Staaro
How it worksIntegrationsPricing
Home/Legal/Privacy policy

Privacy policy

Last modified4 August 2026

Legal documents

  • Terms of service
  • Privacy policy
  • GDPR data protection rights

On this page

  • Our roles
  • Data we process
  • Purposes and legal bases
  • Service providers and transfers
  • Retention
  • Cookies
  • Your GDPR rights
  • Security
  • Contact and complaints

Questions about our legal terms?

Contact us — we reply within 24 hours on business days.

staaro.eu@gmail.com

This policy explains how Staaro OÜ processes personal data when you visit staaro.ee, create or use a Staaro account, contact us, or receive and answer a review request sent through our service. It also explains your rights under the EU General Data Protection Regulation (GDPR).

Staaro OÜ (registry code 17561530, Liivalaia tn 28, 10118 Tallinn, Estonia) is the company responsible for this service. Contact us at staaro.eu@gmail.com or +372 5816 2265.

Our roles

For account, website, billing and direct-support data, Staaro is the data controller. When a business customer uploads a customer phone number and asks Staaro to send a review request, that business normally acts as controller and Staaro acts as its processor. The business must have a valid legal basis for using the number and sending the message. Staaro processes recipient data only to provide, secure and support the contracted service.

Data we process

Account and business data

  • Name, email address, password hash, role and language preference.
  • Business name, country, sender name, Google review link and settings.
  • Billing contact, address, VAT number, plan, subscription and invoice status.
  • Support messages, audit events and records of consent to our terms.

Review-request and recipient data

  • Customer phone number, encrypted at rest, plus a one-way hash used for opt-out enforcement.
  • SMS content, sender, delivery status, message locale and scheduling information.
  • Star rating, optional private feedback and the time it was submitted.
  • A privacy-preserving hash of the submitting IP address for abuse prevention.
  • Opt-out status. We retain a one-way phone hash so the business cannot message that number again.

Integration and technical data

If you connect Google, Pipedrive, Altegio, Merit, WooCommerce or a webhook, we process the credentials, identifiers and event metadata needed to run that integration. We also receive browser, device, IP, request, security and diagnostic data in server logs. CSV column names and API identifiers remain language-neutral and are not translated.

Purposes and legal bases

  • Contract: creating accounts, sending messages, collecting feedback, billing, support and integrations.
  • Legitimate interests: securing the service, preventing fraud and abuse, debugging, improving reliability and measuring aggregate product performance.
  • Consent: optional analytics or marketing cookies and any direct marketing that legally requires consent.
  • Legal obligation: accounting, tax, sanctions, law-enforcement requests and protection of legal claims.

We do not sell personal data. We do not use recipient ratings or private feedback for advertising, profiling or automated decisions with legal or similarly significant effects.

Service providers and international transfers

We share only the data necessary with infrastructure, database, SMS, email, payment, analytics, anti-abuse and connected-integration providers. Current core providers include GatewayAPI for SMS delivery, Resend for transactional email, Stripe for payments, and Google services when you use Google sign-in, Business Profile, Places or reCAPTCHA. Each provider acts under its own terms or a data-processing agreement, as appropriate.

We prefer EU/EEA processing. If a provider processes data outside the EEA, we use an adequacy decision, EU Standard Contractual Clauses or another lawful transfer mechanism, together with appropriate safeguards.

Retention

  • Encrypted recipient phone numbers are automatically removed after the configured retention period, currently 365 days.
  • Phone hashes used to honour opt-outs may be retained for as long as necessary to prevent further messages.
  • Ratings, message records and account settings are kept while the customer account is active, then deleted or anonymised unless needed for claims or law.
  • Billing and invoice records are retained for the period required by Estonian accounting and tax law.
  • Security and diagnostic logs are retained only as long as reasonably necessary for security and operations.

Cookies

Necessary cookies support authentication, security and saved consent. Analytics and marketing storage is denied by default and enabled only after you accept it in the cookie banner. We do not infer a language from Accept-Language; the language comes from the URL or your saved account preference.

Your GDPR rights

Depending on the circumstances, you may ask us to:

  • give you access to your personal data and a copy of it;
  • correct inaccurate or incomplete data;
  • erase data, or restrict how it is used;
  • provide portable data you supplied to us;
  • stop processing based on legitimate interests;
  • withdraw consent at any time, without affecting earlier lawful processing.

If Staaro processes recipient data only for one of our business customers, send your request to that business first. We will assist it in responding. We may ask for information needed to verify your identity and normally respond within one month.

Security

We use access controls, encrypted transport, encryption for sensitive credentials and phone numbers, one-way hashes, tenant isolation, rate limits, signed public tokens, audit logging and restricted retention. No online system is completely risk-free, but we continually review reasonable technical and organisational safeguards.

Contact, children and complaints

Staaro is a business service and is not directed at children. If you have a privacy question or request, email staaro.eu@gmail.com. You may also complain to the Estonian Data Protection Inspectorate or the supervisory authority in your EU/EEA country. We may update this policy when the service or law changes; the current version and modification date are published here.


LAST MODIFIED · 04/08/2026 · Staaro OÜ · 17561530

Staaro

Automated review requests for Baltic businesses.

Staaro OÜ

Product

  • Product
  • Company
  • Legal
  • API documentation

API documentation

  • API documentation

Legal

  • Terms
  • Privacy
  • GDPR
© 2026 Staaro OÜ · reg 17561530 · All rights reserved.