Privacy
Tiraisoft Radar — Review Radar, the Local Rank Tracker and Listing Guard — watches public Google pages for the businesses you track, and emails you when something needs an answer. This page says what we keep, how long we keep it, and who else sees it. There is no account requirement to use the free reply tool on this site.
If you use Review Radar, we keep the businesses you watch and the reviews we fetch for them — each review's star rating, text, publication date and whether the owner replied, but not the reviewer's name — along with the alerts we sent and any reply drafts. For your own listing we also keep a copy of every review on it (for listings with up to 1,000 reviews), and we keep that copy after Google removes a review, because the list of removed reviews is what the product shows you. A competitor's reviews are deleted when you remove that competitor; everything else here, including the copies of removed reviews, is deleted with the watch or with your account.
If you use the Local Rank Tracker, we also keep the business you picked, the search you asked us to track, and each weekly result: the position of the business at every point of its grid and the businesses Google listed there — up to twenty per point, with their public rating, review count and categories. These are public search results about businesses, not about you, and they are deleted with the keyword or with your account.
If you use Listing Guard, we keep the business you picked, what its public Google listing showed at each daily check (its name, categories, address, phone number, website and opening hours) and the changes found between checks. These are public details about a business, not about you, and they are deleted with the listing or with your account.
Cookies and tracking
We use no cookies to identify you and no advertising pixels. We do not build a profile of you across visits, and we do not sell or share your data.
We do measure how the product is used, so we can tell which parts of it are
working. That measurement is first-party — it goes to our own servers and
nowhere else — and it is scoped to a single visit: a random id is kept in your
browser's sessionStorage and is discarded when you close the tab.
We record which steps were taken and how long they took, the page path, and
the host a visit arrived from (for example google.com),
never the full link or anything you typed into a search box.
We also record three broad facts about the visit itself: the
kind of device (phone, tablet, desktop, or an automated
crawler), the operating system and its major version only —
iOS 17, never iOS 17.4.1 — and the
country and region the connection came from, which Cloudflare
works out at its edge so that this measurement never sees or keeps the
address itself (the support chat, below, is the one place an address is
stored). We do
not keep the browser's User-Agent string: it is read once to work
out the device and the system, and then discarded, because the full string is
detailed enough to single somebody out.
Each of those is counted on its own. We keep a daily total per device kind, and a separate daily total per country, and we never keep a row that combines them — so the numbers cannot be narrowed to "the one person on a tablet in Iceland". The cost of that, to us, is that we cannot ask which system a particular country's visitors run. We think that is the right way round.
We also measure how long each page was open and visible, so we can see which pages are actually read. The clock stops whenever you switch away from the tab, so a page left open in the background does not count as time spent reading.
We do not store your IP address for analytics. To count distinct visitors within a day we keep a one-way hash of it combined with the date and a secret, which cannot be reversed and cannot be matched to any other day. Individual event records are deleted after 30 days; only anonymous daily totals are kept after that.
If you are signed in, we keep one small record per account so we can tell repeat use from first-time use: your account id with the first day and the last day it was active. Two dates, and nothing else — not what you did, not which pages, not from where. It is your existing account id, not a new identifier: nothing is written to your browser to make it, and it does not exist at all for a visit you make signed out. It is deleted when your account is deleted.
Support chat
Everything above describes measurement. The support chat is different, because it exists to keep a conversation, and none of the measurement's properties apply to it. If you send a message in it, we store:
- the transcript — every message you send and every reply;
- who it belongs to — your account id if you are signed in,
otherwise a random visitor id that the chat creates when you send your
first message and keeps in your browser's
localStorage, so the conversation can be reopened on a later visit; - the IP address of the connection the conversation started from, stored with the conversation and used to limit abuse of the chat.
Each conversation is classified automatically (for example as a question, a bug report or a feature request). A short summary of a bug report or a feature request is emailed to our own feedback inbox so the team sees it.
Chat conversations are kept until they are deleted; they have no automatic expiry. A signed-in account's conversations are deleted when the account is deleted.
Who else touches your data
- Cloudflare — hosting, including delivery of the support chat's bug-report and feature-request summaries to our feedback inbox.
- A third-party large-language-model provider — the text you submit is sent to it so the product can produce a result, and so are your support chat messages, so it can write the reply and classify the conversation. This applies to the free reply tool, to any assistant chat, and to drafting a reply to a review we fetched for you: when you press "Draft one for me", that review's text is sent to it. Fetching reviews, alerts and reports do not use it. The category is the disclosure: Article 13(1)(e) GDPR asks for the recipients or categories of recipients, and the provider is not named here.
- A third-party payment processor — subscriptions and credit packs are paid for on its own site, so the card or account details you enter go to it and never reach us. We send it the plan you picked and an internal id that links the payment back to your account; it sends back the subscription's status, and we keep the notifications it sends so a payment is never counted twice. The category is the disclosure here for the same reason as above: Article 13(1)(e) GDPR asks for the recipients or categories of recipients.
- A third-party web-data service — it reads public Google Maps data for us, so it is sent what each tool needs looked up: the search text you type to find a business; the public Google listing you ask us to watch and the listings of the competitors you add, so we can fetch their reviews; a rank tracker's keyword and search area (the business's listing, the map location the grid is centred on and the grid's size), so it can search Google Maps from each point; and a Listing Guard listing with its map location, for the daily check of its details. It receives no account details: not your email address, not your account id, and nothing about your payments.
- A third-party map-tile service — when the app shows a rank tracker's map, your browser loads the map images from it directly, so it sees your IP address and the area around the tracked business. It receives nothing about your account.
Your data: access and deletion
To ask for a copy of the data held for your account, or for your account to be deleted, email support@tiraisoft.com from the address you sign in with. There is no delete button in the app; deletion is carried out by the operator.
Deleting an account removes it and everything stored with it: the businesses you watch and their fetched reviews (including the copies of reviews Google has removed) and alerts, your credit balance and billing records, your sign-in sessions, your support chats, the usage events recorded while you were signed in, and the two-date activity record described above. A subscription that is still running has to end before its account can be deleted, and unspent credits are not refunded.
Tiraisoft Radar is operated by Tiraisoft, Indonesia.