PRIVACY POLICY

Last Updated: January 6, 2026

Effective Date: January 6, 2026

This Privacy Policy explains how Turtle Digital Holdings, LLC d/b/a Skrub ("Company," "we," "us," or "our") collects, uses, shares, and protects your personal information when you use the Skrub platform ("Service"). By using our Service, you consent to the data practices described in this policy.

01

DATA WE COLLECT

Account Data

  • Email address (for login and notifications)
  • Encrypted password (hashed, never stored in plain text)
  • Display name and company name (optional)
  • Profile photo (if uploaded)
  • Phone number (if SMS notifications enabled)

Public Data

We collect publicly available reviews and business information from the URLs you provide:

  • Google Maps reviews and business details
  • Facebook reviews and business details
  • Facebook reviews (if enabled)

Note: This data is already publicly accessible on the internet. We do not access private or restricted content.

Payment Data

Payment processing is handled entirely by Stripe. We do not store, process, or have access to your full credit card numbers, CVV, or other sensitive payment information. Stripe is PCI-DSS compliant.

02

HOW WE USE YOUR DATA

We use the data we collect to provide and improve our Service:

  • 1

    Threat Score Calculation

    Analyze review content to detect potential spam, fake reviews, and reputation threats using our AI-powered risk scoring system.

  • 2

    AI Draft Generation

    Generate suggested responses to reviews (both positive and negative) to help you engage with customers effectively.

  • 3

    Removal Request Templates

    Generate informational templates that may assist you in addressing potentially fraudulent or policy-violating reviews.

  • 4

    Service Communications

    Send alerts, notifications, and service updates via email or SMS (if enabled).

Legal Basis & Data Handling

LEGITIMATE INTEREST (GDPR Article 6(1)(f))

We process public review data based on the User's "Legitimate Interest" to defend their business reputation against fraud and spam, per GDPR Article 6(1)(f). This lawful basis applies because reputation defense represents a genuine business need that does not override the rights of reviewers whose data is already publicly accessible.

NO BLACKLISTING OR DATA SHARING

Skrub does not share reputation data between clients. All data is siloed strictly to the User who requested the scan. We do not maintain cross-client databases, reviewer blacklists, or shared risk profiles. Your data remains yours alone.

PUBLIC DATA ONLY

We only process data that is already publicly accessible on third-party platforms (Google Maps, Facebook, TripAdvisor, etc.). We do not expose private individuals' contact information, email addresses, phone numbers, or any data not already visible on the public review platforms.

04

THIRD-PARTY SUB-PROCESSORS

IMPORTANT DISCLOSURE

To provide our Service, we share certain data with the following third-party infrastructure partners. Each partner processes data only as necessary to perform their designated function.

Google (Gemini AI)

AI Processing Partner

Purpose: Text generation, sentiment analysis, spam detection scoring, response drafting, and AI chat assistant functionality.

Data Shared: Review text content, business context, and chat messages for analysis.

Outscraper

Data Retrieval Partner

Purpose: Retrieving publicly available review data from Google Maps and other platforms.

Data Shared: Business URLs you provide for scanning.

Stripe

Payment Processing Partner

Purpose: Subscription billing and payment processing.

Data Shared: Email address for receipts and payment identifiers. Payment card details are sent directly to Stripe and never touch our servers.

Twilio

SMS Notifications Partner

Purpose: Sending SMS alert notifications for high-risk reviews (if enabled).

Data Shared: Phone number and notification message content.

HubSpot

Customer Relationship Management Partner

Purpose: Customer relationship management, marketing automation, email nurturing sequences, and customer support tracking.

Data Shared: Email address, name, company information, subscription status, and service usage activity.

Resend

Transactional Email Partner

Purpose: Sending transactional emails including account verification, password reset, and service notifications.

Data Shared: Email address and email content.

05

INTERNATIONAL DATA TRANSFERS

Skrub is operated from the United States. If you are accessing our Service from outside the US, including from the European Economic Area (EEA), United Kingdom, or other regions with data protection laws, please be aware that your data may be transferred to, stored, and processed in the United States.

Data Processing Location

United States

Your personal data may be processed in the United States and other countries where our service providers operate. The US may not have data protection laws equivalent to those in your jurisdiction.

Transfer Safeguards

Standard Contractual Clauses (SCCs)

For transfers of personal data from the EEA/UK to our sub-processors located outside of adequacy regions, we rely on the European Commission's Standard Contractual Clauses (SCCs) as the legal mechanism for such transfers. Our key sub-processors (Google, Stripe, Twilio, HubSpot, Resend) maintain their own GDPR compliance programs and have committed to SCCs or equivalent safeguards.

Request Transfer Information

Your right to know

You have the right to request information about the specific safeguards we have in place for international data transfers. To request a copy of the SCCs or information about the safeguards applied to your data, please contact us at privacy@skrub.io.

06

AI DATA USAGE

OUR COMMITMENT

Data submitted to our AI models is used solely to generate your requested content. We do not sell your data to third parties for model training purposes.

  • Review content is processed by OpenAI's API to generate scores, drafts, and scripts
  • We use OpenAI's API with data privacy protections enabled
  • Your data is not used by Skrub or our partners to train AI models
  • Processing is transactional — data is sent, processed, and results returned
07

DATA RETENTION & DELETION

We retain your data only as long as necessary to provide our Service or as required by law.

YOUR RIGHT TO DELETION

Users may request full account deletion at any time by contacting support@skrub.io. Upon deletion, all scraped history and generated drafts associated with your account are permanently removed from our systems within 30 days.

  • Active accounts: Data retained while subscription is active
  • Cancelled accounts: Data retained for 30 days after cancellation, then deleted
  • Deletion requests: Processed within 30 days of request
  • Payment records: Retained as required by financial regulations
08

COOKIES & TRACKING

We use minimal cookies necessary for the Service to function:

  • Session cookies: To keep you logged in during your session
  • Security cookies: To protect against cross-site request forgery
  • Preference cookies: To remember your settings

We do not use third-party advertising trackers or sell your browsing data.

09

DATA SECURITY

We implement comprehensive technical and organizational measures to protect your data:

Encryption & Transport Security

  • All data transmitted over HTTPS/TLS encryption
  • HTTP Strict Transport Security (HSTS) enforced
  • Passwords hashed using industry-standard algorithms (never stored in plain text)

Application Security

  • Content Security Policy (CSP) headers to prevent XSS attacks
  • Cross-Site Request Forgery (CSRF) protection on all forms
  • Secure session cookies (HttpOnly, SameSite, Secure flags)
  • Rate limiting on authentication endpoints
  • Password strength requirements enforced

Access & Monitoring

  • Database access restricted to authorized personnel
  • Error monitoring and alerting with Sentry
  • Regular security reviews and updates

No system is 100% secure. While we strive to protect your information using industry best practices, we cannot guarantee absolute security.

10

YOUR RIGHTS (GDPR)

Under the General Data Protection Regulation (GDPR) and other applicable data protection laws, you have specific rights regarding your personal data. We are committed to honoring these rights.

Right to Access

Article 15

You have the right to obtain confirmation as to whether we are processing your personal data, and if so, to request access to that data along with information about how it is processed. You may request a copy of your personal data free of charge.

Right to Rectification

Article 16

You have the right to request correction of inaccurate personal data we hold about you. Taking into account the purposes of the processing, you also have the right to have incomplete personal data completed.

Right to Erasure ("Right to be Forgotten")

Article 17

You have the right to request deletion of your personal data where: the data is no longer necessary for its original purpose; you withdraw consent; you object to processing; the data was unlawfully processed; or deletion is required by law. We will process erasure requests within 30 days.

Right to Data Portability

Article 20

You have the right to receive your personal data in a structured, commonly used, and machine-readable format (such as JSON or CSV). You also have the right to request that we transmit this data directly to another controller where technically feasible.

Right to Object

Article 21

You have the right to object to processing of your personal data based on legitimate interests or for direct marketing purposes. Where you object to processing for direct marketing, we will stop processing your data for that purpose immediately.

Right to Lodge a Complaint

Supervisory Authority

If you believe that our processing of your personal data infringes data protection laws, you have the right to lodge a complaint with a supervisory authority. In the EU, you may contact your local Data Protection Authority. In the UK, you may contact the Information Commissioner's Office (ICO).

EXERCISING YOUR RIGHTS

To exercise any of these rights, please contact our privacy team at privacy@skrub.io. We will respond to your request within 30 days. You may also update certain information directly through your account settings.

We may request verification of your identity before processing your request to ensure we are protecting your data from unauthorized access.

11

DATA PROCESSING AGREEMENTS

Business Customer DPA

If you are a business customer subject to GDPR or other data protection regulations and require a Data Processing Agreement (DPA) with Skrub, we can provide one upon request.

Our DPA includes the EU Standard Contractual Clauses (SCCs) and outlines:

  • The nature, purpose, and duration of data processing
  • Categories of personal data processed
  • Technical and organizational security measures
  • Sub-processor obligations and approvals
  • Data breach notification procedures
  • Audit rights and data return/deletion obligations

To request a DPA, please contact us at privacy@skrub.io with your company name and business requirements.

12

CHANGES TO THIS POLICY

We may update this Privacy Policy from time to time. When we make material changes:

  • We will update the "Last Updated" date at the top of this page
  • We may notify you via email or in-app notification for significant changes
  • Continued use of the Service after changes constitutes acceptance
13

CONTACT US

If you have questions about this Privacy Policy or our data practices, please contact us:

Turtle Digital Holdings, LLC d/b/a Skrub

Illinois, United States

support@skrub.io

Turtle Digital Holdings, LLC d/b/a Skrub
Illinois, United States

If you have any questions about this Privacy Policy, please contact us at support@skrub.io