How We Handle Your Privacy
itreviews.co publishes independent research on managed IT service providers. This page explains what data we collect, what we do not, and what you can do about it — in plain English, with the legal terms attached where the law requires them.
The short version
itreviews.co is a research site, not a review platform. We rank managed IT service providers using publicly available signals — Clutch, Google reviews, Cloudtango, MSP 501, CRN MSP 500, Inc. 5000, and similar sources. Visitors browse rankings; they do not submit reviews, create accounts, or pay us for anything.
Because of that, we collect very little personal data. We run Google Analytics 4 to understand which rankings get traffic, and we receive an email when someone fills out our contact form. That is essentially the entire picture.
We do not sell your data, build advertising profiles, run retargeting pixels, or share information with ad networks. This policy walks through the details — what we collect, why, how long we keep it, and how to reach us if you have a question or want your data deleted.
Data controller: itreviews.co. Registered business address available on written request to info@itreviews.co.
Privacy contact: info@itreviews.co · Editorial lead: Juan Alba, IT Research Analyst.
EU and UK representative (GDPR Art. 27): Our processing activities are occasional, do not involve large-scale processing of special categories of data under Art. 9, and are unlikely to result in a risk to the rights and freedoms of natural persons. On that basis we currently rely on the Art. 27(2) exemption. If a representative is required for your jurisdiction, email info@itreviews.co and we will appoint one and update this section. Data Protection Officer: none required under GDPR Art. 37; privacy matters are handled by the editorial team at info@itreviews.co.
Minimal collection
We only ask for data we actually need. No accounts, no logins, no payment info, no marketing cookies.
No data sale
We do not sell, rent, or trade personal information — ever. We have no ad partners and no affiliate tracking networks.
Plain English
Where the law requires specific wording, we use it. Then we translate it. You should be able to read this policy in ten minutes.
What this policy covers
Information we collect
Section 1What lands in our systems when you visit or contact us
We collect three categories of data, and that is it.
Information you give us. If you fill out the contact form on itreviews.co/contact/, we receive whatever you typed into the form — typically a name, email address, the company you mentioned, and the message body. People use this form to submit provider corrections, ask methodology questions, or send press inquiries.
Information collected automatically. When you load a page, our analytics setup logs standard request data: an anonymized IP address, browser and operating system, the page you viewed, the page that referred you, approximate city-level location, device type, screen size, and timestamps. This happens through Google Analytics 4 and basic web server logs from our host, Hostinger.
Information from cookies. A small set of cookies sit in your browser while you are on the site — WordPress functional cookies, Google Analytics measurement cookies, and a LiteSpeed Cache cookie that helps pages load faster. See section 3 for the full list.
CCPA / CPRA categories of personal information collected
For California residents, the following statutory categories under Cal. Civ. Code 1798.140(v) are collected, used for the business purposes described in section 2, and were not sold or shared for cross-context behavioral advertising in the past 12 months:
- Identifiers — name and email address (contact form), IP address (anonymized), online identifiers in cookies. Source: directly from you, or from your browser.
- Internet or other electronic network activity — pages viewed, referring URL, browser and device data via Google Analytics 4. Source: from your browser.
- Geolocation data — approximate city-level location derived from IP. Source: from your browser. We do not collect precise GPS coordinates.
- Commercial information — none collected. We do not sell anything.
- Audio, electronic, visual, thermal, olfactory, or similar information — none.
- Professional or employment-related information — only what you voluntarily include in a contact form message (e.g., your company name).
- Education information — none.
- Inferences — none. We do not build profiles or predict preferences.
- Sensitive personal information — we do not collect Sensitive Personal Information as defined under CPRA 1798.140(ae): no government IDs, financial account credentials, precise geolocation, racial or ethnic origin, religious beliefs, union membership, genetic or biometric data, health data, or sexual-orientation data.
We do not collect: government IDs, financial information, health data, biometric identifiers, precise GPS location, or any data from public profiles you have not voluntarily shared with us.
How we use it & lawful basis
Section 2The narrow set of jobs your data actually does — and the legal basis for each
We use what we collect for four things:
- To answer you. If you submit the contact form, we reply by email. That email exchange becomes part of our correspondence record.
- To understand traffic patterns. Analytics data tells us which city ranking pages are read, where readers come from, and which sections lose attention. We use this to decide what to research and refresh next.
- To keep the site running. Server logs help us diagnose errors, fight spam, and detect abuse. LiteSpeed Cache cookies make pages load faster on repeat visits.
- To comply with law. If we receive a valid legal demand — subpoena, court order, regulator request — we will respond as required.
We do not provide your data to any third party for the purpose of training AI models, and we do not authorize our processors to use your data for model training beyond what is necessary to provide their service.
GDPR Article 6 lawful basis (EU / UK / EEA visitors)
For visitors covered by GDPR or UK GDPR, the lawful basis for each processing purpose is:
- Contact form replies and correspondence — Art. 6(1)(b) performance of pre-contractual or contractual steps at your request, and Art. 6(1)(f) legitimate interests in responding to inquiries directed at us.
- Google Analytics 4 measurement — Art. 6(1)(a) consent, captured through the cookie banner before any non-essential cookie is set.
- Server logs, security, spam prevention, and caching — Art. 6(1)(f) legitimate interests in maintaining a secure, performant site, balanced against the limited intrusiveness of the data involved.
- Legal and regulatory compliance — Art. 6(1)(c) compliance with a legal obligation to which we are subject.
- Business transfers (rare) — Art. 6(1)(f) legitimate interests of the parties to a corporate transaction.
You can withdraw analytics consent at any time through the cookie banner or browser settings, and you can object to legitimate-interest processing by emailing info@itreviews.co.
Cookies & tracking technologies
Section 3Exactly what sits in your browser and why
itreviews.co uses three categories of cookies. None are advertising cookies.
Strictly necessary cookies. WordPress sets a small number of session and security cookies (such as wordpress_test_cookie and CSRF tokens) so the site functions. These cannot be turned off without breaking the site.
Performance & caching cookies. LiteSpeed Cache uses lightweight cookies to serve faster page versions to repeat visitors. They do not identify you.
Analytics cookies. Google Analytics 4 sets cookies (_ga, _ga_*) that assign your browser a randomized ID and record page views. We have configured GA4 with IP anonymization enabled and Google Signals disabled, so no cross-device or ad-personalization profile is built.
Consent and EU/UK visitors. Non-essential cookies (analytics) are not set for EU/UK/EEA visitors until consent is captured through our cookie banner, in line with GDPR Art. 7 and the ePrivacy Directive Art. 5(3). Consent records are stored by the consent management platform and can be withdrawn at any time by clearing the consent cookie or re-opening the banner from the footer. If you are visiting from the EU/UK/EEA and the banner does not appear, treat that as a configuration issue and email info@itreviews.co so we can confirm and fix it.
You can clear or block cookies through your browser settings at any time. We also honor the Global Privacy Control (GPC) signal as a valid opt-out where required by state law.
Software and services in use
Section 4Vendors we use and what each one sees
The site runs on a short list of named services. Each is listed here with the role it plays and the data it processes.
Third-party processors (your data leaves our environment)
- Hostinger — web hosting. Sees server-level request logs (IP, request URL, user agent). Hostinger acts as our data processor under a standard hosting DPA.
- Google Analytics 4 — traffic measurement. Sees anonymized IP, browser, page views, referrer. We have a Google Analytics data processing addendum on file.
- Google Search Console — search performance reporting. Receives aggregated search query and click data from Google, not from your browser directly.
- Google Workspace — the email environment that receives forwarded contact form submissions and any reply correspondence. Covered by the Google Workspace DPA.
- Gravatar (Automattic) — profile image service used by WordPress when comments are enabled. Comments are disabled on ranking pages; Gravatar requests only occur on the rare pages where they are enabled.
Plugins and software operating locally (no data leaves our environment)
- WordPress core — the publishing platform. Stores published content and the contact form submissions in the WordPress database hosted by Hostinger.
- Yoast SEO — SEO plugin. Operates server-side; does not transmit visitor data to Yoast.
- LiteSpeed Cache — performance plugin. Operates within our hosting environment.
Provider screenshots embedded on ranking pages are static images we host ourselves. We do not load live iframes or remote scripts from MSP websites.
AI crawler treatment. Our robots directives and an llms.txt file at itreviews.co/llms.txt set out how we treat automated AI crawlers (GPTBot, ClaudeBot, PerplexityBot, Google-Extended, and similar). These bots may read public content for citation and answer-engine indexing; they do not receive any non-public personal data.
Information sharing
Section 5When, if ever, your data leaves our environment
We do not sell, rent, lease, or trade personal information. We do not share personal information for cross-context behavioral advertising, as those terms are defined under the CCPA/CPRA. We have no advertising partners, no data brokers, and no affiliate marketing programs.
The narrow situations in which data may be shared:
- With service providers acting on our behalf. Hostinger and Google process data so we can run the site. They are contractually bound to use it only for the services they provide.
- To comply with law. We will disclose information when required by a subpoena, court order, or other lawful process, or to protect our rights, safety, or property.
- In a business transfer. If itreviews.co is acquired or merged, data may transfer to the successor entity. We will post a notice on the site if this happens.
That is the complete list. There is no fourth category.
California notice of right to opt out of sale or sharing
itreviews.co does not sell personal information and does not share personal information for cross-context behavioral advertising, as those terms are defined under the CCPA/CPRA. California residents may still submit an opt-out request to info@itreviews.co and we will confirm our non-sale and non-share status in writing. A site-wide footer link labeled “Your Privacy Choices” points to this section so the disclosure is discoverable.
Data retention
Section 6How long we keep each kind of record
We hold on to data only as long as we need it for the purpose it was collected, plus any period required by law.
- Contact form submissions: 2 years from receipt, then deleted. If a thread is still active or has resulted in a published correction we may retain the record longer for editorial provenance.
- Email correspondence: retained in our email account per standard mailbox policy. You can ask us to delete a thread at any time.
- Google Analytics data: 14 months (the maximum standard GA4 retention; we have set this explicitly — the GA4 system default is 2 months).
- Web server logs: rotated by Hostinger per their standard retention, typically 30–90 days.
- Backups: WordPress backups are rotated on a 30-day cycle. Data deleted from the live site will persist in backups until the cycle completes.
If a longer period is required by law — for example, a litigation hold — we retain only what we have to and isolate it from operational systems.
Data security
Section 7The technical measures behind the site
The site is served over HTTPS with TLS encryption. Hostinger provides server-level security, DDoS protection, and isolation between accounts. WordPress is kept current; plugins are minimized and updated on a rolling basis.
Access to the WordPress admin and the underlying hosting account is restricted to authorized members of the editorial team, protected by strong passwords and two-factor authentication. Contact form submissions are stored in the WordPress database and forwarded to our editorial inbox.
No system is perfectly secure. If a breach occurs that affects personal data, we will notify the relevant supervisory authority within 72 hours of becoming aware, as required by GDPR Art. 33, and notify affected individuals without undue delay where the breach is likely to result in a high risk to their rights and freedoms (Art. 34). US state breach notification laws are followed in parallel where they apply.
Your privacy rights
Section 8What you can ask us to do, by jurisdiction
Your rights depend on where you live. The block below this card lays them out by jurisdiction. To exercise any of them, email info@itreviews.co from the address you want us to look up. We will respond within 30 days (GDPR) or 45 days (CCPA/CPRA), and we will not charge you for a reasonable request.
We will verify your identity before acting on a request — usually by matching your email against records on file. We will not discriminate against you for exercising a privacy right — meaning we will not block you from the site, slow it down, or charge you for using a right the law gives you.
If we deny a request, we will explain why. EU/UK residents can complain to their local supervisory authority. California residents can contact the California Privacy Protection Agency.
Your rights, by jurisdiction
The legal terms — plus what they actually mean
Privacy law uses different words for similar ideas. Here is what GDPR, CCPA/CPRA, and general US privacy law give you, with each right translated.
⚖ GDPR & UK GDPR (EU / UK / EEA)
- Right of access (Art. 15) — ask us what data we hold on you, and get a copy.
- Right to rectification (Art. 16) — ask us to correct anything wrong or incomplete.
- Right to erasure (Art. 17) — ask us to delete your data (“right to be forgotten”).
- Right to restriction (Art. 18) — ask us to pause processing while we sort something out.
- Right to data portability (Art. 20) — receive your data in a machine-readable format.
- Right to object (Art. 21) — tell us to stop processing for analytics or other legitimate-interest uses.
- Right to withdraw consent (Art. 7) — revoke any consent you previously gave us at any time.
- Lawful basis we rely on: Art. 6(1)(a) consent for analytics; Art. 6(1)(b) and 6(1)(f) for contact form replies; Art. 6(1)(f) for server logs and security; Art. 6(1)(c) for legal compliance.
📖 CCPA / CPRA (California)
- Right to know — what categories of personal information we collect, why, and where we got it. Categories are listed in section 1.
- Right to delete — ask us to delete personal information we hold on you.
- Right to correct — fix inaccurate personal information.
- Right to opt out of sale or sharing — we do not sell or share for cross-context behavioral advertising, but you may still submit a request and we will confirm in writing.
- Right to limit use of sensitive personal information — we do not collect Sensitive PI as defined under CPRA 1798.140(ae).
- Right to non-discrimination — we will not charge you more or give you a worse experience for exercising any right.
✓ Other US states & general practice
- Virginia, Colorado, Connecticut, Utah, Texas, and similar state laws — we honor equivalent access, deletion, and correction requests under each state’s consumer privacy act.
- Global Privacy Control — we honor the standardized GPC signal as an opt-out where required.
- Universal request flow — regardless of state, you can email info@itreviews.co and we will treat your request as we would a CCPA request.
⚠ What we may need from you
- Identity verification — we match your request email against records on file. We will not ask for an ID document for a simple analytics deletion.
- Authorized agents — you may use one. We require a signed written permission from you authorizing the agent, plus verification of your identity directly with us. We may require a power of attorney for deletion requests under CCPA 999.326.
- Response window — 30 days for GDPR, 45 days for CCPA, with one possible extension on notice to you.
- If denied — we explain why and tell you how to appeal or complain to your supervisory authority.
Children’s privacy
Section 9COPPA compliance and what we do if a minor reaches us
itreviews.co is a B2B research site. It is not directed to children under 13, and we do not knowingly collect personal information from anyone under 13. We have no features — no accounts, no chat, no community — that would be of interest to children.
If you believe a child under 13 has submitted information to us through the contact form, email info@itreviews.co and we will delete the record. For California residents, we extend the same treatment to users under 16.
International data transfers
Section 10Where your data physically lives
itreviews.co is operated from the United States. Hostinger hosts the site in their global infrastructure; Google Analytics processes data in the United States and other regions where Google operates.
If you access the site from the EU, UK, or EEA, your information will be transferred to and processed in the United States. We rely on the European Commission’s Standard Contractual Clauses (SCCs) and, where applicable, the EU-US Data Privacy Framework as the legal basis for these transfers. Our processors (Google, Hostinger) maintain their own DPF or SCC commitments.
If you have questions about how a transfer affects you, email info@itreviews.co.
Changes to this policy
Section 11How we update the policy and tell you about it
We update this page when our practices change or when the law requires it. Each update bumps the “Last updated” date at the top of the page, and material changes carry a separate “Effective” date that follows a 30-day notice window.
For material changes — new categories of data, new processors, or new sharing — we post a notice at the top of the site for at least 30 days before the new effective date. The current effective date is June 11, 2026.
Continued use of the site after the effective date indicates you have had notice of the update. Where processing requires consent (such as analytics cookies for EU/UK visitors), we will request renewed consent through the cookie banner. If you object to a change, your options are to stop using the site or to email info@itreviews.co and ask us to delete any data we hold on you.
To be clear
What we do NOT do
A short list of common privacy concerns and what itreviews.co will never do with your data. If you ever see behavior that contradicts this list, email us — we will fix it.
Reach the privacy team
Questions, requests, or corrections
Email the address below for any privacy matter — data access, deletion, correction, a question about something on this page, or a concern about how we handled your information. A real person on the editorial team reads it.
✉ info@itreviews.co