We do not sell personal data or share it for cross-context behavioral advertising. We use essential service providers under contract.
Privacy Policy
What Revioli collects, why we use it, how model improvement works, and the boundaries that keep raw customer records private.
Connected records are used within your workspace to provide Revioli. They are not exposed to another customer or used to train public third-party models.
Revioli may learn from de-identified, aggregated patterns that cannot reasonably identify a customer or person. Identifiable shared-model use needs separate permission.
1. Scope and our roles
This Privacy Policy explains how Revioli Labs, Inc. (“Revioli,” “we,” “us,” or “our”) handles personal data through revioli.com, app.revioli.com, the private beta, connectors, APIs, support, recruitment, and related services (the “Service”).
For website visits, account administration, security, sales, and direct communications, Revioli generally decides why and how personal data is processed and acts as a controller or business.
When a business customer connects Stripe, submits files, sends SDK events, or otherwise provides data about its own customers or personnel, that customer generally decides why the data is processed. Revioli then acts as its processor or service provider, subject to the customer's instructions, our Terms, and any data processing addendum. The customer's own privacy notice governs its relationship with those individuals.
2. Personal data we collect
| Category | Examples | Why we need it |
|---|---|---|
| Account and contact data | Name, work email, company, role, invitation and authentication metadata, workspace membership. | Create and secure accounts, provide support, administer the beta, and communicate about the Service. |
| Business and billing data | Company profile, plan, order, invoice, payment status, and business contact details. Payment-card details are handled by payment providers, not stored by Revioli. | Manage the commercial relationship, billing, capacity, and compliance. |
| Connected-source data | Authorized Stripe customer, subscription, invoice, and charge identifiers; amounts, statuses, product or usage events, support metadata, timestamps, and approved CSV fields. | Build the customer's evidence layer, calculate approved features, detect changes, and produce service outputs. |
| Technical and usage data | IP address, device and browser information, session data, request identifiers, pages and features used, timestamps, error and security logs. | Operate, secure, debug, measure, and prevent abuse of the Service. |
| Communications and submissions | Support messages, sales requests, feedback, application forms, CVs, work samples, and interview notes. | Respond to requests, evaluate applicants, and improve customer support. |
| Derived and model data | Mapped entities, approved features, evidence lineage, health or risk signals, uncertainty, rankings, explanations, audit receipts, evaluations, and model-performance statistics. | Provide decision support, explain outputs, evaluate reliability, and improve the Service within Section 5. |
We do not ask customers to provide full payment-card numbers, account passwords, authentication secrets, government identifiers, precise location, health data, or other highly sensitive personal data. If such data is submitted accidentally, we may remove or quarantine it.
3. Where data comes from
- Directly from you, when you create an account, request access, contact us, submit a form, apply for a role, or provide feedback.
- From your organization, when an administrator invites you, configures a workspace, or gives us business contact information.
- From sources a customer authorizes, such as a restricted Stripe connection, approved CSV export, product SDK, or another agreed integration.
- Automatically from the Service, through essential cookies, security logs, audit events, and usage telemetry.
- From service providers, such as authentication, hosting, email, payment, and error-monitoring providers.
4. How and why we use personal data
We use personal data for the following specific purposes:
- provide, personalize, maintain, and support the Service;
- authenticate users, enforce tenant boundaries, prevent fraud or abuse, and investigate security incidents;
- read approved sources, organize evidence, generate Customer-specific outputs, and preserve auditability;
- communicate about access, service changes, security, support, and requested sales conversations;
- manage contracts, invoices, capacity, legal obligations, and disputes;
- evaluate applicants and manage recruiting; and
- develop, test, evaluate, and improve Revioli under the model-training limits below.
Legal grounds
Depending on location and context, we rely on performance of a contract, steps requested before entering a contract, legitimate interests in operating and securing a business service, consent, compliance with law, or another ground permitted by applicable law. Where we rely on legitimate interests, we consider necessity, reasonable expectations, safeguards, and the impact on individuals.
Where we act as a processor, the customer determines the applicable legal ground and instructs Revioli through the agreement and product configuration.
5. Model training and service improvement
Revioli separates Customer-specific learning from general service improvement.
Customer-specific models
Within a customer's workspace, Revioli may use that customer's authorized data and outcomes to configure, train, calibrate, test, evaluate, and operate Customer-specific models and features. Those raw records and tenant-specific artifacts remain access-controlled and are not made available to another customer.
De-identified, aggregated improvement
We may transform service data into De-identified Data that cannot reasonably identify a customer or person, and Aggregated Data that combines patterns across multiple records or customers. We may use this material to benchmark, secure, test, develop, train, evaluate, and improve Revioli's internal models and products.
For cross-customer model improvement, we do not include direct identifiers, credentials, payment-card data, raw message bodies, or raw customer records in training sets. We use technical and organizational measures designed to prevent re-identification, and we do not attempt to re-identify this material.
We do not sell raw customer records, expose one customer's identifiable data to another, use personal data for cross-context behavioral advertising, or permit a third-party general-purpose model provider to train its public or shared models on identifiable Customer Data without separate written authorization.
Future material changes
If we want to use identifiable Customer Data for a materially different shared-model purpose, we will not hide that change in an updated policy. We will provide clear notice and obtain the permission required by the customer agreement and applicable law before that use begins.
Automated decisions
Revioli provides advisory business intelligence. It is not designed to make solely automated decisions that produce legal or similarly significant effects on individuals. Customers must apply human review before consequential action.
8. Retention and deletion
We retain personal data only as long as reasonably necessary for the stated purposes. The period depends on the data's sensitivity, the active customer relationship, contractual deletion instructions, security and audit needs, backup cycles, dispute periods, and legal obligations.
- Account and business records are generally kept while the account or commercial relationship is active and for a reasonable period afterward.
- Customer Data is kept according to the customer's configuration, Order Form, and data processing addendum, then deleted or returned after termination or verified request, subject to limited legal, security, and backup retention.
- Security and audit records are kept for the period needed to investigate incidents, preserve integrity, enforce agreements, and comply with law.
- Applicant data is kept for the hiring process and a legally permitted period afterward, or longer with permission for future roles.
- De-identified and Aggregated Data may be retained while it remains non-identifying and useful for the purposes in Section 5.
Deletion from active systems may not immediately remove data from encrypted backups; backup copies remain protected and expire through the ordinary backup cycle.
9. Security
We use safeguards designed for the nature of the data and the private-beta stage of the Service, including encryption in transit and at rest where supported, access controls, tenant scoping, restricted read-only integration credentials, audit logging, data minimization, and incident-response procedures.
No method of storage or transmission is perfectly secure. You are responsible for choosing authorized data, limiting connector permissions, protecting endpoints, and promptly reporting suspected compromise to founders@revioli.com.
Our current security posture and known certification limits are described on the Security page.
10. International data transfers
Revioli and its service providers may process data in countries other than where it was collected. Where required, we use contractual or other recognized safeguards for international transfers and provide further information through an Order Form or data processing addendum.
11. Your rights and choices
Depending on applicable law, you may have rights to access, correct, delete, restrict, object to, or receive a copy of personal data; withdraw consent; opt out of certain uses; appeal a refusal; or complain to a regulator. You will not be discriminated against for exercising a privacy right.
To make a request, email founders@revioli.com with the subject “Privacy request.” We may verify identity and authority before acting. If your data was provided to Revioli by one of our customers, contact that customer first; we will assist it as required.
You may unsubscribe from optional marketing messages using the link in the message or by contacting us. Essential account, security, and transaction communications cannot be disabled while the account remains active.
12. Regional privacy notices
India
Where India's Digital Personal Data Protection Act and Rules apply, we process digital personal data on consent or another ground permitted by law, provide clear notice of the data and specified purposes, maintain reasonable security safeguards, and support applicable rights and grievance requests through the contact below.
European Economic Area and United Kingdom
Where European or UK data-protection law applies, the legal grounds in Section 4 apply. Individuals may also lodge a complaint with their local supervisory authority. Revioli does not use the Service to make solely automated decisions with legal or similarly significant effects.
California and other United States states
The categories described in Section 2 are the categories we may have collected and disclosed for business purposes during the preceding 12 months. We do not sell personal information or share it for cross-context behavioral advertising, and we do not use or disclose sensitive personal information for purposes requiring a right to limit under California law. Where applicable, residents may request access, correction, deletion, or a copy through the process in Section 11.
13. Children
The Service is for businesses and is not directed to children. We do not knowingly collect personal data directly from anyone under 18. Contact us if you believe a child has provided personal data directly to Revioli.
14. Changes to this Policy
We may update this Policy as the Service or law changes. We will post the updated date and provide additional notice before a material change takes effect. We will not retroactively expand use of identifiable personal data for model training without the notice and permission required by law and contract.
15. Contact and grievances
For privacy questions, rights requests, complaints, or data-protection addenda, contact:
Revioli Labs, Inc.
Privacy and grievance contact
founders@revioli.com