What you may and may not do with reviews
Proofloop enforces the rules on this page in code rather than in a terms-of-use document, because a rule that only lives in a PDF is a rule that gets broken by whoever configures the account at 5pm on a Friday.
It is a practical summary of platform policy and of consumer-protection rules as they stand. Requirements differ by market and change. If you operate at scale or in a regulated sector, have someone qualified read your process.
The short version
| Practice | Why | |
|---|---|---|
| Yes | Ask every customer for a review | Google encourages it. Volume and recency are what move a rating. |
| Yes | Make it easy — a direct link, a QR code, one tap | Reducing friction is not manipulation. |
| Yes | Offer an unhappy customer a private channel first | As long as the public route is still there afterwards. |
| Yes | Reply to every review, good and bad | Replies are visible, and they are read. |
| No | Show the review link only to happy customers | Review gating. Prohibited by Google, actionable by regulators. |
| No | Offer a discount, entry or gift for a Google review | Google prohibits incentivised reviews outright. |
| No | Write, buy or edit reviews | Fraud in most jurisdictions, and detectable. |
| No | Scrape Google, or use a service that does | Breaks Google’s terms and risks your clients’ profiles. |
| No | Mark up imported Google reviews as your site’s own rich snippets | Breaks Google’s structured data guidelines; the page can be penalised. |
Review gating
Gating is filtering who gets shown the public review route, usually by star rating. Google’s prohibited and restricted content policy for reviews forbids selectively soliciting positive reviews or discouraging negative ones, and enforcement has included removing a business’s entire review history.
Proofloop’s default is ask-all: everybody keeps the public route, and dissatisfied customers are additionally offered a private channel first. Gated mode exists, is not the default, sits behind an explicit warning, and records who accepted that warning in the audit log. The reasoning is set out in full on the routing page.
Incentives
Google prohibits offering anything of value in exchange for a review — discounts, entries into a draw, loyalty points, free items. This applies whether the incentive is conditional on the review being positive or not.
Proofloop therefore does not let a coupon be attached to a Google destination, or to any external platform destination. Coupons can only be attached to the first-party testimonial path, where you are collecting for your own website, and the interface says so where you configure it. This is a deliberate difference from products that market “reviews for discounts”; that model is not safe to point at Google.
If a testimonial was given in exchange for anything, several jurisdictions require the relationship to be disclosed where the testimonial is displayed. The FTC’s endorsement guidance is the clearest statement of this. Proofloop records whether an incentive was attached so you can display that disclosure.
Displaying reviews you did not collect
Reviews imported from Google belong to their authors and are displayed under Google’s terms.
- Show them as Google reviews, attributed, not as anonymous praise.
- Do not edit their text. Proofloop cannot edit a review body; the field is immutable by design.
- Do not selectively display only the five-star ones and present that as your rating.
- Do not emit
RevieworAggregateRatingstructured data for them.
Why structured data is locked
Google’s structured data guidelines say review markup is for reviews collected by the site itself, not reviews copied from another platform. Marking up imported Google reviews as your own can cost the page its rich results, and if you are an agency it is your client’s site that takes the penalty.
So the widget renderer decides this, not a setting. First-party testimonials collected through Proofloop are marked up. Imported platform reviews are not, and there is no toggle.
Consent and customer data
- Publication consent is captured explicitly on the collection page, and stored with a timestamp, IP address and user agent. That record is what you produce if somebody later says they never agreed.
- Deletion requests are supported. Deleting a testimonial removes it and its media, and writes an entry to the audit log so you can evidence that you acted.
- Media retention is configurable per organisation. Video is the largest and most personal thing you will hold; keeping it forever by default is not a neutral choice.
- Suppression is permanent and automatic. A hard bounce, a spam complaint or an opt-out puts that contact beyond reach of every future campaign.
- Credentials — your provider passwords and tokens — are encrypted at rest, masked in the interface, redacted in logs, and excluded from every export.
Agencies
If you configure Proofloop for clients, three things are worth putting in writing with them:
- Who owns the collected testimonials if the relationship ends.
- That you will not gate reviews, and why — this protects you when a client asks you to.
- Who is the data controller for the customer contact lists you import on their behalf.
Proofloop keeps each client in a separate workspace with its own data, its own branding and its own reports, and a client user can be given access to their workspace alone.
What Proofloop refuses to do
These are not settings. They are properties of the software.
- It will not scrape Google or any other platform.
- It will not edit the body of a submitted testimonial.
- It will not post an AI-drafted reply without a human approving it.
- It will not attach an incentive to an external review destination.
- It will not emit first-party structured data for third-party reviews.