RevloBack to home

Privacy Policy

Last updated: 14 May 2025

At Revlo, we take your privacy seriously. This policy explains what personal data we collect, how we use it, and what rights you have in relation to it. By using the Revlo platform, you agree to the practices described here.

Information We Collect

Account information

When you create an account we collect your name, email address, organisation name, and password (stored as a secure hash).

Documents and files

We store the documents and files you upload or that are submitted to you through our platform. These files are encrypted at rest and in transit. We do not access these files unless required for technical support requested by the account owner or to comply with legal obligations.

Usage data

We collect metadata about platform interactions — including IP addresses, browser types, and time stamps — to maintain security audit logs and improve the Service.

Payment information

Payments are processed by Stripe. We do not store your full card details. We retain only the last four digits and expiry date for billing management.

How We Use Your Information

Providing the service

We use your information to operate Revlo, including processing document requests and managing subscriptions.

Communications

We send transactional emails (e.g., 'Document Received' alerts). You may opt-out of non-essential product updates at any time.

Sharing of Information

Sub-processors

We share data with trusted infrastructure providers: AWS (Cloud Hosting/Storage), Stripe (Payments), and Resend (Email Delivery). Data is primarily stored on servers located within the United Kingdom or the EEA.

No sale of data

We never sell, rent, or trade your personal information or the content of your documents to third parties for marketing or advertising.

Data Security

All data is encrypted in transit using TLS 1.2+. Uploaded documents are encrypted at rest within our secure document storage. Other account and platform data is stored on infrastructure that provides disk-level encryption at rest through our hosting providers. We restrict production access to a limited number of authorised personnel and maintain strict audit logs.

Data Retention

Account Data

We retain account information while your account is active. Upon closure, we delete or anonymise this data within 90 days.

Collected Documents

Revlo acts as a Data Processor for the documents you collect. These documents are retained according to the settings and instructions of the Account Owner (the Data Controller). If you have submitted a document to a Revlo user, you must contact them directly to request its deletion.

Your Rights

Under the UK GDPR and similar laws, you have rights including Access, Rectification, Erasure, and Portability of your data.

To exercise these rights, contact support@revlo.tech. We respond to all verified requests within 30 days.

Cookies

We use only essential session cookies to keep you logged in. We do not use third-party tracking or advertising cookies.

Contact Us

If you have questions about this policy, please contact our privacy team at support@revlo.tech.