Published on July 21, 2026. Effective from July 21, 2026.
User Privacy Policy
At Revi we value your privacy. Through this policy, we inform you of your rights regarding personal data protection and explain how we collect, use, disclose, transfer and store your information when you use our services to leave reviews about stores or products.
1. Terms used in this policy
For a better understanding of this policy, we explain below some key terms used throughout the document:
- “Revi” or “we”: Refers to REVI DIGITAL, S.L., the company that owns the revi.io platform, with Tax ID (NIF) B23839574 and registered office at Calle Gaudencia Torres 9 16, 46015, Valencia (Spain). Contact email: hola@revi.io. Registered in the Commercial Registry of Valencia, volume 11,473, book 8,751, folio 81, page V-214487, entry 1st. Revi acts as data controller in the cases described in this policy.
- “User” or “you”: Person who accesses the revi.io platform with the purpose of leaving a review, consulting ratings or interacting with public content related to products and businesses.
- “Personal data”: Any information that allows a natural person to be identified directly or indirectly. This may include, for example, your name, email address, IP address, published reviews, attached images, among others.
- “Public personal data”: Information voluntarily published on the platform, visible to any visitor, such as the content of your reviews, your name or pseudonym, the score given, the publication date, or any attached file. It also includes business responses to your ratings.
- “Private personal data”: Data that is not publicly displayed on Revi and is used exclusively for service management or to verify the legitimacy of a rating, such as your email address, order number or technical information collected automatically.
- “Platform”: Refers to the revi.io website and all associated functionalities, such as the review form, user area, moderation systems and any other service accessible from our main domain or subdomains.
- “Data processor”: Natural or legal person that processes personal data on behalf of the data controller. For example, Revi acts as a processor when it manages review invitations on behalf of a business that has contracted its services.
- “Data controller”: Natural or legal person that determines the purposes and means of the processing of personal data. This may be Revi (for example, in the case of user accounts or voluntary reviews) or the business that invites you to rate its service.
- “GDPR”: General Data Protection Regulation (EU Regulation 2016/679), the European regulation that governs the protection of natural persons with regard to the processing of personal data and the free movement of such data.
- “Consent”: A freely given, specific, informed and unambiguous indication by which the user accepts, through a clear affirmative action, the processing of their personal data by Revi for one or more specific purposes.
2. Third-party websites
Our platform may contain links to third-party websites. The existence of these links does not mean that we recommend them or that they are governed by this privacy policy. We encourage you to carefully read the privacy policies of such sites, as their data collection, use and processing practices may differ from ours.
3. Publicly visible reviews
Revi is a public platform designed to promote transparency between consumers and businesses. When you write a review on Revi, that review —together with the information associated with your user profile— will be visible to anyone who accesses our platform.
This includes:
- The content of your review and the score given.
- The publication date.
- Your first name and the initial of your last name (or the pseudonym you choose). In the event that your review is not anonymous.
- The product or service reviewed and, where applicable, the name of the business.
- Your language.
- Any image, video or other content you decide to attach to your review.
When another user accesses your profile, they can see all the ratings you have published, as well as additional information related to your public interactions on Revi.
Likewise, if a business responds to your review, that response will also be publicly visible. Both your review and the business’s response form part of the public record of interactions between consumers and businesses on Revi.
We consider all this information as public personal data, accessible on our platform and on external search engines (for example, Google). You are not required to provide any additional personal data beyond what is strictly necessary to leave a verified review. You decide whether to use your real name or a pseudonym, as well as whether to attach images or additional information that identifies you.
Some technology providers may be located outside the European Economic Area. In such cases, we ensure that processing is carried out under standard contractual clauses approved by the European Commission or equivalent mechanisms in accordance with the GDPR.
4. Private personal data
When a store or business requests Revi to send an invitation for you to rate your shopping experience, it provides us with certain personal data necessary for that purpose. This data usually includes your name, email address and a reference identifier, such as the order number or other equivalent data that allows the transaction to be verified.
In addition, Revi may receive information from third parties in order to detect possible fraud or carry out internal investigations aimed at ensuring the integrity of the review system.
We also automatically collect certain technical information from your device when you access our services. This may include your IP address, approximate location, device type, browser used, operating system, as well as data about your interaction with the platform (such as pages visited, clicks made, time spent) or with our emails (such as opening or interacting with review invitations).
All this information is used exclusively to provide the service securely, improve the user experience and ensure that published reviews are authentic and verifiable.
4.1. Who is the controller of your data?
According to the General Data Protection Regulation (Regulation (EU) 2016/679), the data controller is the one who determines the purposes and means of the processing of your personal data, while a data processor acts following their instructions.
When you receive an invitation to leave a review about a store or business that uses Revi’s services (whether sent directly by us on their behalf or by the business itself), that business acts as the data controller with respect to the data used for that invitation (for example, your name, email or order number). Revi, in this case, acts as the data processor, providing the service on behalf of the business.
Therefore, if you wish to exercise your rights over the personal data used for sending review invitations, such as access, rectification or erasure, you should contact the business that invited you directly, as it is the one that determines the use of that data.
On the other hand, with respect to other personal data linked to the use of the Revi platform —such as creating an account, publishing a review, responding to ratings or using interactive features— Revi acts as the data controller.
Additionally, depending on the services contracted by our clients (the businesses), they may also act as controllers with respect to certain data visible in reviews, such as your name, the content of the review or the experience date, when these are published on their business profile.
Revi has entered into the corresponding data processing agreements with the Businesses in accordance with Article 28 of the GDPR.
Disclosure of data to the business in the incident process: if you submit an incident, we will disclose to the affected business only a minimum summary (order number, purchase date and description of the problem) and, only if you expressly authorize it, your email address. We will not disclose your supporting documents, your IP address or your technical data. The business processes the data received as an independent controller, for the sole purpose of managing the incident.
4.2. What do we use your personal data for?
At Revi we process your personal data for various purposes, all of which are based on the legitimate use of the platform, your consent, or the fulfillment of legal obligations. These are the main purposes for which we may use your information:
- Providing our services: Displaying your reviews publicly on store profiles and giving you access to your user account or functionalities available on the Revi platform.
- Improving the platform: Analyzing system usage, conducting internal testing, detecting errors and developing new features that enhance your experience.
- Responding to your inquiries: Answering messages or requests you send through contact forms, support or email.
- Managing incidents about businesses: processing the incidents you report to us about your shopping experience with a business that has a profile on Revi, verifying your email address, assessing the documentation provided, forwarding a minimum summary of the case to the business and keeping you informed of its status. This process is automated (see section 4.3).
- Sending you communications: If you have subscribed, we may send you newsletters, updates or other relevant communications, always with your consent.
- Personalizing your experience: Adapting content, recommendations or the way we display ratings based on your behavior on the platform.
- Internal management and analysis: Performing tasks such as statistical analysis, audits, fraud detection, quality control, content moderation or identifying usage trends.
- Training and process improvement: Using your interactions (for example, questions or ratings) in an anonymized or pseudonymized manner to train our staff and improve service quality.
- Legal compliance and exercise of rights: Retaining or disclosing information when necessary to fulfill a legal obligation, a court order or a request from a competent authority, as well as to defend Revi’s legitimate rights and interests.
In all cases, we apply technical and organizational measures to ensure that the processing of your data is appropriate, secure and in accordance with current regulations.
4.3. Legal basis for the processing of your data
At Revi we process your personal data in accordance with the legal bases established by the General Data Protection Regulation (GDPR), depending on the type of interaction you have with us. In particular, we process your data on the basis of:
- Performance of a contract: We need to process your data to provide you with our services, allow you to leave verified ratings, give you access to your user account or fulfill other obligations arising from our relationship with you or the business you represent.
- Compliance with legal obligations: We process personal data when necessary to comply with applicable regulations, including legal, tax, data protection or judicial requirements.
- Legitimate interest: We process certain data to manage our platform, improve our services, ensure system security, prevent fraud or carry out statistical analyses. We always ensure that these processing activities are relevant, proportionate and do not unjustifiably affect your rights and freedoms.
- Defense of legal rights: We retain or use your data if necessary to establish, exercise or defend legal claims.
- Explicit consent: In cases where we request your consent (for example, to send you newsletters or install non-essential cookies), we will process your data only if you have given us free and informed permission. You may withdraw your consent at any time from the relevant panel or by writing to us (see “Contact” section).
In the incident process we apply the following legal bases: the handling of the file that you yourself initiate is based on the application of measures at your request (art. 6.1.b GDPR); the disclosure to the business of the minimum summary strictly necessary for it to identify the transaction and respond is based on our legitimate interest and your own interest in the management of the incident (art. 6.1.f GDPR); the disclosure of your email address to the business takes place only if you authorize us to do so by means of a specific checkbox (art. 6.1.a GDPR), an authorization that you may revoke at any time without this affecting the handling of the case; and the processing of your IP address and technical data is based on our legitimate interest in the security and prevention of abuse of the channel (art. 6.1.f GDPR).
You should be aware that the minimum summary (order number, date and description) enables the business, which has its own records, to identify your order and, therefore, to identify you.
Please remember that, even if you withdraw your consent, Revi may continue to process your data if there is another legal basis that justifies it.
As a general rule, Revi does not make solely automated decisions that produce legal effects on you or similarly significantly affect you. In the incident process, the handling is automated (verification of the email, assessment of the documentation provided by means of predefined objective criteria, forwarding to the business, reminders and calculation of time periods). If your incident is automatically closed due to insufficient documentation, you may request a human review of that decision, express your point of view and contest it by writing to hola@revi.io.
You also have the right to object to the processing of your data or to request its restriction in certain cases.
4.4. Retention period for your personal data
At Revi we retain your personal data only for the time necessary to fulfill the purposes for which it was collected, or while there is a legal basis that justifies its processing. The exact period will depend on the type of interaction you have had with us, the service provided and our legal or contractual obligations.
This means we may retain your data while:
- You have a user account on Revi.
- An active contractual relationship exists between you or the business you represent and Revi.
- It is necessary to provide you with our services, display your ratings or ensure the traceability of verified reviews.
- A legal retention obligation exists (for example, tax, commercial or data protection regulations).
- We have a legitimate interest that justifies its retention (such as fraud prevention, platform security or defense against potential claims).
Once these purposes have ceased to apply and there is no legal obligation or legitimate basis that justifies storage, your data will be securely deleted or anonymized, so that it can no longer be associated with you as an identifiable person.
You may exercise your right to request the deletion of your personal data at any time.
In the incident process we apply the following specific periods: unverified contact data is deleted after 7 days; the incident file is retained for 24 months from closure; attached supporting documents are deleted 12 months from closure; and the IP address and technical data are retained for 12 months. Once these periods have elapsed, the data is automatically deleted or anonymized.
At Revi, the security of your personal information is a fundamental priority. Therefore, we implement appropriate technical, organizational and administrative measures to protect your data against unauthorized access, loss, alteration or improper disclosure.
These measures include, for example:
- The use of secure transmission protocols (HTTPS).
- Restricted access controls for authorized personnel.
- Intrusion detection and prevention systems.
- Regular backups.
- Periodic review and auditing of our platforms and systems to detect vulnerabilities.
However, please note that no data transmission over the Internet is completely secure. Although we constantly work to improve the protection of our systems, we cannot 100 % guarantee the security of the information you send us through electronic means.
For this reason, we recommend that you do not include sensitive or confidential data in the emails you send us, as these messages may not be encrypted. If you need to communicate particularly sensitive information, contact us and we will provide you with the most secure means to do so.
4.5. Author identifier and “My Reviews” portal
Author identifier. When you publish a review on Revi, we generate an internal author identifier associated with your email address. This identifier allows us to:
- Group your reviews so that you can view and manage them from a single place.
- Facilitate the exercise of your rights as an author (modification and erasure of your reviews, arts. 16 and 17 GDPR).
- Demonstrate the authenticity of published reviews as originating from real buyers.
The data associated with the author identifier is limited to the minimum necessary: email address, display name and preferred language. Legal basis: the legitimate interest of Revi and of the authors themselves in managing authorship and the rights over reviews (art. 6.1.f GDPR); if you activate access to the “My Reviews” portal, the processing necessary to provide you with that service is based on the performance of the relationship with you (art. 6.1.b GDPR).
“My Reviews” portal. You can access at any time a personal area where you can view all your reviews, edit them (for the 12 months following their publication) or delete them. Access is via a single-use verification link sent to your email address, with limited validity; no password is used. We keep an internal log of the actions carried out (access, editing, deletion), together with the IP address and browser used, for the purpose of preventing fraud and being able to demonstrate that the actions on a review were carried out by its author (art. 6.1.f GDPR).
Retention. The author identifier is retained for as long as you have reviews published. If you exercise your right to erasure, your identifying data is irreversibly deleted and your reviews are anonymized (see section 7.3); only a minimal record of the erasure event is retained, for traceability and regulatory compliance purposes. Verification links expire after 15 minutes and are deleted from our systems within a maximum of 24 hours. The log of actions on your reviews (access, editing, deletion) is kept in pseudonymized form as evidence of the exercise of your rights and for fraud prevention, for the duration of the applicable liability limitation periods.
4.6. Data processed in the incident process
If you submit an incident about a business, we will process: your name (optional) and verified email address; the transaction data you provide (order number, purchase date, amount, contact method used); the description of the problem; the supporting documents you attach; and your IP address and browser technical data, for security and abuse-prevention purposes.
Provide only the essential documentation. Before attaching a supporting document, redact third parties’ data and financial data that is not necessary (for example, your full card number). We do not request police or court reports; if you provide them on your own initiative, we will not disclose them to the business and we may remove them from the file. We may remove any attachment containing excessive data.
The incident is private: its content is not published on the business profile or anywhere else.
4.7. Data processed when reporting content
If you use the content-notification channel (section 6 bis of the Terms of Use) to report to us content that you consider unlawful or contrary to the publication rules, we will process: your name and email address, the explanation and documentation you provide, and your IP address and browser technical data.
Purposes and legal bases: to handle the notification, confirm its receipt and inform you of the decision taken, in compliance with the legal obligation imposed on Revi by Regulation (EU) 2022/2065 (art. 6.1.c GDPR); and to prevent abusive use of the channel, on the basis of our legitimate interest (art. 6.1.f GDPR).
Your identity as the notifier is not disclosed to the author of the notified content, except where required by law or by a request from a competent authority. The notification data and the record of the decision are retained for 12 months from resolution, as evidence of the handling; once that period has elapsed they are automatically deleted or anonymized.
4.8. Data processed when identifying you on the public profile and when voting on reviews
Certain actions on the public profile (marking a review as “Helpful”, reporting via the icon on each review) require you to identify yourself with a single-use access link sent to your email address. When you request it, we process: your email address (normalized, associated with your author identifier described in the author identity section), your IP address and browser technical data linked to the link request, and the record of the helpfulness votes you cast (review voted, date).
Purposes and legal bases: to manage your access and maintain your session (art. 6.1.b GDPR — operation of the service you request when using the feature); and to prevent fraud and manipulation of the vote count and of the reporting channel (art. 6.1.f GDPR — legitimate interest in the integrity of the platform).
Access links expire after 15 minutes and can only be used once. Votes are retained for as long as the voted review remains published; you may revoke each vote at any time with the same action. If you exercise the right to erasure of your author identifier, the votes are irreversibly unlinked.
4.9. Data processed when reporting misuse of the platform and automated analysis of reports
If you use the channel for reporting misuse of the platform by a business (fake reviews, undisclosed incentives, impersonation or selective filtering of invitations), we will process: your author identity (described in the author identity section) and your email address, your name if you provide it, the reference of the business you indicate, the explanation you write, and a technical fingerprint of the request (pseudonymized IP address and browser data). Legal basis: our legitimate interest in the integrity and reliability of the platform (art. 6.1.f GDPR). These reports are always reviewed manually; your identity is not disclosed to the reported business, except where required by law or by a request from a competent authority. The record of the report and of its resolution is retained for 12 months from resolution.
In order to prioritize and prepare the review of content notifications (section 4.7), we may rely on an automated analysis of the text of the report and of the reported content carried out by means of an artificial intelligence provider that acts as a data processor and that does not use this data to train its models. The provider is established in the United States; the international transfer is covered by the EU-U.S. Data Privacy Framework adequacy mechanism or, failing that, by standard contractual clauses (art. 46 GDPR). When a decision is taken by automated means we will indicate this in the communication itself and you will be able to request a human review. The removal of content from this channel is never decided solely by automated means.
4.10. Data processed if a business challenges your review
If a business submits a formal challenge to a review of yours that has already been published (section 8 of the Terms of Use), we will process: the data already associated with your review (display name, email address of the shopping experience), the response you decide to send (free text) and the documentation you attach voluntarily, as well as a case-specific access token so that you can respond without creating an account. Legal basis: our legitimate interest in the integrity and reliability of published reviews and in the objective handling of challenges (art. 6.1.f GDPR). Recipients: our internal infrastructure services (attachment storage and email sending); the challenging business receives only the resolution, never your response or your attachments, and your identity is not disclosed to it beyond what is already visible in the published review.
Some challenges may be resolved by solely automated means when the check is based only on objective transaction data (for example, that the review does not correspond to the indicated order, that it is duplicated, or that the purchase has not been substantiated after the request within the time period); these decisions may result in the removal of your review from publication. In such a case we will indicate this in the reasoned communication and you will have the right to obtain human intervention, express your point of view and contest the decision by requesting a review (art. 22.3 GDPR), responding to that communication or writing to hola@revi.io within fifteen (15) days. Decisions that require assessing the content of the review are always taken by a person.
Retention: the challenge file and your response are retained for twelve (12) months from resolution; the attachments, twelve (12) months. Once the periods have elapsed they are automatically deleted or anonymized.
5. Right to lodge a complaint
You have the right to lodge a complaint with the Spanish Data Protection Agency (www.aepd.es) if you consider that the processing does not comply with current regulations.
6. Use of cookies and similar technologies
At Revi we use cookies and equivalent technologies, such as pixels and tracking codes, in order to improve your user experience, optimize our platform, personalize content, carry out statistical analyses and show you relevant advertising.
6.1. What are cookies?
Cookies are small text files that are stored on your device (computer, mobile phone, tablet, etc.) when you access our website. These files allow the site to remember relevant information for future visits, such as your preferences, settings or previous interactions.
6.2. What other technologies do we use?
In addition to cookies, we may use:
- Pixels: small transparent graphic files that are inserted in emails or web pages. They help us understand whether you have opened a message or interacted with certain content.
- Tracking codes: code snippets that allow us to analyze how you browse our platform, which sections you visit or how you interact with our services.
6.3. Purposes of use
These technologies are used to:
- Identify your user session and facilitate your navigation.
- Remember your preferences, such as language or regional settings.
- Analyze browsing behavior on the site and improve our services.
- Personalize the experience based on your interests.
- Show relevant advertising, based on your previous visits or reviews submitted.
- Measure the effectiveness of marketing campaigns and traffic sources.
6.4. Who installs these cookies?
Cookies may be:
- First-party: managed directly by Revi, for example, to keep your session active or remember your privacy settings.
- Third-party: managed by external platforms such as Google, Meta (Facebook), LinkedIn, among others, which assist us with tasks such as analytics, advertising or social media integration.
6.5. Do I need to give my consent?
Yes. According to current regulations, non-essential cookies (for example, analytics or advertising cookies) require your informed and explicit consent. When you access our website for the first time, we will display a configuration panel where you can accept or reject each category of cookies.
You may change your choice at any time through the Cookie Management Panel, accessible from the footer.
6.6. What happens if I reject them?
You can use Revi without accepting non-essential cookies. However, if you decide to reject them, some website functions may not be available or may not work correctly (for example, remembering your language or showing relevant recommendations).
6.7. Where can I get more information?
You can consult all the details about the types of cookies we use, their purposes, duration and third parties involved in our general Cookie Policy or write to us at hola@revi.io if you have additional questions or wish to exercise your rights.
7. Your data protection rights
As a Revi user, you have a series of rights recognized by the General Data Protection Regulation (GDPR) in relation to your personal data. You may exercise them at any time, free of charge and without the need for justification, by writing to us at hola@revi.io, indicating your identity and the specific request you wish to make.
7.1. Right of access
You have the right to obtain confirmation as to whether or not Revi is processing personal data concerning you, and if so, to access said data, as well as additional information about the processing we carry out (purposes, categories of data, recipients, retention period, etc.).
7.2. Right to rectification
You may request the correction or updating of your personal data if it is inaccurate, incomplete or outdated. This includes, for example, modifying your username, country, or correcting errors in your reviews.
7.3. Right to erasure (“right to be forgotten”)
You may ask us to delete your personal data when it is no longer necessary for the purposes for which it was collected, when you withdraw your consent or when it is being processed unlawfully. This right will apply provided there is no legal obligation or legitimate interest that requires us to retain it (for example, in cases of fraud prevention or exercise of legal rights).
When we fulfil your erasure request, we irreversibly delete the data that identifies you (name, email address, IP address and associated identifiers) both from your author identifier and from your published reviews, which are then displayed anonymously. If you also wish any of your reviews to no longer be publicly displayed, you can delete it individually from the “My Reviews” portal before requesting erasure, or indicate this in the request itself. Please note that reviews that have already been anonymized can no longer be linked to you and therefore cannot be selectively deleted afterwards.
7.4. Right to restriction of processing
You may request that we restrict the processing of your data when you contest its accuracy, the processing is unlawful and you oppose its erasure, we need to retain it for the exercise of claims, or you have objected to the processing and we are assessing the prevalence of our legitimate interests.
7.5. Right to object
You have the right to object to the processing of your personal data when it is based on our legitimate interest, especially in cases where it is used for direct marketing purposes or profiling. In such cases, we will stop processing your data unless there are compelling legitimate grounds.
7.6. Right to data portability
If the processing of your data is based on your consent or a contract, and is carried out by automated means, you may request to receive your data in a structured, commonly used and machine-readable format, or request that we transfer it directly to another controller, provided it is technically feasible.
7.7. Right to withdraw consent
When we have requested your consent to process your data (for example, for sending commercial communications or using non-essential cookies), you may withdraw it at any time, without this affecting the lawfulness of the processing carried out previously.
7.8. Limitations of these rights
Please note that some rights may be subject to certain limitations. For example, we will not be able to delete data that we are legally obligated to retain or if its erasure affects third-party rights. We will evaluate each case with transparency and duly inform you.
8. Information about minors
The Revi platform is not intended for persons under 18 years of age, and we do not knowingly collect personal data from minors of that age.
If you are a mother, father or legal guardian and believe that a minor in your care has provided us with personal data without your consent, please notify us as soon as possible by writing to hola@revi.io. We will proceed to review the situation and, if applicable, will securely delete said information in accordance with current regulations.
9. Changes to this policy
At Revi we may update this Privacy Policy at any time to reflect legal, technical or commercial changes that affect the processing of users’ personal data.
We will publish the modifications on this same page, indicating the date of the last update at the end of the document. We recommend that you periodically review this policy to stay informed about how we protect your information.
In the event that the changes substantially affect your privacy rights, we will notify you clearly and prominently, whether through our platform, by email (if you are registered) or through other appropriate means.
Continued use of our services after the publication or communication of said modifications shall imply acceptance of the changes introduced.
10. Data controller
- REVI DIGITAL S.L.
- Tax ID (NIF): B23839574
- Registered office: Calle Gaudencia Torres 9 16, 46015, Valencia, Spain
- Email: hola@revi.io
- Registered in the Commercial Registry of Valencia, volume 11,473, book 8,751, folio 81, page V-214487, entry 1st