Skip to content
Lukeware/ReviewSpace

Privacy Policy

Last updated: March 2026

Lukeware (“we”, “us”, or “our”) operates lukeware.com and its associated products, including ReviewSpace (accessible at reviewspace.lukeware.com). This Privacy Policy explains how we collect, use, store, and protect your information when you use our platform and services. Lukeware is a New Zealand company. This policy is governed by the New Zealand Privacy Act 2020. Where you are located in another jurisdiction, we also respect applicable local privacy laws.

By using any Lukeware product or service, you agree to the collection and use of information in accordance with this policy. If you do not agree, please discontinue use of our services.


Google API Services

Lukeware’s use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

What Google data we access

ReviewSpace connects to your Google Business Profile via Google OAuth 2.0 using the business.manage scope. This grants us access to:

  • Your Google Business Profile account information (business name, address, phone number, category)
  • Customer reviews posted on your Google Business Profile
  • Review reply content you create and post through ReviewSpace
  • Business listing data including opening hours and location details
  • Notifications and updates related to your business profile

How we use Google data

We use Google Business Profile data exclusively to provide the ReviewSpace service to you. Specifically, we use this data to:

  • Display your Google reviews within the ReviewSpace dashboard
  • Generate AI-assisted draft replies to your reviews
  • Post replies to reviews on your behalf, only with your explicit approval
  • Display your review statistics and ratings
  • Embed your reviews on your website via the ReviewSpace widget
  • Send you notifications about new reviews

Limited Use restrictions

In compliance with the Google API Services User Data Policy Limited Use requirements, we commit that:

  • We do not sell your Google data to any third party
  • We do not use your Google data to serve you advertisements of any kind
  • We do not use your Google data for any purpose other than providing ReviewSpace features you have chosen to use
  • We do not allow human employees to read your Google Business Profile data except where necessary to provide support you have requested, to investigate security incidents, or as required by law
  • We do not transfer your Google data to third parties except as strictly necessary to operate ReviewSpace (e.g. our hosting provider)
  • We do not use your Google data to train AI or machine learning models

Data retention for Google data

In accordance with Google Business Profile API policies, we refresh your Google data regularly and do not retain cached Google data for longer than 30 calendar days without a refresh from the source. When you delete your ReviewSpace account, all stored Google data and OAuth tokens are permanently deleted.

OAuth tokens and credentials

When you authorise ReviewSpace via Google OAuth, we store your OAuth access token and refresh token securely in our database (Supabase, hosted on AWS infrastructure). These tokens are encrypted at rest and used solely to retrieve your business data and post replies on your behalf. You may revoke this access at any time by visiting your Google Account permissions page or by deleting your ReviewSpace account.


Information We Collect

Account information

When you create a Lukeware account, we collect your name, email address, and profile picture from your Google account. We use this to identify you, send you product notifications, and provide account support.

Usage data

We collect information about how you use our products, including pages visited, features used, actions taken (such as approving a review reply), and timestamps. This helps us improve our products and diagnose technical issues.

Customer review request data

When you use ReviewSpace to send review requests, you provide us with your customers’ names and contact details (phone numbers or email addresses). This data is used solely to send the review request on your behalf. We do not contact your customers for any other purpose, and we do not sell or share their details with any third party.

Payment information

Payment processing is handled by Stripe. We do not store your credit card details. Stripe collects your billing information (name, email, payment method) and processes payments in your local currency (USD, NZD, or AUD). Stripe’s privacy policy governs how they handle your payment data.

Technical data

We automatically collect technical data including your IP address, browser type, device type, and operating system. This is used for security monitoring and improving platform performance.


How We Store Your Data

Your data is stored in Supabase (a managed PostgreSQL database hosted on AWS infrastructure). Our application is hosted on Vercel. Both providers maintain high security standards and data is encrypted in transit (TLS) and at rest.

We retain your account data for as long as your account is active. If you delete your account, we will delete your personal data within 30 days, except where we are required to retain it for legal or tax obligations.


Third-Party Services

We use the following third-party services to operate our platform. Each has their own privacy policy governing how they handle data:

ServicePurposeData shared
Google (OAuth & Business Profile API)Authentication and business review managementAccount identity, business profile data
SupabaseDatabase and authentication infrastructureAll account and product data
VercelApplication hosting and deliveryRequest logs, IP addresses
StripePayment processing and subscriptionsBilling name, email, payment method
TwilioSMS notifications and review request deliveryPhone numbers for SMS delivery

We do not sell your data to any third party. We do not share your data with advertising networks, data brokers, or any party for marketing or profiling purposes.


Your Rights

Under the New Zealand Privacy Act 2020, and applicable privacy laws in your jurisdiction, you have the right to:

  • Access — request a copy of the personal information we hold about you
  • Correction — request that we correct inaccurate personal information
  • Deletion — request deletion of your account and personal data
  • Portability — request an export of your data in a common format
  • Revoke Google access — disconnect your Google account from ReviewSpace at any time
  • Withdraw consent — stop using our services and request data deletion at any time

To exercise any of these rights, contact us. We will respond within 20 working days as required by the Privacy Act 2020.


Security

We take the security of your data seriously. We implement industry-standard measures including:

  • TLS encryption for all data in transit
  • Encryption at rest for all stored data
  • Row-level security (RLS) in our database so users can only access their own data
  • OAuth 2.0 for authentication (we never store your Google password)
  • Regular security reviews of our infrastructure

If we become aware of a data breach that affects your personal information, we will notify you and the relevant authorities (including the New Zealand Privacy Commissioner) as required by applicable law.


Cookies

We use cookies and similar technologies to maintain your session (keep you logged in), remember your preferences, and understand how our platform is used. We do not use third-party advertising cookies. You can disable cookies in your browser settings, but this may affect your ability to use our products.


Children’s Privacy

Our services are not directed at children under 16 years of age. We do not knowingly collect personal information from children. If you believe a child has provided us with personal information, please contact us and we will delete it promptly.


Changes to This Policy

We may update this Privacy Policy from time to time. When we make material changes, we will notify you by email and update the “Last updated” date at the top of this page. If you use Google API-connected features (such as ReviewSpace), we will seek your re-consent before using your Google data in any new way not previously disclosed. Continued use of our services after changes are posted constitutes your acceptance of the updated policy.


Contact Us

If you have any questions about this Privacy Policy or how we handle your data, please contact us:

Lukeware

New Zealand

Contact us

If you are not satisfied with our response, you may contact the Office of the New Zealand Privacy Commissioner.