Security & privacy
Your reputation data, handled with care
You're trusting HiFiveStar with your reviews and your customers' contact details. Here's exactly how we protect them — in plain language, with no fine-print surprises.
Encrypted in transit
Every connection to HiFiveStar runs over HTTPS/TLS, so the data moving between you, your customers, and our servers is encrypted end to end.
Hardened by default
A strict Content-Security-Policy, clickjacking protection (X-Frame-Options), MIME-sniffing protection, and a locked-down permissions policy ship on every page.
GDPR-compliant
We process personal data under the EU GDPR — lawful basis, storage limitation, and the full set of data-subject rights, with a Data Processing Addendum available to customers.
You own your data
Your reviews and customer contacts are yours. Request access, correction, export, or deletion at any time — and on request we return or securely wipe your data.
Your data rights, always yours
HiFiveStar is operated by XASCEND LLC and processes personal data in line with the EU General Data Protection Regulation. As a data subject, you can exercise any of these rights at any time:
Access. Get a copy of the personal data we hold about you.
Rectification. Correct anything that's inaccurate or incomplete.
Erasure. Ask us to delete your personal data.
Restriction. Limit how we process your data.
Objection. Object to processing you don't agree with.
Portability. Receive your data in a portable, machine-readable form.
To exercise a right, email support@hifivestar.com. You can also lodge a complaint with your local data-protection supervisory authority.
How we process your data
We only process the personal data we need to run the service — your account details, the reviews we sync on your behalf, and the contacts you ask us to send review invitations to. We process it for the purposes you'd expect, and we keep it only for as long as it's needed, reviewing stored data periodically under the GDPR's storage-limitation principle.
Sub-processors & the DPA
Where we rely on third-party providers to deliver the service (for example, to send messages or host data), they're appointed as data processors under Article 28 of the GDPR — bound by contract to appropriate technical and organizational security measures and strict confidentiality. Business customers can review and sign our Data Processing Addendum, which sets these obligations out in full.
If something goes wrong
We take technical and organizational measures appropriate to the risk to keep your data safe (GDPR Article 32). In the unlikely event of a personal-data breach, we'll notify affected customers without undue delay and assist with the analysis and reporting obligations under Articles 33 and 34 — so you're never left in the dark.
Straight with you
We describe only the protections we actually have in place. As HiFiveStar grows we'll add formal audits and certifications — and we'll publish them here when we do, not before.
Reputation software you can trust
Get more reviews, reply faster, and keep your data protected — all from one simple dashboard. Start free, no contract required.
Free forever plan · No contract required