Privacy Policy

Last updated: August 26, 2026

This Privacy Policy explains how RevCard (“RevCard”, “we”) processes personal data collected through our mobile application, website and related services (together, the “Service”). By using the Service, you agree to the practices described in this policy.

1. Information We Collect

  • Account information: your email address and password when you create an account (passwords are stored in an irreversibly hashed form).
  • Profile and content: your name, profile picture, bio and the links you add (social media, phone, email, address, IBAN, Wi-Fi network name and password, and custom links). This content is displayed on your public card page at your own choice. If you set a PIN to protect a link, the PIN is stored in an irreversibly hashed form.
  • Usage and analytics data: view and click counts for your card pages and unique-visitor statistics. Unique counts are based on a visitor identifier stored in the visitor’s own browser (see section 5).
  • Technical data: your IP address, processed to secure the Service and prevent abuse (rate limiting). When someone opens a public card page we also record the page they arrived from (referrer), their browser and device information (user agent) and the country their request came from, so that the card owner can see basic statistics for their own page.

2. How We Use Information

  • To provide, maintain and improve the Service.
  • To create your account and verify your identity.
  • To publish your card page and the links you add.
  • To provide you with analytics about your own pages.
  • To ensure security and prevent fraud and abuse.
  • To comply with our legal obligations.

3. How We Share Information

We do not sell your personal data and we do not share it for advertising. There is no advertising, analytics or tracking software from any third party in our mobile app.

Your data is shared only with the service providers we need in order to run the Service, and only for that purpose: Supabase (database, authentication, file storage and server functions), Vercel and Cloudflare (website hosting and request handling), and Google (delivery of the account e-mails we send you, and the web fonts a public card page loads when its owner has chosen a non-default typeface). These providers process data on our instructions under agreements that require them to protect it to the same standard as this policy, and they may process it on servers outside your country.

Information you publish on your public card page is visible to anyone who opens that page.

4. Data Retention and Security

Your data is encrypted in transit (HTTPS). Sensitive fields such as passwords and PINs are stored in an irreversibly hashed form.

We keep your account, profile and link content for as long as your account exists. View and click statistics are kept for as long as the card they belong to is linked to your account. Short-lived security records used for rate limiting and failed-attempt limits are deleted automatically within 24 hours. When you delete your account, everything above is deleted as described in section 6; after that we retain only what the law requires us to keep.

5. Cookies and Local Storage

Our website uses cookies that are necessary to maintain your session. These cookies keep you signed in after logging in and are not used for marketing.

The first time you open a public card page, a randomly generated visitor identifier is written to your browser’s local storage under the name “revcard_vid”. It is used only to count the same visitor once in the view and click statistics; it is random, contains no personal information, and is not used for advertising or profiling. It is written and read only by our own domain, is never passed to third parties, and cannot be used to follow you across other sites. Clearing your browser’s site data deletes it. If your browser does not allow local storage (in a private window, for example), no identifier is created at all.

Alongside it we also store, with every recorded view, an irreversible hash derived from your IP address and browser information. The hash cannot be turned back into an IP address; it exists so that repeat views can still be counted once when no local-storage identifier is available.

6. Your Rights and Deleting Your Account

Subject to applicable law, you have the right to access, correct, delete, restrict or object to the processing of your personal data, to receive a copy of it, and to lodge a complaint with your data protection authority.

You do not need to ask us to delete your account — you can do it yourself, immediately, and it takes effect at once:

This permanently deletes your account, profile, groups, links, uploaded images and the statistics for your pages. Your physical cards are not destroyed — they are detached from the account and can be activated again later. For anything else, write to us at the address in section 9.

7. Children’s Privacy

You must be at least 13 years old — or older, where the law of your country sets a higher minimum age for consenting to online services — to create a RevCard account. The Service is not directed to children below that age and we do not knowingly collect their personal data. If you believe a child has created an account, write to us and we will delete it.

8. Changes to This Policy

We may update this policy from time to time. Updates take effect on the date they are published on this page, and the “Last updated” date at the top is revised accordingly.

9. Contact

For questions about this Privacy Policy or your personal data, you can contact us at muhammedgordag@revlith.com.

© 2026 RevCard. All rights reserved.