RatingIQ — a service of UpStar Five Ltd
Effective Date: August 11, 2026 · Version 1.0
The short version. RatingIQ is a business tool for hotels. Most of what we handle is business data, not personal data. The personal data we do handle falls into four groups:
1. People who use RatingIQ — name, work email, role, what you did in the product. We need this to run your account.
2. Guests who wrote public reviews — we collect reviews that guests published on Booking.com, Google, TripAdvisor and Expedia. We replace the reviewer’s displayed name with an irreversible code at the point of collection, but we keep what the guest wrote.
3. Hotel staff — people you add to your account, and people guests name in their reviews (“Eldad at the spa was wonderful”). See section 7.
4. Website visitors — cookies and analytics, only the essential ones until you agree to more. See section 11.
This box is a summary for convenience. The numbered sections below are the policy.
1.1. RatingIQ is a service of UpStar Five Ltd, a company registered in Israel under company number 517163234, with its registered office at HaBrosh St 9, Beit Nekofa, Jerusalem District, Israel (“RatingIQ”, “we”, “us”, “our”).
1.2. Contact. For any privacy question, request or complaint, write to hotels@rating-iq.com or omri@rating-iq.com with “Privacy” in the subject line, or by post to the address above. We answer privacy requests within the time the applicable law allows, and in any case without undue delay.
1.3. Laws we work to. We aim to comply with the EU General Data Protection Regulation (GDPR), the UK GDPR, the Israeli Protection of Privacy Law, 5741-1981 and regulations under it, and other data protection laws that apply to us.
2.1. This policy explains how we handle personal data in connection with the rating-iq.com website, the RatingIQ application, our APIs and our email and notification communications (together, the “Services”). It is part of our Terms of Use.
2.2. What it does not cover. It does not cover the privacy practices of our customers, of the review platforms we collect data from, or of any other third-party website or service. If you are a guest or an employee of a hotel that uses RatingIQ, that hotel’s own privacy notice governs its handling of your data — see section 8.
3.1. We are a controller for personal data we decide the purposes and means of processing — running and securing the website and the platform, managing accounts and billing, our own analytics, our communications with you, and our collection and pseudonymisation of publicly available review content.
3.2. We are a processor for the personal data we process inside a customer’s account on that customer’s instructions — including the review content, staff records, assignments and responses held in their workspace. In that case the customer is the controller and decides why the data is processed.
3.3. Data processing agreement. Customers who require a data processing agreement should write to hotels@rating-iq.com. Where one is in place, it governs our processing on that customer’s behalf and prevails over this policy for that processing.
3.4. Where the roles meet. The same review may be processed by us as controller (when we collect and pseudonymise it) and as processor (when we present and analyse it inside a customer’s workspace). We apply the safeguards in this policy in both cases.
4.1. Account data. Name, work email address, a securely hashed password, the property or group you belong to, your role and access rights, your language preference, notification and report preferences, and the date you accepted our terms.
4.2. Sign-up and invitation data. Where you sign up or are invited, the property or chain name and the review-platform address you give us, and who invited you.
4.3. Usage data. Records of your activity in the Services — pages and screens viewed, features used, filters applied, reports opened, actions taken, and the time each occurred. We use this to operate, secure, support and improve the product. Free-text fields are excluded from this activity record by design.
4.4. Device and log data. IP address, browser and device type, operating system, referring page, and server and error logs. Error reports may include a short technical context needed to diagnose a fault.
4.5. Communications. Emails, support messages, feedback and chat conversations you have with us or with the in-product assistant, and records of the reports and notifications we sent you.
4.6. Billing data. Where you hold a paid subscription: billing contact details, invoices, subscription status and payment history. Card details are entered directly with our payment provider — we do not receive or store full card numbers.
4.7. Push notification data. If you enable browser notifications, the subscription identifier issued by your browser’s push service, the keys needed to encrypt messages to it, and your device’s user-agent string. You can revoke this in your browser at any time.
We hold information about the properties in an account: name, address and location, review-platform listings, plan and configuration, response rules, and the analyses we derive. Most of this is not personal data, but it is described here because it is the context in which the personal data below is processed.
6.1. What we collect. We collect reviews that guests have published publicly about our customers’ properties on review and booking platforms, including Booking.com, Google, TripAdvisor and Expedia. A collected review may include: the review text (positive and negative parts), the title, the numeric rating, the review date, the stay dates and number of nights, the room or stay type, the traveller type, the country or region shown alongside the review, the platform’s own identifier for the review, and any reply the property has published.
6.2. Reviewer names are pseudonymised at collection. We do not store the reviewer’s displayed name. At the point a review enters our systems, the displayed name is replaced with an irreversible cryptographic code that lets us recognise the same review again without holding the name. We cannot recover the name from that code.
6.3. What that does and does not mean. Pseudonymising the name does not make the rest of the review anonymous. Review text is written by people and can contain personal details — about the guest, about people they travelled with, or about staff. We process that text as personal data and protect it accordingly.
6.4. What we do with it. We break reviews into single-topic statements, group them into recurring issues and strengths, calculate ratings, trends, distributions and impact indices, generate summaries and draft replies, translate content, and compare a property with a set of comparable properties.
6.5. Legal basis. Where we act as controller for this collection, we rely on our legitimate interests and those of our customers in understanding publicly published feedback about their businesses (GDPR Article 6(1)(f)). We have assessed that this processing is limited to content the author chose to publish publicly, is pseudonymised at the earliest practical point, is not used to profile or target any guest, and is not used to make any decision about any guest. Where we act as processor, our customer determines the legal basis.
6.6. What we never do with it. We do not sell it. We do not use it to advertise to guests, to build a profile of a guest across properties, to contact guests, or to make any automated decision that produces a legal or similarly significant effect on a guest.
6.7. Removal. Where a review is removed or amended at source, or where a platform or a competent authority requires it, we remove or amend it in our systems. Guests can also contact us directly — see section 8.
7.1. Staff records you enter. Customers can record members of their personnel — name, work email, phone number and position — in order to assign issues and actions to them and to send them notifications. The customer is the controller of that data.
7.2. Staff named in guest reviews. The Services identify people that guests name or describe in their reviews, group different spellings of the same name together, record the phrase in which the person was named, and count how often each person was mentioned over time. This is used for recognition and operational insight, and may be presented to managers and in reports.
7.3. It can be wrong. This extraction is automated and works across many languages. It can miss a mention, credit the wrong person, merge two people who share a name, split one person across spellings, or misread a role. It is an indication, not a personnel record.
7.4. Roles and responsibilities. The customer is the controller for its personnel’s data. The customer is responsible for informing its personnel that this processing takes place, for having a lawful basis for it, and for any consultation its local law requires. We act as processor for it.
7.5. Correction and objection. A member of hotel personnel who wants their data corrected, removed from these features, or explained should contact their employer first, since the employer controls the account. They may also write to us at hotels@rating-iq.com and we will act on the employer’s instruction and assist.
7.6. Not for employment decisions on its own. Our Terms of Use prohibit customers from using this output as the sole or determinative basis for a decision about an individual’s employment or engagement.
8.1. You may be in our systems without ever having used RatingIQ — because you published a review about a property, or because a guest named you in one, or because your employer added you to its account.
8.2. Who to contact. In most of these cases we act on behalf of the property, and the property is the controller. Contact the property first. If you do not know which property is involved, or you would rather come to us, write to hotels@rating-iq.com or omri@rating-iq.com and we will help you identify the right controller and pass your request on, or handle it ourselves where we are the controller.
8.3. What we will need. To act on a request about review content we need enough information to locate it — normally the property, the platform, and the approximate date of the review or the text concerned. We ask for the minimum needed and do not require identity documents unless we genuinely cannot otherwise verify the request.
8.4. Your review on the platform. We do not control the platform on which you published. Deleting a review at source is a request to that platform, not to us. Once it is removed there, it is removed from our systems on the next collection or on request.
| Purpose | Legal basis (GDPR / UK GDPR) |
|---|---|
| Creating and running your account, authenticating you, providing the Services you subscribed to | Performance of a contract, Art. 6(1)(b) |
| Collecting and analysing publicly published guest reviews about our customers’ properties | Legitimate interests, Art. 6(1)(f) — see 6.5. As processor where inside a customer workspace. |
| Sending service messages, alerts and the scheduled reports you or your organisation configured | Contract, Art. 6(1)(b); legitimate interests, Art. 6(1)(f) |
| Billing, invoicing, collections and keeping accounting records | Contract, Art. 6(1)(b); legal obligation, Art. 6(1)(c) |
| Securing the Services, preventing fraud and abuse, investigating incidents, keeping audit logs | Legitimate interests, Art. 6(1)(f); legal obligation, Art. 6(1)(c) |
| Supporting you, diagnosing faults, and improving and developing the Services | Legitimate interests, Art. 6(1)(f) |
| Optional analytics cookies and similar technologies | Consent, Art. 6(1)(a) — withdraw at any time |
| Browser push notifications | Consent, Art. 6(1)(a) — given in your browser, revocable there |
| Marketing emails to business contacts, where sent | Consent, Art. 6(1)(a), or legitimate interests, Art. 6(1)(f), depending on your jurisdiction — unsubscribe at any time |
| Complying with law, responding to lawful requests, establishing or defending legal claims | Legal obligation, Art. 6(1)(c); legitimate interests, Art. 6(1)(f) |
Where we rely on legitimate interests, we have balanced those interests against the rights and freedoms of the people concerned. You can ask us for a summary of that assessment, and you can object — see section 15.
10.1. What is sent to AI providers. To analyse reviews, generate drafts and translate content, we send content — including review text, issue and strength labels, and staff names appearing in reviews — to OpenAI and Anthropic over their business APIs. We send the minimum needed for the task and do not send account passwords or payment details.
10.2. Training. We use those providers under the business API terms on which content submitted for processing is not used to train their general-purpose models. We do not sell content to AI providers and do not license it to them for their own purposes. If we add another AI provider, we will update section 12.3.
10.3. Accuracy. AI output can be wrong. Where output concerns an identifiable person — for example a staff mention — we provide a route to have it corrected (section 7.5), and our Terms prohibit using it as the sole basis for a decision about that person.
10.4. No automated decisions with legal effect. We do not use automated decision-making, including profiling, that produces legal effects concerning a guest or a member of staff or similarly significantly affects them. Decisions taken inside a customer’s organisation are taken by that organisation’s people.
11.1. How consent works here. Optional cookies are off until you choose otherwise. Analytics and advertising storage are set to denied before any measurement script can run, and our optional analytics tools are only loaded once you have accepted analytics cookies. Essential cookies are always used, because the site cannot work without them.
| Cookie or technology | What it does | Category | Typical lifetime |
|---|---|---|---|
| Session token (next-auth) | Keeps you signed in | Essential | Session |
| CSRF token (next-auth) | Protects sign-in forms from cross-site request forgery | Essential | Session |
| cookie_consent | Remembers your cookie choices | Essential | 12 months |
| ratingiq_locale | Remembers your language | Essential | 12 months |
| Google Analytics (_ga and related) | Measures site traffic and which pages are used | Analytics — consent | Up to 24 months |
| Contentsquare | Measures how pages are used so we can improve them | Analytics — consent | Up to 13 months |
| Mixpanel (browser storage) | Product analytics — which features are used | Analytics — consent | Up to 12 months |
11.2. Changing your mind. Use the “Cookie preferences” link in the site footer to reopen the cookie panel at any time, or clear cookies in your browser. Withdrawing consent does not affect processing carried out before you withdrew it.
11.3. Signing in. Where you accept our terms at sign-in or sign-up, we treat that as your agreement to the essential and analytics cookies described above. You can still change analytics at any time under 11.2.
11.4. Do Not Track. Browsers send Do Not Track signals inconsistently and there is no agreed standard for honouring them, so we do not respond to them. Use the cookie panel instead.
12.1. We do not sell personal data and we do not share it for cross-context behavioural advertising.
12.2. Within your organisation. Data in an account is visible to the users your organisation has authorised, according to the access they hold. Access controls are enforced per property and per group.
12.3. Service providers. We use the categories of provider below. They act on our instructions under written terms.
| Provider | What they do for us | Where they process |
|---|---|---|
| Amazon Web Services | Hosting, database, storage and queueing | Ireland (EU), with support access from other regions |
| Apify | Collection of publicly available review content | EU / United States |
| OpenAI | Language-model processing | United States |
| Anthropic | Language-model processing | United States |
| Website analytics, with storage denied until you consent | EU / United States | |
| Stripe | Subscription billing and payment processing | EU / United States |
| Postmark | Transactional and report email delivery | United States |
| Sentry | Error monitoring and diagnostics | EU / United States |
| Honeycomb | Performance and reliability telemetry | United States |
| Contentsquare | Website experience analytics (only with consent) | European Union |
| Mixpanel | Product analytics (only with consent) | EU / United States |
This list is accurate as at the effective date of this policy and may change as our providers change. Where it has been agreed with a customer, email for that customer’s property may be delivered through an alternative mail provider instead of the one named above. Customers who need advance notice of sub-processor changes should ask for a data processing agreement.
12.4. Review platforms. We do not publish replies for you. The Services draft the text; you copy it into your own account on the review platform and publish it there. Once you do, that platform holds it under its own terms, not ours.
12.5. Professional advisers. Lawyers, accountants, auditors and insurers, under a duty of confidence, where necessary.
12.6. Legal and safety. Authorities, courts and other parties where we are legally required to disclose, or where disclosure is necessary to establish, exercise or defend legal claims, to enforce our Terms, or to protect the rights, property or safety of any person. Where we are permitted to tell you about such a request, we will.
12.7. Corporate transactions. If we are involved in a merger, acquisition, financing or sale of assets, personal data may be transferred as part of that transaction, subject to this policy or a policy at least as protective.
13.1. Where the data lives. Our production systems and database are hosted in Amazon Web Services in Ireland (EU). We are established in Israel, and our personnel there access the systems to operate and support them.
13.2. Transfers out of the EEA and the UK. Some of our providers process data in the United States or in other countries. For those transfers we rely on the European Commission’s Standard Contractual Clauses and the UK International Data Transfer Addendum, together with additional technical and organisational measures where appropriate, or on another lawful transfer mechanism available for that provider.
13.3. Israel. Israel is the subject of a European Commission adequacy decision. Where that decision applies and remains in force, transfers to us in Israel are permitted on that basis; where it does not, we rely on Standard Contractual Clauses.
13.4. Copies. You can ask us for information about the safeguards we use for a particular transfer by writing to hotels@rating-iq.com.
14.1. Principle. We keep personal data only as long as we need it for the purposes described in this policy, and then delete or anonymise it.
14.2. Account and user data. For as long as the account is active, and normally for up to 12 months after it closes, so that an account can be restored and questions can be answered.
14.3. Review content and derived analysis. For as long as the property is in an active account. On termination it is deleted or anonymised within a reasonable period, subject to 14.6 and 14.7. Reviews removed at source are removed from our systems on the next collection or on request.
14.4. Billing and tax records. For the period Israeli tax and company law requires, currently seven years from the end of the relevant tax year.
14.5. Logs, telemetry and error reports. For a limited operational period, normally not more than 12 months.
14.6. Backups. Backups are kept on a rolling schedule and are overwritten in the ordinary course. Data deleted from the live system persists in backups until they cycle.
14.7. Aggregated and de-identified data. Statistics and benchmarks that no longer identify any person or property may be kept indefinitely.
14.8. Legal holds. We may keep data longer where we must, for example to comply with a legal obligation or to establish, exercise or defend a legal claim.
15.1. What you can ask for. Subject to the conditions in the law that applies to you, you may ask us to: confirm whether we hold personal data about you and give you a copy; correct data that is inaccurate or incomplete; delete data; restrict how we use it; provide it in a portable, machine-readable form; object to processing we base on legitimate interests, including a general right to object to direct marketing at any time; and withdraw a consent you gave, without affecting processing carried out before you withdrew it.
15.2. How to exercise them. Write to hotels@rating-iq.com or omri@rating-iq.com with “Privacy request” in the subject. We do not charge for this, unless a request is manifestly unfounded or excessive.
15.3. If the request concerns a customer’s account. Where we act as processor, we will refer your request to the customer who controls the data and assist them in answering it.
15.4. Verification. We may ask for information to satisfy ourselves that a request comes from the right person. We ask for the minimum necessary.
15.5. Israel. If the Israeli Protection of Privacy Law applies to you, you have rights of access and correction under that law, and may complain to the Israeli Privacy Protection Authority.
15.6. California. If you are a California resident, you have rights to know, delete, correct and limit under the CCPA as amended. We do not sell personal information and do not share it for cross-context behavioural advertising, so there is nothing to opt out of in that respect. We will not discriminate against you for exercising a right.
15.7. Complaints. We would like the chance to put things right first, so please contact us. You also have the right to complain to a data protection authority — in the EU or the UK, the authority in the country where you live, work, or where you believe an infringement occurred; in Israel, the Privacy Protection Authority.
16.1. Measures. We use technical and organisational measures appropriate to the risk, including encryption of data in transit, encryption at rest for our database and storage, hashed passwords, database-level access rules that separate one customer’s data from another’s, restricted and logged administrative access on a need-to-know basis, network isolation, and monitoring and alerting on errors and anomalies.
16.2. Your part. Use a strong, unique password, do not share accounts, remove access for people who leave, and tell us at once if you suspect a compromise.
16.3. No absolute guarantee. No method of transmission or storage is completely secure. We cannot guarantee absolute security, and we do not warrant that the Services will be free from unauthorised access.
16.4. Breach notification. If a personal data breach occurs that is likely to result in a risk to people’s rights and freedoms, we will notify the competent authority and, where required, the people affected and our affected customers, without undue delay.
The Services are for business use by adults. They are not directed at children, and we do not knowingly collect personal data from children. Review text written by a guest may in principle mention a child; we do not seek such data, do not use it to identify anyone, and will delete it on request. If you believe a child’s personal data has reached us, write to hotels@rating-iq.com and we will delete it.
18.1. We may update this policy. The current version is always on this page with its effective date at the top.
18.2. For changes that materially affect how we handle your personal data, we will give reasonable notice by email, by in-product notice, or by a notice on this page before the change takes effect.
This policy is written in English, and the English text governs. Any translation we publish is provided for convenience only, and in the event of any inconsistency the English version prevails.
Privacy questions, requests and complaints: hotels@rating-iq.com or omri@rating-iq.com (please put “Privacy” in the subject line), or by post to UpStar Five Ltd, HaBrosh St 9, Beit Nekofa, Jerusalem District, Israel. For questions about the agreement itself, see our Terms of Use.