This policy explains how Staaro OÜ processes personal data when you visit staaro.ee, create or use a Staaro account, contact us, or receive and answer a review request sent through our service. It also explains your rights under the EU General Data Protection Regulation (GDPR).
Staaro OÜ (registry code 17561530, Liivalaia tn 28, 10118 Tallinn, Estonia) is the company responsible for this service. Contact us at staaro.eu@gmail.com or +372 5816 2265.
Our roles
For account, website, billing and direct-support data, Staaro is the data controller. When a business customer uploads a customer phone number and asks Staaro to send a review request, that business normally acts as controller and Staaro acts as its processor. The business must have a valid legal basis for using the number and sending the message. Staaro processes recipient data only to provide, secure and support the contracted service.
Data we process
Account and business data
- Name, email address, password hash, role and language preference.
- Business name, country, sender name, Google review link and settings.
- Billing contact, address, VAT number, plan, subscription and invoice status.
- Support messages, audit events and records of consent to our terms.
Review-request and recipient data
- Customer phone number, encrypted at rest, plus a one-way hash used for opt-out enforcement.
- SMS content, sender, delivery status, message locale and scheduling information.
- Star rating, optional private feedback and the time it was submitted.
- A privacy-preserving hash of the submitting IP address for abuse prevention.
- Opt-out status. We retain a one-way phone hash so the business cannot message that number again.
Integration and technical data
If you connect Google, Pipedrive, Altegio, Merit, WooCommerce or a webhook, we process the credentials, identifiers and event metadata needed to run that integration. We also receive browser, device, IP, request, security and diagnostic data in server logs. CSV column names and API identifiers remain language-neutral and are not translated.
Purposes and legal bases
- Contract: creating accounts, sending messages, collecting feedback, billing, support and integrations.
- Legitimate interests: securing the service, preventing fraud and abuse, debugging, improving reliability and measuring aggregate product performance.
- Consent: optional analytics or marketing cookies and any direct marketing that legally requires consent.
- Legal obligation: accounting, tax, sanctions, law-enforcement requests and protection of legal claims.
We do not sell personal data. We do not use recipient ratings or private feedback for advertising, profiling or automated decisions with legal or similarly significant effects.
Service providers and international transfers
We share only the data necessary with infrastructure, database, SMS, email, payment, analytics, anti-abuse and connected-integration providers. Current core providers include GatewayAPI for SMS delivery, Resend for transactional email, Stripe for payments, and Google services when you use Google sign-in, Business Profile, Places or reCAPTCHA. Each provider acts under its own terms or a data-processing agreement, as appropriate.
We prefer EU/EEA processing. If a provider processes data outside the EEA, we use an adequacy decision, EU Standard Contractual Clauses or another lawful transfer mechanism, together with appropriate safeguards.
Retention
- Encrypted recipient phone numbers are automatically removed after the configured retention period, currently 365 days.
- Phone hashes used to honour opt-outs may be retained for as long as necessary to prevent further messages.
- Ratings, message records and account settings are kept while the customer account is active, then deleted or anonymised unless needed for claims or law.
- Billing and invoice records are retained for the period required by Estonian accounting and tax law.
- Security and diagnostic logs are retained only as long as reasonably necessary for security and operations.
Cookies
Necessary cookies support authentication, security and saved consent. Analytics and marketing storage is denied by default and enabled only after you accept it in the cookie banner. We do not infer a language from Accept-Language; the language comes from the URL or your saved account preference.
Your GDPR rights
Depending on the circumstances, you may ask us to:
- give you access to your personal data and a copy of it;
- correct inaccurate or incomplete data;
- erase data, or restrict how it is used;
- provide portable data you supplied to us;
- stop processing based on legitimate interests;
- withdraw consent at any time, without affecting earlier lawful processing.
If Staaro processes recipient data only for one of our business customers, send your request to that business first. We will assist it in responding. We may ask for information needed to verify your identity and normally respond within one month.
Security
We use access controls, encrypted transport, encryption for sensitive credentials and phone numbers, one-way hashes, tenant isolation, rate limits, signed public tokens, audit logging and restricted retention. No online system is completely risk-free, but we continually review reasonable technical and organisational safeguards.
Contact, children and complaints
Staaro is a business service and is not directed at children. If you have a privacy question or request, email staaro.eu@gmail.com. You may also complain to the Estonian Data Protection Inspectorate or the supervisory authority in your EU/EEA country. We may update this policy when the service or law changes; the current version and modification date are published here.
LAST MODIFIED · 04/08/2026 · Staaro OÜ · 17561530