What one star that nobody meant to leave taught us about the difference between a tap and a decision.
Every so often a message arrives that you read twice. This one came in on a Sunday morning, from an owner running two restaurants. Guests had left low ratings after their visits — and at least one of them had no idea she had done it.
The restaurant had written to her first, kindly, asking what had gone wrong so they could put it right. Her reply came back within minutes. She hadn’t meant to leave a bad review at all. She had enjoyed the meal. She wasn’t sure how it had happened, and she asked whether she could change it.
For a small independent restaurant, a low rating isn’t a data point. It’s a bad morning. The owner described the first one as soul-destroying, and then spent the rest of the day waiting to hear back about the second. That sting is bad enough when the rating is deserved. When it turns out to be an accident, it’s worse — because it never needed to happen.
We went looking, expecting to find something odd about those two bookings. What we found was our own design.
A tap was a verdict
After a visit, NomNom can send a short follow-up email asking how it went. Inside it are five stars. The idea was to make rating effortless: tap a star in your inbox, land on the rating page with that star already chosen, done.
It was effortless. That was the problem. Those five stars were links, and opening one didn’t just carry your choice to the page — it recorded it, immediately, before the guest had seen anything at all.
How it used to work. The five stars were live links. Opening one didn’t carry your choice to the rating page — it was the rating.
Now picture that on a phone. Five stars, forty pixels each, sitting shoulder to shoulder in an email you’re half-reading. One star is at the far left, exactly where a thumb lands when you’re scrolling. A tap you didn’t mean to make became a verdict you never gave — and the first the guest knew of it was the restaurant writing to ask what had gone wrong.
The rating page had the same flaw. Your first tap on a star was the submission. There was no confirm, no undo, nothing that distinguished “I’m choosing” from “I’ve chosen”.
Why we built it that way
Honestly? To catch more ratings. If you record on the first tap, you capture the guest who taps and then wanders off. Wait for a second action and some of those never finish.
That reasoning isn’t wrong, exactly. It’s just answering the wrong question. We were optimising for how many ratings we collected, when the thing that actually matters is whether each one means what it appears to mean. A rating nobody intended isn’t a rating we captured. It’s a restaurant being told something untrue about itself, and a guest being quoted saying something she never said.
What we changed
Rating is now two steps. Tapping a star selects it — it paints the stars, shows you what you’ve chosen, and offers a button. Nothing reaches us until you press that button.
How it works now. A tap chooses; a press submits. In between the guest can change their mind as often as they like — and afterwards they can still tap a different star to correct it.
The stars stay in the email, because they’re genuinely the thing that gets people to respond. They just do less now: tapping one carries your choice to the page and waits there for you.
Everything a guest can do by accident now saves nothing. The only thing that records a rating is the one action that says it will.
Changing your mind is a first-class action rather than a support request. Before submitting, tap any other star. After submitting, tap a different one and the button comes back reading Update my rating. If a guest realises within half an hour that they’ve mis-tapped, the restaurant is never told about the first one at all.
The wording changed too, in both the email and on the page: nothing is sent until you confirm. A promise like that is part of the fix, not decoration around it. If the words and the behaviour ever drift apart, guests are surprised all over again — so both sentences are now covered by tests that fail if the behaviour changes underneath them.
The one we hadn’t thought of
While rewriting this, we noticed something we’d never considered. Plenty of organisations run every incoming email through a security service that visits the links before a human ever clicks them.
Under the old design, a checker thorough enough to load the page fully could have left a rating on a guest’s behalf, with nobody involved at all. We have no proof that happened. But we couldn’t prove it hadn’t either, which is its own kind of answer — and the same change closes it, because now there is nothing on that page a machine can trip.
Where these ratings actually go
Worth saying plainly, because it was the first thing the owner asked. Ratings left through a NomNom follow-up email are private. They go to the restaurant and nowhere else — not to Google, not to Tripadvisor, not to any public listing. If a guest wants to post publicly, we offer them the links, but that is their choice and a separate step.
So a mis-tap like this one was never sitting somewhere out in the world. It just landed in an inbox on a Sunday morning and ruined someone’s day.
What we took from it
The lesson isn’t “add a confirmation step”. Confirmation dialogs are mostly a tax on people who knew what they were doing. The lesson is narrower and more useful: be careful when the easiest possible action is also an irreversible one. A single tap, on a small target, in a medium as casual as email, is not a considered judgement about somebody’s livelihood — and it shouldn’t have been recorded as one.
Our thanks to the owner who raised it rather than shrugging it off, and to the guest who took the trouble to write back and say it wasn’t what she meant. Between them they found something we’d been shipping to every restaurant on the platform.