Legal Documentation

Security Headers Policy

The HTTP security headers, Content Security Policy, HSTS configuration and violation-reporting endpoints applied across scorereview.io, the dashboard, the API and every embedded widget.

Last reviewed: February 2026 · 25 sections · Version 3.2

scorereview-security-headers.pdf · A4 · brandedAll documents
1

Purpose and scope of the policy

  1. 1.1

    Policy & legal framework

    This clause addresses purpose and scope of the policy within the Security Headers Policy that governs your relationship with ScoreReview UK, operated by UK REAL REVIEWS LTD (company number 14587101). It is drafted to satisfy the Consumer Rights Act 2015, the Digital Markets, Competition and Consumers Act 2024, the UK GDPR and the Data Protection Act 2018 as they apply to a UK-registered review platform published at scorereview.io.

    Where an obligation in this clause conflicts with mandatory statute or with a signed Order Form, the more protective provision prevails. Nothing in Security Headers Policy limits statutory rights that cannot be excluded by contract.

  2. 1.2

    Your rights

    You retain the right to receive plain-English information about purpose and scope of the policy, to challenge any decision we take under this clause, and to escalate an unresolved complaint to the relevant supervisory authority — the Information Commissioner's Office for data matters and the Competition and Markets Authority for consumer-law matters. Escalation does not require you to waive any right of action.

    Reviewers keep ownership of the content they submit; businesses keep ownership of the transactional data they upload. ScoreReview UK holds only the licence necessary to operate scorereview.io and to publish verified reviews to the audience the reviewer intended.

  3. 1.3

    Your obligations

    In relation to purpose and scope of the policy you must provide accurate information, act in good faith, and refrain from any conduct that would mislead consumers, distort the trust ledger, or breach the acceptable-use rules published at scorereview.io/acceptable-use. Repeated or wilful breach is grounds for suspension without refund.

    Where you act on behalf of a business you warrant that you have authority to bind that business to Security Headers Policy, that any customer contact you upload consented to receive a review invitation, and that you will keep records sufficient to demonstrate that consent for at least 24 months.

  4. 1.4

    Disclosure, data, privacy & cookies

    Personal data processed under this clause is handled in accordance with the ScoreReview UK Privacy Policy and, where you are a business customer, the Data Processing Agreement. Lawful basis is legitimate interest for platform integrity, contract for paid services, and consent for optional analytics or non-essential cookies set on scorereview.io.

    We publish a disclosure log covering enforcement actions, moderation decisions and material policy changes relevant to purpose and scope of the policy. Cookies used to support this clause are strictly necessary; any analytics or preference cookies require prior opt-in via the cookie banner and can be withdrawn at any time from the footer.

2

Baseline security posture

  1. 2.1

    Policy & legal framework

    This clause addresses baseline security posture within the Security Headers Policy that governs your relationship with ScoreReview UK, operated by UK REAL REVIEWS LTD (company number 14587101). It is drafted to satisfy the Consumer Rights Act 2015, the Digital Markets, Competition and Consumers Act 2024, the UK GDPR and the Data Protection Act 2018 as they apply to a UK-registered review platform published at scorereview.io.

    Where an obligation in this clause conflicts with mandatory statute or with a signed Order Form, the more protective provision prevails. Nothing in Security Headers Policy limits statutory rights that cannot be excluded by contract.

  2. 2.2

    Your rights

    You retain the right to receive plain-English information about baseline security posture, to challenge any decision we take under this clause, and to escalate an unresolved complaint to the relevant supervisory authority — the Information Commissioner's Office for data matters and the Competition and Markets Authority for consumer-law matters. Escalation does not require you to waive any right of action.

    Reviewers keep ownership of the content they submit; businesses keep ownership of the transactional data they upload. ScoreReview UK holds only the licence necessary to operate scorereview.io and to publish verified reviews to the audience the reviewer intended.

  3. 2.3

    Your obligations

    In relation to baseline security posture you must provide accurate information, act in good faith, and refrain from any conduct that would mislead consumers, distort the trust ledger, or breach the acceptable-use rules published at scorereview.io/acceptable-use. Repeated or wilful breach is grounds for suspension without refund.

    Where you act on behalf of a business you warrant that you have authority to bind that business to Security Headers Policy, that any customer contact you upload consented to receive a review invitation, and that you will keep records sufficient to demonstrate that consent for at least 24 months.

  4. 2.4

    Disclosure, data, privacy & cookies

    Personal data processed under this clause is handled in accordance with the ScoreReview UK Privacy Policy and, where you are a business customer, the Data Processing Agreement. Lawful basis is legitimate interest for platform integrity, contract for paid services, and consent for optional analytics or non-essential cookies set on scorereview.io.

    We publish a disclosure log covering enforcement actions, moderation decisions and material policy changes relevant to baseline security posture. Cookies used to support this clause are strictly necessary; any analytics or preference cookies require prior opt-in via the cookie banner and can be withdrawn at any time from the footer.

3

HTTP Strict Transport Security (HSTS)

  1. 3.1

    Policy & legal framework

    This clause addresses http strict transport security (hsts) within the Security Headers Policy that governs your relationship with ScoreReview UK, operated by UK REAL REVIEWS LTD (company number 14587101). It is drafted to satisfy the Consumer Rights Act 2015, the Digital Markets, Competition and Consumers Act 2024, the UK GDPR and the Data Protection Act 2018 as they apply to a UK-registered review platform published at scorereview.io.

    Where an obligation in this clause conflicts with mandatory statute or with a signed Order Form, the more protective provision prevails. Nothing in Security Headers Policy limits statutory rights that cannot be excluded by contract.

  2. 3.2

    Your rights

    You retain the right to receive plain-English information about http strict transport security (hsts), to challenge any decision we take under this clause, and to escalate an unresolved complaint to the relevant supervisory authority — the Information Commissioner's Office for data matters and the Competition and Markets Authority for consumer-law matters. Escalation does not require you to waive any right of action.

    Reviewers keep ownership of the content they submit; businesses keep ownership of the transactional data they upload. ScoreReview UK holds only the licence necessary to operate scorereview.io and to publish verified reviews to the audience the reviewer intended.

  3. 3.3

    Your obligations

    In relation to http strict transport security (hsts) you must provide accurate information, act in good faith, and refrain from any conduct that would mislead consumers, distort the trust ledger, or breach the acceptable-use rules published at scorereview.io/acceptable-use. Repeated or wilful breach is grounds for suspension without refund.

    Where you act on behalf of a business you warrant that you have authority to bind that business to Security Headers Policy, that any customer contact you upload consented to receive a review invitation, and that you will keep records sufficient to demonstrate that consent for at least 24 months.

  4. 3.4

    Disclosure, data, privacy & cookies

    Personal data processed under this clause is handled in accordance with the ScoreReview UK Privacy Policy and, where you are a business customer, the Data Processing Agreement. Lawful basis is legitimate interest for platform integrity, contract for paid services, and consent for optional analytics or non-essential cookies set on scorereview.io.

    We publish a disclosure log covering enforcement actions, moderation decisions and material policy changes relevant to http strict transport security (hsts). Cookies used to support this clause are strictly necessary; any analytics or preference cookies require prior opt-in via the cookie banner and can be withdrawn at any time from the footer.

4

HSTS preload and subdomain coverage

  1. 4.1

    Policy & legal framework

    This clause addresses hsts preload and subdomain coverage within the Security Headers Policy that governs your relationship with ScoreReview UK, operated by UK REAL REVIEWS LTD (company number 14587101). It is drafted to satisfy the Consumer Rights Act 2015, the Digital Markets, Competition and Consumers Act 2024, the UK GDPR and the Data Protection Act 2018 as they apply to a UK-registered review platform published at scorereview.io.

    Where an obligation in this clause conflicts with mandatory statute or with a signed Order Form, the more protective provision prevails. Nothing in Security Headers Policy limits statutory rights that cannot be excluded by contract.

  2. 4.2

    Your rights

    You retain the right to receive plain-English information about hsts preload and subdomain coverage, to challenge any decision we take under this clause, and to escalate an unresolved complaint to the relevant supervisory authority — the Information Commissioner's Office for data matters and the Competition and Markets Authority for consumer-law matters. Escalation does not require you to waive any right of action.

    Reviewers keep ownership of the content they submit; businesses keep ownership of the transactional data they upload. ScoreReview UK holds only the licence necessary to operate scorereview.io and to publish verified reviews to the audience the reviewer intended.

  3. 4.3

    Your obligations

    In relation to hsts preload and subdomain coverage you must provide accurate information, act in good faith, and refrain from any conduct that would mislead consumers, distort the trust ledger, or breach the acceptable-use rules published at scorereview.io/acceptable-use. Repeated or wilful breach is grounds for suspension without refund.

    Where you act on behalf of a business you warrant that you have authority to bind that business to Security Headers Policy, that any customer contact you upload consented to receive a review invitation, and that you will keep records sufficient to demonstrate that consent for at least 24 months.

  4. 4.4

    Disclosure, data, privacy & cookies

    Personal data processed under this clause is handled in accordance with the ScoreReview UK Privacy Policy and, where you are a business customer, the Data Processing Agreement. Lawful basis is legitimate interest for platform integrity, contract for paid services, and consent for optional analytics or non-essential cookies set on scorereview.io.

    We publish a disclosure log covering enforcement actions, moderation decisions and material policy changes relevant to hsts preload and subdomain coverage. Cookies used to support this clause are strictly necessary; any analytics or preference cookies require prior opt-in via the cookie banner and can be withdrawn at any time from the footer.

5

Content Security Policy (CSP)

  1. 5.1

    Policy & legal framework

    This clause addresses content security policy (csp) within the Security Headers Policy that governs your relationship with ScoreReview UK, operated by UK REAL REVIEWS LTD (company number 14587101). It is drafted to satisfy the Consumer Rights Act 2015, the Digital Markets, Competition and Consumers Act 2024, the UK GDPR and the Data Protection Act 2018 as they apply to a UK-registered review platform published at scorereview.io.

    Where an obligation in this clause conflicts with mandatory statute or with a signed Order Form, the more protective provision prevails. Nothing in Security Headers Policy limits statutory rights that cannot be excluded by contract.

  2. 5.2

    Your rights

    You retain the right to receive plain-English information about content security policy (csp), to challenge any decision we take under this clause, and to escalate an unresolved complaint to the relevant supervisory authority — the Information Commissioner's Office for data matters and the Competition and Markets Authority for consumer-law matters. Escalation does not require you to waive any right of action.

    Reviewers keep ownership of the content they submit; businesses keep ownership of the transactional data they upload. ScoreReview UK holds only the licence necessary to operate scorereview.io and to publish verified reviews to the audience the reviewer intended.

  3. 5.3

    Your obligations

    In relation to content security policy (csp) you must provide accurate information, act in good faith, and refrain from any conduct that would mislead consumers, distort the trust ledger, or breach the acceptable-use rules published at scorereview.io/acceptable-use. Repeated or wilful breach is grounds for suspension without refund.

    Where you act on behalf of a business you warrant that you have authority to bind that business to Security Headers Policy, that any customer contact you upload consented to receive a review invitation, and that you will keep records sufficient to demonstrate that consent for at least 24 months.

  4. 5.4

    Disclosure, data, privacy & cookies

    Personal data processed under this clause is handled in accordance with the ScoreReview UK Privacy Policy and, where you are a business customer, the Data Processing Agreement. Lawful basis is legitimate interest for platform integrity, contract for paid services, and consent for optional analytics or non-essential cookies set on scorereview.io.

    We publish a disclosure log covering enforcement actions, moderation decisions and material policy changes relevant to content security policy (csp). Cookies used to support this clause are strictly necessary; any analytics or preference cookies require prior opt-in via the cookie banner and can be withdrawn at any time from the footer.

6

CSP nonces and strict-dynamic

  1. 6.1

    Policy & legal framework

    This clause addresses csp nonces and strict-dynamic within the Security Headers Policy that governs your relationship with ScoreReview UK, operated by UK REAL REVIEWS LTD (company number 14587101). It is drafted to satisfy the Consumer Rights Act 2015, the Digital Markets, Competition and Consumers Act 2024, the UK GDPR and the Data Protection Act 2018 as they apply to a UK-registered review platform published at scorereview.io.

    Where an obligation in this clause conflicts with mandatory statute or with a signed Order Form, the more protective provision prevails. Nothing in Security Headers Policy limits statutory rights that cannot be excluded by contract.

  2. 6.2

    Your rights

    You retain the right to receive plain-English information about csp nonces and strict-dynamic, to challenge any decision we take under this clause, and to escalate an unresolved complaint to the relevant supervisory authority — the Information Commissioner's Office for data matters and the Competition and Markets Authority for consumer-law matters. Escalation does not require you to waive any right of action.

    Reviewers keep ownership of the content they submit; businesses keep ownership of the transactional data they upload. ScoreReview UK holds only the licence necessary to operate scorereview.io and to publish verified reviews to the audience the reviewer intended.

  3. 6.3

    Your obligations

    In relation to csp nonces and strict-dynamic you must provide accurate information, act in good faith, and refrain from any conduct that would mislead consumers, distort the trust ledger, or breach the acceptable-use rules published at scorereview.io/acceptable-use. Repeated or wilful breach is grounds for suspension without refund.

    Where you act on behalf of a business you warrant that you have authority to bind that business to Security Headers Policy, that any customer contact you upload consented to receive a review invitation, and that you will keep records sufficient to demonstrate that consent for at least 24 months.

  4. 6.4

    Disclosure, data, privacy & cookies

    Personal data processed under this clause is handled in accordance with the ScoreReview UK Privacy Policy and, where you are a business customer, the Data Processing Agreement. Lawful basis is legitimate interest for platform integrity, contract for paid services, and consent for optional analytics or non-essential cookies set on scorereview.io.

    We publish a disclosure log covering enforcement actions, moderation decisions and material policy changes relevant to csp nonces and strict-dynamic. Cookies used to support this clause are strictly necessary; any analytics or preference cookies require prior opt-in via the cookie banner and can be withdrawn at any time from the footer.

7

CSP report-uri and report-to endpoints

  1. 7.1

    Policy & legal framework

    This clause addresses csp report-uri and report-to endpoints within the Security Headers Policy that governs your relationship with ScoreReview UK, operated by UK REAL REVIEWS LTD (company number 14587101). It is drafted to satisfy the Consumer Rights Act 2015, the Digital Markets, Competition and Consumers Act 2024, the UK GDPR and the Data Protection Act 2018 as they apply to a UK-registered review platform published at scorereview.io.

    Where an obligation in this clause conflicts with mandatory statute or with a signed Order Form, the more protective provision prevails. Nothing in Security Headers Policy limits statutory rights that cannot be excluded by contract.

  2. 7.2

    Your rights

    You retain the right to receive plain-English information about csp report-uri and report-to endpoints, to challenge any decision we take under this clause, and to escalate an unresolved complaint to the relevant supervisory authority — the Information Commissioner's Office for data matters and the Competition and Markets Authority for consumer-law matters. Escalation does not require you to waive any right of action.

    Reviewers keep ownership of the content they submit; businesses keep ownership of the transactional data they upload. ScoreReview UK holds only the licence necessary to operate scorereview.io and to publish verified reviews to the audience the reviewer intended.

  3. 7.3

    Your obligations

    In relation to csp report-uri and report-to endpoints you must provide accurate information, act in good faith, and refrain from any conduct that would mislead consumers, distort the trust ledger, or breach the acceptable-use rules published at scorereview.io/acceptable-use. Repeated or wilful breach is grounds for suspension without refund.

    Where you act on behalf of a business you warrant that you have authority to bind that business to Security Headers Policy, that any customer contact you upload consented to receive a review invitation, and that you will keep records sufficient to demonstrate that consent for at least 24 months.

  4. 7.4

    Disclosure, data, privacy & cookies

    Personal data processed under this clause is handled in accordance with the ScoreReview UK Privacy Policy and, where you are a business customer, the Data Processing Agreement. Lawful basis is legitimate interest for platform integrity, contract for paid services, and consent for optional analytics or non-essential cookies set on scorereview.io.

    We publish a disclosure log covering enforcement actions, moderation decisions and material policy changes relevant to csp report-uri and report-to endpoints. Cookies used to support this clause are strictly necessary; any analytics or preference cookies require prior opt-in via the cookie banner and can be withdrawn at any time from the footer.

8

X-Content-Type-Options and MIME sniffing

  1. 8.1

    Policy & legal framework

    This clause addresses x-content-type-options and mime sniffing within the Security Headers Policy that governs your relationship with ScoreReview UK, operated by UK REAL REVIEWS LTD (company number 14587101). It is drafted to satisfy the Consumer Rights Act 2015, the Digital Markets, Competition and Consumers Act 2024, the UK GDPR and the Data Protection Act 2018 as they apply to a UK-registered review platform published at scorereview.io.

    Where an obligation in this clause conflicts with mandatory statute or with a signed Order Form, the more protective provision prevails. Nothing in Security Headers Policy limits statutory rights that cannot be excluded by contract.

  2. 8.2

    Your rights

    You retain the right to receive plain-English information about x-content-type-options and mime sniffing, to challenge any decision we take under this clause, and to escalate an unresolved complaint to the relevant supervisory authority — the Information Commissioner's Office for data matters and the Competition and Markets Authority for consumer-law matters. Escalation does not require you to waive any right of action.

    Reviewers keep ownership of the content they submit; businesses keep ownership of the transactional data they upload. ScoreReview UK holds only the licence necessary to operate scorereview.io and to publish verified reviews to the audience the reviewer intended.

  3. 8.3

    Your obligations

    In relation to x-content-type-options and mime sniffing you must provide accurate information, act in good faith, and refrain from any conduct that would mislead consumers, distort the trust ledger, or breach the acceptable-use rules published at scorereview.io/acceptable-use. Repeated or wilful breach is grounds for suspension without refund.

    Where you act on behalf of a business you warrant that you have authority to bind that business to Security Headers Policy, that any customer contact you upload consented to receive a review invitation, and that you will keep records sufficient to demonstrate that consent for at least 24 months.

  4. 8.4

    Disclosure, data, privacy & cookies

    Personal data processed under this clause is handled in accordance with the ScoreReview UK Privacy Policy and, where you are a business customer, the Data Processing Agreement. Lawful basis is legitimate interest for platform integrity, contract for paid services, and consent for optional analytics or non-essential cookies set on scorereview.io.

    We publish a disclosure log covering enforcement actions, moderation decisions and material policy changes relevant to x-content-type-options and mime sniffing. Cookies used to support this clause are strictly necessary; any analytics or preference cookies require prior opt-in via the cookie banner and can be withdrawn at any time from the footer.

9

X-Frame-Options and framing rules

  1. 9.1

    Policy & legal framework

    This clause addresses x-frame-options and framing rules within the Security Headers Policy that governs your relationship with ScoreReview UK, operated by UK REAL REVIEWS LTD (company number 14587101). It is drafted to satisfy the Consumer Rights Act 2015, the Digital Markets, Competition and Consumers Act 2024, the UK GDPR and the Data Protection Act 2018 as they apply to a UK-registered review platform published at scorereview.io.

    Where an obligation in this clause conflicts with mandatory statute or with a signed Order Form, the more protective provision prevails. Nothing in Security Headers Policy limits statutory rights that cannot be excluded by contract.

  2. 9.2

    Your rights

    You retain the right to receive plain-English information about x-frame-options and framing rules, to challenge any decision we take under this clause, and to escalate an unresolved complaint to the relevant supervisory authority — the Information Commissioner's Office for data matters and the Competition and Markets Authority for consumer-law matters. Escalation does not require you to waive any right of action.

    Reviewers keep ownership of the content they submit; businesses keep ownership of the transactional data they upload. ScoreReview UK holds only the licence necessary to operate scorereview.io and to publish verified reviews to the audience the reviewer intended.

  3. 9.3

    Your obligations

    In relation to x-frame-options and framing rules you must provide accurate information, act in good faith, and refrain from any conduct that would mislead consumers, distort the trust ledger, or breach the acceptable-use rules published at scorereview.io/acceptable-use. Repeated or wilful breach is grounds for suspension without refund.

    Where you act on behalf of a business you warrant that you have authority to bind that business to Security Headers Policy, that any customer contact you upload consented to receive a review invitation, and that you will keep records sufficient to demonstrate that consent for at least 24 months.

  4. 9.4

    Disclosure, data, privacy & cookies

    Personal data processed under this clause is handled in accordance with the ScoreReview UK Privacy Policy and, where you are a business customer, the Data Processing Agreement. Lawful basis is legitimate interest for platform integrity, contract for paid services, and consent for optional analytics or non-essential cookies set on scorereview.io.

    We publish a disclosure log covering enforcement actions, moderation decisions and material policy changes relevant to x-frame-options and framing rules. Cookies used to support this clause are strictly necessary; any analytics or preference cookies require prior opt-in via the cookie banner and can be withdrawn at any time from the footer.

10

Referrer-Policy and cross-origin leaks

  1. 10.1

    Policy & legal framework

    This clause addresses referrer-policy and cross-origin leaks within the Security Headers Policy that governs your relationship with ScoreReview UK, operated by UK REAL REVIEWS LTD (company number 14587101). It is drafted to satisfy the Consumer Rights Act 2015, the Digital Markets, Competition and Consumers Act 2024, the UK GDPR and the Data Protection Act 2018 as they apply to a UK-registered review platform published at scorereview.io.

    Where an obligation in this clause conflicts with mandatory statute or with a signed Order Form, the more protective provision prevails. Nothing in Security Headers Policy limits statutory rights that cannot be excluded by contract.

  2. 10.2

    Your rights

    You retain the right to receive plain-English information about referrer-policy and cross-origin leaks, to challenge any decision we take under this clause, and to escalate an unresolved complaint to the relevant supervisory authority — the Information Commissioner's Office for data matters and the Competition and Markets Authority for consumer-law matters. Escalation does not require you to waive any right of action.

    Reviewers keep ownership of the content they submit; businesses keep ownership of the transactional data they upload. ScoreReview UK holds only the licence necessary to operate scorereview.io and to publish verified reviews to the audience the reviewer intended.

  3. 10.3

    Your obligations

    In relation to referrer-policy and cross-origin leaks you must provide accurate information, act in good faith, and refrain from any conduct that would mislead consumers, distort the trust ledger, or breach the acceptable-use rules published at scorereview.io/acceptable-use. Repeated or wilful breach is grounds for suspension without refund.

    Where you act on behalf of a business you warrant that you have authority to bind that business to Security Headers Policy, that any customer contact you upload consented to receive a review invitation, and that you will keep records sufficient to demonstrate that consent for at least 24 months.

  4. 10.4

    Disclosure, data, privacy & cookies

    Personal data processed under this clause is handled in accordance with the ScoreReview UK Privacy Policy and, where you are a business customer, the Data Processing Agreement. Lawful basis is legitimate interest for platform integrity, contract for paid services, and consent for optional analytics or non-essential cookies set on scorereview.io.

    We publish a disclosure log covering enforcement actions, moderation decisions and material policy changes relevant to referrer-policy and cross-origin leaks. Cookies used to support this clause are strictly necessary; any analytics or preference cookies require prior opt-in via the cookie banner and can be withdrawn at any time from the footer.

11

Permissions-Policy (feature policy)

  1. 11.1

    Policy & legal framework

    This clause addresses permissions-policy (feature policy) within the Security Headers Policy that governs your relationship with ScoreReview UK, operated by UK REAL REVIEWS LTD (company number 14587101). It is drafted to satisfy the Consumer Rights Act 2015, the Digital Markets, Competition and Consumers Act 2024, the UK GDPR and the Data Protection Act 2018 as they apply to a UK-registered review platform published at scorereview.io.

    Where an obligation in this clause conflicts with mandatory statute or with a signed Order Form, the more protective provision prevails. Nothing in Security Headers Policy limits statutory rights that cannot be excluded by contract.

  2. 11.2

    Your rights

    You retain the right to receive plain-English information about permissions-policy (feature policy), to challenge any decision we take under this clause, and to escalate an unresolved complaint to the relevant supervisory authority — the Information Commissioner's Office for data matters and the Competition and Markets Authority for consumer-law matters. Escalation does not require you to waive any right of action.

    Reviewers keep ownership of the content they submit; businesses keep ownership of the transactional data they upload. ScoreReview UK holds only the licence necessary to operate scorereview.io and to publish verified reviews to the audience the reviewer intended.

  3. 11.3

    Your obligations

    In relation to permissions-policy (feature policy) you must provide accurate information, act in good faith, and refrain from any conduct that would mislead consumers, distort the trust ledger, or breach the acceptable-use rules published at scorereview.io/acceptable-use. Repeated or wilful breach is grounds for suspension without refund.

    Where you act on behalf of a business you warrant that you have authority to bind that business to Security Headers Policy, that any customer contact you upload consented to receive a review invitation, and that you will keep records sufficient to demonstrate that consent for at least 24 months.

  4. 11.4

    Disclosure, data, privacy & cookies

    Personal data processed under this clause is handled in accordance with the ScoreReview UK Privacy Policy and, where you are a business customer, the Data Processing Agreement. Lawful basis is legitimate interest for platform integrity, contract for paid services, and consent for optional analytics or non-essential cookies set on scorereview.io.

    We publish a disclosure log covering enforcement actions, moderation decisions and material policy changes relevant to permissions-policy (feature policy). Cookies used to support this clause are strictly necessary; any analytics or preference cookies require prior opt-in via the cookie banner and can be withdrawn at any time from the footer.

12

Cross-Origin-Opener-Policy (COOP)

  1. 12.1

    Policy & legal framework

    This clause addresses cross-origin-opener-policy (coop) within the Security Headers Policy that governs your relationship with ScoreReview UK, operated by UK REAL REVIEWS LTD (company number 14587101). It is drafted to satisfy the Consumer Rights Act 2015, the Digital Markets, Competition and Consumers Act 2024, the UK GDPR and the Data Protection Act 2018 as they apply to a UK-registered review platform published at scorereview.io.

    Where an obligation in this clause conflicts with mandatory statute or with a signed Order Form, the more protective provision prevails. Nothing in Security Headers Policy limits statutory rights that cannot be excluded by contract.

  2. 12.2

    Your rights

    You retain the right to receive plain-English information about cross-origin-opener-policy (coop), to challenge any decision we take under this clause, and to escalate an unresolved complaint to the relevant supervisory authority — the Information Commissioner's Office for data matters and the Competition and Markets Authority for consumer-law matters. Escalation does not require you to waive any right of action.

    Reviewers keep ownership of the content they submit; businesses keep ownership of the transactional data they upload. ScoreReview UK holds only the licence necessary to operate scorereview.io and to publish verified reviews to the audience the reviewer intended.

  3. 12.3

    Your obligations

    In relation to cross-origin-opener-policy (coop) you must provide accurate information, act in good faith, and refrain from any conduct that would mislead consumers, distort the trust ledger, or breach the acceptable-use rules published at scorereview.io/acceptable-use. Repeated or wilful breach is grounds for suspension without refund.

    Where you act on behalf of a business you warrant that you have authority to bind that business to Security Headers Policy, that any customer contact you upload consented to receive a review invitation, and that you will keep records sufficient to demonstrate that consent for at least 24 months.

  4. 12.4

    Disclosure, data, privacy & cookies

    Personal data processed under this clause is handled in accordance with the ScoreReview UK Privacy Policy and, where you are a business customer, the Data Processing Agreement. Lawful basis is legitimate interest for platform integrity, contract for paid services, and consent for optional analytics or non-essential cookies set on scorereview.io.

    We publish a disclosure log covering enforcement actions, moderation decisions and material policy changes relevant to cross-origin-opener-policy (coop). Cookies used to support this clause are strictly necessary; any analytics or preference cookies require prior opt-in via the cookie banner and can be withdrawn at any time from the footer.

13

Cross-Origin-Embedder-Policy (COEP)

  1. 13.1

    Policy & legal framework

    This clause addresses cross-origin-embedder-policy (coep) within the Security Headers Policy that governs your relationship with ScoreReview UK, operated by UK REAL REVIEWS LTD (company number 14587101). It is drafted to satisfy the Consumer Rights Act 2015, the Digital Markets, Competition and Consumers Act 2024, the UK GDPR and the Data Protection Act 2018 as they apply to a UK-registered review platform published at scorereview.io.

    Where an obligation in this clause conflicts with mandatory statute or with a signed Order Form, the more protective provision prevails. Nothing in Security Headers Policy limits statutory rights that cannot be excluded by contract.

  2. 13.2

    Your rights

    You retain the right to receive plain-English information about cross-origin-embedder-policy (coep), to challenge any decision we take under this clause, and to escalate an unresolved complaint to the relevant supervisory authority — the Information Commissioner's Office for data matters and the Competition and Markets Authority for consumer-law matters. Escalation does not require you to waive any right of action.

    Reviewers keep ownership of the content they submit; businesses keep ownership of the transactional data they upload. ScoreReview UK holds only the licence necessary to operate scorereview.io and to publish verified reviews to the audience the reviewer intended.

  3. 13.3

    Your obligations

    In relation to cross-origin-embedder-policy (coep) you must provide accurate information, act in good faith, and refrain from any conduct that would mislead consumers, distort the trust ledger, or breach the acceptable-use rules published at scorereview.io/acceptable-use. Repeated or wilful breach is grounds for suspension without refund.

    Where you act on behalf of a business you warrant that you have authority to bind that business to Security Headers Policy, that any customer contact you upload consented to receive a review invitation, and that you will keep records sufficient to demonstrate that consent for at least 24 months.

  4. 13.4

    Disclosure, data, privacy & cookies

    Personal data processed under this clause is handled in accordance with the ScoreReview UK Privacy Policy and, where you are a business customer, the Data Processing Agreement. Lawful basis is legitimate interest for platform integrity, contract for paid services, and consent for optional analytics or non-essential cookies set on scorereview.io.

    We publish a disclosure log covering enforcement actions, moderation decisions and material policy changes relevant to cross-origin-embedder-policy (coep). Cookies used to support this clause are strictly necessary; any analytics or preference cookies require prior opt-in via the cookie banner and can be withdrawn at any time from the footer.

14

Cross-Origin-Resource-Policy (CORP)

  1. 14.1

    Policy & legal framework

    This clause addresses cross-origin-resource-policy (corp) within the Security Headers Policy that governs your relationship with ScoreReview UK, operated by UK REAL REVIEWS LTD (company number 14587101). It is drafted to satisfy the Consumer Rights Act 2015, the Digital Markets, Competition and Consumers Act 2024, the UK GDPR and the Data Protection Act 2018 as they apply to a UK-registered review platform published at scorereview.io.

    Where an obligation in this clause conflicts with mandatory statute or with a signed Order Form, the more protective provision prevails. Nothing in Security Headers Policy limits statutory rights that cannot be excluded by contract.

  2. 14.2

    Your rights

    You retain the right to receive plain-English information about cross-origin-resource-policy (corp), to challenge any decision we take under this clause, and to escalate an unresolved complaint to the relevant supervisory authority — the Information Commissioner's Office for data matters and the Competition and Markets Authority for consumer-law matters. Escalation does not require you to waive any right of action.

    Reviewers keep ownership of the content they submit; businesses keep ownership of the transactional data they upload. ScoreReview UK holds only the licence necessary to operate scorereview.io and to publish verified reviews to the audience the reviewer intended.

  3. 14.3

    Your obligations

    In relation to cross-origin-resource-policy (corp) you must provide accurate information, act in good faith, and refrain from any conduct that would mislead consumers, distort the trust ledger, or breach the acceptable-use rules published at scorereview.io/acceptable-use. Repeated or wilful breach is grounds for suspension without refund.

    Where you act on behalf of a business you warrant that you have authority to bind that business to Security Headers Policy, that any customer contact you upload consented to receive a review invitation, and that you will keep records sufficient to demonstrate that consent for at least 24 months.

  4. 14.4

    Disclosure, data, privacy & cookies

    Personal data processed under this clause is handled in accordance with the ScoreReview UK Privacy Policy and, where you are a business customer, the Data Processing Agreement. Lawful basis is legitimate interest for platform integrity, contract for paid services, and consent for optional analytics or non-essential cookies set on scorereview.io.

    We publish a disclosure log covering enforcement actions, moderation decisions and material policy changes relevant to cross-origin-resource-policy (corp). Cookies used to support this clause are strictly necessary; any analytics or preference cookies require prior opt-in via the cookie banner and can be withdrawn at any time from the footer.

15

CORS and API allow-lists

  1. 15.1

    Policy & legal framework

    This clause addresses cors and api allow-lists within the Security Headers Policy that governs your relationship with ScoreReview UK, operated by UK REAL REVIEWS LTD (company number 14587101). It is drafted to satisfy the Consumer Rights Act 2015, the Digital Markets, Competition and Consumers Act 2024, the UK GDPR and the Data Protection Act 2018 as they apply to a UK-registered review platform published at scorereview.io.

    Where an obligation in this clause conflicts with mandatory statute or with a signed Order Form, the more protective provision prevails. Nothing in Security Headers Policy limits statutory rights that cannot be excluded by contract.

  2. 15.2

    Your rights

    You retain the right to receive plain-English information about cors and api allow-lists, to challenge any decision we take under this clause, and to escalate an unresolved complaint to the relevant supervisory authority — the Information Commissioner's Office for data matters and the Competition and Markets Authority for consumer-law matters. Escalation does not require you to waive any right of action.

    Reviewers keep ownership of the content they submit; businesses keep ownership of the transactional data they upload. ScoreReview UK holds only the licence necessary to operate scorereview.io and to publish verified reviews to the audience the reviewer intended.

  3. 15.3

    Your obligations

    In relation to cors and api allow-lists you must provide accurate information, act in good faith, and refrain from any conduct that would mislead consumers, distort the trust ledger, or breach the acceptable-use rules published at scorereview.io/acceptable-use. Repeated or wilful breach is grounds for suspension without refund.

    Where you act on behalf of a business you warrant that you have authority to bind that business to Security Headers Policy, that any customer contact you upload consented to receive a review invitation, and that you will keep records sufficient to demonstrate that consent for at least 24 months.

  4. 15.4

    Disclosure, data, privacy & cookies

    Personal data processed under this clause is handled in accordance with the ScoreReview UK Privacy Policy and, where you are a business customer, the Data Processing Agreement. Lawful basis is legitimate interest for platform integrity, contract for paid services, and consent for optional analytics or non-essential cookies set on scorereview.io.

    We publish a disclosure log covering enforcement actions, moderation decisions and material policy changes relevant to cors and api allow-lists. Cookies used to support this clause are strictly necessary; any analytics or preference cookies require prior opt-in via the cookie banner and can be withdrawn at any time from the footer.

17

Sub-resource integrity (SRI)

  1. 17.1

    Policy & legal framework

    This clause addresses sub-resource integrity (sri) within the Security Headers Policy that governs your relationship with ScoreReview UK, operated by UK REAL REVIEWS LTD (company number 14587101). It is drafted to satisfy the Consumer Rights Act 2015, the Digital Markets, Competition and Consumers Act 2024, the UK GDPR and the Data Protection Act 2018 as they apply to a UK-registered review platform published at scorereview.io.

    Where an obligation in this clause conflicts with mandatory statute or with a signed Order Form, the more protective provision prevails. Nothing in Security Headers Policy limits statutory rights that cannot be excluded by contract.

  2. 17.2

    Your rights

    You retain the right to receive plain-English information about sub-resource integrity (sri), to challenge any decision we take under this clause, and to escalate an unresolved complaint to the relevant supervisory authority — the Information Commissioner's Office for data matters and the Competition and Markets Authority for consumer-law matters. Escalation does not require you to waive any right of action.

    Reviewers keep ownership of the content they submit; businesses keep ownership of the transactional data they upload. ScoreReview UK holds only the licence necessary to operate scorereview.io and to publish verified reviews to the audience the reviewer intended.

  3. 17.3

    Your obligations

    In relation to sub-resource integrity (sri) you must provide accurate information, act in good faith, and refrain from any conduct that would mislead consumers, distort the trust ledger, or breach the acceptable-use rules published at scorereview.io/acceptable-use. Repeated or wilful breach is grounds for suspension without refund.

    Where you act on behalf of a business you warrant that you have authority to bind that business to Security Headers Policy, that any customer contact you upload consented to receive a review invitation, and that you will keep records sufficient to demonstrate that consent for at least 24 months.

  4. 17.4

    Disclosure, data, privacy & cookies

    Personal data processed under this clause is handled in accordance with the ScoreReview UK Privacy Policy and, where you are a business customer, the Data Processing Agreement. Lawful basis is legitimate interest for platform integrity, contract for paid services, and consent for optional analytics or non-essential cookies set on scorereview.io.

    We publish a disclosure log covering enforcement actions, moderation decisions and material policy changes relevant to sub-resource integrity (sri). Cookies used to support this clause are strictly necessary; any analytics or preference cookies require prior opt-in via the cookie banner and can be withdrawn at any time from the footer.

18

Cache-Control and stale-while-revalidate

  1. 18.1

    Policy & legal framework

    This clause addresses cache-control and stale-while-revalidate within the Security Headers Policy that governs your relationship with ScoreReview UK, operated by UK REAL REVIEWS LTD (company number 14587101). It is drafted to satisfy the Consumer Rights Act 2015, the Digital Markets, Competition and Consumers Act 2024, the UK GDPR and the Data Protection Act 2018 as they apply to a UK-registered review platform published at scorereview.io.

    Where an obligation in this clause conflicts with mandatory statute or with a signed Order Form, the more protective provision prevails. Nothing in Security Headers Policy limits statutory rights that cannot be excluded by contract.

  2. 18.2

    Your rights

    You retain the right to receive plain-English information about cache-control and stale-while-revalidate, to challenge any decision we take under this clause, and to escalate an unresolved complaint to the relevant supervisory authority — the Information Commissioner's Office for data matters and the Competition and Markets Authority for consumer-law matters. Escalation does not require you to waive any right of action.

    Reviewers keep ownership of the content they submit; businesses keep ownership of the transactional data they upload. ScoreReview UK holds only the licence necessary to operate scorereview.io and to publish verified reviews to the audience the reviewer intended.

  3. 18.3

    Your obligations

    In relation to cache-control and stale-while-revalidate you must provide accurate information, act in good faith, and refrain from any conduct that would mislead consumers, distort the trust ledger, or breach the acceptable-use rules published at scorereview.io/acceptable-use. Repeated or wilful breach is grounds for suspension without refund.

    Where you act on behalf of a business you warrant that you have authority to bind that business to Security Headers Policy, that any customer contact you upload consented to receive a review invitation, and that you will keep records sufficient to demonstrate that consent for at least 24 months.

  4. 18.4

    Disclosure, data, privacy & cookies

    Personal data processed under this clause is handled in accordance with the ScoreReview UK Privacy Policy and, where you are a business customer, the Data Processing Agreement. Lawful basis is legitimate interest for platform integrity, contract for paid services, and consent for optional analytics or non-essential cookies set on scorereview.io.

    We publish a disclosure log covering enforcement actions, moderation decisions and material policy changes relevant to cache-control and stale-while-revalidate. Cookies used to support this clause are strictly necessary; any analytics or preference cookies require prior opt-in via the cookie banner and can be withdrawn at any time from the footer.

19

Content-Type charset enforcement

  1. 19.1

    Policy & legal framework

    This clause addresses content-type charset enforcement within the Security Headers Policy that governs your relationship with ScoreReview UK, operated by UK REAL REVIEWS LTD (company number 14587101). It is drafted to satisfy the Consumer Rights Act 2015, the Digital Markets, Competition and Consumers Act 2024, the UK GDPR and the Data Protection Act 2018 as they apply to a UK-registered review platform published at scorereview.io.

    Where an obligation in this clause conflicts with mandatory statute or with a signed Order Form, the more protective provision prevails. Nothing in Security Headers Policy limits statutory rights that cannot be excluded by contract.

  2. 19.2

    Your rights

    You retain the right to receive plain-English information about content-type charset enforcement, to challenge any decision we take under this clause, and to escalate an unresolved complaint to the relevant supervisory authority — the Information Commissioner's Office for data matters and the Competition and Markets Authority for consumer-law matters. Escalation does not require you to waive any right of action.

    Reviewers keep ownership of the content they submit; businesses keep ownership of the transactional data they upload. ScoreReview UK holds only the licence necessary to operate scorereview.io and to publish verified reviews to the audience the reviewer intended.

  3. 19.3

    Your obligations

    In relation to content-type charset enforcement you must provide accurate information, act in good faith, and refrain from any conduct that would mislead consumers, distort the trust ledger, or breach the acceptable-use rules published at scorereview.io/acceptable-use. Repeated or wilful breach is grounds for suspension without refund.

    Where you act on behalf of a business you warrant that you have authority to bind that business to Security Headers Policy, that any customer contact you upload consented to receive a review invitation, and that you will keep records sufficient to demonstrate that consent for at least 24 months.

  4. 19.4

    Disclosure, data, privacy & cookies

    Personal data processed under this clause is handled in accordance with the ScoreReview UK Privacy Policy and, where you are a business customer, the Data Processing Agreement. Lawful basis is legitimate interest for platform integrity, contract for paid services, and consent for optional analytics or non-essential cookies set on scorereview.io.

    We publish a disclosure log covering enforcement actions, moderation decisions and material policy changes relevant to content-type charset enforcement. Cookies used to support this clause are strictly necessary; any analytics or preference cookies require prior opt-in via the cookie banner and can be withdrawn at any time from the footer.

20

TLS configuration and cipher suites

  1. 20.1

    Policy & legal framework

    This clause addresses tls configuration and cipher suites within the Security Headers Policy that governs your relationship with ScoreReview UK, operated by UK REAL REVIEWS LTD (company number 14587101). It is drafted to satisfy the Consumer Rights Act 2015, the Digital Markets, Competition and Consumers Act 2024, the UK GDPR and the Data Protection Act 2018 as they apply to a UK-registered review platform published at scorereview.io.

    Where an obligation in this clause conflicts with mandatory statute or with a signed Order Form, the more protective provision prevails. Nothing in Security Headers Policy limits statutory rights that cannot be excluded by contract.

  2. 20.2

    Your rights

    You retain the right to receive plain-English information about tls configuration and cipher suites, to challenge any decision we take under this clause, and to escalate an unresolved complaint to the relevant supervisory authority — the Information Commissioner's Office for data matters and the Competition and Markets Authority for consumer-law matters. Escalation does not require you to waive any right of action.

    Reviewers keep ownership of the content they submit; businesses keep ownership of the transactional data they upload. ScoreReview UK holds only the licence necessary to operate scorereview.io and to publish verified reviews to the audience the reviewer intended.

  3. 20.3

    Your obligations

    In relation to tls configuration and cipher suites you must provide accurate information, act in good faith, and refrain from any conduct that would mislead consumers, distort the trust ledger, or breach the acceptable-use rules published at scorereview.io/acceptable-use. Repeated or wilful breach is grounds for suspension without refund.

    Where you act on behalf of a business you warrant that you have authority to bind that business to Security Headers Policy, that any customer contact you upload consented to receive a review invitation, and that you will keep records sufficient to demonstrate that consent for at least 24 months.

  4. 20.4

    Disclosure, data, privacy & cookies

    Personal data processed under this clause is handled in accordance with the ScoreReview UK Privacy Policy and, where you are a business customer, the Data Processing Agreement. Lawful basis is legitimate interest for platform integrity, contract for paid services, and consent for optional analytics or non-essential cookies set on scorereview.io.

    We publish a disclosure log covering enforcement actions, moderation decisions and material policy changes relevant to tls configuration and cipher suites. Cookies used to support this clause are strictly necessary; any analytics or preference cookies require prior opt-in via the cookie banner and can be withdrawn at any time from the footer.

21

Certificate transparency and pinning

  1. 21.1

    Policy & legal framework

    This clause addresses certificate transparency and pinning within the Security Headers Policy that governs your relationship with ScoreReview UK, operated by UK REAL REVIEWS LTD (company number 14587101). It is drafted to satisfy the Consumer Rights Act 2015, the Digital Markets, Competition and Consumers Act 2024, the UK GDPR and the Data Protection Act 2018 as they apply to a UK-registered review platform published at scorereview.io.

    Where an obligation in this clause conflicts with mandatory statute or with a signed Order Form, the more protective provision prevails. Nothing in Security Headers Policy limits statutory rights that cannot be excluded by contract.

  2. 21.2

    Your rights

    You retain the right to receive plain-English information about certificate transparency and pinning, to challenge any decision we take under this clause, and to escalate an unresolved complaint to the relevant supervisory authority — the Information Commissioner's Office for data matters and the Competition and Markets Authority for consumer-law matters. Escalation does not require you to waive any right of action.

    Reviewers keep ownership of the content they submit; businesses keep ownership of the transactional data they upload. ScoreReview UK holds only the licence necessary to operate scorereview.io and to publish verified reviews to the audience the reviewer intended.

  3. 21.3

    Your obligations

    In relation to certificate transparency and pinning you must provide accurate information, act in good faith, and refrain from any conduct that would mislead consumers, distort the trust ledger, or breach the acceptable-use rules published at scorereview.io/acceptable-use. Repeated or wilful breach is grounds for suspension without refund.

    Where you act on behalf of a business you warrant that you have authority to bind that business to Security Headers Policy, that any customer contact you upload consented to receive a review invitation, and that you will keep records sufficient to demonstrate that consent for at least 24 months.

  4. 21.4

    Disclosure, data, privacy & cookies

    Personal data processed under this clause is handled in accordance with the ScoreReview UK Privacy Policy and, where you are a business customer, the Data Processing Agreement. Lawful basis is legitimate interest for platform integrity, contract for paid services, and consent for optional analytics or non-essential cookies set on scorereview.io.

    We publish a disclosure log covering enforcement actions, moderation decisions and material policy changes relevant to certificate transparency and pinning. Cookies used to support this clause are strictly necessary; any analytics or preference cookies require prior opt-in via the cookie banner and can be withdrawn at any time from the footer.

22

Widget iframe sandboxing

  1. 22.1

    Policy & legal framework

    This clause addresses widget iframe sandboxing within the Security Headers Policy that governs your relationship with ScoreReview UK, operated by UK REAL REVIEWS LTD (company number 14587101). It is drafted to satisfy the Consumer Rights Act 2015, the Digital Markets, Competition and Consumers Act 2024, the UK GDPR and the Data Protection Act 2018 as they apply to a UK-registered review platform published at scorereview.io.

    Where an obligation in this clause conflicts with mandatory statute or with a signed Order Form, the more protective provision prevails. Nothing in Security Headers Policy limits statutory rights that cannot be excluded by contract.

  2. 22.2

    Your rights

    You retain the right to receive plain-English information about widget iframe sandboxing, to challenge any decision we take under this clause, and to escalate an unresolved complaint to the relevant supervisory authority — the Information Commissioner's Office for data matters and the Competition and Markets Authority for consumer-law matters. Escalation does not require you to waive any right of action.

    Reviewers keep ownership of the content they submit; businesses keep ownership of the transactional data they upload. ScoreReview UK holds only the licence necessary to operate scorereview.io and to publish verified reviews to the audience the reviewer intended.

  3. 22.3

    Your obligations

    In relation to widget iframe sandboxing you must provide accurate information, act in good faith, and refrain from any conduct that would mislead consumers, distort the trust ledger, or breach the acceptable-use rules published at scorereview.io/acceptable-use. Repeated or wilful breach is grounds for suspension without refund.

    Where you act on behalf of a business you warrant that you have authority to bind that business to Security Headers Policy, that any customer contact you upload consented to receive a review invitation, and that you will keep records sufficient to demonstrate that consent for at least 24 months.

  4. 22.4

    Disclosure, data, privacy & cookies

    Personal data processed under this clause is handled in accordance with the ScoreReview UK Privacy Policy and, where you are a business customer, the Data Processing Agreement. Lawful basis is legitimate interest for platform integrity, contract for paid services, and consent for optional analytics or non-essential cookies set on scorereview.io.

    We publish a disclosure log covering enforcement actions, moderation decisions and material policy changes relevant to widget iframe sandboxing. Cookies used to support this clause are strictly necessary; any analytics or preference cookies require prior opt-in via the cookie banner and can be withdrawn at any time from the footer.

23

Reporting API and NEL

  1. 23.1

    Policy & legal framework

    This clause addresses reporting api and nel within the Security Headers Policy that governs your relationship with ScoreReview UK, operated by UK REAL REVIEWS LTD (company number 14587101). It is drafted to satisfy the Consumer Rights Act 2015, the Digital Markets, Competition and Consumers Act 2024, the UK GDPR and the Data Protection Act 2018 as they apply to a UK-registered review platform published at scorereview.io.

    Where an obligation in this clause conflicts with mandatory statute or with a signed Order Form, the more protective provision prevails. Nothing in Security Headers Policy limits statutory rights that cannot be excluded by contract.

  2. 23.2

    Your rights

    You retain the right to receive plain-English information about reporting api and nel, to challenge any decision we take under this clause, and to escalate an unresolved complaint to the relevant supervisory authority — the Information Commissioner's Office for data matters and the Competition and Markets Authority for consumer-law matters. Escalation does not require you to waive any right of action.

    Reviewers keep ownership of the content they submit; businesses keep ownership of the transactional data they upload. ScoreReview UK holds only the licence necessary to operate scorereview.io and to publish verified reviews to the audience the reviewer intended.

  3. 23.3

    Your obligations

    In relation to reporting api and nel you must provide accurate information, act in good faith, and refrain from any conduct that would mislead consumers, distort the trust ledger, or breach the acceptable-use rules published at scorereview.io/acceptable-use. Repeated or wilful breach is grounds for suspension without refund.

    Where you act on behalf of a business you warrant that you have authority to bind that business to Security Headers Policy, that any customer contact you upload consented to receive a review invitation, and that you will keep records sufficient to demonstrate that consent for at least 24 months.

  4. 23.4

    Disclosure, data, privacy & cookies

    Personal data processed under this clause is handled in accordance with the ScoreReview UK Privacy Policy and, where you are a business customer, the Data Processing Agreement. Lawful basis is legitimate interest for platform integrity, contract for paid services, and consent for optional analytics or non-essential cookies set on scorereview.io.

    We publish a disclosure log covering enforcement actions, moderation decisions and material policy changes relevant to reporting api and nel. Cookies used to support this clause are strictly necessary; any analytics or preference cookies require prior opt-in via the cookie banner and can be withdrawn at any time from the footer.

24

Header change management

  1. 24.1

    Policy & legal framework

    This clause addresses header change management within the Security Headers Policy that governs your relationship with ScoreReview UK, operated by UK REAL REVIEWS LTD (company number 14587101). It is drafted to satisfy the Consumer Rights Act 2015, the Digital Markets, Competition and Consumers Act 2024, the UK GDPR and the Data Protection Act 2018 as they apply to a UK-registered review platform published at scorereview.io.

    Where an obligation in this clause conflicts with mandatory statute or with a signed Order Form, the more protective provision prevails. Nothing in Security Headers Policy limits statutory rights that cannot be excluded by contract.

  2. 24.2

    Your rights

    You retain the right to receive plain-English information about header change management, to challenge any decision we take under this clause, and to escalate an unresolved complaint to the relevant supervisory authority — the Information Commissioner's Office for data matters and the Competition and Markets Authority for consumer-law matters. Escalation does not require you to waive any right of action.

    Reviewers keep ownership of the content they submit; businesses keep ownership of the transactional data they upload. ScoreReview UK holds only the licence necessary to operate scorereview.io and to publish verified reviews to the audience the reviewer intended.

  3. 24.3

    Your obligations

    In relation to header change management you must provide accurate information, act in good faith, and refrain from any conduct that would mislead consumers, distort the trust ledger, or breach the acceptable-use rules published at scorereview.io/acceptable-use. Repeated or wilful breach is grounds for suspension without refund.

    Where you act on behalf of a business you warrant that you have authority to bind that business to Security Headers Policy, that any customer contact you upload consented to receive a review invitation, and that you will keep records sufficient to demonstrate that consent for at least 24 months.

  4. 24.4

    Disclosure, data, privacy & cookies

    Personal data processed under this clause is handled in accordance with the ScoreReview UK Privacy Policy and, where you are a business customer, the Data Processing Agreement. Lawful basis is legitimate interest for platform integrity, contract for paid services, and consent for optional analytics or non-essential cookies set on scorereview.io.

    We publish a disclosure log covering enforcement actions, moderation decisions and material policy changes relevant to header change management. Cookies used to support this clause are strictly necessary; any analytics or preference cookies require prior opt-in via the cookie banner and can be withdrawn at any time from the footer.

25

Bug bounty and responsible disclosure

  1. 25.1

    Policy & legal framework

    This clause addresses bug bounty and responsible disclosure within the Security Headers Policy that governs your relationship with ScoreReview UK, operated by UK REAL REVIEWS LTD (company number 14587101). It is drafted to satisfy the Consumer Rights Act 2015, the Digital Markets, Competition and Consumers Act 2024, the UK GDPR and the Data Protection Act 2018 as they apply to a UK-registered review platform published at scorereview.io.

    Where an obligation in this clause conflicts with mandatory statute or with a signed Order Form, the more protective provision prevails. Nothing in Security Headers Policy limits statutory rights that cannot be excluded by contract.

  2. 25.2

    Your rights

    You retain the right to receive plain-English information about bug bounty and responsible disclosure, to challenge any decision we take under this clause, and to escalate an unresolved complaint to the relevant supervisory authority — the Information Commissioner's Office for data matters and the Competition and Markets Authority for consumer-law matters. Escalation does not require you to waive any right of action.

    Reviewers keep ownership of the content they submit; businesses keep ownership of the transactional data they upload. ScoreReview UK holds only the licence necessary to operate scorereview.io and to publish verified reviews to the audience the reviewer intended.

  3. 25.3

    Your obligations

    In relation to bug bounty and responsible disclosure you must provide accurate information, act in good faith, and refrain from any conduct that would mislead consumers, distort the trust ledger, or breach the acceptable-use rules published at scorereview.io/acceptable-use. Repeated or wilful breach is grounds for suspension without refund.

    Where you act on behalf of a business you warrant that you have authority to bind that business to Security Headers Policy, that any customer contact you upload consented to receive a review invitation, and that you will keep records sufficient to demonstrate that consent for at least 24 months.

  4. 25.4

    Disclosure, data, privacy & cookies

    Personal data processed under this clause is handled in accordance with the ScoreReview UK Privacy Policy and, where you are a business customer, the Data Processing Agreement. Lawful basis is legitimate interest for platform integrity, contract for paid services, and consent for optional analytics or non-essential cookies set on scorereview.io.

    We publish a disclosure log covering enforcement actions, moderation decisions and material policy changes relevant to bug bounty and responsible disclosure. Cookies used to support this clause are strictly necessary; any analytics or preference cookies require prior opt-in via the cookie banner and can be withdrawn at any time from the footer.

Contact

Questions about this document? Email legal@scorereview.io. For a signed counterpart or a redlined version, contact your account manager.

This document is provided by UK REAL REVIEWS LTD (trading as ScoreReview UK), a company registered in England and Wales under company number 14587101. Registered office: Windlehall, Crank Road, St Helens, Merseyside, WA11 7RG. It is not legal advice; take independent legal advice on how it applies to your organisation.