceding twelve months for the business purposes described. We have sold none. Identifiers and internet activity from our public marketing pages may have been "shared" with Google and Meta through advertising tags, as described in Sections 10 and 11; you may opt out there or through Global Privacy Control. We do not process sensitive personal information for purposes requiring a right-to-limit disclosure. You have the right to know, delete, correct, opt out, and not be retaliated against.

Colorado, Connecticut, Virginia, Texas, Oregon, Montana, and other state privacy law residents. You have rights of access, correction, deletion, portability, and opt-out of targeted advertising, sale, and profiling in furtherance of decisions producing legal or similarly significant effects. We conduct none of those three activities. You have a right to appeal a denied request, described in Section 15. We recognize universal opt-out mechanisms including Global Privacy Control.

Nevada residents. We do not sell covered information as defined by NRS 603A and have no such sales to opt out of.

 


21. Contact

Privacy: [email protected] Support: [email protected] Security: [email protected] Accessibility: [email protected]

Full Service Review LLC 110 North Hillside Street, Wichita, Kansas 67214, United States

 

Free Listing Offer Ends Nov 1. See More 21 days   left Claim free listing