Privacy Policy

Last updated: 13 August 2026

1. Who We Are

fairstar.dev ("we", "us") is currently developed and operated by an individual based in Belgium. The Service is not currently operated through a registered company; this section will be updated with formal registration details once an entity is incorporated. For any data protection question, request, or complaint, contact us via email. We aim to respond to all privacy requests within 30 days, in line with GDPR requirements.

Depending on the specific processing activity, we act as the data controller (for example, for business owner account data) or as a joint controller together with the site owner embedding our widget (for example, for reviews submitted on their site).

2. Privacy Philosophy

We build privacy-first, lightweight review tools. We do not track users across the web, build advertising profiles, or sell or monetize personal information.

3. Data We Collect From Reviewers, and Why

A. Identity Verification (Legal basis: legitimate interest in fraud and spam prevention)

To prevent spam and fake reviews, identity verification is conducted via OAuth 2.0 through the provider you choose (Google, GitHub, or LinkedIn). We receive a unique provider user ID and your public account name. Depending on the provider and your account privacy settings, we may or may not receive your email address. Some providers do not share it, or allow you to withhold it. We issue a short-lived, cryptographically signed session token solely to authenticate your submission.

B. Review Content & Display Name (Legal basis: your consent)

Your rating (1–5 stars), review text, and public display name (editable before submission) are published publicly on the website where the review was submitted, only after you explicitly check the consent box confirming you agree to this public display.

C. Optional Email for Reply Notifications (Legal basis: your consent)

If you opt in to be notified when a business replies to your review:

  • Never shared: Your email address is never passed, exposed, or sold to third parties, other websites, or the owner of the site where you left the review.
  • Encrypted at rest using industry-standard encryption prior to database storage.
  • Automatically deleted 10 days after submission. After this period only a pseudonymized provider ID remains, used solely to enforce the one-review-per-account limit.

D. Local Draft Storage

Our widget uses your browser's localStorage strictly to save your review draft locally, so content isn't lost if you close or refresh the page. This storage is essential for functionality, does not track you across sites, and is never transmitted to us until you submit.

4. Data We Collect From Site / Business Owners, and Why

  • Account email (legal basis: performance of our agreement with you), used only to send operational notices, updates, and review alerts. Encrypted at rest. Never sold or shared for marketing.
  • Widget configuration and allowed domains (legal basis: legitimate interest in security), used to enforce origin checks and prevent unauthorized use of your widget ID.

5. Where Your Data Is Stored & International Transfers

Our infrastructure runs on Cloudflare. Data is primarily stored in the EU-West region. Cloudflare may cache or replicate certain data across its global network, including locations outside the European Economic Area, to deliver fast load times worldwide. Where this occurs, the transfer is covered by Cloudflare's Data Processing Addendum and Standard Contractual Clauses. Cloudflare, the OAuth providers you choose to authenticate with, and any other infrastructure or service providers we use to operate the Service act as our data processors or sub-processors. A current list of sub-processors is available on request.

6. Data Retention

  • Reviewer email (if opted in for notifications): deleted automatically after 10 days.
  • Provider ID, star rating, review text, display name: retained for as long as the review remains published, or until you request deletion.
  • Business owner account email and widget configuration: retained for the life of the account, deleted upon account closure request.

7. Your Rights (GDPR)

If you are in the EU/EEA or UK, you have the right to:

  • Access the personal data we hold about you;
  • Request correction of inaccurate data;
  • Request erasure of your data (subject to our anti-fraud pseudonymization noted above);
  • Restrict or object to certain processing;
  • Request a portable copy of your data;
  • Withdraw consent at any time, without affecting past processing;
  • Lodge a complaint with your local supervisory authority. In Belgium, this is the Gegevensbeschermingsautoriteit (Data Protection Authority), Drukpersstraat 35, 1000 Brussels (gegevensbeschermingsautoriteit.be).

To exercise any of these rights, contact us via email.

8. Children's Privacy

The Service is not directed at individuals under 16, and we do not knowingly collect personal data from them. If you believe a minor has submitted data through our widget, contact us and we will delete it.

9. Security

We apply industry-standard technical and organizational measures to protect personal data, including encryption of sensitive fields at rest and short-lived authentication tokens. No system is 100% secure, and we cannot guarantee absolute security of information transmitted to us.

10. Changes to This Policy

We may update this Privacy Policy as the Service evolves, including once a formal business entity is registered. We will update the "Last updated" date above and, for material changes, provide notice on the site or by email where applicable.

11. Contact

For any privacy question or request, reach out via email.