Information we collect
We collect information you choose to provide, including your name, business name, email address, phone number, message, business address, website, Google Business Profile link, onboarding responses, signed agreement information, and client portal credentials.
For customers using the optional CRM + Customer Tracker, the client or its authorized users may enter customer names, phone numbers, appointment or visit details, services, prices, tips, assigned team members, follow-up status, and operational notes.
Our website may also process technical information such as IP address, browser information, device information, timestamps, security logs, and essential cookies or signed session tokens. The electronic agreement records the signing time, signature, and IP address as evidence of acceptance.
The free QCR Score uses the business name, address, selected Google listing, and publicly available business information. Report requests also collect the email address where the report should be delivered.
How we use information
We use information to provide requested reports, verify payments, prepare and retain business records, complete onboarding, create and secure client accounts, operate review-growth campaigns, generate reputation intelligence, provide customer support, manage billing, improve service quality, prevent fraud, troubleshoot delivery, and comply with applicable obligations.
We do not sell personal information. We do not use client customer lists for unrelated advertising or for another client's campaigns.
Service providers and platforms
We share information only as reasonably needed to operate the requested service. Current categories include website hosting and WordPress, Stripe for checkout and subscription billing, email delivery providers, Google services for business listing information and authorized profile work, GoHighLevel or another authorized CRM/communications provider when included in the client's setup, and OpenAI or another authorized analysis provider for review-based reporting.
Payment card details are entered on Stripe-hosted pages and are not stored in the QCR WordPress website. Third-party providers process information under their own terms and privacy practices.
We may also disclose information when required by law, to protect rights and security, or as part of a business transaction where appropriate safeguards apply.
Client-provided customer data
Business clients remain responsible for having the lawful authority and required consent to provide customer information and send review requests, email, or text messages. QCR uses that information only to deliver the agreed services and authorized workflows.
Clients should not submit Social Security numbers, payment card numbers, medical records, government identification numbers, passwords, or other information that is not necessary for review growth or the selected CRM workflow. QCR is not designed to store protected health information.
Retention and deletion
We retain information for as long as needed to provide services, maintain account and transaction records, resolve disputes, enforce agreements, meet legal or accounting needs, and preserve security logs. Signed agreements, payment records, and related business records may be retained after service ends.
Operational CRM and onboarding data may be deleted, returned, or anonymized after termination when reasonably requested, subject to technical backup cycles and records we must retain. We periodically review whether information is still needed.
Your choices and requests
You may ask to access, correct, or delete personal information associated with you. You may also unsubscribe from optional marketing messages. Some information cannot be deleted immediately when it is needed for an active service, security, billing, contractual, or legal record.
To make a request, email info@qualitycontrolreviews.com. We may need to verify your identity or authority before completing the request.
Security
QCR uses administrative and technical safeguards appropriate to the information handled, including HTTPS, role-based WordPress access, password hashing, private client pages, signed checkout handoffs, verified Stripe webhook signatures, access controls, and account monitoring. Administrative accounts and critical business services should use multifactor authentication, and website data should be backed up outside the production server.
No system is completely secure. If we identify a security incident affecting information, we will investigate, contain it, and provide notices when required.
Children and policy updates
QCR provides business services and is not directed to children under 13. We may update this policy as services, providers, or legal requirements change. The updated date above shows the latest published version.
Contact us
Questions or privacy requests can be sent to info@qualitycontrolreviews.com or made by calling 980-485-9330.