Cookie Policy
This Cookie Policy explains how Bhatt Group Ltd uses cookies and similar storage or access technologies on https://review.ministerai.app, ReviewMinister, public review pages, checkout pages, account dashboards, and other digital services operated by us.
In this Policy, “we”, “us”, “our”, and “Company” refer to Bhatt Group Ltd. “Website” includes https://review.ministerai.app and associated web applications, public review links, QR and NFC destinations, checkout interfaces, and Platform pages.
Your choices matter. Strictly necessary technologies may operate automatically because they are required to provide requested services, maintain security, or remember privacy choices. Other technologies will be activated only where the necessary consent or other lawful permission applies.
1. Who We Are
The Website and Platform are operated by:
65A High Street, Littlehampton West Sussex BN17 5EJ, UK
Website: https://review.ministerai.app
Privacy email:
Support email: support@review.ministerai.app
2. What Are Cookies?
Cookies are small text files placed on a computer, mobile device, tablet, or other connected device when a person visits a website or uses an online service.
Cookies may store or retrieve information such as:
- a randomly generated identifier;
- session or authentication status;
- language or interface preferences;
- shopping-cart or checkout information;
- privacy and cookie choices;
- information about pages or features used;
- security and fraud-prevention indicators;
- advertising or campaign attribution information.
Cookies may be stored for the duration of a browsing session or for a longer period, depending on their purpose.
3. Similar Technologies
This Policy also applies to technologies that store information on a device or access information already stored on it, including:
- HTML5 local storage and session storage;
- software-development-kit storage;
- tracking pixels and web beacons;
- scripts and tags;
- device identifiers;
- link decoration and campaign parameters;
- browser cache and application storage;
- device fingerprinting techniques;
- embedded third-party content;
- other storage or access technologies.
References to “cookies” in this Policy include these similar technologies unless the context requires otherwise.
4. Applicable Rules
Our use of cookies and similar technologies may be governed by:
- the Privacy and Electronic Communications Regulations 2003, commonly known as PECR;
- the UK General Data Protection Regulation;
- the Data Protection Act 2018;
- other applicable privacy and electronic-communications laws.
Where a technology stores or accesses information on a device, we assess whether consent is required under the applicable storage and access rules.
Where information collected through a technology is personal data, we also process that data according to our Privacy Policy: .
5. First-Party and Third-Party Cookies
5.1 First-Party Cookies
First-party cookies are set by our Website or Platform domain. They may be used for authentication, security, preferences, checkout, consent management, and first-party analytics.
5.2 Third-Party Cookies
Third-party cookies are set or accessed by an external provider whose technology is included in the Website or Platform.
Third-party providers may include:
- payment processors;
- authentication providers;
- analytics and performance providers;
- error-monitoring providers;
- customer-support or chat providers;
- advertising and campaign providers;
- fraud-prevention and bot-protection providers;
- embedded media or mapping providers.
Third parties may process data according to their own privacy policies and may act as processors, joint controllers, or independent controllers, depending on the circumstances.
6. Session and Persistent Cookies
6.1 Session Cookies
Session cookies usually expire when the browser is closed or the active session ends.
They may be used to:
- maintain a secure login session;
- remember temporary checkout information;
- protect forms and requests;
- enable navigation between Platform pages;
- maintain temporary language or workflow state.
6.2 Persistent Cookies
Persistent cookies remain on the device until their stated expiry date or until they are deleted.
They may be used to:
- remember cookie choices;
- remember login or trusted-device preferences where enabled;
- retain language and interface settings;
- recognise returning browsers;
- measure usage over time;
- support campaign attribution.
7. Cookie Categories
Strictly Necessary
These technologies are essential to provide requested functionality, protect the service, complete checkout, maintain sessions, or remember privacy choices.
They cannot ordinarily be disabled through our consent tool because the relevant service may not function without them.
Functional
These technologies remember optional settings or provide enhanced functionality, such as language, region, interface preferences, embedded tools, or optional support features.
Analytics and Performance
These technologies help us understand visits, feature usage, errors, performance, engagement, conversion, and service reliability.
Marketing and Advertising
These technologies may measure campaigns, attribute conversions, personalise advertising, build audiences, or recognise activity across websites or services.
8. Strictly Necessary Cookies
Strictly necessary cookies and technologies may be used without consent where the applicable legal exemption applies.
They may be necessary to:
- authenticate users and maintain secure sessions;
- remember that a user is signed in;
- route requests securely between Platform services;
- prevent cross-site request forgery and similar attacks;
- detect fraud, bots, abuse, or suspicious traffic;
- apply security and rate-limiting controls;
- remember cookie-consent choices;
- maintain a shopping cart or checkout session;
- process a payment or complete an Order;
- balance traffic or maintain technical availability;
- remember a user-requested language during a session;
- provide accessibility or privacy settings requested by the user;
- prevent technical faults or recover an interrupted session.
A technology is not treated as strictly necessary merely because it is useful to us. It must be essential to provide a service requested by the user or fall within another applicable legal exception.
9. Functional Cookies
Functional cookies support optional or enhanced features. Depending on the feature and applicable law, we may request consent before using them.
They may remember:
- preferred language or regional language variant;
- appearance or interface preferences;
- dashboard layout choices;
- selected business or workspace;
- notification preferences;
- optional embedded support or chat settings;
- video, map, or media preferences;
- other convenience settings.
Rejecting functional cookies may mean that some optional features do not remember previous choices or operate as expected.
10. Analytics and Performance Cookies
Analytics and performance technologies help us understand how the Website, public review pages, and Platform are used.
They may measure:
- page views and unique visits;
- traffic sources and referring pages;
- navigation paths;
- feature usage;
- QR, NFC, and direct-link visits;
- review-generation and copy events;
- checkout progress and conversions;
- subscription engagement;
- page-load speed and technical performance;
- errors, crashes, and failed requests;
- device, browser, and approximate regional information.
Where consent is required, analytics technologies remain disabled until the user has consented.
We may use aggregated operational measurements that do not require access to information on the user’s device or that fall within another applicable exception. Such processing will still be assessed under data-protection law where personal data is involved.
11. Marketing and Advertising Cookies
Marketing technologies may be used where we advertise or measure promotional campaigns.
They may:
- record that a user arrived through a particular advertisement;
- measure whether an advertisement resulted in registration or purchase;
- limit how often an advertisement is shown;
- create or exclude advertising audiences;
- support retargeting or remarketing;
- measure campaign effectiveness;
- associate activity across websites, apps, or devices;
- personalise promotional content.
Marketing and advertising technologies will not be activated before the necessary consent has been obtained.
Rejecting marketing cookies does not necessarily mean that no advertising will be shown. It means that advertising may be less personalised and that campaign measurement may be limited.
12. Authentication Cookies
Authentication cookies may be set by us or our authentication provider to:
- sign users into the Platform;
- maintain a secure session;
- refresh authorised access;
- remember authentication state;
- support multi-factor or social authentication;
- detect suspicious login activity;
- sign users out securely.
Authentication cookies are generally treated as strictly necessary when required to provide the signed-in service requested by the user.
13. Supabase Technologies
We may use Supabase for authentication, database, storage, and backend services.
Supabase authentication may use browser storage or cookies to maintain login sessions, refresh authorised access, and secure account activity.
The exact cookie or storage names, formats, and durations may depend on our implementation and the version of the Supabase software or client library in use.
14. Payment and Stripe Technologies
We may use Stripe to process subscription payments, product Orders, refunds, and fraud checks.
Stripe may use cookies, scripts, device signals, and similar technologies to:
- process payments;
- secure checkout sessions;
- prevent fraudulent transactions;
- remember payment-related session state;
- meet legal and regulatory obligations;
- improve payment reliability.
Technologies essential to complete a payment or prevent payment fraud may be treated as strictly necessary. Stripe may also process information under its own privacy and cookie notices.
15. Google Authentication and Embedded Services
Where Google Sign-In or another Google service is enabled, Google may use cookies or similar technologies to:
- authenticate the user;
- maintain account security;
- provide authorised identity information;
- prevent fraud and abuse;
- provide an embedded map, video, or other service.
Optional embedded Google services may require consent before loading where they set or access non-essential technologies.
16. Public Review Pages
Public review pages may use technologies needed to:
- maintain the review journey between steps;
- remember the selected language during the session;
- protect the form from bots or abuse;
- apply generation and retry limits;
- identify the business and review-link source;
- prevent duplicate or suspicious events;
- record consent choices;
- measure visits and conversions where consent permits.
QR, NFC, and direct-link source identifiers may be included in the URL or stored during the session so that the relevant business can understand how its review page was reached.
17. Local Storage and Session Storage
The Platform may use browser local storage or session storage instead of, or in addition to, cookies.
These technologies may store:
- authentication-session information;
- temporary review-form selections;
- language and interface preferences;
- business-switcher state;
- checkout or workflow progress;
- cookie and privacy choices;
- temporary technical information needed to prevent state loss.
Session storage is normally removed when the relevant browser tab or session ends. Local storage can remain until it expires through application logic or is deleted by the user or Website.
18. Pixels, Tags, and Scripts
Pixels, tags, and scripts are small pieces of code that may collect technical and interaction information.
They may be used to:
- measure whether a page or email was opened;
- record a conversion or campaign event;
- load analytics or support functionality;
- monitor errors and performance;
- detect fraud, bots, or security threats;
- provide embedded third-party functionality.
A script or pixel that accesses or stores information on a device is subject to the same storage and access rules as a traditional cookie.
19. Email Tracking Technologies
Some emails may contain pixels or tracked links that allow us to determine:
- whether an email was delivered;
- whether it was opened;
- whether a link was selected;
- the approximate time or device category associated with the event;
- whether a communication campaign was effective.
We will use such technologies in accordance with applicable electronic communications and data-protection rules.
Transactional emails may use limited delivery and security tracking required to confirm delivery, diagnose failures, or protect the service.
20. Consent
Where consent is required, we request it through a cookie banner, preference centre, or similar interface.
Consent must be:
- freely given;
- specific;
- informed;
- indicated through a clear positive action;
- capable of being withdrawn.
Merely continuing to browse, silence, inactivity, or pre-enabled settings are not treated as valid consent where active consent is required.
21. Consent Categories
Our consent interface may allow separate choices for:
- strictly necessary technologies, which remain active;
- functional technologies;
- analytics and performance technologies;
- marketing and advertising technologies.
Where practical, more detailed controls may also be offered for individual providers or purposes.
Consent to one optional category does not automatically constitute consent to another category.
22. Accepting or Rejecting Cookies
When the consent banner is presented, users may be offered options such as:
- Accept All;
- Reject Non-Essential;
- Manage Preferences;
- Save Selected Preferences.
Rejecting optional cookies should be as straightforward as accepting them.
Non-essential technologies should remain disabled unless and until the relevant permission has been recorded.
23. Withdrawing or Changing Consent
You may withdraw or change consent at any time through:
Withdrawal does not affect the lawfulness of processing carried out before consent was withdrawn.
After withdrawal, we will stop activating the relevant optional technologies for future activity. Previously collected information may still be retained where another lawful basis or legal obligation permits.
24. Consent Records
We may retain records to demonstrate and manage cookie choices.
These records may include:
- a consent identifier;
- the categories accepted or rejected;
- the date and time of the choice;
- the version of the cookie notice or consent interface;
- the domain or service on which the choice was made;
- an IP address or IP hash;
- browser or device information;
- the date of withdrawal or modification.
A strictly necessary consent cookie may be used to remember these choices so that the banner is not displayed on every page.
25. How Long Consent Lasts
We may ask users to review their choices again:
- after a proportionate period;
- when the consent record expires;
- when new providers or purposes are introduced;
- when the Cookie Policy or consent interface changes materially;
- when required by law or regulatory guidance;
- when previous consent can no longer be demonstrated reliably.
The exact consent-review period may be configured through our consent management system.
26. Cookie Duration
Cookie duration depends on its purpose and provider.
Common duration descriptions include:
- Session: removed when the browser or active session ends;
- Minutes or hours: used for security, checkout, temporary state, or short-lived attribution;
- Days or months: used for preferences, analytics, authentication, or campaign measurement;
- Up to one year or another disclosed period: commonly used for consent records or persistent preferences.
We aim to set retention periods that are proportionate to the stated purpose and avoid keeping identifiers longer than reasonably necessary.
27. Cookie Inventory
The following table is a maintainable cookie and technology inventory. It should be populated from the actual technologies detected in the production Website and updated whenever providers or configurations change.
| Name or Identifier | Provider | Category | Purpose | Type | Duration |
|---|---|---|---|---|---|
| Bhatt Group Ltd | Strictly Necessary | Remembers cookie categories accepted or rejected by the user. | First-party persistent cookie or local storage | ||
| Strictly Necessary | Maintains the authenticated Platform session and authorised access. | First-party or provider cookie/storage | |||
| Bhatt Group Ltd | Strictly Necessary | Protects forms and authenticated actions against request-forgery attacks. | First-party session cookie | Session | |
| Strictly Necessary | Maintains checkout state, processes payment, and helps prevent fraud. | First-party or third-party cookie/script | |||
| Bhatt Group Ltd | Strictly Necessary or Functional, depending on implementation | Remembers a user-selected language or regional-language preference. | First-party cookie or local storage | ||
| Analytics and Performance | Measures visits, usage patterns, engagement, conversion, and performance. | First-party or third-party cookie/script | |||
| Strictly Necessary or Analytics, depending on purpose and configuration | Identifies technical errors, failed requests, and application performance issues. | Cookie, script, storage, or event identifier | |||
| Marketing and Advertising | Measures campaigns, attributes conversions, or supports advertising audiences. | Third-party cookie, pixel, or script |
Implementation requirement: Replace all placeholder rows with the actual production cookie names, providers, purposes, categories, and durations before publishing this Policy. A cookie scanner and manual technical review should be performed after each material deployment.
28. Provider Inventory
The providers used by the Website may change as the Platform develops. Current providers may include categories such as:
- Supabase for authentication and infrastructure;
- Stripe for payment and fraud prevention;
- Google for authentication or embedded services;
- analytics and performance-monitoring providers;
- error and application-monitoring providers;
- email and communications providers;
- bot-protection or CAPTCHA providers;
- advertising providers, where enabled.
Our current service-provider or subprocessor information may be available at: .
29. Browser Controls
Most browsers allow users to:
- view cookies stored on the device;
- delete individual or all cookies;
- block first-party or third-party cookies;
- block cookies from particular websites;
- clear local storage and site data;
- configure automatic deletion when the browser closes;
- use private or incognito browsing modes.
Browser controls operate separately from our consent tool. Deleting cookies may also remove the stored consent choice, causing the cookie banner to appear again.
Blocking all cookies may prevent authentication, checkout, saved settings, and other Platform functionality from working correctly.
30. Mobile Device Controls
Mobile operating systems and browsers may provide controls for:
- clearing application or browser storage;
- restricting advertising identifiers;
- limiting cross-site tracking;
- controlling location or device permissions;
- resetting device identifiers;
- restricting third-party content.
The available controls depend on the device, operating system, and browser.
31. Global Privacy Signals
Browsers or extensions may transmit privacy preference signals, such as Global Privacy Control or “Do Not Track”.
We may recognise legally required or technically supported signals where applicable. Because standards and legal requirements continue to develop, not all browser signals are currently interpreted in the same way.
The most reliable way to manage choices for our Website is through: .
32. Embedded Third-Party Content
Some pages may contain embedded content, such as:
- maps;
- videos;
- social-media content;
- support widgets;
- booking tools;
- payment forms;
- review-platform content.
Loading embedded content may allow the external provider to place or access cookies and collect information about the visitor.
Where required, optional embedded content will remain blocked until the relevant consent has been provided.
33. Security and Fraud Prevention
We may use cookies and similar technologies to detect or prevent:
- account takeover;
- credential stuffing;
- payment fraud;
- automated bot traffic;
- spam submissions;
- abuse of AI-generation limits;
- fake or manipulated review activity;
- circumvention of rate limits;
- malicious requests and technical attacks.
Security technologies may use device, session, browser, network, and behavioural signals.
Technologies essential to protect a requested service may fall within a strictly necessary exception. We assess each technology according to its actual purpose and configuration.
34. IP Addresses and Device Information
Cookies and related technologies may be associated with:
- an IP address or IP hash;
- browser type and version;
- device type and operating system;
- screen or viewport dimensions;
- language and time-zone settings;
- approximate regional location;
- session and request identifiers;
- security or fraud indicators.
Further information about this processing is provided in our Privacy Policy: .
35. International Processing
Some cookie and technology providers may process information outside the United Kingdom.
Where personal data is transferred internationally, we use or require an appropriate transfer mechanism where necessary, as described in our Privacy Policy.
36. Data Retention
Information collected through cookies and similar technologies is retained only for as long as reasonably necessary for the relevant purpose.
Retention depends on:
- the cookie’s stated duration;
- whether it is a session or persistent technology;
- the provider’s retention settings;
- the consent and configuration selected;
- security, fraud, and legal requirements;
- whether data has been aggregated or anonymised.
Expiry of a browser cookie does not necessarily mean that all server-side records associated with an earlier event are immediately deleted. Those records may be retained according to our Privacy Policy and applicable retention schedule.
37. Children
The Website and Platform are primarily intended for adults and business users, not children.
We do not intentionally use advertising or profiling technologies to target children.
If a public review link is accessed by a child, the child should not submit personal or sensitive information.
38. Changes to Cookies and Providers
Cookie names, durations, providers, and purposes may change because of:
- Platform updates;
- security improvements;
- changes to authentication or payment systems;
- changes to analytics or support tools;
- provider software updates;
- changes in law or regulatory guidance.
We will update the cookie inventory and consent controls where changes are material.
Where a new purpose is incompatible with the consent already obtained, we will request a new choice before activating the relevant technology.
39. Changes to This Cookie Policy
We may update this Policy to reflect:
- changes to cookies or similar technologies;
- changes to service providers;
- changes to the Website or Platform;
- legal or regulatory developments;
- security or operational improvements;
- changes to our consent-management process.
The version, effective date, and last-updated date shown at the top identify the current version.
We may display a renewed cookie banner or other notice where a material change requires users to make a new choice.
40. Complaints and Privacy Rights
Questions or concerns about cookies and similar technologies may be sent to: .
Where information collected through a technology is personal data, you may have rights of access, rectification, erasure, restriction, objection, data portability, and withdrawal of consent, depending on the circumstances.
Further information about privacy rights and complaints to the Information Commissioner’s Office is available in our Privacy Policy.
41. Contact Us
65A High Street, Littlehampton West Sussex BN17 5EJ, UK
Privacy email:
Support email: support@review.ministerai.app
Cookie settings:
Privacy Policy:
Website: https://review.ministerai.app
Document Version Information
| Field | Value |
|---|---|
| Document | Cookie Policy |
| Version | 1.0 |
| Effective Date | 1 Aug 2026 |
| Last Updated | 1 Aug 2026 |
| Company | Bhatt Group Ltd |
| Platform | ReviewMinister |
| Website | https://review.ministerai.app |
| Cookie Settings | |
| Privacy Contact |
