How verification works
A review platform is worth exactly the trust people place in it. A TrueAvis review marked verified means something specific and checkable: a real payment happened, and this review is the one thing that payment bought.
- A customer pays. Your shop knows the order reference and the email address.
- TrueAvis mints one token for that payment. Here the path forks, and the fork is the point.
sent once
The readable token, in the link that reaches the customer. TrueAvis never stores it.
stored
Its SHA-256 hash, and nothing else. A stolen database holds no usable links.
- The review arrives carrying the token. It counts as verified only if the hash matches, the token has never been spent, and it has not expired.
- The token is burned. One payment bought one review, and that review can never be made twice from the same link.
One key, one payment, one review
Every invitation is a single-use key tied to one payment. That is enforced in four places, none of which a merchant can switch off:
| Rule | What it prevents |
|---|---|
| Only the token’s hash is stored | A leaked or seized database cannot be replayed into forged reviews. |
A spent token is burned (usedAt) | One payment cannot become five reviews by reusing the link. |
| One invitation per customer, order and product | A retried webhook or a double-clicked job cannot mint a second link. |
| Tokens expire | A link found in an old inbox years later cannot be redeemed. |
The badge is derived, never set
Uninvited reviews are allowed, and labelled
Anyone can leave a review through the widget without an invitation. That is deliberate: a platform that accepts only invited reviews lets a merchant decide who is allowed to complain. Those reviews appear without the verified mark, so a reader can weigh them accordingly.
A merchant can moderate — a review waits as pending until it is published or rejected. A merchant cannot mark an uninvited review as verified, and cannot edit what a reviewer wrote.
Limits
Invitations are metered per month. The ceiling controls cost, and it is also a brake on bulk-minting links:
| Plan | Projects | Invitations a month |
|---|---|---|
| Starter | 1 | 500 |
| Growth | 5 | 5,000 |
| Scale | Unlimited | Unlimited |
| Trial, 14 days | 5 | 5,000 |
The quota is checked in the single place every invitation is minted, so the admin API and the Shopify webhook are held to the same limit. Past it, minting returns 429 and no link is issued.
Where reviews may be read and written
A project can name the origins its widget may load from. Requests from anywhere else are refused, so a public key lifted from your page cannot be used to post reviews from somebody else’s site.
Keys are scoped to one project: a key for one site can neither read nor write another’s reviews, and a product slug is only ever resolved inside the project that owns it.
What this does not claim
Verified means a real payment sits behind the review. It does not mean the reviewer is truthful, that the goods arrived, or that the opinion is fair. No review system can promise that, and one implying otherwise is selling something it cannot deliver. What TrueAvis guarantees is narrower and checkable: this review exists because that payment did.