Know which responsibilities stay with the store
Rava Reviews provides tools and contractual information that can support a store's privacy and review-compliance work, but installing an app does not make a store compliant by itself. The rules that apply depend on where the business and its customers are located, what data the store collects, and how the store uses reviews and email.
For customer, order, review, and media data controlled by a merchant, the merchant generally decides why the data is used and Rava generally processes it to provide the service. Under the GDPR, this is commonly described as the controller and processor relationship. Under the California Consumer Privacy Act, as amended by the CPRA, similar responsibilities may be described using business and service-provider language. Read the European Commission's GDPR guidance and the California Attorney General's CCPA overview for the official starting points.
Practical rule: the store chooses the lawful purpose, audience, timing, disclosures, and publication policy. Rava carries out the configured review workflow.
Put the right notices and agreements in place
The store's privacy notice should explain what review data is collected, why order and customer data is used for review requests, what becomes public, which providers receive data, how long data is kept, and how a person can exercise privacy rights. If review photos or videos may show faces, voices, homes, or other people, explain that clearly before submission.
Use Rava's Privacy policy, Data Processing Addendum, Subprocessors list, Security page, Cookie policy, and Terms for vendor review and procurement. These documents describe Rava; they do not replace the merchant's own storefront notice or legal assessment. Keep a current copy of the applicable agreement and review international-transfer safeguards if customer data crosses borders.
Check email consent, unsubscribes, fonts, and tracking
Decide the lawful basis for each review request before enabling automation. A review request may be treated differently from a promotional campaign depending on the message, customer relationship, destination, and local law. Keep the email focused on the completed purchase, avoid adding unrelated marketing unless the recipient is eligible to receive it, and apply any consent filter your policy requires.
Every Rava review request and reminder includes an unsubscribe route, and recorded opt-outs are suppressed from future review-request workflows for that store. Test that flow before launch. If the store requires marketing opt-in as an additional send condition, confirm that the customer data and email configuration enforce it before turning requests on.
Also inspect the live storefront and email experience for third-party fonts, analytics, pixels, or embeds. A remote font or tracking request can transmit technical data such as an IP address and browser details. Prefer the theme's inherited font or a locally hosted font when practical, and place non-essential tracking behind consent where applicable. Rava's public policy pages describe Rava's own current use; the merchant remains responsible for everything else installed on its storefront.
Show shoppers how reviews are collected and moderated
EU consumer rules strengthened by the Omnibus Directive require stores that present consumer reviews to explain whether and how they check that reviews come from people who used or purchased the product. The rules also prohibit fake reviews and misleading claims about verification. See the official text of Directive (EU) 2019/2161.
- Use a verified label only when an order, customer relationship, review request, or another reliable method supports it.
- Keep imported, unverified, translated, or incentivized reviews distinguishable when omitting that context could mislead a shopper.
- Explain the basic collection and moderation process somewhere shoppers can easily reach from the reviews.
- Do not remove a review only because its rating or message is negative.
- Disclose incentives where required, and never make a reward depend on a positive rating or particular sentiment.
Use the Review authenticity policy as the operating standard and Moderate incoming reviews for the daily workflow.
Be ready for privacy and deletion requests
Depending on the person's location, a shopper or reviewer may be able to ask for access, correction, deletion, export, restriction, or another privacy choice. The merchant should provide a clear contact route, verify the requester without collecting unnecessary extra data, and record what was completed.
Separate the parts of the request: account or order data, the public review, reviewer identity, uploaded media, email suppression, and any required business record may need different handling. After removing published material, check the live widgets and cached storefront surfaces. Start with Handle privacy and data requests; contact privacy@ravanix.app when Rava needs to act on merchant-controlled data.
Run this check before publishing
- Link a current store privacy notice at or before review-data collection.
- Review Rava's Data Processing Addendum, subprocessors, security information, and transfer needs.
- Document the lawful basis and eligibility rule for review-request recipients.
- Send a test request and confirm unsubscribe suppression works.
- Inspect the storefront for remote fonts, pixels, embeds, and non-essential cookies.
- Verify that purchase, import, and incentive labels are accurate and that the review process is explained.
- Test moderation with both positive and critical reviews.
- Walk through one access or deletion request from verification to storefront removal.
Repeat the check after changing email content, consent tools, themes, review incentives, integrations, or the countries where the store sells. This guide is operational information, not legal advice; a qualified adviser should review requirements specific to the business.
