Revly

Privacy Policy

How Revly collects, uses, and protects information for businesses and their customers.

Last updated: 6 September 2026

1. Who we are

Revly (“we”, “us”) provides QR code review assistance, digital menu, and website services for restaurants, cafes, and other hospitality businesses. Revly is based in London. You can reach us through our contact form.

2. Information we collect

Business client information

End-customer (reviewer) information

Revly's QR review flow is designed to collect as little as possible:

3. How we use information

4. Legal bases (GDPR)

Where the UK GDPR applies, we process business client data on the basis of contract (to deliver the service) or legitimate interests (to respond to enquiries and improve our service). Anonymous reviewer interaction data does not relate to identified individuals.

5. Sharing

We do not sell personal data. We share data only with service providers necessary to run the business: hosting and content delivery (Cloudflare), email delivery (Resend), and Google Fonts for typography. These providers process data on our instructions. Business information shown on a client's generated website or menu is published at the client's direction.

6. Cookies

Our website uses no advertising or tracking cookies. Only strictly necessary, functional cookies may be used (for example to remember session state). Google Fonts is loaded from Google's servers, which may log the request.

7. Retention

We keep business client records for the duration of the business relationship and as long afterwards as reasonably needed for accounts, tax, or legal purposes. Anonymous usage statistics are kept in aggregate form only.

8. Your rights

If you are a business client or have received outreach from us, you may request access to, correction of, or deletion of your personal data, object to our processing, or request that we restrict it. You can also lodge a complaint with the UK Information Commissioner's Office (ico.org.uk). To exercise any right, use our contact form. We respond within 30 days.

9. Security

We apply reasonable technical and organisational measures to protect the information we hold, including encrypted connections (HTTPS) and access controls. No method of transmission over the internet is completely secure, and we cannot guarantee absolute security.

10. Changes

If we change this policy we will update the date above and, for material changes, notify affected business clients by email.