1. What this covers
Reveno stores small amounts of data in your browser. Some of it is in cookies; most is in local storage, a similar browser feature. This policy covers both, because the law treats them the same way — what matters is that something is stored on your device, not the technique used.
We use browser storage to keep you signed in, remember your loyalty progress, remember your preferences, and — only if you agree — to understand how the product is used.
We do not use advertising cookies, tracking pixels, fingerprinting or any cross-site tracking. Nothing here is shared with advertisers. We do not run ads.
2. Strictly necessary — always active
These are required for Reveno to work. They are not used for tracking and cannot be turned off while you use the service. Clearing them will sign you out and, if you are a guest, lose your progress.
Cookies
| Name | Purpose | Lifetime |
|---|---|---|
sb-…-auth-token | Keeps you signed in. Set and managed by our authentication provider, Supabase. May be split across several cookies | Until you sign out or the session expires |
auth_redirect | Remembers which page to return you to after signing in with Google | 10 minutes |
auth_role | Remembers whether you started signing in as a business or a customer, so we land you in the right place | 10 minutes |
auth_action | Distinguishes signing in from signing up | 10 minutes |
anon_transfer_id | A single-use token that merges your guest progress into your account when you sign in. Without it, signing in would lose your loyalty card | 10 minutes |
reveno_active_business | If you work at more than one business, remembers which you last opened. A pointer, not a credential — it cannot grant access to anything | Persistent, cleared on sign-out |
All of these are first-party cookies set by Reveno or by our authentication provider. None are read by any third party.
Local storage
| Key | Purpose |
|---|---|
cookie_consent | Records whether you accepted or declined analytics. This is the record of your own choice — deleting it makes the banner ask again |
reveno_nickname | The nickname you chose, so the scan screen does not ask every time |
reveno_had_account | A yes/no flag noting that a signed-in customer has used this browser. It holds no identity — no name, no email, no identifier. Its only job is to offer you the chance to recover your progress instead of silently starting a new card |
reveno-theme-v2 | Light or dark theme |
reveno_notification_sound | Whether the new-scan chime is on for this device (business dashboard only) |
reveno_seen_… | When this device last opened each dashboard tab, so notification badges can show what is new (business dashboard only) |
reveno-business | The business and role currently open in the dashboard, so a refresh does not lose your place (business dashboard only) |
auth_redirect | A fallback for the sign-in redirect cookie above |
Our authentication provider may also store a small amount of session data under keys beginning sb-.
3. Analytics — only with your consent
We use PostHog to understand which features are used and where people get stuck.
It is switched off until you accept.
The analytics library starts in an opted-out state and captures nothing — no events, no identifiers — unless and until you press Accept on the banner. If you press Decline, or ignore the banner entirely, nothing is captured.
Analytics also runs only on the live site. It does not run in development or preview environments at all.
| Provider | Sets | Purpose | Requires consent |
|---|---|---|---|
| PostHog | Keys beginning ph_ in local storage and cookies | Product usage analytics | Yes |
To change your mind at any time, use the Reset Cookie Preferences button at the bottom of this page. It clears your recorded choice, stops analytics immediately, and asks again.
4. Error monitoring
We use Sentry to be told when something breaks. It reports errors, stack traces and the context of the failing request so we can fix faults.
Being straightforward about this: error monitoring is currently active for everyone and is not covered by the consent banner. We treat it as necessary to keep the service working and secure rather than as analytics — it exists to detect faults, not to observe you, and it is not used to build any profile of you or to target anything at you.
Sentry does not record your screen. We have not enabled session replay.
5. Third parties contacted when a page loads
| Provider | Why it is contacted | What it receives |
|---|---|---|
| Supabase | Database, sign-in and live updates | Your session, and the data you are viewing |
| Google Fonts | Page typography is loaded from Google's servers | Your IP address, on every page load |
| Razorpay | Only on the billing page, when you open checkout | Payment details you enter, directly |
| PostHog | Only after you accept analytics | Product usage events |
| Sentry | Only when an error occurs | The error report |
About Google Fonts: because fonts are fetched from Google's servers, your IP address is disclosed to Google whenever a Reveno page loads — even if you never sign in and never accept analytics. We consider this avoidable and intend to serve fonts ourselves.
6. Managing browser storage
Through Reveno
| Action | Effect |
|---|---|
| Reset Cookie Preferences (below) | Clears your analytics choice and asks again |
| Signing out | Clears your session, the sign-in cookies and the active-business pointer |
| Deleting your account | Removes your server-side data — see the Privacy Policy |
Through your browser
Every major browser lets you view and delete cookies and site data, and block them for specific sites. The settings are usually under Privacy or Site Settings.
| If you block | Result |
|---|---|
| Analytics only | Everything works normally. This is a supported choice |
| All cookies for Reveno | You cannot stay signed in. Sign-in will fail or loop |
| Local storage | Guest loyalty progress will be lost and cannot be recovered. Preferences reset each visit |
A specific warning for guests
If you collect rewards without signing in, your loyalty card is tied to this browser's storage. Clearing site data, using private browsing, or switching device will lose it permanently — there is no email address for us to find you by. Signing in with Google is what makes it recoverable.
7. Changes
We will update this page whenever the storage we use changes, and revise the date at the top.
Questions: revenoapp.support@gmail.com.