Privacy Policy
REVLO ("we", "us", "our") operates the REVLO referral management platform at joinrevlo.com and through the REVLO mobile app. This policy explains what we collect, how we use it, and the choices you have.
Information we collect
- Dealership account info: business name, address, owner name, email, phone.
- Referrer account info: name, email, phone, optional address, tax ID last 4 digits (for 1099 threshold tracking).
- Referral data: lead names, contact details, status, notes, commission amounts.
- Payment information: processed by Stripe. Dealerships add a card via Stripe Checkout; referrers complete onboarding via Stripe Connect Express. We do not store full card numbers, bank account numbers, or CVCs. We only store Stripe references (customer ID, payment method ID, connected account ID).
- Authentication data: hashed password (scrypt), session cookie (revlo.sid), last login timestamp.
- Usage and device data: standard server logs (IP, user agent, request paths) for security and debugging.
How we use information
- Operate the referral platform: route leads to dealerships, track pipeline, calculate commissions, send notifications.
- Process payouts from dealerships to referrers via Stripe Connect.
- Track IRS $600 1099-NEC thresholds per referrer for tax compliance.
- Send transactional emails (welcome, referral submitted, commission approved, cashout receipts).
- Secure the service: rate limiting, abuse detection, debugging.
Third parties we share with
- Stripe (payment processing, Stripe Connect, identity verification) — stripe.com/privacy
- Google / Gmail SMTP (transactional email delivery)
- Replit (application hosting)
- Neon / Postgres (managed database)
We do not sell personal information. We do not share data with advertisers.
Cookies
We use a single first-party session cookie (revlo.sid) to keep you signed in. No third-party advertising or analytics cookies are set.
Data retention
Account and referral data is retained while your account is active. Upon written request to privacy@joinrevlo.com, we will delete personal data within 30 days, except records we are legally required to retain (e.g. 1099 tax records).
Account deletion
You can permanently delete your REVLO account and all associated personal data at any time:
- In the REVLO mobile app: Open Settings → Delete Account (dealership admins) or Profile → Delete Account (referrers). Type
DELETEto confirm. Deletion is immediate and permanent. - On the web: Visit joinrevlo.com/delete-account to submit a deletion request.
- By email: Email privacy@joinrevlo.com from the address on file and we will delete your account within 30 days.
When you delete your account we permanently remove: your profile, all referrals and rewards you created, your saved Stripe references (we also cancel any active subscription and detach your Stripe Connect Express account), all sessions, and any uploaded files. Dealership owners who delete their account delete the entire dealership tenant — all team members, referrers under that rooftop, and their referral history. We retain only records we are legally required to keep (for example, 1099-NEC tax records for paid commissions, billing invoices, and abuse logs) for the period required by law.
Your rights
You may request access, correction, deletion, or export of your personal data at any time by emailing privacy@joinrevlo.com. California residents (CCPA) and EU/UK residents (GDPR) have additional rights including the right to object to processing and the right to lodge a complaint with a supervisory authority.
Children
REVLO is not intended for, and not directed to, children under 13. We do not knowingly collect data from children under 13.
Changes to this policy
We will post any changes here and update the effective date. Material changes will be emailed to account owners.
Contact
Questions: privacy@joinrevlo.com