Legal

Privacy Policy

This policy explains how Revaru handles personal data when you visit our website, contact us, or use the Revaru service.

1. Who is responsible for your data?

The Revaru legal entity identified in your order form, subscription, or invoice is the data controller for website visitors, prospects, and merchant account contacts. Contact us at feras.swe@gmail.com.

When a merchant uses Revaru to manage customer returns, the merchant normally acts as controller and Revaru processes customer data on the merchant’s documented instructions. Those responsibilities are governed by the merchant agreement and data processing terms.

2. Data we process

  • Contact details, such as your name, work email, company, and store URL.
  • Account and workspace details, including roles, settings, and integration configuration.
  • Return and order information supplied by merchants and their connected services.
  • Billing, subscription, invoice, and payment-status information.
  • Technical and security data, including timestamps, device or browser information, logs, and IP addresses.
  • Messages and requests you send through demo, integration, support, or other contact flows.

3. Why we use personal data

To provide the service

We process account, store, return, and integration data to perform our contract and deliver Revaru.

To operate safely

We use technical and security information where necessary for our legitimate interests in preventing abuse, protecting accounts, troubleshooting, and maintaining reliable operations.

To respond and improve

We use contact and request information to answer enquiries, arrange demos, prioritise integrations, and improve the service. Where required, we ask for consent.

To meet legal obligations

We may retain or disclose information when required by accounting, tax, security, or other applicable law.

4. Who receives data?

We use carefully selected providers for cloud hosting, databases, email delivery, payments, support, and security. Connected commerce platforms, carriers, and payment providers receive information only when needed for the workflow chosen by the merchant.

If data is transferred outside the EU/EEA, we use an applicable legal transfer mechanism, such as an adequacy decision or approved standard contractual clauses, together with appropriate safeguards.

5. How long we keep data

We keep personal data only for as long as needed for the purpose collected. Account and operational data is generally kept while the customer relationship is active and for a limited period afterwards for support, security, disputes, and legal obligations. Merchant-controlled return data follows the merchant agreement and documented instructions. Billing records are retained for the period required by applicable accounting law.

6. Your rights

Depending on the circumstances, you may request access, correction, deletion, restriction, or portability of your personal data, and object to certain processing. Where processing is based on consent, you may withdraw it. Contact us to exercise a right.

You may also lodge a complaint with the Swedish Authority for Privacy Protection (IMY) or the data protection authority where you live or work.

7. Security and changes

We use technical and organisational measures designed to protect personal data. No service can guarantee absolute security, so we continually review access, encryption, monitoring, and incident processes.

We may update this policy when our service or legal obligations change. The effective date above identifies the current version.