Productmate Review QR: privacy notice
Last updated: 6 October 2026.
This notice explains how PRODUCTMATE GmbH processes information when you use its Google review link and QR plugin in ChatGPT. It supplements our general privacy notice, which explains your data protection rights and our contact details.
Who is responsible
PRODUCTMATE GmbH, Falkenried 32F, 20251 Hamburg, Germany. For privacy questions or deletion requests, contact info@productmate.de. See our company details.
What the plugin receives
ChatGPT sends the tool inputs needed for your request: a business search and location, a Google Maps URL or Place ID, your chosen language, and any signed selection context from an earlier result. The plugin does not require a Productmate account. It does not request your full chat history, contacts, payment details, or Google account credentials.
How information is used and shared
We send business searches to Google Places to find matching public business listings. Google Maps short links are resolved through Google. We create the direct review URL and QR files on Productmate servers hosted on Google Cloud. Tool results are returned to ChatGPT for display. OpenAI and Google process information under their own applicable privacy notices.
We record successful link generations to measure use of this service and identify technical issues. A record includes a random result ID, generation time, the source “chatgpt”, language, input type, and the public business Place ID. Available business details and location information can be stored in our shared business directory. Generation records do not contain the complete review URL, signed context token, ChatGPT account ID, or email address.
The plugin widget sends no optional PostHog usage events and shows no product offers. Infrastructure can process request metadata for security and operation. Rate limits use a hashed network address, not a user account identifier. The general privacy notice describes server logs and your rights.
Retention
A daily cleanup deletes ChatGPT generation records older than 90 days. It also deletes business entries that no longer have generation records and are not used by saved business research, research lists, or newsletter subscriptions. Records used by those other Productmate services remain subject to those services' purposes and retention rules. This cleanup does not delete API or browser generation records.
Signed result and selection context expires after seven days. Cached QR files expire after 24 hours. Rate-limit counters expire after 60 seconds. These periods describe active application data; they do not change the retention of independent Google or OpenAI records, infrastructure logs, or backups.
Your choices
You can stop using the plugin or disconnect it in ChatGPT. Contact us for access, correction, deletion, or objections as described in our general privacy notice. A business name or Place ID and approximate generation date can help us find a record. Do not send your signed download token or passwords. We do not hold a ChatGPT account identifier that lets us identify all requests from a particular user.