How verification works

A review platform is worth exactly the trust people place in it. A TrueAvis review marked verified means something specific and checkable: a real payment happened, and this review is the one thing that payment bought.

  1. A customer pays. Your shop knows the order reference and the email address.
  2. TrueAvis mints one token for that payment. Here the path forks, and the fork is the point.
  3. sent once

    The readable token, in the link that reaches the customer. TrueAvis never stores it.

    stored

    Its SHA-256 hash, and nothing else. A stolen database holds no usable links.

  4. The review arrives carrying the token. It counts as verified only if the hash matches, the token has never been spent, and it has not expired.
  5. The token is burned. One payment bought one review, and that review can never be made twice from the same link.
The customer’s copy and the stored record are never the same value — which is what makes a leaked database useless for forging reviews.

One key, one payment, one review

Every invitation is a single-use key tied to one payment. That is enforced in four places, none of which a merchant can switch off:

RuleWhat it prevents
Only the token’s hash is storedA leaked or seized database cannot be replayed into forged reviews.
A spent token is burned (usedAt)One payment cannot become five reviews by reusing the link.
One invitation per customer, order and productA retried webhook or a double-clicked job cannot mint a second link.
Tokens expireA link found in an old inbox years later cannot be redeemed.

The badge is derived, never set

Nothing the reviewer submits can make a review verified. The flag comes only from a valid, unspent, unexpired token — a review posted without one is accepted and shown, but it is plainly not verified. There is no API field, no admin toggle and no plan that changes this.

Uninvited reviews are allowed, and labelled

Anyone can leave a review through the widget without an invitation. That is deliberate: a platform that accepts only invited reviews lets a merchant decide who is allowed to complain. Those reviews appear without the verified mark, so a reader can weigh them accordingly.

A merchant can moderate — a review waits as pending until it is published or rejected. A merchant cannot mark an uninvited review as verified, and cannot edit what a reviewer wrote.

Limits

Invitations are metered per month. The ceiling controls cost, and it is also a brake on bulk-minting links:

PlanProjectsInvitations a month
Starter1500
Growth55,000
ScaleUnlimitedUnlimited
Trial, 14 days55,000

The quota is checked in the single place every invitation is minted, so the admin API and the Shopify webhook are held to the same limit. Past it, minting returns 429 and no link is issued.

Where reviews may be read and written

A project can name the origins its widget may load from. Requests from anywhere else are refused, so a public key lifted from your page cannot be used to post reviews from somebody else’s site.

Keys are scoped to one project: a key for one site can neither read nor write another’s reviews, and a product slug is only ever resolved inside the project that owns it.

What this does not claim

Verified means a real payment sits behind the review. It does not mean the reviewer is truthful, that the goods arrived, or that the opinion is fair. No review system can promise that, and one implying otherwise is selling something it cannot deliver. What TrueAvis guarantees is narrower and checkable: this review exists because that payment did.