Privacy Policy
Last updated: March 4, 2026
ReviPass (hereinafter "we") is committed to protecting the privacy of its users. This privacy policy explains how we collect, use and protect your personal data when you use our digital loyalty card service.
1. Data We Collect
We collect the following data: • Merchants: name, email, password, business name, logo, payment information (processed by Stripe). • End customers: name, email (or data provided via Google Sign-In), points/stamps balance, transaction history. • Technical data: IP address, browser type, pages visited, analytics data via Microsoft Clarity.
2. How We Use Your Data
Your data is used to: • Provide and manage the loyalty card service. • Generate Apple Wallet and Google Wallet passes. • Send transactional emails (verification codes, reward notifications). • Process payments via Stripe. • Improve our service through anonymized analytics.
3. Data Sharing
We never sell your personal data. We share your data only with: • Stripe — for payment processing. • Resend — for transactional emails. • Supabase — for database hosting. • Apple and Google — for Wallet pass generation. • Microsoft Clarity — for anonymized behavioral analytics.
4. Cookies
We use essential cookies for service operation (authentication, language preferences). We also use Microsoft Clarity for analytics, which may set analytical cookies. You can disable cookies in your browser settings.
5. Data Retention
Merchant data is retained for the duration of the subscription and deleted 90 days after cancellation. End customer data is retained as long as their loyalty card is active. OTP codes are automatically deleted after verification or expiration (5 minutes).
6. Your Rights
Under the GDPR, you have the following rights: • Access to your personal data. • Correction of your data. • Deletion of your data. • Data portability. • Objection to data processing. To exercise these rights, contact us at [email protected].
7. Security
We implement appropriate technical and organizational measures to protect your data: encryption in transit (TLS), strict access policies (Row Level Security), secure hosting on European servers.
8. Changes
We may modify this privacy policy at any time. In case of material changes, we will notify you by email or via a notification in the service.
9. Contact
For any questions regarding this privacy policy, contact us at: [email protected]