Account and billingWorkspace and account

Security and privacy questions

Short answers on where your data is kept, who processes it, sign-in security, team access, and deleting and exporting your data.

Quick answers for a security, IT or legal review. Each one links to the article with the steps, or to the public page that holds the full statement: our Security page, Subprocessor Register and privacy policy.

Where is my data stored, and can I choose a region?

Your testimonials, files and videos are kept with the hosting, database, storage and video providers named in our Subprocessor Register. Our privacy policy says these providers may process information in the United States and in the other countries where they operate.

There's no setting for choosing a country or region, in your workspace's settings or in a project's. If your review needs the location details that apply to your account, the register gives the address to ask.

Who else processes my data?

The providers that host, store and deliver ReTestimonial, some that help us find errors and understand how the dashboard is used, and others that are used only when a feature needs them, such as email, payments, gift cards, AI features and review imports. The Subprocessor Register names each one, what it's used for and which kinds of data it may handle.

The privacy policy also says we don't sell personal information and don't use your customers' testimonials for third-party advertising.

Is my data encrypted?

Connections to ReTestimonial use HTTPS, so data is encrypted on its way to and from us. For stored data, our Security page says the database and storage providers encrypt it as part of their platforms.

Does ReTestimonial have a SOC 2 or ISO 27001 certificate?

No. ReTestimonial holds neither certificate, and no outside penetration test has been done. Our Security page says so, and lists the safeguards that are in place instead. If your review needs a specific question answered in writing, that page gives the address to write to.

Can my team sign in with SAML or single sign-on (SSO)?

No. Everyone signs in to their own account with Continue with Google, with an email address and password, or with a one-time code we email them. SAML and single sign-on through an identity provider such as Okta aren't offered.

For what each person can set up on their account, see Update your profile and sign-in security.

Is two-step verification available, and can I require it for my team?

Yes, it's available. Each person turns it on for their own account under Security in Account Settings, using an authenticator app, with backup codes in case they lose their phone. Codes by text message aren't offered. See Turn on two-step verification.

You can't require it. It's each person's own setting, and a workspace owner can't turn it on for teammates.

Who in my team can see testimonials and customers' email addresses?

Everyone you give access to a project. Admins, Members and Viewers can all open its inbox and read its testimonials, and a customer's email address isn't hidden from any of them: searching the inbox for an address finds its testimonial.

Only the workspace owner and Admins can download every address at once with Export to CSV, or open the project's Email Log, which lists who each email was sent to. To keep a project away from a teammate, set their role in it to No Access, and it no longer appears for them. See Roles.

A customer asked me to remove their testimonial. What do I do, and what is deleted?

Delete it: in the inbox, click Show more on its card, then Delete. Only the workspace owner and the project's Admins can delete; see What each action does. To take a testimonial off your site but keep it, archive it instead.

Deleting is permanent. The testimonial goes with its translations and AI analysis, and it leaves your widgets, Walls of Love, its share page and its video player, though a cached page can take a little while to catch up. Its uploaded photos, audio and video are deleted too, except a video that a copy of the testimonial in another project still uses. Its earlier deliveries are removed from your webhook delivery log, and a gift card still waiting for approval is canceled. If it came through one of your forms, the answers, email address and IP address saved with that submission are removed too. The form's Analytics still count the submission.

Three more places are cleared with it:

  • Notifications. The ones that named the customer, such as "… submitted a new testimonial", leave your team's notification lists.
  • The Email Log. The emails about that testimonial are blanked: the address, subject and text go, and the entry keeps its status. An email that was still waiting to be sent when you deleted is blanked within a day of going out. If it's never sent, it's blanked with the rest of the log, after 30 days.
  • A multi-clip video recording. The IP address and browser details of the recording are removed.

A delete removes the testimonial, not everything the project may hold about that person. These stay:

  • Their contact in a Smart Invites campaign, and their address on the project's do-not-email list, until you remove them there.
  • The record of a reward you sent them: the name and address the gift card went to. It's a payment record, so it's kept.
  • Proof Impact reports. Views and conversions recorded while the testimonial was live keep the name and company it was shown under, marked Deleted, until Proof Impact clears that history.
  • Text a widget took from it. A quote or summary that a widget's builder wrote from the testimonial stays in the widget until you edit the widget.
  • The file it was imported from. A CSV, Excel or JSON import keeps the file you uploaded for as long as the import is in History.
  • A file that's also in the project's file library, and any copy of the testimonial you duplicated to another project.

If your customer wants everything about them removed, contact us.

How do I get my data out?

In a project's inbox, click Options and choose Export to CSV. Every plan has it, and the workspace owner and the project's Admins can use it. The file lists every testimonial in the project with its author, email address, text, rating, tags and source; photos, audio and video files aren't in it. See Export your testimonials.

To save a video testimonial's file, see Download the video. Imported reviews have their own export; see Review and export imported content.

If an account is terminated, our Terms of Service give its owner a limited time to ask us for an export, unless the content was already deleted at the owner's request.

What happens to my data when I delete my workspace and account?

Your paid plan is canceled straight away, and the workspace is permanently deleted with every project in it, their testimonials, files, forms, widgets and Walls of Love, and your sign-in account. Only the workspace owner can do it, so export what you need first. The steps and the full list are in Delete your workspace and account.

Some records outlive the workspace. We keep a record that its subscription was canceled, and our privacy policy lists the rest under "Retention and deletion", with how long each is kept: billing and tax records, security logs, a note of the marketing emails you unsubscribed from, and backups.

To delete one project and keep the rest, see Delete a project.

How long are logs and other records kept?

Testimonials are kept until you delete them, or the project or workspace they're in. The exception is Spam, which is emptied on a schedule; see Keep spam out of your inbox. The records around them clear on their own:

  • In-app notifications: after 90 days.
  • A project's Email Log: after 30 days. The emails about a testimonial you delete are blanked at once. One that was still waiting to be sent is blanked within a day of going out, or after those 30 days if it never goes out.
  • Webhook delivery logs: after 30 days for delivered events, 90 days for failed and canceled ones.
  • Smart Invites webhook events: after 30 days.
  • A multi-clip video recording: the customer's IP address and browser details are removed after 90 days, or when you delete the testimonial.

For what we keep on our side, such as billing records and backups, see "Retention and deletion" in our privacy policy.

Do your widgets set cookies or track my visitors?

The widget and Wall of Love code on your website writes no cookies. A widget does keep a few values in the visitor's browser storage and reports views and video plays to ReTestimonial. For privacy signals and for measuring only the visitors who agree, see Privacy in the Proof Impact article.

Does my card number reach ReTestimonial?

No. You enter card details on a page hosted by our payment provider, so card numbers don't pass through ReTestimonial and we don't store them. To see invoices or change a payment method, see Where do I find my invoices and receipts?

Was this page helpful?

On this page