Privacy Policy
Last updated: August 4, 2026
1. Introduction
RevTouch.io ("RevTouch", "we", "us") operates a marketing attribution and affiliate payout platform. This policy explains what we collect, why, and the rights you have. It applies to visitors, customer users and the end customers whose touches our customers track, in the European Economic Area, the United Kingdom, Switzerland, Canada, Brazil and every US state with a consumer privacy law in force.
2. Controller and processor roles
When you visit revtouch.io or hold a RevTouch account, RevTouch is the controller (US laws: "business").
When a customer installs our collector on their own site, the customer is the controller of the resulting touch and conversion data and RevTouch is the processor (US laws: "service provider" / "processor"). We process that data only on the customer's documented instructions under our Data Processing Agreement.
3. What we collect
Account data
- Name, email address, organization and role
- Authentication credentials handled by our auth provider (passwords are never stored in plaintext)
- Billing identifiers and subscription state (card data stays with Stripe)
Attribution data collected on customer sites
- UTM parameters, click identifiers (gclid, fbclid, ttclid, msclkid), affiliate references
- Landing path, referrer, event name and timestamp
- A first-party visitor cookie identifier
- Hashed identity keys: email and phone are SHA-256 hashed before storage
- IP address, salted and hashed at the edge for rate limiting and fraud prevention
- Hashed user agent string
Data minimisation by design: raw email addresses, raw phone numbers and raw IP addresses never reach our database. They are hashed inside the collector edge function and discarded in the same request.
What we never collect
- Special category / sensitive data (health, biometrics, precise geolocation, race, religion)
- Payment card numbers
- Cross-customer behavioural profiles: data is isolated per organization by row-level security
4. Legal bases (EU / UK GDPR)
- Contract, Art. 6(1)(b): providing the platform to account holders
- Legitimate interests, Art. 6(1)(f): security, fraud prevention, service improvement and measuring our own marketing
- Consent, Art. 6(1)(a): non-essential cookies and marketing email; our customers are responsible for obtaining consent for tracking on their own sites
- Legal obligation, Art. 6(1)(c): tax, accounting and payout records
5. How we use data
- Stitch touches into a single identity and calculate attribution credit
- Produce the payout ledger: one payable touch per conversion, with a full audit trail
- Generate partner statements, exports and invoices
- Detect abuse, rate-limit ingest and secure accounts
- Provide support and send service notices
No automated decision-making with legal effect is performed on data subjects. Payout election is a deterministic rule applied to a commercial transaction, and every decision is reviewable and manually overridable with a recorded reason.
6. Sharing and sub-processors
We do not sell personal information, and we do not share it for cross-context behavioural advertising or targeted advertising as those terms are defined in CPRA, VCDPA, CPA, CTDPA, TDPSA and the other state laws listed below.
| Provider | Purpose | Location |
|---|---|---|
| Supabase | Database, authentication, edge functions | USA / EU |
| Netlify | Front-end hosting and the first-party collector proxy | USA / EU |
| Stripe | Subscription billing and conversion webhooks | USA / EU |
| Whop | Conversion webhooks (only if the customer connects it) | USA |
| Omnisend | Email/SMS campaign metadata (only if connected) | EU |
We also disclose data where legally required, and in connection with a merger or acquisition (with notice to affected customers).
7. International transfers
Data may be processed in the United States and the European Union. For transfers out of the EEA, UK or Switzerland we rely on the European Commission's Standard Contractual Clauses, the UK International Data Transfer Addendum, and adequacy decisions where available, together with transfer impact assessments and encryption in transit and at rest.
8. Security
TLS in transit, encryption at rest, hashed identifiers, per-organization row-level security on every table, encrypted integration credentials, least-privilege service keys, append-only audit logs, and signature verification on every inbound webhook. We notify affected controllers without undue delay and within 72 hours of becoming aware of a personal data breach, as required by GDPR Art. 33 and equivalent state breach laws.
9. Retention
| Data type | Retention |
|---|---|
| Touch events (hashed identity keys only) | 26 months, then aggregated |
| Conversions and attribution credits | Duration of account + 30 days |
| Payout decisions, runs and statements | 7 years (financial record keeping) |
| Billing records | 7 years (legal obligation) |
| Audit log and payout audit | 7 years (append-only, immutable) |
| Account profile data | Duration of account + 30 days |
| Consent records | 5 years (proof of compliance) |
| Data subject requests | 24 months after closure |
10. Your rights in the EEA, UK and Switzerland
- Access (Art. 15), rectification (Art. 16), erasure (Art. 17), restriction (Art. 18), portability (Art. 20), objection (Art. 21)
- Withdraw consent (Art. 7(3)) at any time, without affecting prior processing
- Complain to your supervisory authority: in the UK, the Information Commissioner's Office at ico.org.uk
Exercise these in Settings → Privacy & data or by emailing privacy@revtouch.io. We respond within 30 days. Our data protection contact is privacy@revtouch.io.
11. Your rights in US states
Residents of the following states have rights under their state consumer privacy law. We apply the strongest available standard to every US resident regardless of state.
| State | Law | In force |
|---|---|---|
| California | CCPA / CPRA | 2020 / 2023 |
| Virginia | VCDPA | 2023 |
| Colorado | CPA | 2023 |
| Connecticut | CTDPA | 2023 |
| Utah | UCPA | 2023 |
| Texas | TDPSA | 2024 |
| Oregon | OCPA | 2024 |
| Montana | MTCDPA | 2024 |
| Florida | FDBR | 2024 |
| Delaware | DPDPA | 2025 |
| Iowa | ICDPA | 2025 |
| Nebraska | NDPA | 2025 |
| New Hampshire | NHPA | 2025 |
| New Jersey | NJDPA | 2025 |
| Tennessee | TIPA | 2025 |
| Minnesota | MCDPA | 2025 |
| Maryland | MODPA | 2025 |
| Indiana | INCDPA | 2026 |
| Kentucky | KCDPA | 2026 |
| Rhode Island | RIDTPPA | 2026 |
Rights available to all US residents
- Know and access the categories and specific pieces of personal information we hold
- Delete personal information, subject to statutory exceptions
- Correct inaccurate personal information
- Obtain a portable copy
- Opt out of sale, sharing, targeted advertising and profiling: we do none of these
- Limit the use of sensitive personal information: we collect none
- Non-discrimination for exercising any right
- Appeal a refused request. We respond to appeals within 45 days and tell you how to contact your state Attorney General
We honour the Global Privacy Control browser signal as a valid opt-out. Requests are answered within 45 days (extendable once by 45 days where the law permits); in practice we target 30 days. California residents may use an authorised agent, and may request "Shine the Light" disclosures under Civil Code § 1798.83.
Categories collected in the last 12 months: identifiers (hashed email, hashed phone, cookie ID, account email), commercial information (subscriptions, conversions, payouts), internet activity (page and campaign touches), and professional information (organization and role). Sources: you, your browser, and the integrations you connect. Business purposes: providing, securing and billing for the service.
12. Cookies and tracking
On revtouch.io we set an essential session cookie and, only with your consent, analytics, marketing and functional cookies. Manage your choice from the banner, or under Settings → Privacy & data. We honour Global Privacy Control and Do Not Track signals by declining all non-essential cookies automatically.
On customer sites, our collector sets a first-party cookie with a 400-day lifetime to recognise return visits. Our customers are the controllers of that cookie and are responsible for surfacing their own consent notice; the collector can be configured to fire only after consent.
13. Children
RevTouch is a B2B product not directed at children. We do not knowingly collect data from anyone under 16 (EEA/UK) or under 13 (US), and will delete such data on discovery. We do not process the personal data of known minors for targeted advertising or profiling under any state law.
14. Data Processing Agreement
Our DPA incorporates the EU Standard Contractual Clauses and the UK Addendum and forms part of the customer agreement automatically. For a signed copy, email privacy@revtouch.io.
15. Changes and contact
We post material changes here, update the date above, and notify account holders by email or in-app notice. Reach us at privacy@revtouch.io (privacy), privacy@revtouch.io (data protection) or privacy@revtouch.io (legal). Logged-in users can self-serve at Settings → Privacy & data.