Privacy Policy

Last updated: 30 July 2026

This policy explains what RevCruise does with personal data. It covers two different groups of people, and the difference matters:

  • Merchants — people who create a RevCruise account and use it to generate and publish pages.
  • Shoppers — members of the public who visit a page a merchant has published. Shoppers never signed up for anything, so we deliberately collect as little about them as possible.

Who we are

RevCruise is operated by Random Unicorn SIA, a company registered in Latvia under registration number 40203681590, with its registered office at Paleju iela 52 - 2, Marupe, Marupes novads, LV-2167, Latvia. We are the data controller for the processing described below.

You can reach us about anything in this policy at help@revcruise.io.

What we collect from merchants

Account data. Your name and email address. If you sign in with Google we receive your name, email address and profile picture from Google — we never see your Google password. If you sign in with a password, we store only a hashed version of it. We also store a workspace record created automatically for you when you sign up.

Content you create. The product details and brand information you enter, the Shopify Buy Button embed code you paste, and the page content generated from them. We keep a record of each generation request (the inputs, the model used, and the output) so we can debug problems and improve quality.

Payment data. If you subscribe, payment is handled by Stripe. We never see or store your card details. We store the identifiers Stripe gives us — a customer ID, a subscription ID, the price you bought and its status — so we know what you have access to.

Product analytics. We use PostHog to understand how the product is used: pages viewed, actions taken (for example generating or publishing a page), and which of the three page types you choose. This is linked to your account, so it is personal data.

Session recordings. PostHog also records sessions inside the RevCruise app. This captures your interactions — clicks, navigation, and text you type into the app — so we can see where people get stuck. It does not cover pages you publish, and it does not capture card details, which are entered on Stripe's own hosted checkout rather than in our app. If you would prefer not to be recorded, email help@revcruise.io and we will exclude your account.

Support correspondence. Anything you send us by email.

What we collect from shoppers on published pages

When a merchant publishes a page with RevCruise, that page includes a small analytics script. It is deliberately minimal, and we want to be specific about what it does and does not do.

It collects:

  • that the page was viewed, and that a "Buy Now" button was interacted with;
  • the referring URL, if the browser sends one;
  • a coarse device category — mobile, tablet, or desktop, derived from the browser window width.

It does not:

  • set any cookies;
  • store IP addresses;
  • fingerprint the device or browser;
  • attempt to identify the visitor or follow them across sites.

Because of this we cannot identify individual shoppers, and the data is not linked to a person. It tells a merchant how many people saw a page and how many showed buying intent — nothing more.

Note that "Buy Now" counts are an approximation. Shopify renders its buy button inside an iframe, which our script cannot see into, so interest is inferred rather than measured exactly. Actual orders are recorded by Shopify, not by us.

When a shopper clicks through to checkout, they leave RevCruise. The checkout is the merchant's own Shopify store. We do not process the order, see the shopper's payment details, or receive their personal information. Shopify's and the merchant's own privacy policies apply from that point.

Who we share data with

We use the following providers. Each processes data on our behalf under a contract.

  • Railway — application hosting and database (United States)
  • Netlify — hosting merchant-published pages (United States)
  • Stripe — payment processing (United States / Ireland)
  • Resend — transactional email: sign-in links, verification, notifications (United States)
  • PostHog — product analytics and session recording (United States)
  • OpenAI — generating page content from your inputs (United States)
  • Google — sign-in, if you choose Google (United States)

The product details and brand information you enter are sent to OpenAI to generate page content. Do not enter anything confidential that you would not want processed by a third-party AI provider.

We do not sell personal data, and we do not share it for advertising.

International transfers

Our providers are largely in the United States. Where data leaves the European Economic Area, those transfers rely on the safeguards offered by the provider, typically the EU Standard Contractual Clauses or an adequacy decision such as the EU–US Data Privacy Framework.

Legal bases for processing

  • Performance of a contract — running your account, generating and publishing your pages, taking payment.
  • Legitimate interests — product analytics, session recordings, security, and preventing abuse. We limit these to what is needed to run and improve the service.
  • Consent — where we ask for it specifically.
  • Legal obligation — keeping records we are required to keep, such as for tax.

How long we keep it

  • Account and content data: while your account exists, and for a short period afterwards.
  • Generation records: retained to debug quality issues.
  • Session recordings: retained for a limited period, then deleted automatically.
  • Payment records: retained as long as tax and accounting law requires, typically several years.
  • Shopper analytics on published pages: retained in aggregate. It contains no identifiers, so it cannot be traced back to a person.

Your rights

If you are in the EEA or UK you can ask us to give you a copy of your data, correct it, delete it, restrict or object to how we use it, or provide it in a portable format. You can also withdraw consent where processing relies on it, and complain to your local data protection authority — in Latvia, the Data State Inspectorate.

Email help@revcruise.io and we will respond within one month.

Cookies

The RevCruise app and marketing site use cookies that are necessary to sign you in and keep you signed in, and cookies set by PostHog for analytics and session recording. Pages published by merchants through RevCruise set no cookies at all.

Children

RevCruise is a business tool and is not intended for anyone under 16. We do not knowingly collect data from children.

Changes

If we make a material change to this policy we will update the date at the top and, where the change is significant, tell account holders by email.

Contact

help@revcruise.io