Privacy Policy

Last updated: September 6, 2026

1. Introduction

Revly ("we," "our," or "us") operates the Revly platform at revly.io and app.revly.io. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our website and services.

2. Information We Collect

Account Information: When you create an account, we collect your name, email address, and password.

Product & Review Data: We collect information about the products you add to Revly and the reviews we monitor or collect on your behalf, including review content, ratings, reviewer names, and platform metadata.

Usage Data: We automatically collect information about how you interact with our services, including pages visited, features used, and device/browser information.

Cookies: We use essential cookies to keep you logged in and functional cookies to remember your preferences. We do not use third-party advertising cookies.

Integration Data: If you connect Slack, we store your Slack workspace ID and name, the bot access token Slack issues to Revly (encrypted at rest), the ID and name of the channel you select for notifications, and which Revly user made the connection. See "Slack Integration" below.

3. How We Use Your Information

We use the information we collect to:

  • Provide, maintain, and improve our services
  • Monitor and aggregate reviews from third-party platforms on your behalf
  • Generate AI-enhanced review drafts from customer feedback
  • Send you notifications about new reviews and platform activity
  • Respond to your support requests
  • Protect against fraud and abuse

4. How We Share Your Information

We do not sell your personal information. We may share information with:

  • Service Providers: Third-party services that help us operate our platform (e.g., hosting, AI processing, email delivery)
  • Slack: If you connect the Revly Slack app, we send review notifications (rating, review title and text, reviewer name, and links to the review and to your Revly dashboard) to the Slack channel you choose. Nothing is sent to Slack until you connect it, and nothing else is sent.
  • Legal Requirements: When required by law, subpoena, or legal process
  • Business Transfers: In connection with a merger, acquisition, or sale of assets

5. Data Security

We implement industry-standard security measures to protect your data, including encryption in transit (TLS), secure cloud infrastructure (AWS), and access controls. However, no method of electronic storage is 100% secure, and we cannot guarantee absolute security.

6. Data Retention

We retain your account information and review data for as long as your account is active. If you delete your account, we will delete your personal data within 30 days, except where we are required to retain it for legal purposes.

7. Your Rights

Depending on your location, you may have the right to:

  • Access the personal data we hold about you
  • Request correction of inaccurate data
  • Request deletion of your data
  • Export your data in a portable format
  • Opt out of marketing communications

To exercise these rights, contact us at hello@revly.io.

8. Third-Party Platforms

Our service interacts with third-party review platforms (Shopify, G2, QuickBooks, WordPress, Xero, WooCommerce, and others). Review data collected from these platforms is subject to their respective terms of service and privacy policies. We access only publicly available review information.

9. Slack Integration

You can connect Revly to Slack from Settings → Integrations so that review notifications are posted to a Slack channel you choose. This section explains how we collect, use, store, and delete Slack data.

What we collect from Slack

When you authorize the Revly Slack app, Slack gives us your workspace ID and name and a bot access token. When you pick a channel, we store that channel's ID and name. We also record which Revly user made the connection. We request three permissions: chat:write (post messages to the channel you choose), channels:read (list your public channels so you can pick one), and groups:read (list the private channels Revly has been invited to, for the same purpose).

How we use it

We use the bot token only to list your channels in the channel picker and to post review notifications to the one channel you select. We never read messages, member profiles, files, or any other content from your Slack workspace, and we do not send direct messages to your members.

How we store it

The bot token is encrypted at rest (AES-256-GCM) on our AWS infrastructure and is never displayed in the Revly interface or returned by our API.

How long we keep it

We keep the connection for as long as it is active. When you press Disconnect in Revly, we revoke the token with Slack and delete the stored workspace, token, and channel details immediately. Deleting your Revly account does the same. If you remove the app from Slack's side instead, Slack invalidates the token; you can then delete the remaining record via Disconnect in Settings or by emailing hello@revly.io.

Your choices

You can change the channel, pause notifications, or disconnect Slack at any time from Settings → Integrations. To request a copy of, or the deletion of, any Slack-related data we hold, email hello@revly.io.

10. Children's Privacy

Our services are not directed to individuals under 18. We do not knowingly collect personal information from children.

11. Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of material changes by posting the updated policy on this page and updating the "Last updated" date.

12. Contact Us

If you have questions about this Privacy Policy, please contact us at hello@revly.io.