Skip to content

Legal

Privacy Policy

Last updated September 2026

How Reveliqo handles personal data — both the data of people who use Reveliqo, and the visitor data we process on a customer's behalf.

Data we hold about our own users

Account details, workspace membership, billing information and product usage needed to operate the service and support you. We do not sell it and we do not share it with advertising networks.

Visitor data is processed, not owned

Edge request records, browser events, business events, aggregates and analysis traces are processed on the customer's instructions as a processor. Their DPA governs that relationship, not this policy — the website you visited is the controller.

What is collected by default

Reveliqo is designed to minimise. Defaults avoid storing request bodies, authentication headers, cookies, arbitrary query strings and secrets. Campaign parameters are read from an allowlist, unknown parameters are discarded or redacted, and route templates replace identifiers in paths so /orders/883729 is stored as /orders/:id.

Identity modes

Minimal mode stores no persistent visitor identifier. Visit mode adds a short-lived first-party visit identifier where a customer configures it and their policy permits. Customer mode uses a pseudonymous account key the customer's own application supplies. No fingerprinting is required for the core product.

IP addresses

The edge needs an address to route a request; that is how the internet works. Reveliqo does not retain raw addresses in analytics storage beyond the short-lived processing the edge itself requires, and derived signals such as country are stored instead.

AI processing

Selected aggregates, metric results and context are sent to AI providers so an analysis can be planned and explained. Which providers and models may process data is disclosed and, on enterprise plans, controllable. Customer data is not used to train shared models without an explicit agreement.

Retention

Raw events, aggregates, analysis traces and archives have configurable retention. Deleting a site deletes its events, aggregates and indexes within a defined window, and the DPA states that window.

Your rights

Access, correction, export and deletion. For visitor data collected on a customer's site, requests go to that customer as controller and we assist them as processor.

Contact

Write to [email protected] for anything in this policy, including requests about your own personal data.

This is placeholder legal copy for the marketing site. Replace it with your reviewed Terms & Privacy before launch.