OnlozLegal · Privacy Policy
Privacy Policy
Last updated · September 10, 2026
Onloz (“Onloz”, “we”, “us”, or “our”) respects your privacy and is committed to protecting personal information.
This Privacy Policy explains how we collect, use, disclose, store, and protect personal information when you:
- visit https://onloz.com;
- create or use an Onloz account;
- use our software and services;
- interact with a business using Onloz;
- submit feedback through an Onloz-powered experience;
- contact us; or
- otherwise interact with Onloz.
This Privacy Policy applies to information processed by Onloz through our websites, applications, software, and related services (collectively, the “Service”).
Please read this Privacy Policy carefully.
01
Who We Are
Onloz is a software platform that helps businesses collect customer feedback and helps customers turn their genuine experiences into polished review text.
The identity of the legal entity responsible for your personal information may depend on the service you use and the relationship between you, Onloz, and the business using Onloz.
02
The Different People Whose Information We Process
Because Onloz is a business-to-business software platform, we may process information relating to different categories of people.
Business users
These are business owners, employees, administrators, and other people who create or use an Onloz account.
For these users, Onloz generally acts as a controller or equivalent responsible party for account, billing, support, security, and service-management information.
Customers of businesses using Onloz
These are people who interact with an Onloz-powered feedback or review experience after visiting, purchasing from, or interacting with a business.
Depending on the arrangement, the business may determine why and how that customer’s information is collected, while Onloz may process the information on the business’s behalf.
In those circumstances, the business may be responsible for providing the appropriate privacy notice to its customers.
Website visitors
These are people who visit our website without creating an account.
We may process limited technical and analytics information about these visitors as described below.
03
Information We Collect
The information we collect depends on how you interact with Onloz.
Account information
When you create an Onloz account, we may collect:
- name;
- email address;
- phone number, if provided;
- password or authentication information;
- business name;
- business address;
- business category;
- website;
- account preferences;
- branding information;
- profile information; and
- other information you choose to provide.
04
Customer Feedback Information
When you interact with an Onloz-powered customer feedback experience, we may process information such as:
- star rating;
- selected feedback categories;
- answers to feedback questions;
- written comments;
- review drafts;
- generated review text;
- edits made to generated text;
- feedback about the review-generation experience;
- business or location associated with the interaction;
- campaign or QR-code identifier;
- date and time of the interaction; and
- limited technical information associated with the session.
A customer may be able to use an Onloz feedback experience without creating an Onloz account.
We do not require a customer’s name, email address, or phone number unless a particular feature or business configuration requires it.
05
Information You Provide to Us
We may collect information when you:
- create an account;
- purchase a subscription;
- contact customer support;
- submit a support request;
- respond to a survey;
- communicate with us;
- submit feedback;
- configure your business profile;
- customize your Onloz experience;
- participate in promotional activities; or
- otherwise voluntarily provide information.
06
Payment Information
If you purchase a paid Onloz subscription, payment information may be processed by our third-party payment provider.
Depending on the payment method, Onloz may receive limited information such as:
- billing name;
- billing address;
- transaction identifier;
- subscription information;
- payment status;
- payment method type;
- last four digits of a payment card, where provided by the payment processor; and
- transaction dates and amounts.
We generally do not store complete payment-card numbers on our own systems.
Payments are subject to the privacy policy and terms of the applicable payment provider.
07
Technical and Usage Information
When you access the Service, we may automatically collect information such as:
- IP address;
- browser type;
- operating system;
- device type;
- device identifiers;
- approximate geographic information derived from IP address;
- pages or screens viewed;
- referring URLs;
- session information;
- timestamps;
- interactions with the Service;
- features used;
- error logs;
- performance information; and
- security-related information.
We use this information to operate, secure, troubleshoot, analyze, and improve the Service.
09
How We Use Personal Information
We may use personal information for the following purposes.
Providing the Service
To:
- create and maintain accounts;
- provide customer-feedback experiences;
- generate AI-assisted content;
- provide dashboards and analytics;
- provide integrations;
- process subscriptions;
- provide customer support; and
- otherwise provide features requested by you.
Security and fraud prevention
To:
- authenticate users;
- detect unauthorized activity;
- prevent fraud;
- investigate abuse;
- protect accounts;
- protect our infrastructure; and
- maintain the security of the Service.
Service improvement
To:
- understand how customers use the Service;
- identify bugs;
- improve performance;
- develop features;
- analyze aggregate usage;
- improve customer experience; and
- conduct internal research and analytics.
Where we use information for product improvement, we seek to use appropriate safeguards and minimize the use of directly identifying information where reasonably practical.
Communications
We may use contact information to:
- respond to support requests;
- provide service notifications;
- send transactional messages;
- communicate about subscriptions;
- provide security notifications;
- communicate important changes; and
- send marketing communications where permitted by applicable law and your preferences.
You can opt out of non-essential marketing communications at any time.
Legal compliance
We may process information when necessary to:
- comply with applicable laws;
- respond to lawful requests;
- enforce our agreements;
- protect our rights;
- investigate fraud or abuse;
- resolve disputes; or
- protect the safety and security of people and systems.
10
AI and Automated Processing
Onloz may use artificial intelligence and machine-learning technologies to assist with review drafting and other Service functionality.
For example, a customer may provide:
- a star rating;
- selected feedback categories; and/or
- written feedback.
Onloz may process that information to generate suggested review language.
The purpose of this processing is to help express the customer’s own experience in natural language.
AI-generated content may be inaccurate or contain errors. Customers and businesses remain responsible for reviewing generated content before publishing it.
Onloz does not use AI to independently determine whether a customer had a genuine experience.
We do not intentionally use AI-generated review text to create fabricated customer experiences.
Where third-party AI providers are used, relevant information may be transmitted to those providers as necessary to provide the requested feature, subject to applicable agreements and safeguards. Our current third-party AI provider is DeepSeek.
11
Lawful Bases for Processing
Where laws such as the UK GDPR or EU GDPR apply, we rely on one or more lawful bases depending on the circumstances. These may include the following.
Performance of a contract
Where processing is necessary to:
- create an account;
- provide the Service;
- process a subscription;
- provide requested functionality; or
- provide customer support.
Legitimate interests
Where processing is necessary for legitimate business interests, such as:
- securing our systems;
- preventing fraud;
- improving the Service;
- understanding Service usage;
- maintaining business operations;
- communicating with business customers; or
- defending legal claims.
When relying on legitimate interests, we consider the impact on individuals and applicable legal requirements.
Consent
Where applicable law requires consent, we will request it.
For example, consent may be required for certain:
- non-essential cookies;
- marketing communications;
- optional processing activities; or
- other activities where consent is the appropriate legal basis.
You may withdraw consent where applicable.
Withdrawal of consent does not affect processing that occurred before withdrawal.
Legal obligations
We may process information where necessary to comply with applicable legal obligations.
12
Business Customer Data
If you use Onloz as a business, you may provide us with personal information belonging to your customers, employees, or other individuals.
Depending on the nature of the processing, you may be the controller or equivalent responsible party and Onloz may act as your processor or service provider.
You are responsible for ensuring that:
- you have a lawful basis for collecting and providing the information;
- you provide appropriate privacy information;
- you obtain required consents;
- your instructions to Onloz are lawful;
- your use of Onloz complies with applicable privacy laws; and
- you have the necessary rights to provide the information to us.
Where required, Onloz may enter into a Data Processing Agreement with a business customer.
14
Third-Party Review Platforms
Onloz may direct customers to third-party review platforms such as Google or other services selected by a business.
If you choose to submit information to a third-party platform, that platform may independently collect and process your information.
Once you leave Onloz and interact directly with a third-party service, that service’s privacy policy and terms apply.
Onloz does not control:
- third-party privacy practices;
- third-party review moderation;
- third-party data retention;
- third-party account policies; or
- third-party data processing.
You should review the privacy policy of the relevant third-party service before submitting information to it.
15
International Data Transfers
Because Onloz is intended to operate globally, your information may be processed in countries other than the country where you live.
For example, our service providers may operate infrastructure or personnel in different countries.
Where applicable law restricts international transfers of personal information, we will use appropriate mechanisms and safeguards required by that law.
Depending on the circumstances, these may include:
- adequacy decisions;
- standard contractual clauses;
- UK International Data Transfer Agreements or Addendums;
- contractual protections;
- technical safeguards; and
- other legally recognized transfer mechanisms.
16
Data Retention
We retain personal information only for as long as reasonably necessary for the purposes described in this Privacy Policy, unless a longer period is required or permitted by law.
Retention periods may depend on:
- the type of information;
- why it was collected;
- whether your account remains active;
- contractual requirements;
- legal obligations;
- dispute resolution;
- security requirements; and
- legitimate business needs.
For example:
Account information
Generally retained while your account is active and for a reasonable period after termination where necessary for legal, accounting, security, or dispute-resolution purposes.
Customer feedback
Retained according to the configuration of the relevant business and our contractual requirements.
Billing information
Retained for periods necessary to comply with applicable accounting, tax, and financial obligations.
Security logs
May be retained for a limited period necessary for security monitoring, fraud prevention, and investigation.
When information is no longer required, we may delete it, anonymize it, or securely dispose of it.
17
Your Privacy Rights
Depending on where you live and applicable law, you may have rights regarding your personal information.
These may include the right to:
- access personal information;
- correct inaccurate information;
- request deletion;
- request restriction of processing;
- object to certain processing;
- request data portability;
- withdraw consent;
- request information about how your data is used;
- object to certain direct marketing;
- lodge a complaint with a relevant supervisory authority; and
- exercise other rights provided by applicable law.
These rights are subject to applicable legal exceptions and limitations.
For example, we may be permitted or required to retain certain information for legal, security, fraud-prevention, or accounting purposes.
18
How to Exercise Your Rights
To exercise a privacy right, contact us at:
Please provide enough information for us to understand your request and verify your identity where reasonably necessary.
If you use Onloz through a business, some requests relating to information collected by that business may need to be directed to the business itself.
For example, if a restaurant uses Onloz to collect customer feedback, the restaurant may be responsible for determining the purposes of that processing.
Where appropriate, Onloz may assist the business in responding to your request.
19
Verification of Requests
For security reasons, we may need to verify your identity before completing certain privacy requests.
We will try to avoid requesting information beyond what is reasonably necessary to verify your identity.
If we cannot verify your identity, we may be unable to fulfill the request.
20
Children’s Privacy
Onloz is intended for businesses and their customers and is not directed at children.
We do not knowingly design the Service to collect personal information from children where prohibited by applicable law.
If you believe that a child has provided personal information to Onloz in circumstances where such collection was not appropriate, please contact us so that we can investigate and take appropriate action.
Businesses using Onloz are responsible for configuring and using the Service in accordance with applicable age-related privacy requirements.
21
Data Security
We use reasonable technical and organizational measures designed to protect personal information against:
- unauthorized access;
- accidental loss;
- misuse;
- alteration;
- disclosure; and
- destruction.
Security measures may include:
- encryption in transit;
- access controls;
- authentication mechanisms;
- monitoring;
- logging;
- backups;
- infrastructure security;
- least-privilege access; and
- security reviews.
However, no internet service or security system can guarantee absolute security.
You should use appropriate security practices when using the Service.
22
Data Breaches
If we become aware of a security incident involving personal information, we will assess the incident and take steps required by applicable law.
Where legally required, we may notify affected customers, businesses, regulators, or other relevant parties.
If you use Onloz as a business customer and a security incident affects information processed on your behalf, we will provide notifications and assistance as required by applicable law and any applicable Data Processing Agreement.
23
Marketing Communications
We may send transactional communications necessary to provide the Service.
Examples include:
- account verification;
- password resets;
- subscription confirmations;
- billing notifications;
- security alerts;
- service announcements; and
- important legal notices.
These communications cannot generally be opted out of while maintaining an account where they are necessary to operate the Service.
We may also send marketing communications where permitted by applicable law.
You can unsubscribe from marketing communications using the unsubscribe mechanism included in the message or by contacting us.
24
Analytics
We may use analytics technologies to understand:
- website traffic;
- feature usage;
- conversion rates;
- errors;
- performance;
- customer journeys; and
- overall Service usage.
Where required by applicable law, we will obtain consent before using non-essential analytics technologies.
Analytics data may be aggregated or de-identified for product and business analysis.
25
Do Not Track
Some browsers provide a “Do Not Track” signal.
Because there is currently no universally accepted technical standard for responding to all such signals, Onloz may not respond to every browser-level Do Not Track setting.
Where applicable law requires a particular response to such signals, we will comply with the applicable requirement.
26
Data Deletion
You may request deletion of personal information by contacting us.
If you have an Onloz account, you may also be able to delete information through available account controls.
Deletion may be subject to legal, security, contractual, or operational requirements.
For example, we may retain limited information where necessary to:
- comply with law;
- establish or defend legal claims;
- prevent fraud;
- maintain security;
- complete financial records; or
- enforce our agreements.
Where complete deletion is not possible, we may instead restrict access or anonymize the information.
27
Aggregated and De-Identified Information
We may create aggregated, statistical, or de-identified information from information collected through the Service.
Where permitted by law, we may use such information for purposes including:
- analytics;
- product development;
- benchmarking;
- research;
- security;
- business planning; and
- improving the Service.
We will not attempt to re-identify information that has been properly de-identified except where necessary for permitted purposes such as security or legal compliance.
28
Business Transfers
If Onloz is involved in a merger, acquisition, financing, restructuring, bankruptcy, sale of assets, or similar transaction, personal information may be transferred as part of that transaction.
Where required by law, we will provide appropriate notice.
29
Links to Other Websites
The Service may contain links to third-party websites.
We are not responsible for the privacy practices, security, or content of third-party websites.
You should review the privacy policy of each third-party website you visit.
30
Changes to This Privacy Policy
We may update this Privacy Policy from time to time.
When we make material changes, we may provide notice through:
- the Service;
- our website;
- email; or
- another appropriate communication method.
The “Last Updated” date at the top of this Privacy Policy indicates when it was most recently updated.
If we introduce a new use of personal information that requires additional notice or consent under applicable law, we will provide the required notice or obtain the required consent before commencing that processing.
31
Complaints
If you have a concern about how we handle your personal information, please contact us first:
You may also have the right to lodge a complaint with the relevant data-protection authority in your country.
For individuals in the UK, the relevant supervisory authority is the Information Commissioner’s Office (ICO).
For individuals in the European Economic Area, complaints may generally be made to the data-protection supervisory authority in the country where you live, work, or where you believe a violation occurred.
For individuals in other jurisdictions, the applicable local privacy regulator may provide a similar complaint mechanism.
32
UK and European Economic Area Privacy
Where applicable, Onloz processes personal information in accordance with applicable data-protection requirements, including the UK GDPR and EU GDPR.
Where these laws apply, individuals may have rights including access, rectification, erasure, restriction, objection, portability, and rights relating to automated decision-making, subject to applicable legal requirements and exceptions.
Where Onloz processes personal information on behalf of a business customer, the business may remain responsible for determining the purposes and means of processing.
33
India Privacy
Where applicable, Onloz will process personal information in accordance with applicable Indian data-protection and privacy laws, including the Digital Personal Data Protection Act, 2023 and applicable rules and regulations as they come into force.
India’s Digital Personal Data Protection Rules, 2025 were notified by the Ministry of Electronics and Information Technology and provide for phased commencement of different provisions.
Where applicable, individuals may exercise rights available under Indian law by contacting us through the details provided in this Privacy Policy.
34
California and Other U.S. State Privacy Laws
Depending on the nature of our business and the laws applicable to you, residents of certain U.S. states may have additional privacy rights.
These may include rights relating to:
- access;
- deletion;
- correction;
- portability;
- opting out of certain forms of processing;
- targeted advertising;
- sale of personal information;
- profiling; and
- other rights established by applicable state law.
Onloz does not operate as a data broker and does not sell personal information as a data-broker business.
Where a specific U.S. state privacy law applies to Onloz, we will comply with applicable requirements and provide additional disclosures or mechanisms where required.
35
Contact Us
For privacy questions, requests, complaints, or data-protection matters, contact:
In summary
Onloz is designed around a simple principle: we use personal information to provide and improve the Service, protect our users, and help businesses and their customers use Onloz as intended.
We aim to collect only the information reasonably necessary for those purposes, explain how information is used, provide applicable privacy rights, and use appropriate safeguards to protect information.
Nothing in this Privacy Policy limits privacy rights that cannot legally be limited.