Legal

Privacy Policy

Last updated: 2026-07-20

This Privacy Policy explains how Optinize GmbH (“Revdeo”, “we”, “us”) collects, uses and protects personal data when you visit revdeo.io, use the Builder app (app.revdeo.io), the Rev app (rev.revdeo.io), or interact with our services. We comply with the EU General Data Protection Regulation (GDPR) and the German Federal Data Protection Act (BDSG).

1. Controller

The controller responsible for data processing within the meaning of Art. 4 (7) GDPR is:

Optinize GmbH
Halle (Saale), Germany
Email: privacy@revdeo.io
See our Imprint for postal address and company registration details.

2. Categories of personal data we process

Depending on how you interact with Revdeo, we process:

  • Account data — email address, hashed password, display name, country, handle (Revs) or company name (Builders).
  • Payment data — Stripe customer IDs (Builders), Stripe Connect account IDs (Revs). We never see card numbers; Stripe handles PCI-DSS scope on our behalf.
  • Attribution data — first-party cookie value (_rv), salted IP hashes, user-agent strings, referrer, country (from x-vercel-ip-country header), Shopify cart attributes, Stripe metadata, promo codes you used. We do not store raw IP addresses.
  • Integration data — Shopify installation tokens (scoped, encrypted at rest), Shopify shop domain, app scopes granted.
  • Meta advertising data (Builders, opt-in) — when a Builder connects a Meta (Facebook / Instagram) ad account, we store the ad account ID, connected Page ID, Pixel/Dataset ID, an access token (encrypted at rest) or a reference to our central concierge system-user token, and the ad-performance metrics we pull for reporting (spend, impressions, clicks per ad). We do notimport the Builder’s customers’ personal data from Meta, and we use this Meta Platform Data solely to provide the advertising features described here, in line with the Meta Platform Terms — we never sell it. Builders can disconnect at any time — see Data Deletion.
  • Rev Meta / Instagram identity (Revs only, opt-in) — a Rev who chooses to run Partnership Ads stores their Instagram handle, numeric Instagram user ID and a Meta partnership ad code. The Rev can remove this at any time in the Rev app — see Data Deletion.
  • Connected-account data (Revs only, opt-in)— when a Rev connects a TikTok / Instagram / YouTube account via Phyllo, handle, follower count, public view metrics and post URLs flow to us via Phyllo’s API. The Rev controls disconnection in the Rev app.
  • Communications — messages exchanged in the in-app Rev↔Builder messenger, support emails, and transactional email logs.
  • Behavioural / product data — click events on tracking links (/r/<slug>), conversion events received from Shopify or Stripe webhooks, view-poll snapshots for Rev submissions.

3. Purposes and legal bases

PurposeLegal basis
Operating your account, providing the marketplaceArt. 6 (1)(b) GDPR — contract performance
Creating and managing ads in a Builder’s connected Meta ad account on their instruction, and reading back ad performanceArt. 6 (1)(b) GDPR — contract performance (Builder)
Running Partnership Ads under a Rev’s Instagram handle, where the Rev opted in and supplied a partnership ad codeArt. 6 (1)(b) GDPR — contract performance (Rev)
Click tracking and attribution via first-party cookieArt. 6 (1)(f) GDPR — legitimate interest in measuring whether a Rev caused a sale, balanced by minimisation (hashed IP, no cross-site tracking)
Stripe payouts to Revs / Stripe billing for BuildersArt. 6 (1)(b) and (c) GDPR — contract + legal obligation
DAC7 reporting to the German Federal Central Tax Office (BZSt)Art. 6 (1)(c) GDPR — legal obligation under EU Directive 2021/514 (see DAC7 disclosure)
Anti-fraud, view-spike detection, account-reputation scoringArt. 6 (1)(f) GDPR — legitimate interest in platform integrity
Transactional emails (sign-in, payout receipts)Art. 6 (1)(b) GDPR — contract performance
Marketing emails (with separate consent)Art. 6 (1)(a) GDPR — consent. Withdrawable at any time via the unsubscribe link in every email.

4. Cookies and similar technologies

Most of what Revdeo sets is strictly necessary or functional (see the table). Any non-essential tracker — currently the Meta Pixel on our creator-recruitment pages — loads only after you choose “Accept all” in our consent banner.

CookiePurposeDurationType
_rvAttribution: links a click on a Rev’s tracking link to a later purchase so the Rev gets paid. First-party, set on the redirect endpoint (/r/<slug>), not readable by third parties.90 daysFunctional. Processed under legitimate interest (Art. 6 (1)(f) GDPR). Object via privacy@revdeo.io or by clearing your browser cookies.
rv_consentStores your consent banner choice (in localStorage and a same-site cookie).1 yearStrictly necessary.
Session / auth cookiesSupabase SSR session, CSRF protection on the Builder and Rev apps.SessionStrictly necessary.
_fbp / _fbcSet by the Meta Pixel on our public creator-recruitment landing pages (e.g. /zarabiaj) and in the Rev app to measure our own recruitment ads. Loaded only after you choose “Accept all”. Never set in the Builder app (app.revdeo.io).90 daysMarketing (third-party, Meta Platforms Ireland Ltd.). Requires your consent — Art. 6 (1)(a) GDPR, § 25 (1) TDDDG.

In the Builder app (app.revdeo.io) we load no advertising or analytics trackers at all — paying customers are never tracked. We use the Meta Pixel only on our public creator-recruitment pages (e.g. /zarabiaj) and in the Rev app, to measure our own recruitment campaigns, and only after you accept it. We do not use Google Analytics or any cross-site advertising trackers. You can change or withdraw your choice at any time via the “Cookie settings” link in the footer.

5. Sub-processors

We use the following processors. Where data leaves the EEA, we rely on adequacy decisions (UK) or EU Standard Contractual Clauses plus a Transfer Impact Assessment.

Sub-processorPurposeLocationTransfer basis
Supabase Inc.Database, auth, file storageEU (eu-central-1, Frankfurt)EU hosting; no transfer
Stripe Payments Europe Ltd. / Stripe Inc.Billing (Builders), Stripe Connect payouts (Revs)Ireland + USAEU SCCs; Data Privacy Framework
Shopify International Ltd.Shopify embedded app, cart-attribute injection on Builder shopsIreland / CanadaAdequacy decision (Canada PIPEDA); legitimate interest for merchant onboarding
Vercel Inc.Hosting, edge runtime, CDNUSA (with EU-region functions for /api/*)EU SCCs; Data Privacy Framework
Resend, Inc.Transactional email deliveryUSAEU SCCs; Data Privacy Framework
Phyllo Inc.Social-account connection (Revs only, opt-in). Only invoked after a Rev explicitly connects a TikTok / Instagram / YouTube account in the Rev app.USAEU SCCs; consent-based per Art. 6 (1)(a) GDPR
Meta Platforms Ireland Ltd.Meta Marketing API (Builders, opt-in). Only invoked after a Builder connects a Meta ad account — to create and manage ads in that account on the Builder’s instruction and read back ad performance.Ireland (EU) / USAEU SCCs; Data Privacy Framework

6. Retention

  • Account data — for the duration of your account, plus up to 30 days after closure for backup overlap.
  • Invoices and payout receipts — 10 years (§ 147 AO, German tax retention).
  • Click and attribution events — 24 months from event date, then aggregated and anonymised.
  • IP hashes — 6 months for fraud review, then deleted.
  • Webhook payloads — 90 days, then payload truncated; metadata retained for reconciliation.

7. Your rights

Under Art. 15–22 GDPR you have the right to:

  • Access — receive a copy of the personal data we hold about you.
  • Rectification — correct inaccurate data.
  • Erasure — request deletion where there is no legal retention duty.
  • Restriction — limit processing during a dispute.
  • Portability — receive your data in a machine-readable format (JSON export from the Builder or Rev app dashboard, or by email).
  • Objection — object to processing based on legitimate interest, including attribution tracking.
  • Withdraw consent at any time, with effect for the future.

To exercise any right, email privacy@revdeo.io. We respond within 30 days. You also have the right to lodge a complaint with the competent supervisory authority — for Optinize GmbH this is the Landesbeauftragte für den Datenschutz Sachsen-Anhalt.

8. Security

We protect data in transit with TLS 1.2+ and at rest via the encryption defaults of our sub-processors. Passwords are stored as bcrypt hashes. Shopify access tokens are encrypted in the database. IP addresses are salted and hashed (SHA-256) before persistence and never stored in raw form.

9. Children

Revdeo is not directed at people under 18. The Rev programme requires a Stripe Connect account, which Stripe gates by age. We do not knowingly collect data from minors.

10. Changes to this policy

We may update this policy when our processing changes. The “Last updated” date at the top reflects the most recent version. Material changes will be announced via in-app banner and email at least 14 days in advance.

11. Contact

Questions about data protection at Revdeo: privacy@revdeo.io. For general contact see our Imprint.