Privacy Policy
How Revara handles personal data
Revara is quote, invoice and client management software for small businesses. We use personal data to provide the service, secure accounts, process subscriptions, send transactional emails, support users and meet legal, accounting and security obligations.
1. Who we are and how to contact us
Revara provides software for managing clients, quotes, invoices, credit notes, document details, subscriptions and support requests. You can contact us at support@revara.uk. Website enquiries may also be sent to info@revara.uk.
For data protection matters, use support@revara.uk. Revara has not appointed a Data Protection Officer at this stage.
2. Our role: controller and processor
For account administration, billing, support, security, website enquiries and service operation, Revara acts as the controller of personal data.
For client and document data that a Revara customer enters about their own customers, Revara usually acts as a processor/service provider on behalf of that Revara customer. The Revara customer remains responsible for deciding what client data is entered, why it is used, who receives documents and how long it should be kept, except where Revara must process limited information for security, legal compliance, billing, dispute handling or service operation.
3. Information we collect and process
Depending on how Revara is used, we may process:
- account details, such as name, email address, business or trading name and optional telephone number;
- login and security data, including encrypted or hashed password/authentication records managed through Supabase Auth, hashed one-time passcode records, session metadata, password reset, password change, reauthentication and email-change events;
- private beta allowlist data, where enabled, such as approved email addresses and internal notes visible only to service administrators;
- business and document details, including legal or trading name, business address, business email, telephone number, VAT number, company number, bank account name, sort code, account number and uploaded logo;
- client records entered by users, including customer names, companies, email addresses, telephone numbers, billing addresses, notes, system activity events and document history;
- quotes, invoices, credit notes, line items, PDF documents, statuses, immutable issued-document records, email-send records, reminder records and online quote response records, including accept or decline status, response time and any decline reason provided;
- subscription and billing information, including plan, subscription status, Stripe customer IDs, Stripe subscription IDs, connected Stripe account status, checkout records, invoice payment attempt records, verified invoice payment records and safe billing reconciliation records;
- support and contact messages, including name, email address, optional mobile number, message content and whether the message came from the public website or signed-in support area;
- technical, security and operational data, such as API request metadata, rate-limit events, error logs, provider event identifiers, browser/device metadata available from requests and safe operational logs.
We do not intentionally collect special category data. Users should not enter special category data, payment-card numbers, passwords, authentication codes or unnecessary sensitive information into client notes, documents or support messages.
4. How we use information
We use personal data to:
- create, verify, authenticate and secure Revara accounts;
- provide client, quote, online quote response, invoice, credit note, PDF, document branding, dashboard, analytics and subscription features;
- send account, security, support, quote, invoice, credit note, reminder, welcome and subscription emails;
- process subscriptions, manage access to Basic, Plus and Pro plans and prevent billing abuse, duplicate checkout issues and subscription mismatches;
- enforce plan limits, rate limits, private beta access where enabled, account deletion controls and security protections;
- respond to support requests, investigate faults, improve reliability and maintain service records;
- protect Revara, users and third parties against fraud, misuse, unauthorised access, cross-account access, spam and technical abuse;
- comply with legal, accounting, tax, dispute, regulatory and security obligations.
5. Lawful bases
Our lawful bases under UK data protection law may include:
- Contract: to provide Revara, create accounts, manage subscriptions, generate documents, send requested transactional emails and provide support.
- Legitimate interests: to secure the service, prevent misuse, maintain logs, improve reliability, manage business operations, investigate faults and protect legal rights.
- Legal obligation: where records must be kept or processed for tax, accounting, regulatory, court, fraud prevention or law-enforcement reasons.
- Consent: where required for optional communications or any future non-essential cookies or analytics.
6. Payments and subscriptions
Subscription payments and optional online invoice payments are handled by Stripe. Revara does not store full card numbers, card security codes, bank account details, identity documents or KYC files. Stripe may process payment details, billing details, transaction information, connected-account onboarding information, payout information and fraud-prevention data under its own privacy and security controls. Revara stores the limited Stripe identifiers, subscription state, connected-account status and invoice-payment records needed to open Checkout, activate plans, manage billing portal access, reconcile billing and payment events, and show payment history safely.
7. Service providers and recipients
We use trusted providers to operate Revara, including Supabase for authentication, database and private storage, Vercel for hosting and serverless functions, Stripe for subscription billing and Resend for transactional email delivery. We may also use DNS, domain, security, logging or support tools required to operate the service.
We share personal data with these providers only where needed to provide, secure, monitor and support Revara. We may disclose data if required by law, court order, regulator, payment dispute process or to protect Revara, users or third parties.
8. Emails sent through Revara
Revara may send account verification codes, password reset or change codes, reauthentication codes, email-change notices, support messages, quote emails, invoice emails, credit note emails, quote response notifications, reminders, plan welcome emails and subscription cancellation notices. Document emails are sent on behalf of the user’s business and may include customer information and attached PDFs chosen by that user.
Quote recipients may use secure quote response pages without creating a Revara account. When they accept or decline a quote, Revara may process their response, response time, optional decline reason and limited technical/security metadata needed to operate and protect the response link. These events may be shown to the Revara user in quote status and client activity records.
9. Cookies, local storage and similar technologies
Revara uses necessary browser storage and session mechanisms so users can sign in securely, keep a session active and use the app.
10. Security
Revara is designed with account-level access controls, Supabase Row Level Security, server-side validation, private storage for sensitive documents and logos, protected Stripe webhook handling, rate limiting, immutable issued-document controls, safe error responses and log redaction. No internet service can be guaranteed completely secure, but we use technical and organisational safeguards intended to reduce risk.
11. Data retention and deletion
We keep account and workspace data while the account is active. If a user deletes their account through Revara, the software is designed to cancel a verified active Stripe subscription where required, globally sign out the session, delete the Supabase Auth user, remove associated workspace records and remove owned private storage objects such as logos and issued document PDFs, subject to records we are required or permitted to retain.
Limited records may be retained where needed for legal, accounting, tax, fraud prevention, payment disputes, security investigation, backup recovery, provider logs or defence of legal claims. Where possible, retained operational records are limited to what is necessary and should not include unnecessary document contents.
Users should export or retain any business, accounting or tax records they need before deleting their account. Revara account deletion may remove records that the user later needs for their own legal or accounting obligations.
12. International transfers
Some providers may process data outside the UK. Where this happens, appropriate safeguards should be used, such as UK adequacy regulations, standard contractual clauses, the UK International Data Transfer Addendum or equivalent lawful transfer mechanisms.
13. Your rights
Depending on the circumstances, you may have the right to access, correct, delete, restrict or object to processing of your personal data, request portability of your data and withdraw consent where processing is based on consent. These rights may be limited in some cases, for example where we must keep records for legal, accounting, security or dispute reasons.
You can contact us at support@revara.uk. You also have the right to complain to the UK Information Commissioner’s Office at ico.org.uk.
14. Your responsibilities for customer data
Revara users may add personal data about their own customers or clients. Users are responsible for ensuring they have a lawful basis to add, store, use and email that information through Revara, and for providing their own privacy information to customers where required. Users are also responsible for checking recipient addresses before sending documents or reminders.
15. Automated decision-making
Revara does not currently make solely automated decisions that have legal or similarly significant effects on individuals. Automated controls may enforce security, rate limits, plan limits, document state rules and billing access, but these are operational controls for service integrity.
16. Children
Revara is intended for business use and is not aimed at children. Users should not create accounts or submit personal data if they are under 18.
17. Changes to this policy
We may update this Privacy Policy as Revara develops. Material changes should be reflected on this page, with the updated date shown above. If a change materially affects how we use personal data, we will take reasonable steps to bring it to users’ attention.