InfinitIQ Tech LLC (“InfinitIQ Tech,” “we,” “us,” or “our”) operates ReviewDesk. This Privacy Policy explains the information we process, why we process it, how it may be shared, and the choices available to ReviewDesk customers and users.
This Policy applies to the public ReviewDesk pages on infinitiqtech.com and to the ReviewDesk service. Apple, Google, Atlassian, Shopify, and other connected services operate under their own privacy notices and terms.
1. Information we process
Account and workspace information
We may process a username, display name, email address, password verifier, workspace membership, roles, product access, session records, and account-lifecycle information. We also process security information such as sign-in times, privacy-keyed network identifiers, a coarse network source, browser or device labels, and authentication audit events.
Review and customer content
When an organization connects a review source, ReviewDesk may process source identifiers, ratings, titles, review text, public author names or identifiers, timestamps, language, locale, territory, app version, available device or verification metadata, edits, and the source payload and its revisions. We call this and other information submitted or connected by a customer “Customer Content.”
Connected-service information
-
Google Play: the authorizing Google account’s
stable identifier and verified email, app names and package
identifiers visible to that account, the apps a ReviewDesk
administrator selects, their review data, the selected-app
allowlist, and an encrypted refresh token. ReviewDesk does not
receive the Google password, two-factor authentication data,
or Google browser cookies. Short-lived access tokens are kept
in backend process memory rather than stored in the ReviewDesk
database. Google exposes review retrieval through the broader
androidpublisherOAuth scope; Google Play Console permissions, ReviewDesk’s backend app allowlist, and the approved API calls constrain how ReviewDesk uses that grant. - App Store Connect: key and issuer metadata, a protected private API key, visible and selected app metadata, and reviews for selected apps. The private key is encrypted for storage, and short-lived App Store Connect tokens are not persisted. An Apple team key can expose every app in its App Store Connect account even when ReviewDesk processes only the administrator-selected allowlist, so customers should use the narrowest available Apple role and app assignments.
- Jira Cloud: Atlassian authorization data, the selected Jira site and projects, issue metadata and content needed for matching, configured issue fields, and records of ReviewDesk actions. When authorized, ReviewDesk sends the evidence and fields needed to search, match, draft, or create Jira work.
- Configured Shopify review providers: review data and provider identifiers made available through the customer’s configured provider connection.
Derived, operational, and website information
ReviewDesk creates normalized and redacted text, classifications, translations when configured, embeddings, clusters, trends, priorities, routes, drafts, approvals, audit records, and service-health information. When you visit this website, our hosting and content-delivery providers may receive standard request information such as an IP address, user agent, requested page, and timestamp. The site also loads fonts from Google Fonts and software assets from jsDelivr and unpkg, which receive the technical information needed to deliver those resources.
ReviewDesk uses essential session and cross-site request-forgery cookies to authenticate users and protect account actions. These cookies are part of the service’s security controls, not advertising cookies.
2. How we use information
We process information to:
- create accounts, isolate workspaces, authenticate users, and enforce permissions;
- limit ReviewDesk processing to the apps, sites, and projects an administrator selects;
- collect, preserve, normalize, and trace revisions to customer reviews;
- detect and redact certain sensitive patterns before downstream processing;
- classify, group, prioritize, route, and present review evidence;
- prepare, approve, match, or create Jira work as configured;
- operate, secure, troubleshoot, audit, and improve the reliability of ReviewDesk;
- respond to support requests and communicate about the service; and
- comply with law, enforce agreements, and protect users, InfinitIQ Tech, and others.
3. Google API data
ReviewDesk uses Google account information to identify the account that authorized the integration, discover the Google Play apps available to it, and read reviews only for apps selected by an authorized ReviewDesk administrator. We use that information only to provide and protect ReviewDesk’s user-facing review workflow.
ReviewDesk’s use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including its Limited Use requirements. We do not use Google API data for advertising. We transfer it only to provide or improve ReviewDesk’s visible, user-facing features with the user’s consent, for security, or when legally required, and always within the Limited Use requirements.
Disconnecting Google Play stops new provider calls, removes durable Google token material from ReviewDesk, and attempts to revoke the Google grant. Previously collected reviews remain subject to the organization’s retention settings, deletion controls, and any legal hold. A Google administrator may also revoke access from the Google account.
4. Automated analysis and redaction
ReviewDesk uses automated methods to normalize, classify, group, score, route, and draft work from review evidence. Configured deployments may also use translation or model-processing providers. Automated outputs can be incomplete or wrong, so ReviewDesk preserves evidence and provides human-review paths for ambiguous, conflicting, or unsupported actions.
ReviewDesk is designed to detect and redact certain email addresses, phone numbers, credentials, and common secret formats before downstream processing. Detection is not perfect. Customers should not intentionally place credentials, regulated data, or other unnecessary sensitive information in ReviewDesk.
5. When information is shared
We may share information with:
- Authorized workspace users, according to their role and product scope.
- Connected services, such as Apple, Google, Atlassian, and a configured Shopify review provider, when necessary to perform an action the customer configured.
- Service providers, that help host, secure, monitor, support, communicate, translate, or process information for the service. The providers used can vary by deployment; contact us for the current deployment-specific list before connecting production data.
- Authorities or other parties, when reasonably necessary to comply with law, protect rights and safety, investigate abuse, or support a corporate transaction.
Section 3 controls how Google API data is transferred. Nothing in this general sharing section permits a use or transfer of Google API data outside Google’s Limited Use requirements.
6. Retention, deletion, and legal holds
ReviewDesk supports scoped retention and deletion controls. Under the standard application policy, raw review evidence and workflow artifacts become eligible for deletion after 365 days, trace spans after 30 days, model telemetry after 90 days, and structured feedback after 730 days. Authentication-attempt telemetry is designed for a 30-day retention period. Actual deletion timing depends on deployment configuration, scheduled retention operations, backups, an organization’s instructions, and legal requirements.
ReviewDesk-managed Apple, Google, and Jira credentials are kept while the connection remains active and are removed or made unusable when the relevant connection is disconnected, subject to provider behavior. A configured Shopify adapter may manage its own credentials under that adapter’s deployment and provider terms. An authorized administrator can request deletion of a review and its linked workflow data. ReviewDesk may retain a redacted, hashed deletion record, and an active legal hold may delay deletion. Account, audit, security, billing, and support records may follow different periods where needed for the service, our agreements, or law.
Available ReviewDesk export controls provide scoped aggregate counts and privacy-redacted operational records. They are not a full portable copy of every account record or every item of Customer Content. Contact us before termination if your organization needs an export beyond the controls available in its deployment.
7. Security
ReviewDesk is designed with password hashing, opaque and hashed session capabilities, scoped workspace permissions, protected integration credentials, redaction, separate restricted raw evidence, and append-only audit records. Production security also depends on deployment controls such as transport encryption, managed secrets, protected storage, backups, and ingress configuration. No method of storage or transmission is completely secure.
8. Your choices and privacy requests
Workspace administrators can limit selected apps and Jira projects and can disconnect provider integrations. Depending on your location and relationship with ReviewDesk, you may be able to request access, correction, or deletion of information, object to or restrict certain processing, or withdraw consent where consent applies. These rights are subject to applicable law, the organization that controls the workspace, available product controls, and lawful retention requirements.
Send a request to info@infinitiqtech.com. We may need to verify your identity and authority and may direct a workspace user to the organization that controls the account.
9. International processing
InfinitIQ Tech is based in the United States. ReviewDesk and its service providers may process information in the United States and other locations where they operate. International processing is subject to applicable law and any written agreement with the customer.
10. Children
ReviewDesk is intended only for people who are at least 18 years old and authorized to act for an organization. If you believe a child provided personal information to ReviewDesk, contact us so we can investigate.
11. Changes to this Policy
We may update this Policy as ReviewDesk or legal requirements change. We will post the updated version here and change the effective date. When a material change affects how previously collected information is used, we will provide additional notice or seek consent where law requires it.
12. Contact
For privacy questions or requests, contact InfinitIQ Tech LLC at info@infinitiqtech.com. InfinitIQ Tech is based in Boston, Massachusetts, USA.
ReviewDesk use is also governed by our Terms of Service.