Privacy Policy
What data we collect, why we collect it, who we share it with, and every right you have over it — explained in plain English, not legal boilerplate.
This Privacy Policy applies to trustedbuyerreport.com and all services operated under the Trusted Buyer Report brand ("we", "us", "our"). It explains how we collect, use, share, and protect your personal information when you visit our site, use our AI tools, submit a review, subscribe to our newsletter, or contact us.
Data controller: Trusted Buyer Report · Contact: privacy@trustedbuyerreport.com
| If you… | We collect… | Legal basis (GDPR) |
|---|---|---|
| Browse the site | IP address, browser type, pages visited, referrer URL | Legitimate interest |
| Create an account | Name, email, hashed password, account activity | Contract |
| Subscribe to newsletter | Email address, subscription date, open/click events | |
| Submit a review | Name/username, review text, rating, timestamp | |
| Contact us | Name, email, message content, enquiry type | Contract |
| Click an affiliate link | Click event, referral cookie (via affiliate network) | |
| Use AI tools | Search query text, tool interaction logs | Legitimate interest |
- Log data: IP address, browser type and version, operating system, referring URL, pages visited, time spent, error logs. Retained for 90 days. Used for security, analytics, and abuse prevention.
- Device data: Screen resolution, device type (desktop/mobile), language setting. Used to serve the correct layout and improve site performance.
- Analytics data: Aggregated page-view and session data via Google Analytics 4 (anonymised IP). Used to understand which content is useful and improve the site.
- Account data: First and last name, email address, bcrypt-hashed password, profile photo (optional), account creation date.
- Review data: Store or product reviews you submit, star ratings, verified-purchase flag (if you connect a purchase receipt), and any photos you attach.
- Newsletter data: Email address, subscription date, and whether you open or click emails (via ESP tracking pixel, which you can opt out of).
- Contact data: Name, email, subject, and message body when you use our contact form.
- Affiliate networks: Click-through and purchase confirmation events from Amazon Associates, ShareASale, CJ, Impact, Rakuten, Walmart, and eBay Partner Network. This data is used solely to attribute commissions.
- Social login (optional): If you choose to sign in via Google or Apple, we receive your name, email, and profile picture from that provider. We do not receive your social media password.
| Purpose | Data used | Legal basis |
|---|---|---|
| Operate and serve the website | Log data, device data | Legitimate interest |
| Manage your user account | Account data, activity log | Contract performance |
| Publish your reviews | Review data, username | |
| Send newsletter | Email address, send/open data | |
| Respond to contact enquiries | Contact form data | Contract performance |
| Attribute affiliate commissions | Click events, referral cookie | |
| Improve AI tools & search | Anonymised query logs | Legitimate interest |
| Fraud prevention & security | IP address, log data | Legal obligation |
| Comply with legal requests | Any data specified in request | Legal obligation |
We do not use your data for automated decision-making that produces legal or similarly significant effects. Our AI tools analyse store data — not individual user profiles.
We use cookies and similar tracking technologies (local storage, pixel tags) on this site. Strictly necessary cookies are set automatically. All other categories require your consent via the cookie banner shown on your first visit.
Amazon and the Amazon logo are trademarks of Amazon.com, Inc. or its affiliates. Amazon collects data through its own tracking mechanisms when you visit Amazon.com via a link on this site. This data collection is governed by Amazon's Privacy Notice , not this policy.
- When you click a link to Amazon.com on this site, a referral tag (e.g.
tag=trustedbuy-20) is appended to the URL. - Amazon sets a 24-hour session cookie on Amazon.com. If you purchase within that session, we receive a commission of 1–10% depending on the product category.
- We receive aggregated commission data from Amazon — we do not receive your name, address, payment details, or any personally identifiable information about your purchase.
- Amazon's tracking operates under Amazon's own privacy policy. If you are an Amazon Prime member or logged-in user, Amazon's privacy terms apply to data Amazon collects about your behaviour on its platform.
| Third party | Data shared | Purpose | Privacy policy |
|---|---|---|---|
| Google Analytics 4 | Anonymised usage data, truncated IP | Site analytics | Link |
| Amazon Associates | Referral click events | Affiliate attribution | Link |
| ShareASale / CJ / Impact / Rakuten / Walmart / eBay | Referral click events | Affiliate attribution | See each network's policy |
| Email service provider (ESP) | Email address, send/open events | Newsletter delivery | Varies by provider |
| Hosting / CDN provider | IP address (log data) | Site delivery & security | Varies by provider |
| Law enforcement / courts | As specified in legal request | Legal obligation | N/A |
We do not sell your personal data to data brokers, advertising networks, or any other third parties for their own commercial use. This applies to all users, including California residents under CCPA.
| Data category | Retention period | Reason |
|---|---|---|
| Server log data | 90 days | Security monitoring, abuse prevention |
| Account data (active) | Life of account + 30 days | Service delivery |
| Account data (deleted) | 30 days then purged | Account recovery window |
| Published reviews | Indefinite unless deletion requested | Public editorial record |
| Newsletter subscriptions | Until unsubscribe + 14 days | Unsubscribe confirmation |
| Contact form messages | 24 months | Correspondence record |
| Affiliate click data | As required by network (typically 90 days) | Commission attribution |
| Analytics data | 14 months (GA4 default) | Trend analysis |
| Legal hold data | As required by law | Legal obligation |
You may request early deletion of your personal data at any time — see §9 GDPR rights and §10 CCPA rights. Note that published reviews credited to your account will be anonymised (not deleted) to preserve the integrity of our editorial record, unless there is a legal basis for full deletion.
- All data transmitted between your browser and our servers is encrypted with TLS 1.3 (HTTPS enforced site-wide).
- Passwords are hashed with bcrypt (cost factor 12) — we never store plaintext passwords and cannot retrieve them.
- Database access is restricted to application-layer processes; no direct external database access is permitted.
- All internal staff access to personal data is role-based and logged. Only staff with a legitimate operational need can access user data.
- Automated security scanning and dependency updates are run on a weekly schedule.
- Backups are encrypted at rest using AES-256 and stored in a geographically separate region.
- Categories of personal information collected
- Sources from which it was collected
- Business purpose for collection
- Third parties with whom it is shared
- Request deletion of personal information we hold
- We will respond within 45 days (extendable to 90)
- We will instruct service providers to delete your data
- Certain exceptions apply (legal obligation, security)
- We do not sell personal information
- No opt-out needed — no data sale occurs
- Affiliate click data is shared, not sold (no compensation for the data itself)
- Exercising your CCPA rights will not result in different pricing
- You will not receive a lower level of service
- You will not be denied goods or services
This site is intended for users aged 13 and older. We do not knowingly collect personal data from children under 13 (or under 16 in the EU/UK where applicable). If we become aware that we have inadvertently collected personal data from a child under the applicable age threshold, we will delete it promptly.
If you believe a child has provided us with personal information, please contact us immediately at privacy@trustedbuyerreport.com.
We review this Privacy Policy at minimum every 6 months and whenever there is a material change to our data practices. The version number and effective date at the top of this page always reflect the current version.
For material changes — changes that affect how we use your personal data in a significant way — we will notify registered users by email at least 14 days before the change takes effect. Continued use of the site after the effective date constitutes acceptance of the revised policy.
Non-material changes (grammar, formatting, clarifications that do not alter the substance of our data practices) will be updated without individual notification, though the version number will increment.
Smarter shopping, weekly
New store reviews, buying guides, and research-backed insights delivered to your inbox. No spam, no fluff.