Back to home

Privacy Policy

Draft — pending legal review before publication. This text is a drafting starting point, not legal advice, and bracketed items are placeholders.

Version 0.1-draft · Effective [Effective date — set at publication] · Last updated 6 October 2026

1. Who we are and what we do

Revaizo is operated by [Operator legal name], [Registered address] (“we”). Business owners place QR codes at their locations. Customers scan one, rate their visit, tick what they liked or didn't, and receive an editable review draft that they post on Google themselves. We never post anything on anyone's behalf.

For the purposes of the Digital Personal Data Protection Act, 2023 (DPDP Act), we are the data fiduciary for owner data and for the abuse-prevention data described below. For customer ratings and ticked items, the business owner decides why the feedback is collected and we process it on the owner's behalf to run the service. This policy also serves as our privacy policy under the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011.

2. Data we collect

Owners

  • Google sign-in details: email address, name and Google account ID. We request only the openid, email and profile permissions.
  • Business details you enter (name, locations, categories, checklist items) and logos you upload. We also store the Google rating and review count for each branch, entered by you or read from public Google data, to show your progress, and a device label for each signed-in device so you can see and end sessions.
  • Support messages you send from the dashboard (category, subject and message) and any replies in the same conversation, from you or from us. They are stored linked to your business and your account, used only to respond to you, and we email you an acknowledgement and, once resolved, the resolution.
  • Billing data via Razorpay once billing is enabled. Razorpay handles card and payment details; we do not store them. Our staff can access owner and support data only as needed to run and support the service.

Prospects

If you ask for pilot access on our website, we collect your name, business name, email, phone number (if you give one), any notes and an optional Google review link you paste. We use them only to respond to your request and set up your account, on your consent given by submitting the form. Our staff can see them. If you do not become an owner we delete them after [period to be confirmed, e.g. 12 months].

Customers

We do not collect your name, email, phone number or any account. When you use the flow we record:

  • your star rating and the checklist items you ticked;
  • device type (for example mobile or desktop) and timestamps;
  • a hashed form of your IP address and device identifier, used only for rate limiting and abuse prevention (this may still be personal data, so we treat it as such);
  • your requests for review drafts and the drafts generated, which draft you select, whether you edited it (we record that you edited it, not what you wrote), and whether you were sent on to Google.

The flow does not collect free text, so nothing you type is sent to us. Edits you make to a draft stay on your own device.

3. Purposes and legal basis

  • Customer data is processed on your consent. You give it by a clear action, such as pressing an “I agree, continue” button shown before the flow starts, after reading this notice; it is separate from accepting the terms. We use it to produce your review draft and to protect the service from abuse and fake use. You can withdraw consent at any time as easily as you gave it, by closing the flow or emailing us.
  • Owner data is processed on your consent and for the specific purposes for which you voluntarily provide it: sign-in, the dashboard, QR codes, analytics, support and billing.
  • Owners see the feedback entries for their business (time, rating, ticked items, which QR code and status) and aggregated statistics. We do not show owners your IP address, device identifier or anything else that identifies you.
  • We use automated checks (rate limits and an abuse score built from your hashed IP and device identifier and your request patterns) to throttle, flag or block fake or abusive use. No person reviews each decision. If you think you were blocked wrongly, contact the grievance officer and we will review it.
  • We process data where the law requires it, for example tax, court or government orders. We may disclose data to courts or government authorities when lawfully required, and we tell you where the law allows.

4. Processors and sub-processors

We share data only with service providers that process it on our behalf:

ProviderPurpose
VercelApplication hosting and Blob storage for business logos
SupabaseDatabase (owner, business, session and draft records)
UpstashRate-limit counters (hashed IP and device identifiers only)
Groq, NVIDIA, Google (Gemini)Generating review drafts. We send the ticked checklist items, the business name and category, and the draft language and tone. We never send your IP address, device identifier or anything that identifies you
RazorpayPayments and subscription billing, once billing is enabled
ResendSign-in, support and notification emails, if enabled. These are service messages only; we send marketing emails only with your separate consent

Data is processed in [regions to be confirmed, naming each country per provider, e.g. India / Singapore / United States]. Your data may therefore be transferred outside India. The DPDP Act permits such transfers except to countries the Government of India restricts. We will update this list when providers change and tell owners of material changes. We do not sell personal data. If we merge with or are acquired by another business, your data may pass to the successor, which must honour this policy; we will tell owners beforehand. Reviews you post on Google are governed by Google's own policies.

5. Retention and deletion

DataRetention
Owner account (email, name, Google account ID)While the account is active; deleted on request or account closure, subject to legal retention
Business details and logosWhile the account is active; deleted with the business
Billing recordsAt least 6 years, as required by Indian tax and GST law [confirm with your accountant]
Customer ratings, ticked chips, device type, timestamps, draft requests[Period to be confirmed, e.g. 12 months], then deleted or aggregated
Hashed IP / device identifiers (rate-limit counters only)[Short period to be confirmed, e.g. 24 hours to 30 days]
Support messages, replies from you and from us, and resolution notes[Period to be confirmed, e.g. 24 months after resolution]; deleted with the business
Pilot-access requests (leads)[Period to be confirmed, e.g. 12 months] if no account is created; otherwise handled as owner data
Operator action logKept for security and accountability; records the staff member and the records affected, not message content [confirm contents with counsel]
Security and server logs[Period to be confirmed: at least 1 year, with cyber-incident logs kept 180 days within India as required by law]. Kept apart from the rate-limit counters and not used for any other purpose

When an account or business is deleted, we delete or irreversibly anonymise its data, including linked customer sessions and drafts, except what we must keep by law. Backups are overwritten on their normal cycle. If a trial ends without a paid plan, or an account is unused for [12 months], we email a warning and then delete the account's data after [30 days]. If you ask us to erase your data we do so promptly; any export window offered when an owner closes an account does not delay an erasure request. Operator action logs are append-only and cannot be edited, so they are kept as set out above.

6. Your rights under the DPDP Act, 2023

As a data principal you have the right to:

  • access a summary of the personal data we process and who we share it with;
  • correct inaccurate or incomplete data, and complete or update it;
  • erase your personal data, unless we must retain it by law;
  • have your grievance redressed;
  • nominate another person to exercise these rights if you die or become incapacitated;
  • withdraw consent at any time (this does not affect processing already done).

Email hello@example.com with your request. Because customers are not identified, a customer request may need details such as the business, location and approximate time of visit so we can find the data. We will respond within 30 days.

You must give true information, must not impersonate anyone and must not file false or frivolous complaints. This policy is available in English; [Hindi and other Eighth Schedule languages on request].

Grievance officer

[Grievance officer name] · hello@example.com · [Registered address]. We acknowledge grievances promptly and resolve them within 30 days. If we do not resolve your grievance, you may complain to the Data Protection Board of India once it is operational and you have first used this process.

7. Security

We use reasonable safeguards, including hashed session tokens, httpOnly and secure cookies, rate limiting, same-origin request checks and encrypted connections. No system is perfectly secure; if a personal data breach affects you we will notify you and the Data Protection Board of India as the law requires, and we report cyber incidents to CERT-In within 6 hours.

8. Children

The service is for people aged 18 or over. Owners must be 18 or over, and customers confirm they are 18 or over before the flow starts. We do not knowingly process data of anyone under 18, and we do not track or monitor children or target them with advertising. If you believe a child has provided data to us, contact the grievance officer and we will delete it.

9. Cookies and browser storage

  • Owners: one functional session cookie to keep you signed in, plus short-lived functional cookies for sign-in and for remembering your last-used business.
  • Customers: the flow keeps your progress in session storage in your browser, which is cleared when you close the tab, and one strictly functional cookie (valid for one day) that links your answers to a single anonymous session so your draft can be produced. It holds a random session ID, not your identity.
  • We use no advertising or cross-site tracking cookies.

10. Changes to this policy

We may update this policy. The version and last-updated date above will change, and for material changes we will notify owners by email or in the dashboard at least 30 days before they take effect. If we add a new purpose for your data, we will ask for your consent again. For minor updates, continued use after that date means you accept them; if you do not, you can close your account.