Privacy Policy
Resenix ("we") analyzes public customer reviews to help businesses improve their reputation. This policy explains what personal data we process, why, and the rights you have under the GDPR. The data controller is Resenix; you can reach us at hello@resenix.com.
1. Data we collect
Account data: email address, a hashed password (never the password itself), optional name, and your language and theme preferences.
Business data: the Google Maps URLs you submit, the public reviews we fetch for them, and the analyses, scores and reports we generate.
Billing: handled end to end by Polar as Merchant of Record. We never store card details; we keep only order and subscription references.
Technical data: server logs (IP address, user agent) kept for security and abuse prevention, and pseudonymous product analytics events (PostHog, EU cloud).
2. How we use it and legal bases
To provide the service you request — running analyses, rendering reports, radar monitoring (performance of a contract).
To send service emails: verification, password reset, report delivery and digest emails you enabled (performance of a contract).
To keep the service secure and prevent abuse (legitimate interest).
To understand product usage through EU-hosted, pseudonymous analytics without advertising trackers (legitimate interest).
Marketing emails only with your explicit opt-in (consent, revocable at any time).
3. Google user data (Business Profile)
If you connect your Google Business Profile, we access — with your explicit permission (scope business.manage) — your business locations, their reviews, and we publish the review replies you approve.
Refresh tokens are encrypted at rest (AES-256-GCM); short-lived access tokens are never stored. We do not sell Google user data, do not use it for advertising, and no human reads it except for support with your consent.
Our use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
You can disconnect at any time from Settings in Resenix, or revoke access from your Google Account security settings (myaccount.google.com/permissions).
4. Processors and third parties
Anthropic (AI analysis, US — your data is not used to train models), Outscraper (fetching public Google Maps reviews), Resend (transactional email), Polar (billing, Merchant of Record), Neon (Postgres database, EU region), Vercel (hosting, EU region), PostHog (product analytics, EU cloud).
5. International transfers
Our infrastructure runs in the EU. Where a processor operates from the US (e.g. Anthropic, Resend), transfers are safeguarded by Standard Contractual Clauses and/or the EU-US Data Privacy Framework.
6. Retention
Account data is kept until you delete your account; deletion is immediate and cascades to your analyses and connections. One-shot reports remain available for the access window stated at purchase. Backups expire on a rolling schedule.
7. Your rights
Under the GDPR you can access, rectify, erase, port, restrict or object to the processing of your data. Most actions are self-service from the dashboard; for anything else write to hello@resenix.com. You can also lodge a complaint with your supervisory authority (in Spain, the AEPD).
8. Cookies
Strictly necessary cookies: session (Auth.js), language and theme preferences, the guest-score ownership token, and a 10-minute signup handoff. Product analytics identifiers (PostHog, EU) are pseudonymous. No third-party advertising trackers.
9. Changes
We will update this page when the policy changes and notify you by email about material changes.
Questions? Write to hello@resenix.com