RevRaptor

Privacy Policy

Draft — not yet in force. This document is a working draft prepared for review. It has not been reviewed by a lawyer and the highlighted values are still to be confirmed. Do not rely on it as the agreement between you and RevRaptor until this notice is removed.

Last updated Tuesday September 1st

This explains what RevRaptor collects, why, who else touches it, how long we keep it, and how to get it back or get rid of it.

1. Who is responsible

RevRaptor (legal entity name to be confirmed), of business address to be confirmed, is responsible for the personal information described here. This policy covers the RevRaptor application. Questions go to legal contact address to be confirmed or to a support ticket.

2. What we collect

Your account

  • Email address, an optional name, and a password (stored only as a one-way hash -- we cannot read it).
  • Sign-in timestamps, and the invite or referral code you signed up with.

Your shop profile

This is what you fill in during onboarding and can edit afterwards: business name, industry, the services you offer, your city, region and country, the coordinates we geocode from that, how far you travel, your opening hours, how many jobs a week you can take, your slow days, your website and social handles, a description of your typical customer, and how playful or premium you want the copy to sound.

What you do in the app

  • The Hunts generated for you, and whether you ran, skipped or reopened each one.
  • Revenue figures you choose to log against a Hunt, for your own Trophy Wall.
  • Your credit ledger -- every grant and every spend, with the reason.
  • Your notification, timezone, unit and date-format preferences.
  • Support tickets you open, everything written in them, and any screenshot you attach.

Payment

Card details go straight to Stripe and never touch our servers. We keep what Stripe hands back: the amount, the pack you bought, a payment reference, and whether it succeeded.

Technical

  • Server logs, which include your IP address, for security and debugging.
  • A session cookie that keeps you signed in. It is required for the app to work.
  • Small preferences your browser stores locally -- for example whether the sidebar is collapsed. Those never leave your device.
  • If you turn on browser notifications, a subscription identifier from our push provider that lets us send to that device.

Your customers, if you connect a CRM

CRM sync is optional and off unless you turn it on. If you do connect one, or upload a customer list, we receive customer names, email addresses, phone numbers, visit history and spend totals so Hunts can be aimed at real segments -- lapsed customers, top spenders, and so on. That data belongs to you and your customers; see section 7.

3. Local data we collect about your area

Separately from anything about you, we poll public sources for what is happening near the areas we cover: events and their venues and dates, weather forecasts, sports fixtures, local news headlines, and a seasonal calendar. This is public information about places, not about people, and it is collected per area rather than per member -- several shops in the same city share one set of local signals.

4. Why we use it

  • To run your account -- sign you in, take payment, keep your credit balance right, and answer your support tickets.
  • To generate Hunts -- your shop profile plus the local signals for your area are what a Hunt is made from.
  • To send what you asked for -- new-Hunt notifications, receipts, password resets and account notices, by email and, if you enabled it, browser push.
  • To keep the service working and safe -- diagnosing errors, preventing abuse, and detecting fraudulent payments.
  • To meet legal and tax obligations.

We do not sell your personal information. We do not sell or share your customer list. We do not run advertising trackers in the app.

5. AI processing

Hunts are written by artificial intelligence. To produce one, we send third-party AI providers the parts of your shop profile that make the copy specific -- business name, services, location, opening hours, capacity, typical customer and voice preference -- together with the local signals chosen for that Hunt. The same providers also score incoming local signals so we can tell a useful one from noise.

We do not send your customers' names, email addresses or phone numbers to an AI provider. Where a Hunt is aimed at a group of customers, only counts and summary descriptions of the group are used, never the list itself.

Those providers process the data on our instructions to return the copy. We do not name our AI providers on this page.

6. Who else touches your data

We use a small number of service providers. Each one gets only what it needs to do its job:

  • Payments -- Stripe. Handles the checkout and holds your card details. We receive a reference and the result.
  • Email -- Mailgun. Delivers notifications, receipts, password resets and account notices. It processes your email address and the contents of those messages.
  • Browser push -- our push provider. Only if you turn notifications on. It holds a device subscription identifier tied to your account id.
  • AI providers. As described in section 5.
  • Hosting. The servers that run the application and store the database.
  • Your CRM, if you connect one. Data flows from it to us; we do not push your data back into it without you asking.

We may also disclose information if the law requires it, to protect the service or someone's safety, or as part of a sale or reorganisation of the business -- in which case this policy travels with the data.

7. Your customers' data

If you sync a CRM or upload a list, those records are about your customers, not about you. You decide what to collect and why; we hold and process it on your behalf so the app can build segments and aim Hunts. We do not use your customer list for our own purposes, do not market to it, and do not share it with another member.

You are responsible for having the right to give us that data and for handling your customers' own privacy requests. Disconnect the CRM and the synced records can be removed on request.

8. Cookies and local storage

The app sets one cookie: a session cookie that keeps you signed in. It is restricted to the app's own subdomain, sent only over HTTPS, and not readable by scripts. Without it you cannot stay logged in.

Your browser also stores a few display preferences locally -- whether the sidebar is collapsed, and which release notes you have read. Those stay on your device and are never sent to us.

There are no advertising or analytics cookies in the app.

9. How long we keep it

  • While your account is open -- we keep your profile, Hunts, credit ledger and tickets so the app works and your history is intact.
  • When you close your account -- it is locked immediately and stays recoverable for 30 days. Within that window we can put it back; after it, we cannot.
  • After that -- we keep the remaining records for up to 24 months and then remove or anonymise the personal information in them.
  • Payment and tax records -- kept 7 years, because we are required to.
  • Email delivery logs and server logs -- kept for a short operational period for troubleshooting and abuse prevention.

Credits do not expire while an account is open. Closing the account forfeits any unused balance -- see the Refund Policy before you close it.

10. Where it is processed

RevRaptor and its service providers operate in Canada and the United States, and your information may be stored or processed in either. Where the law requires a safeguard for that transfer, we rely on the standard contractual protections our providers offer.

11. Your rights, and how to use them

Most of these you can exercise yourself, immediately:

  • See and correct your information -- your profile is editable in Settings and onboarding.
  • Take a copy -- Account exports your profile, Hunts, credit ledger and support tickets as a JSON file.
  • Change your email or password -- also on the Account page.
  • Delete your account -- on the Account page. It is locked at once and removable after the 30-day recovery window.
  • Turn off notifications -- in Notifications. Account and payment notices cannot be turned off while the account is open.

Depending on where you live you may also have the right to object to or restrict certain processing, and to complain to your local privacy regulator. Ask us through a support ticket or at legal contact address to be confirmed and we will not charge you or make it hard.

12. Security

  • Everything is served over HTTPS.
  • Passwords are stored as one-way hashes. Nobody at RevRaptor can read yours.
  • CRM API keys are encrypted at rest and never shown back to you or written to a log.
  • Support attachments are stored outside the public web directory and served only to the member who owns the ticket.
  • Application code, configuration and database credentials sit outside the public directory.

No system is perfect. If a breach affects your information we will tell you and the relevant regulator without undue delay.

13. Children

RevRaptor is a tool for businesses and is not intended for anyone under 18. We do not knowingly collect information from children.

14. Changes to this policy

If we change how we handle your information we will update this page and, for a material change, tell you in the app or by email. The date at the top shows when it last changed.

15. Contact

Open a support ticket for anything routine. For privacy requests and formal notices, write to legal contact address to be confirmed or to business address to be confirmed.

Terms of Service Privacy Policy Refund Policy Support
What's new RevRaptor