REVLINE

Privacy

Plain, like everything else.

What we collect, why, where it lives, and how to make us change or delete it. Covers the website and the Revline portal and app. Last updated 7 October 2026.

The notice

Who we are

Revline is Revline Group Ltd, registered in England and Wales, company number 17391117, registered office 66 Paul Street, London, EC2A 4NA. This notice covers revlinehq.com, the booking calendar, client onboarding, and the Revline portal and app. Anything in this notice, ask us directly: support@revlinehq.com. Revline Group Ltd is the controller for everything in this notice, except where a section says otherwise.

What we collect, and why

Booking a call: your name, email, phone if you give it, and the appointment details, used to hold the call, send confirmations and reminders, and follow up. Legal basis: steps taken at your request before entering a contract. Client onboarding (your personal onboarding link): company and billing details, your name and contact details, and any figures you choose to share, used to set up your engagement, invoice correctly, and provision your workspace. Legal basis: performance of a contract. Website analytics: our own Revline beacon, which counts visits without storing anything on your device until you say otherwise; a CRM attribution script, so we know how people find us; and the Meta pixel, which measures our ads. The attribution script and the pixel store things on your device, so they run only after you accept. What each of those keeps, and for how long, is set out in full in our cookie policy, including how to change your mind later. Email: if you correspond with us, we keep the correspondence in our CRM.

At a glance: each use, its lawful basis, and how long we keep it

What forLawful basisHow long
Replying to the fit form and the Stack AuditSteps at your request; legitimate interests in answering enquiries2 years from our last contact
Booking and holding a callSteps at your request before a contract2 years from our last contact
Running a client engagement and invoicingContract; legal obligation for tax recordsThe engagement, then 6 years
Counting visits with our own beacon, nothing stored on your deviceLegitimate interests in knowing how the site is usedUp to 26 months, then aggregated
Ad attribution and the Meta pixel, stored on your deviceConsentUntil you withdraw; see the cookie policy
Emailing businesses from our lead bankLegitimate interests in business-to-business outreach2 years from collection or last contact
Hosting The Check-In and publishing episodesContract with guests; legitimate interests in publishing the showPublished episodes stay up; contact details as client data
Portal and app accountsContract; legitimate interests in securityWhile the account is open, then 6 years for records
Fixing errors (Sentry)Legitimate interests in a working service90 days

Forms on this website

See if we're a fit collects your answers to five questions, your name, email, and your phone and website if you give them, so we can reply about working together. The Stack Audit collects the suppliers you list, what each does, costs and reports, your monthly revenue band, your name, email, business name and website, so we can write and send your audit and follow up about it. Both also record the page you came from. Legal basis: steps taken at your request, and our legitimate interest in replying to enquiries. Both forms send your answers to our CRM (GoHighLevel). To stop spam we use a hidden field and count sends from each IP address for ten minutes in Cloudflare; the count is then discarded. If a form fails, Sentry receives the error and which form it was, without your answers. We keep form answers as prospect data, set out below.

The Meta pixel

With your consent, pages on this site load the Meta pixel. It tells Meta that a browser visited a page here and, if you send a form, that a form was sent, so we can measure which ads bring enquiries and show them to similar people. Meta can link this to a Meta account you are signed into. For the collection and sending of this data, Meta and Revline are joint controllers; what Meta does with it after that is covered by Meta's own privacy policy. Change your answer any time from the cookie policy; withdrawing reloads the page so the pixel stops at once.

Search engines and AI assistants

Our public pages are open to search engines and to AI assistants such as ChatGPT, Claude, Perplexity and Gemini, so they can read and cite what we publish. These pages hold information about Revline, never about you as a visitor. The qualifier is closed to them, and form answers are never published.

If we emailed you: our lead bank

We run cold email for Revline and for our clients. To do it we keep a lead bank: the name, job title, work email address, company, company website and public business signals (such as recent funding, hiring or advertising) of people at businesses who may want what we or a client sell. We collect these from public business sources such as company websites, business directories and professional profiles, and from business data providers, and we check that each address can receive email.

We use this information to send business-to-business emails about a relevant product or service, and to stop emailing anyone who asks. Our lawful basis is legitimate interests: ours and our clients' in reaching businesses that may benefit, balanced against yours, which is why every email says who is sending it and gives you a one-step way to stop. We keep each record for 2 years from when we collected it or last contacted you, then delete it. If you ask us to stop, we keep only your email address on a suppression list so you are never contacted again.

To object, have your record deleted or ask where we got it, reply to any email from us or write to support@revlinehq.com. Your right to object to direct marketing is absolute: we stop.

When we work for a client

When we run acquisition for a client, the leads, contacts and customer records in that client's systems belong to the client, who decides what happens to them. For that data we act on the client's instructions as their processor, under the data terms in our engagement agreement. Questions about it are best sent to the client; we will help them answer.

The Revline portal and app

The same company runs the Revline portal and the Revline app for iPhone and Android, the tools our reps, setters, staff, our growth partner, and our clients use to run the business day to day. Every account is issued by Revline; there is no public sign-up. Everything in this section applies to a portal or app account, in addition to everything above.

Facebook, Instagram and Meta ads

If you are a client, you can connect your Facebook Page, your Instagram professional account and your Meta ad account to Revline, using Meta's own Facebook Login for Business. You choose which accounts to share on Meta's screen, and you can change that at any time.

What we read from Meta

From your ad account: each campaign, ad set and ad, with its name, status, spend, impressions, reach, frequency, clicks, click-through rate, cost per thousand impressions, results, and the ad's image or video thumbnail. From your Facebook Page: its name, follower count, your posts, and Page Insights such as views and follows. From your Instagram account: its username, follower count, your posts and reels, and Insights such as reach, views, accounts engaged, profile views, link taps, saves and shares. These are totals for your accounts and your posts; they do not name the people who saw or engaged with them. We also keep the name and ID of each account you connect, and the name and email address Meta gives us for the person who connected them. We do not read your direct messages, and we do not read any account you have not connected.

Why we read it

To show you how your marketing is performing, next to the leads and bookings it produces, and to run the service you have hired us for. Legal basis: performance of our contract with you, and our legitimate interest in running and improving that service.

Who sees your Meta data

You and the people at your business you give a portal account to; Revline's own staff who work on your account; and, only if you have given us written permission, the partner who runs your ads or social content for you, currently Proteus Digital Ltd. A partner sees your marketing figures and lead and booking counts, read only, and never the names or contact details of your leads. We bind any such partner by contract to use your data only to work on your account, to keep it confidential, not to pass it on, and to delete it when the work ends, and we remain responsible to you for how they handle it. You can withdraw that permission at any time by emailing support@revlinehq.com; the partner's access stops the same working day.

Where Meta data is stored

On Revline's own server (meta.revlinehq.com and the portal's database), run through Coolify, with access tokens encrypted. Each client's data is kept separate from every other client's.

How long we keep Meta data

We keep the daily figures for as long as you are a client, because Meta itself keeps only a limited history and ours is the record of your growth, and then for up to six years for tax and contractual records. Details that identify a person, such as the name and email of whoever connected your accounts, are deleted when you disconnect or ask us to.

Disconnecting and deleting Meta data

You can disconnect at any time: remove Revline in your Meta Business Settings (under Partners or Business Integrations), remove it from your Facebook account under Settings, Business Integrations, or ask us. We stop reading from that moment. If you remove Revline from your Facebook account and ask for your data to be deleted, Meta tells us automatically and we delete it; you will be given a confirmation code and a page where you can check the request. You can also ask for deletion at any time by emailing support@revlinehq.com. We keep only what the law requires us to keep, as set out above.

Meta's own terms

Your use of Facebook, Instagram and Meta's ad tools stays under Meta's own terms and privacy policy. Our use of data received from Meta follows the Meta Platform Terms.

What the portal and app collect

Identity and contact: your name, email, phone, physical address if we need to invoice or reach you by post, and other contact info you give us for the job, including your Instagram and other posting accounts. Payment info: a rep's bank details for payouts, encrypted at rest and readable only when a founder reveals them to run a payment; every reveal is logged. Other financial info: pay and earnings, so you and we can both see what has been earned and paid. Messages: anything sent through the portal's messaging. Photos: your profile photo. Support requests: anything you send us to get help. Other user content: your bio, the Instagram handles of leads you work, and day reports. Identifiers: your account's user ID and, if you have the app installed, your device's push token, used only to deliver notifications to that device. Product interaction: when you were last active and which pages or features you used, so we know what is actually being used. Crash and performance data: collected automatically by Sentry when something breaks or runs slowly, so we can fix it.

Where it lives

Our CRM (GoHighLevel), our project workspace (ClickUp), Revolut for payments, Google Workspace for email and documents, Cloudflare for hosting, analytics and form handling, Sentry for error reports, and Meta for ad measurement when you consent. Some providers process data outside the UK under their own safeguards, standard contractual clauses or adequacy decisions.

Where portal and app data lives

The portal's database is Postgres, run on our own server through Coolify, not a third-party data platform. Beyond that: Cloudflare for network and security; Sentry for crash and performance monitoring; Google Workspace and Google Drive for invoices and internal documents; DocuSeal, which we run ourselves, for agreements and signatures; GoHighLevel for bookings and calendars; Apple's and Google's own push services to deliver notifications to your device; and Revolut for payments and payouts. Meta, for the Facebook, Instagram and ad accounts you choose to connect, as set out above.

What we never do

We do not sell personal data, share it with third parties for their marketing, or send marketing to client contacts who have not engaged with us. The portal and app carry no advertising and no tracking of any kind: nothing collected there is used to track you across other companies' apps or websites, and none of it is passed to a data broker.

If you apply to work with us

If you send us a Loom video as part of an application, we read the video and its transcript with the help of software, including AI, which suggests a score against our criteria. A person always makes the decision, and nothing is rejected automatically. The transcript is kept with your application and removed under our retention periods: 6 months for unsuccessful applicants, and 12 months for the talent pool if you have agreed to it. You can ask for a person to review your application without the software, and you can withdraw your consent to future contact at any time using the unsubscribe link in our emails.

How long we keep it

Enquiries from our forms and bookings: 2 years from our last contact. Lead bank records: 2 years from collection or last contact, as set out above. Client data: for the engagement plus the period we must keep records for tax and legal purposes, generally six years for contractual records. Portal and app data: for as long as your account is active, then for the same tax and legal periods once it closes. Payout bank details are deleted, not just hidden, once we no longer need them to pay you and any tax record requirement has passed.

Who processes data for us

  • GoHighLevel (LeadConnector): CRM, bookings, form leads and follow-up emails. United States.
  • Cloudflare: Website hosting, form handling, security and the cache behind our spam limits. United States and its global network.
  • Sentry: Error reports from the website forms, the portal and the app. United States.
  • Google Workspace: Email, documents and Drive. United States.
  • ClickUp: Project and task management. United States.
  • Revolut: Payments and payouts. United Kingdom and EEA.
  • Meta: The pixel, with your consent, and the accounts clients choose to connect. Ireland and United States.
  • Email sending, data and verification providers: Sending cold email, finding business contact details and checking addresses. United States and EEA.
  • Our own server, run through Coolify: The portal database and DocuSeal, which we run ourselves.
  • Apple and Google: Delivering app notifications. United States.

International transfers

Several processors above sit outside the UK. Each transfer relies on UK adequacy regulations (including the UK extension to the EU-US Data Privacy Framework, for US providers certified under it) or on the UK International Data Transfer Addendum to the EU standard contractual clauses. Ask us for a copy of the safeguard behind any provider.

Children

The website, the portal, and the app are not for anyone under 18. We do not knowingly collect data from a child, and if we learn that we have, we delete it.

Account and data deletion

Ask us to delete your account and its data at any time: email support@revlinehq.com, or use the delete request inside the app, under Account. We act on it, keeping only what we are required to keep for tax and legal purposes as set out above. This is also how the app meets Apple App Store Review Guideline 5.1.1(v): anyone who can open an account in the app can ask, from inside the app, for it to be closed.

Your choices

Push notifications: turn these off any time in your device's notification settings, or inside the app under Account. Photos: change or remove your profile photo any time inside the app under Account. Deletion: ask us to delete your account and data, as set out above.

Your rights

Access, correction, deletion, restriction, portability, objection, and withdrawing any consent you gave, without affecting what happened before: email support@revlinehq.com and we will act on it. If you think we have handled your data badly, you can complain to the ICO at ico.org.uk.