Legal
Privacy Policy
Last updated: 2026-07-20
This Privacy Policy explains how Optinize GmbH (“Revdeo”, “we”, “us”) collects, uses and protects personal data when you visit revdeo.io, use the Builder app (app.revdeo.io), the Rev app (rev.revdeo.io), or interact with our services. We comply with the EU General Data Protection Regulation (GDPR) and the German Federal Data Protection Act (BDSG).
1. Controller
The controller responsible for data processing within the meaning of Art. 4 (7) GDPR is:
Optinize GmbH
Halle (Saale), Germany
Email: privacy@revdeo.io
See our Imprint for postal address and company registration details.
2. Categories of personal data we process
Depending on how you interact with Revdeo, we process:
- Account data — email address, hashed password, display name, country, handle (Revs) or company name (Builders).
- Payment data — Stripe customer IDs (Builders), Stripe Connect account IDs (Revs). We never see card numbers; Stripe handles PCI-DSS scope on our behalf.
- Attribution data — first-party cookie value (
_rv), salted IP hashes, user-agent strings, referrer, country (fromx-vercel-ip-countryheader), Shopify cart attributes, Stripe metadata, promo codes you used. We do not store raw IP addresses. - Integration data — Shopify installation tokens (scoped, encrypted at rest), Shopify shop domain, app scopes granted.
- Meta advertising data (Builders, opt-in) — when a Builder connects a Meta (Facebook / Instagram) ad account, we store the ad account ID, connected Page ID, Pixel/Dataset ID, an access token (encrypted at rest) or a reference to our central concierge system-user token, and the ad-performance metrics we pull for reporting (spend, impressions, clicks per ad). We do notimport the Builder’s customers’ personal data from Meta, and we use this Meta Platform Data solely to provide the advertising features described here, in line with the Meta Platform Terms — we never sell it. Builders can disconnect at any time — see Data Deletion.
- Rev Meta / Instagram identity (Revs only, opt-in) — a Rev who chooses to run Partnership Ads stores their Instagram handle, numeric Instagram user ID and a Meta partnership ad code. The Rev can remove this at any time in the Rev app — see Data Deletion.
- Connected-account data (Revs only, opt-in)— when a Rev connects a TikTok / Instagram / YouTube account via Phyllo, handle, follower count, public view metrics and post URLs flow to us via Phyllo’s API. The Rev controls disconnection in the Rev app.
- Communications — messages exchanged in the in-app Rev↔Builder messenger, support emails, and transactional email logs.
- Behavioural / product data — click events on tracking links (
/r/<slug>), conversion events received from Shopify or Stripe webhooks, view-poll snapshots for Rev submissions.
3. Purposes and legal bases
| Purpose | Legal basis |
|---|---|
| Operating your account, providing the marketplace | Art. 6 (1)(b) GDPR — contract performance |
| Creating and managing ads in a Builder’s connected Meta ad account on their instruction, and reading back ad performance | Art. 6 (1)(b) GDPR — contract performance (Builder) |
| Running Partnership Ads under a Rev’s Instagram handle, where the Rev opted in and supplied a partnership ad code | Art. 6 (1)(b) GDPR — contract performance (Rev) |
| Click tracking and attribution via first-party cookie | Art. 6 (1)(f) GDPR — legitimate interest in measuring whether a Rev caused a sale, balanced by minimisation (hashed IP, no cross-site tracking) |
| Stripe payouts to Revs / Stripe billing for Builders | Art. 6 (1)(b) and (c) GDPR — contract + legal obligation |
| DAC7 reporting to the German Federal Central Tax Office (BZSt) | Art. 6 (1)(c) GDPR — legal obligation under EU Directive 2021/514 (see DAC7 disclosure) |
| Anti-fraud, view-spike detection, account-reputation scoring | Art. 6 (1)(f) GDPR — legitimate interest in platform integrity |
| Transactional emails (sign-in, payout receipts) | Art. 6 (1)(b) GDPR — contract performance |
| Marketing emails (with separate consent) | Art. 6 (1)(a) GDPR — consent. Withdrawable at any time via the unsubscribe link in every email. |
4. Cookies and similar technologies
Most of what Revdeo sets is strictly necessary or functional (see the table). Any non-essential tracker — currently the Meta Pixel on our creator-recruitment pages — loads only after you choose “Accept all” in our consent banner.
| Cookie | Purpose | Duration | Type |
|---|---|---|---|
_rv | Attribution: links a click on a Rev’s tracking link to a later purchase so the Rev gets paid. First-party, set on the redirect endpoint (/r/<slug>), not readable by third parties. | 90 days | Functional. Processed under legitimate interest (Art. 6 (1)(f) GDPR). Object via privacy@revdeo.io or by clearing your browser cookies. |
rv_consent | Stores your consent banner choice (in localStorage and a same-site cookie). | 1 year | Strictly necessary. |
| Session / auth cookies | Supabase SSR session, CSRF protection on the Builder and Rev apps. | Session | Strictly necessary. |
_fbp / _fbc | Set by the Meta Pixel on our public creator-recruitment landing pages (e.g. /zarabiaj) and in the Rev app to measure our own recruitment ads. Loaded only after you choose “Accept all”. Never set in the Builder app (app.revdeo.io). | 90 days | Marketing (third-party, Meta Platforms Ireland Ltd.). Requires your consent — Art. 6 (1)(a) GDPR, § 25 (1) TDDDG. |
In the Builder app (app.revdeo.io) we load no advertising or analytics trackers at all — paying customers are never tracked. We use the Meta Pixel only on our public creator-recruitment pages (e.g. /zarabiaj) and in the Rev app, to measure our own recruitment campaigns, and only after you accept it. We do not use Google Analytics or any cross-site advertising trackers. You can change or withdraw your choice at any time via the “Cookie settings” link in the footer.
5. Sub-processors
We use the following processors. Where data leaves the EEA, we rely on adequacy decisions (UK) or EU Standard Contractual Clauses plus a Transfer Impact Assessment.
| Sub-processor | Purpose | Location | Transfer basis |
|---|---|---|---|
| Supabase Inc. | Database, auth, file storage | EU (eu-central-1, Frankfurt) | EU hosting; no transfer |
| Stripe Payments Europe Ltd. / Stripe Inc. | Billing (Builders), Stripe Connect payouts (Revs) | Ireland + USA | EU SCCs; Data Privacy Framework |
| Shopify International Ltd. | Shopify embedded app, cart-attribute injection on Builder shops | Ireland / Canada | Adequacy decision (Canada PIPEDA); legitimate interest for merchant onboarding |
| Vercel Inc. | Hosting, edge runtime, CDN | USA (with EU-region functions for /api/*) | EU SCCs; Data Privacy Framework |
| Resend, Inc. | Transactional email delivery | USA | EU SCCs; Data Privacy Framework |
| Phyllo Inc. | Social-account connection (Revs only, opt-in). Only invoked after a Rev explicitly connects a TikTok / Instagram / YouTube account in the Rev app. | USA | EU SCCs; consent-based per Art. 6 (1)(a) GDPR |
| Meta Platforms Ireland Ltd. | Meta Marketing API (Builders, opt-in). Only invoked after a Builder connects a Meta ad account — to create and manage ads in that account on the Builder’s instruction and read back ad performance. | Ireland (EU) / USA | EU SCCs; Data Privacy Framework |
6. Retention
- Account data — for the duration of your account, plus up to 30 days after closure for backup overlap.
- Invoices and payout receipts — 10 years (§ 147 AO, German tax retention).
- Click and attribution events — 24 months from event date, then aggregated and anonymised.
- IP hashes — 6 months for fraud review, then deleted.
- Webhook payloads — 90 days, then payload truncated; metadata retained for reconciliation.
7. Your rights
Under Art. 15–22 GDPR you have the right to:
- Access — receive a copy of the personal data we hold about you.
- Rectification — correct inaccurate data.
- Erasure — request deletion where there is no legal retention duty.
- Restriction — limit processing during a dispute.
- Portability — receive your data in a machine-readable format (JSON export from the Builder or Rev app dashboard, or by email).
- Objection — object to processing based on legitimate interest, including attribution tracking.
- Withdraw consent at any time, with effect for the future.
To exercise any right, email privacy@revdeo.io. We respond within 30 days. You also have the right to lodge a complaint with the competent supervisory authority — for Optinize GmbH this is the Landesbeauftragte für den Datenschutz Sachsen-Anhalt.
8. Security
We protect data in transit with TLS 1.2+ and at rest via the encryption defaults of our sub-processors. Passwords are stored as bcrypt hashes. Shopify access tokens are encrypted in the database. IP addresses are salted and hashed (SHA-256) before persistence and never stored in raw form.
9. Children
Revdeo is not directed at people under 18. The Rev programme requires a Stripe Connect account, which Stripe gates by age. We do not knowingly collect data from minors.
10. Changes to this policy
We may update this policy when our processing changes. The “Last updated” date at the top reflects the most recent version. Material changes will be announced via in-app banner and email at least 14 days in advance.
11. Contact
Questions about data protection at Revdeo: privacy@revdeo.io. For general contact see our Imprint.