RevVane
Platform Solutions Pricing Integrations Docs
Log in Start free
  • Platform
  • Solutions
  • Pricing
  • Integrations
  • Docs
Log in Start free

Legal

Privacy Policy

What RevVane collects, why we hold it, how long we keep it, and what you can make us do with it.

Last updated: 2026

Privacy Terms Cookies DPA Subprocessors Security
Draft

This document is a draft for review. It has not been reviewed by qualified legal counsel and must be before RevVane accepts paying customers. Nothing on this page is legal advice. Bracketed values are placeholders and are not real details.

1. Who we are

RevVane is operated by [LEGAL ENTITY], a company registered in [JURISDICTION], registered address [ADDRESS]. In this policy, "we", "us" and "RevVane" mean that entity. "You" means the person or business using the service.

Data protection contact: [PRIVACY CONTACT EMAIL]. We have not appointed a Data Protection Officer; where one is required, the appointee will be named here as [DPO NAME AND CONTACT].

2. The short version

  • We hold your account details, your workspace configuration, and the call and search data you connect.
  • We never use customer call data — recordings, transcripts, or the labels we derive from them — to train models. See section 5.
  • For call recordings and transcripts you are normally the controller and we are your processor. See section 4.
  • You can export everything, at any tier, at any time, and you can tell us to delete it.

3. What we collect

3.1 Account data

Name, work email address, hashed password, workspace name and role, invitations you send, and authentication events (sign-in times, IP address, user agent) kept for security.

3.2 Workspace data

Configuration you create: workspaces, seats, connection settings, API keys, saved views, alert rules, and the credentials for connected sources. Source credentials and API tokens are stored encrypted and scoped to a single workspace.

3.3 Connected-source data

When you connect a source (Ringba, Google Search Console, and later CSV, Sheets, CallRail and similar), we import the records that source exposes. For call platforms this typically includes:

  • Call metadata — timestamp, duration, connected time, inbound and caller number, caller geography, campaign, target, publisher, payout and revenue fields, disposition codes, duplicate flags, attribution tags.
  • Call recordings — where your call platform holds them and you enable analysis. We fetch the recording to transcribe it.
  • Transcripts and derived labels — the text of the call and the structured read we attach: outcome, intent score, estimated job value, spam and voicemail flags, and a dispute recommendation.
  • Search data — queries, pages, clicks, impressions and positions from Search Console, which contain no personal data of callers.

3.4 Usage and telemetry

Product events (pages viewed, features used, exports run, sync and analysis job outcomes), error traces, and request logs. We use this to keep the service working and to decide what to build. We do not build advertising profiles from it.

3.5 Billing data

Plan, billing contact, invoices and payment status. Card details are handled by our payment processor (see subprocessors) and are never stored on our systems. No call data is sent to the payment processor.

3.6 Support and correspondence

Messages you send us, and any call examples you attach to a support request.

4. Call recordings and transcripts — read this section

A call recording contains the personal data of a third party: the caller. So does the transcript, and so do labels derived from it. That caller is not our customer and has no relationship with us. This is the most sensitive data on the platform and we treat it accordingly.

  • Roles. For account and billing data we are the controller. For call metadata, recordings, transcripts and derived labels you connect, you are normally the controller and we act as your processor, processing only on your documented instructions. The Data Processing Addendum sets out those terms.
  • Lawful basis for the recording is yours. You are responsible for having a lawful basis and, where the law requires it, consent and notice for recording and for sending those recordings to a processor. Recording consent rules differ by jurisdiction — including all-party consent states in the US — and by whether the call was disclosed as recorded. We cannot assess that for you.
  • Transcripts may contain anything the caller said, including addresses, health details, financial details or other special-category data. Do not connect a source whose recordings you are not entitled to process.
  • Caller requests. If a caller contacts us directly about a recording, we will normally direct them to you as the controller and notify you, unless the law requires otherwise.

5. We do not train models on your call data

Your recordings, transcripts, labels and revenue data are not used to train, fine-tune or evaluate any model, ours or a third party's. This applies on every plan, including trials, and there is no setting that turns it off.

Transcription and labelling run through third-party AI providers. We select providers on the basis that they offer a no-training, zero-retention processing configuration, and we will name each provider and the applicable contractual terms on the subprocessors page once each agreement is executed. Until a vendor is named there, treat it as not yet confirmed.

Aggregate, non-identifying operational statistics (for example, how many calls failed to transcribe) are used to run and improve the service. These contain no call content.

6. Why we process, and on what legal basis

Where UK/EU data protection law applies to us as controller, we rely on:

  • Performance of a contract — creating your account, running syncs and analysis, billing, and providing support.
  • Legitimate interests — securing the service, preventing abuse and fraud, debugging, and product analytics. Balanced against your rights; you may object (section 11).
  • Legal obligation — tax, accounting, and responding to lawful requests.
  • Consent — where we ask for it explicitly, for example optional product emails. You can withdraw consent at any time.

For the caller personal data inside recordings and transcripts, the legal basis is determined by you as controller, not by us.

7. Who we share it with

  • Subprocessors. A short list, published and kept current at /subprocessors: speech-to-text, LLM routing, cloud hosting, and payments. No subprocessor receives customer data until it is under a written agreement binding it to process only on our instructions, under confidentiality and security obligations. Vendors still shown there as to be confirmed are not yet contracted.
  • Professional advisers — accountants and lawyers, under confidentiality.
  • Legal and safety — where we are required by law, or to establish or defend legal claims. We will notify you of a request for your data unless legally prohibited.
  • Business transfer — if the business is acquired or merged, data may transfer with it, subject to this policy or a materially equivalent one, with notice to you.

We do not sell personal data. We do not share it for cross-context behavioural advertising. We do not disclose one customer's data to another customer.

8. International transfers

Our infrastructure and subprocessors are located in [HOSTING REGIONS]. Where personal data leaves the UK or EEA, the transfer relies on [TRANSFER MECHANISM — ADEQUACY DECISION / STANDARD CONTRACTUAL CLAUSES / UK IDTA] together with a transfer risk assessment. A copy of the mechanism is available on request from [PRIVACY CONTACT EMAIL].

9. How long we keep it

Retention periods below are proposed and must be confirmed before launch.

DataRetentionOn deletion request
Account and workspace data Life of the account + [N] days Deleted or anonymised
Call metadata and derived labels [N] months rolling Deleted
Recordings fetched for transcription Not stored after transcription completes[CONFIRM] Not applicable
Transcripts [N] months, or until you purge Deleted
Logs and telemetry [N] days Aged out on schedule
Invoices and tax records As required by law in [JURISDICTION] Retained — legal obligation

Backups persist for a short window after deletion and are then overwritten on their own cycle. Data in backups is not restored into the live service except as part of a full disaster recovery.

10. Security

Passwords are hashed with argon2. Source credentials are held in an encrypted, per-workspace vault. Tenant isolation is default-deny: a workspace can only reach its own data. Authenticated state-changing requests carry CSRF protection. Our technical and organisational measures are described at /security and in Annex II of the DPA.

We do not hold a SOC 2 report or any other security certification, and we do not claim one.

11. Your rights

Subject to the law that applies to you, you can ask us to:

  • Access — confirm what we hold and get a copy.
  • Export — take your data out. Full CSV export is available in-product on every tier without asking us.
  • Correct — fix inaccurate account or workspace data. Labels our models produce are human-correctable in-product.
  • Delete — erase your data, subject to records we must keep by law.
  • Object or restrict — object to processing based on legitimate interests, or ask us to pause processing while a dispute is resolved.
  • Portability — receive data in a structured, machine-readable format.
  • Withdraw consent — where processing relies on consent.

Exercise any of these through /contact or by writing to [PRIVACY CONTACT EMAIL]. We will respond within the period the applicable law requires — [RESPONSE PERIOD] unless extended, and we will tell you if it is extended. We may need to verify your identity first.

If you are a caller whose call was recorded by one of our customers, the business you called is the controller of that recording. Contact them first. If you cannot identify them, write to us and we will pass the request on.

US state privacy laws: we do not sell or share personal data as those terms are defined, and we do not use it for targeted advertising or profiling with legal effects. Rights to know, delete, correct and appeal are handled through the same route above.

You may also complain to your supervisory authority. In the UK that is the Information Commissioner's Office; in the EEA it is the authority for your country. We would rather you came to us first.

12. Cookies

We use one strictly necessary cookie and no advertising or cross-site tracking cookies. Details are in the Cookie Policy.

13. Children

RevVane is a business tool. It is not directed at children and we do not knowingly collect personal data from anyone under [AGE THRESHOLD FOR JURISDICTION]. Callers' ages are not something we can verify; if you learn that a recording you connected concerns a child and should not be processed, delete it or tell us and we will.

14. Changes to this policy

We will post the updated policy here with a new "last updated" year and, for material changes, notify account owners by email at least [NOTICE PERIOD] before the change takes effect.

15. Contact

Write to [PRIVACY CONTACT EMAIL], use /contact, or post to [LEGAL ENTITY], [ADDRESS].

Terms of Service Cookie Policy DPA Subprocessors Security
RevVane

Call intelligence for businesses that answer the phone. Hear what callers wanted, and what your team couldn't answer.

Product

  • Platform
  • Call analysis
  • Demand intelligence
  • Team performance
  • Tracking & revenue
  • API & MCP
  • Pricing

Solutions

  • Business owners
  • Lead generation
  • Call networks
  • Agencies
  • Home services
  • Multi-location

Integrations

  • All integrations
  • Ringba
  • Search Console
  • Google Sheets
  • Claude / MCP

Resources

  • Glossary
  • How we count
  • Docs
  • Changelog
  • Who it isn't for

Company

  • About
  • Who it isn't for
  • Security
  • Contact
  • Privacy
  • Terms
We never train models on your calls Export everything, any time
© 2026 RevVane. No contracts, no setup fees.