PRIVACY POLICY
Last Updated: January 6, 2026
Effective Date: January 6, 2026
This Privacy Policy explains how Turtle Digital Holdings, LLC d/b/a Skrub ("Company," "we," "us," or "our") collects, uses, shares, and protects your personal information when you use the Skrub platform ("Service"). By using our Service, you consent to the data practices described in this policy.
DATA WE COLLECT
Account Data
- Email address (for login and notifications)
- Encrypted password (hashed, never stored in plain text)
- Display name and company name (optional)
- Profile photo (if uploaded)
- Phone number (if SMS notifications enabled)
Public Data
We collect publicly available reviews and business information from the URLs you provide:
- Google Maps reviews and business details
- Facebook reviews and business details
- Facebook reviews (if enabled)
Note: This data is already publicly accessible on the internet. We do not access private or restricted content.
Payment Data
Payment processing is handled entirely by Stripe. We do not store, process, or have access to your full credit card numbers, CVV, or other sensitive payment information. Stripe is PCI-DSS compliant.
HOW WE USE YOUR DATA
We use the data we collect to provide and improve our Service:
-
1
Threat Score Calculation
Analyze review content to detect potential spam, fake reviews, and reputation threats using our AI-powered risk scoring system.
-
2
AI Draft Generation
Generate suggested responses to reviews (both positive and negative) to help you engage with customers effectively.
-
3
Removal Request Templates
Generate informational templates that may assist you in addressing potentially fraudulent or policy-violating reviews.
-
4
Service Communications
Send alerts, notifications, and service updates via email or SMS (if enabled).
Legal Basis & Data Handling
LEGITIMATE INTEREST (GDPR Article 6(1)(f))
We process public review data based on the User's "Legitimate Interest" to defend their business reputation against fraud and spam, per GDPR Article 6(1)(f). This lawful basis applies because reputation defense represents a genuine business need that does not override the rights of reviewers whose data is already publicly accessible.
NO BLACKLISTING OR DATA SHARING
Skrub does not share reputation data between clients. All data is siloed strictly to the User who requested the scan. We do not maintain cross-client databases, reviewer blacklists, or shared risk profiles. Your data remains yours alone.
PUBLIC DATA ONLY
We only process data that is already publicly accessible on third-party platforms (Google Maps, Facebook, TripAdvisor, etc.). We do not expose private individuals' contact information, email addresses, phone numbers, or any data not already visible on the public review platforms.
LEGAL BASIS FOR PROCESSING (GDPR ARTICLE 6)
Under the General Data Protection Regulation (GDPR), we rely on the following legal bases to process your personal data:
Contract Performance
Article 6(1)(b)
Processing is necessary to perform the contract you have with us. This includes providing the Skrub platform services you signed up for, managing your account, processing subscription payments, delivering scan results, generating AI-powered analysis, and providing customer support.
Legitimate Interests
Article 6(1)(f)
Processing is necessary for our legitimate interests or those of a third party, where those interests are not overridden by your rights. Our legitimate interests include:
- Improving and optimizing our Service and user experience
- Fraud prevention and security measures
- Analyzing public review data to detect spam and fraudulent content
- Defending your business reputation against malicious reviews
- Internal analytics and business intelligence
Consent
Article 6(1)(a)
Where we rely on your consent, you have the right to withdraw it at any time. We seek consent for:
- Marketing emails and promotional communications
- SMS notifications (optional feature)
- Optional product features and beta testing
- Non-essential cookies and analytics
To withdraw consent, contact us at privacy@skrub.io or use the unsubscribe link in any marketing email.
Legal Obligations
Article 6(1)(c)
Processing is necessary to comply with our legal obligations. This includes:
- Maintaining tax and accounting records as required by law
- Responding to lawful requests from law enforcement or regulatory bodies
- Complying with court orders and legal proceedings
- Meeting anti-money laundering and fraud prevention obligations
THIRD-PARTY SUB-PROCESSORS
IMPORTANT DISCLOSURE
To provide our Service, we share certain data with the following third-party infrastructure partners. Each partner processes data only as necessary to perform their designated function.
Google (Gemini AI)
AI Processing Partner
Purpose: Text generation, sentiment analysis, spam detection scoring, response drafting, and AI chat assistant functionality.
Data Shared: Review text content, business context, and chat messages for analysis.
Outscraper
Data Retrieval Partner
Purpose: Retrieving publicly available review data from Google Maps and other platforms.
Data Shared: Business URLs you provide for scanning.
Stripe
Payment Processing Partner
Purpose: Subscription billing and payment processing.
Data Shared: Email address for receipts and payment identifiers. Payment card details are sent directly to Stripe and never touch our servers.
Twilio
SMS Notifications Partner
Purpose: Sending SMS alert notifications for high-risk reviews (if enabled).
Data Shared: Phone number and notification message content.
HubSpot
Customer Relationship Management Partner
Purpose: Customer relationship management, marketing automation, email nurturing sequences, and customer support tracking.
Data Shared: Email address, name, company information, subscription status, and service usage activity.
Resend
Transactional Email Partner
Purpose: Sending transactional emails including account verification, password reset, and service notifications.
Data Shared: Email address and email content.
INTERNATIONAL DATA TRANSFERS
Skrub is operated from the United States. If you are accessing our Service from outside the US, including from the European Economic Area (EEA), United Kingdom, or other regions with data protection laws, please be aware that your data may be transferred to, stored, and processed in the United States.
Data Processing Location
United States
Your personal data may be processed in the United States and other countries where our service providers operate. The US may not have data protection laws equivalent to those in your jurisdiction.
Transfer Safeguards
Standard Contractual Clauses (SCCs)
For transfers of personal data from the EEA/UK to our sub-processors located outside of adequacy regions, we rely on the European Commission's Standard Contractual Clauses (SCCs) as the legal mechanism for such transfers. Our key sub-processors (Google, Stripe, Twilio, HubSpot, Resend) maintain their own GDPR compliance programs and have committed to SCCs or equivalent safeguards.
Request Transfer Information
Your right to know
You have the right to request information about the specific safeguards we have in place for international data transfers. To request a copy of the SCCs or information about the safeguards applied to your data, please contact us at privacy@skrub.io.
AI DATA USAGE
OUR COMMITMENT
Data submitted to our AI models is used solely to generate your requested content. We do not sell your data to third parties for model training purposes.
- Review content is processed by OpenAI's API to generate scores, drafts, and scripts
- We use OpenAI's API with data privacy protections enabled
- Your data is not used by Skrub or our partners to train AI models
- Processing is transactional — data is sent, processed, and results returned
DATA RETENTION & DELETION
We retain your data only as long as necessary to provide our Service or as required by law.
YOUR RIGHT TO DELETION
Users may request full account deletion at any time by contacting support@skrub.io. Upon deletion, all scraped history and generated drafts associated with your account are permanently removed from our systems within 30 days.
- Active accounts: Data retained while subscription is active
- Cancelled accounts: Data retained for 30 days after cancellation, then deleted
- Deletion requests: Processed within 30 days of request
- Payment records: Retained as required by financial regulations
DATA SECURITY
We implement comprehensive technical and organizational measures to protect your data:
Encryption & Transport Security
- All data transmitted over HTTPS/TLS encryption
- HTTP Strict Transport Security (HSTS) enforced
- Passwords hashed using industry-standard algorithms (never stored in plain text)
Application Security
- Content Security Policy (CSP) headers to prevent XSS attacks
- Cross-Site Request Forgery (CSRF) protection on all forms
- Secure session cookies (HttpOnly, SameSite, Secure flags)
- Rate limiting on authentication endpoints
- Password strength requirements enforced
Access & Monitoring
- Database access restricted to authorized personnel
- Error monitoring and alerting with Sentry
- Regular security reviews and updates
No system is 100% secure. While we strive to protect your information using industry best practices, we cannot guarantee absolute security.
YOUR RIGHTS (GDPR)
Under the General Data Protection Regulation (GDPR) and other applicable data protection laws, you have specific rights regarding your personal data. We are committed to honoring these rights.
Right to Access
Article 15
You have the right to obtain confirmation as to whether we are processing your personal data, and if so, to request access to that data along with information about how it is processed. You may request a copy of your personal data free of charge.
Right to Rectification
Article 16
You have the right to request correction of inaccurate personal data we hold about you. Taking into account the purposes of the processing, you also have the right to have incomplete personal data completed.
Right to Erasure ("Right to be Forgotten")
Article 17
You have the right to request deletion of your personal data where: the data is no longer necessary for its original purpose; you withdraw consent; you object to processing; the data was unlawfully processed; or deletion is required by law. We will process erasure requests within 30 days.
Right to Data Portability
Article 20
You have the right to receive your personal data in a structured, commonly used, and machine-readable format (such as JSON or CSV). You also have the right to request that we transmit this data directly to another controller where technically feasible.
Right to Object
Article 21
You have the right to object to processing of your personal data based on legitimate interests or for direct marketing purposes. Where you object to processing for direct marketing, we will stop processing your data for that purpose immediately.
Right to Lodge a Complaint
Supervisory Authority
If you believe that our processing of your personal data infringes data protection laws, you have the right to lodge a complaint with a supervisory authority. In the EU, you may contact your local Data Protection Authority. In the UK, you may contact the Information Commissioner's Office (ICO).
EXERCISING YOUR RIGHTS
To exercise any of these rights, please contact our privacy team at privacy@skrub.io. We will respond to your request within 30 days. You may also update certain information directly through your account settings.
We may request verification of your identity before processing your request to ensure we are protecting your data from unauthorized access.
DATA PROCESSING AGREEMENTS
Business Customer DPA
If you are a business customer subject to GDPR or other data protection regulations and require a Data Processing Agreement (DPA) with Skrub, we can provide one upon request.
Our DPA includes the EU Standard Contractual Clauses (SCCs) and outlines:
- The nature, purpose, and duration of data processing
- Categories of personal data processed
- Technical and organizational security measures
- Sub-processor obligations and approvals
- Data breach notification procedures
- Audit rights and data return/deletion obligations
To request a DPA, please contact us at privacy@skrub.io with your company name and business requirements.
CHANGES TO THIS POLICY
We may update this Privacy Policy from time to time. When we make material changes:
- We will update the "Last Updated" date at the top of this page
- We may notify you via email or in-app notification for significant changes
- Continued use of the Service after changes constitutes acceptance
CONTACT US
If you have questions about this Privacy Policy or our data practices, please contact us:
Turtle Digital Holdings, LLC d/b/a Skrub
Illinois, United States
support@skrub.io
Turtle Digital Holdings, LLC d/b/a Skrub
Illinois, United States
If you have any questions about this Privacy Policy, please contact us at support@skrub.io