Skip to main content
← Back to home

Privacy Policy

Last updated: 11 September 2026

1. Introduction

RevNext ("we", "us", "our") operates the RevNext platform at revnext.io(the "Service"). This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our Service.

By using RevNext, you agree to the collection and use of information in accordance with this policy. If you do not agree, please do not use the Service.

Google API Services / Limited Use Disclosure

RevNext's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

Google scopes we use: RevNext requests access to Google Calendar (creating and reading calendar events). This data is used only to provide the user-facing calendar and booking features - creating meetings for your bookings and keeping your availability in sync. We do not use Google user data for advertising, and we do not sell it or transfer it to third parties except as needed to provide these features.

2. Information We Collect

2.1 Information you provide

  • Account information - name, email address, and organisation details when you sign up via Clerk (our authentication provider).
  • Client and lead data - names, email addresses, phone numbers, social media handles, and any other information you enter about your clients and leads within the platform.
  • Payment information - processed and stored by Stripe. We do not store full card numbers on our servers.
  • Content - messages, notes, templates, forms, check-in responses, and any other content you create within the platform.

2.2 Information collected automatically

  • Usage data - pages visited, features used, and interaction patterns via Vercel Analytics and Speed Insights.
  • Device information - browser type, operating system, and device identifiers.
  • Log data - IP addresses, access times, and referring URLs.

2.3 Information from third-party integrations

When you connect third-party services (Stripe, Google, Zoom, Calendly, Notion, Meta/Instagram/Facebook/WhatsApp, or others), we may receive data from those services as authorised by your integration settings. This may include:

  • Customer and payment records from Stripe
  • Calendar events and availability from Google Calendar
  • Meeting links and scheduling data from Zoom
  • Scheduling and booking data from Calendly
  • Messages and conversation data from Instagram, Facebook Messenger, and WhatsApp
  • Database records from Notion
  • Publicly available business review content from Google (via the Google Places API), displayed on your public pages if you add a Google Reviews block

3. How We Use Your Information

We use the information we collect to:

  • Provide, operate, and maintain the Service
  • Process transactions and send related information (invoices, receipts)
  • Send you administrative communications (account updates, security alerts)
  • Provide customer support
  • Generate AI-powered insights, page content, and report suggestions using Anthropic's Claude models, and AI image generation and content moderation using OpenAI. Under our commercial API agreements with these providers, data submitted through their APIs is not used to train their models unless we explicitly opt in to that (we have not).
  • Fetch and analyse the layout of a web page you paste into our "Inspire from URL" feature, using Cloudflare Browser Rendering, so we can generate a similarly structured page for you - see how RevNextBot works for details on what it reads and does not read
  • Deliver social messaging features (Instagram DM, Facebook Messenger, WhatsApp)
  • Monitor usage patterns to improve the Service
  • Detect, prevent, and address technical issues or abuse

4. Data Sharing and Disclosure

We do not sell your personal data. We may share information with:

  • Infrastructure providers - Vercel (application hosting, file storage, and analytics), Neon (Postgres database, hosted in the EU), Upstash (Redis, used only for rate limiting and short-lived operational data), and Clerk (authentication and session management) - to run the Service itself.
  • Payments- Stripe, for platform billing and for processing your clients' payments if you use Stripe Connect within RevNext.
  • Email - Resend, for transactional email delivery (hosted in the EU), including branded open/click tracking links on emails you send from your own domain.
  • AI features - Anthropic (content generation, insights, and lead scoring) and OpenAI (image generation and content moderation only). See Section 3 for how we use these.
  • Analytics and monitoring - PostHog (product analytics), Sentry (error monitoring and, with your consent, session replay diagnostics), and Vercel Analytics/Speed Insights (cookieless usage metrics).
  • Cloudflare- video hosting and delivery (Stream), bot protection on public forms (Turnstile), and page rendering for the "Inspire from URL" feature (Browser Rendering).
  • Third-party integrations you choose to connect - Google (Calendar sync and public review display), Zoom (meeting scheduling), Meta (Instagram, Facebook, and WhatsApp messaging, and pixel-based advertising analytics where enabled with consent), Calendly (schedule sync), Notion (data import), Trustpilot (review widget), and Unsplash (stock image search) - each used only within the scope of the feature you enable.
  • Legal requirements - if required by law, regulation, legal process, or governmental request.
  • Business transfers - in connection with a merger, acquisition, or sale of assets, your data may be transferred as part of that transaction.

5. Data Security

We implement industry-standard security measures to protect your data:

  • AES-256-GCM encryption for stored integration credentials and sensitive data
  • All data transmitted over HTTPS/TLS
  • Authentication and session management via Clerk with MFA support
  • Multi-tenant data isolation - every database query is scoped by organisation
  • Rate limiting on all mutation endpoints
  • Webhook signature verification for all incoming third-party data
  • Static application security testing (SAST) via Semgrep on every code change, complemented by Sentry error monitoring and PostHog product analytics that help us spot problems quickly

While we strive to protect your data, no method of transmission or storage is 100% secure. We cannot guarantee absolute security.

6. Data Retention

We retain your data for as long as your account is active or as needed to provide the Service. If you cancel your subscription:

  • Your data remains accessible for 30 days after cancellation
  • You may export your data (leads, clients, payments) as CSV during this period
  • After 30 days, your data is permanently deleted from our systems

7. Your Rights

Depending on your jurisdiction, you may have the right to:

  • Access - request a copy of the personal data we hold about you
  • Rectification - request correction of inaccurate data
  • Erasure - request deletion of your personal data (see our Data Deletion page)
  • Portability - request your data in a machine-readable format
  • Restriction - request that we limit processing of your data
  • Objection - object to processing based on legitimate interests

To exercise any of these rights, contact us at support@revnext.io.

8. Cookies and Analytics

RevNext uses essential cookies for authentication and session management - these are required for the Service to work and are always active.

PostHog (product analytics) runs by default in a cookieless mode - stored only in memory, nothing written to your device - so we can see aggregate usage before you make a choice. If you accept via the cookie banner, it upgrades to persistent storage (cookies and local storage) so we can recognise you across visits; if you choose Essential only, it stays in cookieless, memory-only mode. Sentry session replay(anonymised, text-masked session diagnostics) only starts if you accept - it never runs pre-consent. You can change your mind by clearing this site's data in your browser, which will show the banner again.

With your consent, we also load the Meta Pixelfor advertising analytics - both on RevNext's own marketing pages and, if a coach has added their own Pixel ID, on that coach's public pages. It does not load before you accept.

We use Vercel Analytics for aggregate usage insights (cookieless), and Sentry error monitoring to detect faults (no cookies) - both run regardless of your cookie choice, on the basis of our legitimate interest in keeping the Service working. Other than the consent-gated Meta Pixel described above, we do not use advertising or cross-site tracking cookies.

9. Third-Party Services

Our Service integrates with third-party platforms. Each has its own privacy policy:

10. Children's Privacy

RevNext is not directed at individuals under the age of 16. We do not knowingly collect personal data from children. If you become aware that a child has provided us with personal data, please contact us and we will delete it.

11. International Data Transfers

Your data may be processed in countries other than your own, including the United States (where our hosting and service providers operate). We ensure appropriate safeguards are in place for any such transfers.

12. Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of any material changes by posting the updated policy on this page with a revised "Last updated" date. Your continued use of the Service after changes constitutes acceptance of the updated policy.

13. Contact Us

If you have questions about this Privacy Policy or our data practices, contact us at:

Email: support@revnext.io
Website: revnext.io