1. Who we are
Reveno is a digital loyalty platform. Businesses use Reveno to run QR-based reward programs; customers scan a business's QR code to record a visit and collect rewards. Our service is at reveno.in.
This policy explains what personal data we handle, why, who else touches it, how long we keep it, and what you can ask us to do about it.
Our primary legal framework is India's Digital Personal Data Protection Act, 2023 and the Digital Personal Data Protection Rules, 2025. Reveno is offered to businesses in India and priced in Indian Rupees. If you are outside India, section 12 sets out the additional rights you may have.
Privacy contact and Grievance Officer: revenoapp.support@gmail.com.
2. The two roles we play
Reveno sits between two groups of people, and our responsibilities differ for each. This matters because it decides who you should approach with a request.
When a business is responsible
When a business runs its own loyalty program on Reveno, that business decides who the program is for, what a reward requires, whether a visit is approved or rejected, and what its own terms say. For that data — the visits recorded there, the rewards it issues, the approvals its staff make — the business is the Data Fiduciary and Reveno processes on its instructions.
If you are a customer and your question is about a specific shop's program ("why was my visit rejected", "why didn't I get my reward"), that shop is the right first point of contact. We will help you reach them.
When Reveno is responsible
We decide the purposes, and are directly answerable, for:
- Business, manager and staff accounts — sign-in, roles and access control.
- Subscriptions and billing — purchases, renewals, cancellations and the payment records that follow.
- Your Reveno customer account, including the cross-business wallet that shows your progress at every participating business in one place. No individual business decided that should exist; we did.
- Platform security — rate limiting, audit logs, fraud prevention.
- Analytics and error monitoring, where you have consented or the law otherwise permits it.
A business cannot see your activity at any other business.
Each business sees only the visits, rewards and nickname tied to its own program. The combined wallet view exists only for you, in your own account.
3. What we collect
We collect only what the service needs. We do not collect your address, date of birth, government ID, contacts, precise location, biometrics, or any sensitive personal data.
If you are a customer
| Data | Where it comes from | Why |
|---|---|---|
| Nickname (optional) | You type it | So staff can identify you at the counter |
| A random customer code | Generated by us | Lets staff find your card without knowing your name |
| Visit records — which business, when, approved or rejected, and any reason staff wrote | Created when you scan and when staff act on it | The loyalty program itself |
| Reward claims — which reward, status, timestamps | Created when you claim | To issue and track rewards |
| Account identifier | Created at sign-in | Ties the above to you |
| Email, name and profile picture only if you sign in with Google | Your Google account | To recognise you across devices and recover your progress |
You can use Reveno as a guest without giving us anything. The default path — scanning without signing in — creates an anonymous account with no email, no name and no phone number. Your progress lives on that device and in our database under a random identifier.
Please read this if you use Reveno as a guest
A guest account exists only in the browser you created it in. If you clear your browser data, switch device, or use private browsing, your progress cannot be recovered by us or by anyone — there is no email address to find you by. Guest accounts are also deleted on the schedule in section 7.
Signing in with Google is what makes your progress durable.
We do not collect passwords. Reveno has no password-based sign-in of any kind. You either sign in with Google or use the service as a guest.
If you are a business owner, manager or staff member
| Data | Where it comes from | Why |
|---|---|---|
| Email, name, profile picture | Your Google account at sign-in | To create and secure your account |
| Your display name on the staff list | You type it | So the owner knows who is who |
| Business profile — name, logo, brand colour, welcome message, your own terms of use | You provide it | Shown to your customers on the scan screen |
| Reward configuration — titles, descriptions, images, thresholds | You provide it | Your program |
| Role and membership — owner, manager or staff, and status | Set by the owner or manager | Access control |
| Subscription state — plan, cycle, status, renewal, trial and grace dates | Generated by billing | To run your subscription |
| Payment records — payment, subscription and customer identifiers, amount, currency, status | Razorpay, by webhook | Invoicing, refunds, chargebacks, tax |
| Audit records — role changes, staff approvals and removals, subscription changes, with the acting account | Generated automatically | Security and dispute resolution |
Payment notification records
Card and UPI details never reach Reveno's servers from your browser — Razorpay collects them directly. But when Razorpay tells us a payment succeeded, failed or was refunded, we store the notification it sends, so a dispute or chargeback months later can be settled from the original record.
That notification can include the payer's email address, phone number, UPI ID, and the last four digits, network and issuing bank of a card. It never contains a full card number, CVV or UPI PIN. These records are not readable from any browser session, including the account owner's — your invoice list is built from a few specific fields, and the underlying notification stays on our servers.
Technical data
| Data | Purpose | Retention |
|---|---|---|
| IP address | Rate limiting, to prevent abuse of scan, payment and deletion endpoints | Transient — only for the rate-limit window |
| Request metadata (URL, time, user agent, response status) | Delivering and securing the service | Per our hosting provider's defaults |
| Error diagnostics (stack traces, request context) | Diagnosing faults | Per our monitoring provider's retention |
| Product usage events — only after you consent | Understanding which features are used | Per our analytics provider's retention |
We do not use tracking pixels, advertising cookies, fingerprinting or cross-site tracking. We do not run ads and we do not sell data.
4. Why we process it
Under the DPDP Act our processing rests on your consent, or on certain legitimate uses the Act recognises.
| Purpose | Basis |
|---|---|
| Creating and running your account | Consent, given when you sign in or scan |
| Recording visits and issuing rewards | Consent — this is the service you asked for |
| Showing your progress across businesses | Consent |
| Running a business's subscription and billing | Necessary to perform our contract |
| Tax, accounting, refunds and chargebacks | Compliance with law |
| Security, fraud prevention, rate limiting, audit logs | Legitimate use — protecting the service and its users |
| Error monitoring | Legitimate use — keeping the service working |
| Product analytics | Consent only. Off unless you accept; withdrawable at any time |
You can withdraw consent at any time (section 8). Withdrawing consent to core processing means we can no longer provide the service, and your account will be closed.
5. Who else handles your data
We do not sell, rent or trade personal data. We share it only with the providers below, each bound to use it solely to provide their service to us.
| Provider | What it does | What it receives |
|---|---|---|
| Supabase | Database, authentication, file storage, live updates | All account, visit, reward, business and billing data |
| Vercel | Hosting and edge network | Request metadata including IP |
| Razorpay | Payment processing and subscription mandates | Business owner payment identity; card and UPI details collected directly by them |
| Upstash | Rate limiting | IP-derived keys only |
| Sentry | Error monitoring | Error reports, stack traces, request context |
| PostHog — only with your consent | Product analytics | Product usage events |
| Sign-in and web font delivery | Your Google identity if you sign in; your IP address whenever a page loads |
Razorpay is not simply our processor. As a regulated payment institution it determines its own purposes for the payment data it collects and has its own legal duties. Its handling of your payment details is governed by Razorpay's privacy policy.
About web fonts: our pages currently load fonts from Google's servers, so your IP address is disclosed to Google on each page load. We consider this avoidable and intend to serve fonts ourselves.
We will also disclose data where legally required, or where necessary to establish, exercise or defend a legal claim.
6. Where your data goes
Reveno is operated from India. Some providers above process data outside India, principally in the United States and the European Union. Under the DPDP Act, transfers outside India are permitted except to territories the Central Government restricts by notification, and no such restriction currently affects the providers we use. We will update this policy if that changes.
7. How long we keep it
| Data | Retained for |
|---|---|
| Guest accounts with saved progress | 6 months from your last visit. After that the account and all its visits and rewards are permanently deleted |
| Guest accounts with no visits at all | 14 days — these are abandoned sign-ins that never recorded anything |
| Signed-in customer accounts | Until you delete the account. Deletion is immediate and permanent |
| Business accounts and their data | Until the business is deleted by its owner |
| Payment records | Retained after a business is deleted, because refunds, chargebacks and tax assessments can arise afterwards |
| Trial-eligibility record | Retained after deletion, to enforce one free trial per person |
| Payment provider notifications | 90 days once processed |
| Staff invitation codes | Deleted one day after expiry |
Guest customers, in plain terms
If you collect rewards without signing in and then do not visit any business for six months, everything is deleted — your card, your visits, your progress. It cannot be restored. Signing in with Google removes this expiry.
Stated plainly: we do not currently apply an automated retention limit to the visit and reward history of signed-in customers, to payment records, or to audit logs. Those are kept while the account exists. We are working on defined limits and will update this section.
8. Your rights
Under the DPDP Act you have the right to:
- Access a summary of the personal data we hold about you and how it is processed.
- Correct, complete, update or erase your personal data.
- Withdraw consent as easily as you gave it.
- Grievance redressal — a response from us before you approach the Data Protection Board.
- Nominate another person to exercise your rights if you die or become incapacitated.
What you can do yourself, right now
| Action | Where |
|---|---|
| Delete your customer account and all your data | Profile settings in the rewards wallet. Permanently deletes your visits, reward claims, customer record and sign-in identity. It cannot be undone |
| Change your nickname | Profile settings |
| Delete a business and its data | Business settings — cancels the subscription and removes the tenant |
| Withdraw analytics consent | "Reset Cookie Preferences" on the Cookie Policy page |
| Leave a business you work at | Staff list in the business dashboard |
What to email us for
Access requests, corrections we do not expose in the interface, nomination, and grievances: revenoapp.support@gmail.com. We aim to acknowledge promptly and respond as quickly as we reasonably can.
Honest note on data portability: we do not currently offer a self-service export. If you ask us for a copy of your data we will assemble it manually and send it to you. A proper export is on our roadmap.
We will not treat you differently for exercising any of these rights.
Grievances
If you are unhappy with how we handled your request, contact our Grievance Officer at revenoapp.support@gmail.com. If you remain unsatisfied, you may complain to the Data Protection Board of India.
9. How we protect your data
Reveno's access controls are enforced in the database itself rather than only in the application, so a fault in the interface cannot expose another business's data.
- Every table enforces row-level access rules; privileged writes go through audited, restricted database functions.
- Billing fields cannot be written from a browser session at all.
- Payment notification bodies are not readable by any client, including the account owner's.
- Payment webhooks are verified with timing-safe signature checks and protected against replay.
- Sign-in uses Google OAuth with PKCE. We never see or store a password.
- Rate limiting at the network edge on scan, payment and deletion endpoints.
- Strict security headers, including HSTS, a Content Security Policy, and clickjacking and MIME-sniffing protection.
- Access-control rules are covered by an automated test suite that runs against a real database.
What we do not claim: we hold no ISO 27001 or SOC 2 certification, and we have not appointed a Data Protection Officer. Encryption at rest and in transit is provided by our infrastructure providers under their own certifications.
No system is perfectly secure. If a breach occurs that is likely to affect you, we will notify you without delay and report to the Data Protection Board of India within 72 hours, as required.
10. Children
Reveno is not for anyone under 18.
The DPDP Act treats everyone under 18 as a child and requires verifiable consent from a parent or guardian, and prohibits tracking or behavioural advertising directed at children. We do neither — we run no advertising and no behavioural profiling.
We do not knowingly collect personal data from anyone under 18. If you believe a child has used Reveno, contact revenoapp.support@gmail.com and we will delete the account and its data.
11. Automated decision-making
We do not make decisions about you by purely automated means that produce legal or similarly significant effects. Reward progress is calculated automatically from your visits, but a person at the business approves or rejects every visit and every reward claim.
12. If you are outside India
Reveno is offered to businesses in India and priced in Indian Rupees. We do not currently market the service in the European Economic Area, the United Kingdom, the United States or elsewhere, and we do not believe those regimes' extraterritorial tests are met on the facts today.
We say this rather than claiming compliance we have not built. If we begin offering Reveno in those markets, we will implement the required measures and update this policy before doing so.
Wherever you are, we will honour requests to access, correct or delete your data and to withdraw consent — write to revenoapp.support@gmail.com.
If you are in the EEA or UK and believe the GDPR or UK GDPR applies to you, tell us and we will engage with your request on that basis. You keep the right to complain to your national supervisory authority.
If you are in the United States: we do not sell or share personal information as those terms are defined in state privacy laws, we do not use it for targeted advertising, and we do not profile.
13. Changes
If we change this policy materially we will update the date at the top and, where the change affects data you have already given us, tell you in the app before it takes effect.
14. Contact
Privacy questions, data requests and grievances: revenoapp.support@gmail.com.
Storage keys and cookies are listed separately in our Cookie Policy. Terms governing use of the platform are in our Terms of Service. Reference: reveno.in