Legal
Privacy Policy
Last updated: July 2026
Revinsta helps hospitality businesses manage their online reviews. This policy explains what personal data we process, why, and the rights you have over it. It covers both our customers (the businesses that create Revinsta accounts) and the guests whose data those businesses process through Revinsta.
Data we process about our customers
When you create an account we store your name, email address, and a one-way hash of your password (we can never read the password itself). If you sign in with Google we store the identifier Google provides. As you use the product we store the content you create: properties, review replies, brand-voice settings, surveys, team invitations, and an audit trail of administrative actions. Billing is handled by Stripe; we store your subscription status and customer reference, never your card details.
Data we process on behalf of our customers
Revinsta ingests publicly posted reviews (author display name, rating, review text, date, platform) from sources our customers connect, such as Google. Customers may also provide guest contact details (name, email, checkout date) from their property-management system or by upload, which we use solely to send a single post-stay feedback invitation on that customer's behalf. For this data the customer is the controller and Revinsta is a processor: we act on the customer's instructions, and requests about this data should be directed to the business you stayed with. Every such email contains a one-click unsubscribe; unsubscribed addresses are added to a suppression list and never contacted again.
AI processing
Review text is sent to our AI providers to draft replies, classify topics, translate, and generate summaries. We send only what is needed for the specific task, our providers are contractually barred from using this data to train their models, and generated drafts are always subject to our customer's review before publication unless the customer explicitly enables automation.
Where data lives and how long
Data is stored in our hosted database in the European Union, encrypted in transit and at rest, with platform credentials additionally encrypted at the application level. We keep account data while the account exists and for a short wind-down period afterwards; error logs are kept for 30 days; backups age out on a rolling schedule. When a property or account is deleted, its reviews, drafts, analytics and stored credentials are permanently removed.
Sharing
We share data only with the service providers needed to run Revinsta: hosting, email delivery, payment processing, and AI inference. We do not sell personal data, and we never share guest contact details with anyone other than the business that provided them.
Your rights
Depending on where you live (including under the GDPR), you may have the right to access, correct, export, or delete your personal data, and to object to or restrict certain processing. Account holders can exercise most of these directly in the product; for anything else, contact us at the address below and we will respond within 30 days. If you are a guest of a Revinsta customer, contact that business first; we will support them in fulfilling your request.
Cookies
Revinsta uses only functional storage: a session token to keep you signed in and a small number of preference values (such as theme). We set no advertising or cross-site tracking cookies.
Contact
Questions about this policy or your data: use the contact form linked in the site footer and choose the privacy topic. We will update this policy as the product evolves and note material changes here.