Privacy Policy
What we collect, on what basis, who receives it, where it is stored and what you can ask of us.
Updated: August 28, 2026
This is a courtesy translation. The binding version of this policy is the Hebrew version; if the two diverge, the Hebrew version prevails.
1. Who this document applies to
revyou ("we" or "the service") operates two kinds of pages, and the information collected on each differs:
- The marketing site — the pages you are reading now, aimed at business owners.
- A business's review page — the page a customer reaches after tapping the tag or scanning the QR code at a business.
This policy applies to any use of these pages. Using them does not require providing information; wherever information is collected, we spell out below exactly what, why and to whom.
2. You are under no legal duty to provide information
You are not required by law to provide us with any personal information. Providing information — in the contact form, in the private-feedback form or in any other way — is done of your own free will and with your consent, which is the legal basis for processing it. The only consequence of not providing it is that we cannot get back to you or pass the feedback to the business — no other part of the site is conditioned on it.
3. What is collected from a customer on a business's page
The customer is not asked to register, install an app or provide any details to use the page. What is stored is only what they chose to share:
- The face they picked — happy, neutral or unhappy — and when.
- The service or topic selected, if one was selected.
- How the visit ended — continuing to Google, private feedback, or leaving.
- On the private-feedback path only: the text the customer wrote, the topics they marked, and contact details (name, phone or email) — if and only if they chose to leave them, so the business can get back to them.
What is not collected: the customer's name, email address or location — unless volunteered in private feedback — and the review they published on Google. The Google review is written and published directly with Google, under the customer's own account and subject to Google's privacy policy; we do not see it and do not store it.
4. What is collected from a business owner who leaves details
The contact form stores the business name, the contact person's name, a phone number or email, a website or Google page if provided, the plan marked as interesting and the free-text message. These are used solely to get back to you, prepare an example and manage the engagement.
5. Technical information
As on any website, our infrastructure providers keep basic technical server logs of requests — such as IP address, browser type and request time — for security, troubleshooting and operations only. These logs are kept for a short period and are not used by us to identify visitors or build profiles.
6. Cookies
The public pages — the marketing site and the review pages — set no cookies for advertising, marketing or tracking, and run no third-party analytics or trackers. The internal admin interface, used by our team only, uses essential storage strictly for managing sign-in.
7. What the information is used for
- Delivering private feedback to the business it was written to.
- Showing the business trends and aggregate data for its page.
- Responding to business inquiries and managing sales and engagement.
- Operating, securing and improving the service.
- Meeting legal obligations, if and to the extent they apply.
The information is used for no purpose beyond these.
8. Who the information is shared with
- The business: private feedback, including any contact details left in it, reaches the business it was written to. The business is bound to us to use those details solely to handle that feedback.
- Infrastructure providers: Supabase (database) and Vercel (hosting) process data on our behalf, under our instructions and their data-processing agreements.
- Authorities: where required by law, court order or a competent authority's demand.
The information is not sold, not rented and not passed to advertisers or other commercial parties — not today and not in the future, except by a policy change published in advance.
9. Where the information is stored — transfer abroad
Data is stored on Supabase servers in the European Union (eu-central-1, Frankfurt), and the site is served through Vercel. Storing data in EU member states is permitted under the Privacy Protection (Transfer of Data to Databases Abroad) Regulations, 5761-2001, since the data protection law that applies there (GDPR) ensures a level of protection no lower than Israeli law.
10. How long the information is kept
- Feedback and sentiment choices — for as long as the business subscribes to the service, so it can see the trend over time; they are deleted or anonymized within a reasonable time after the subscription ends.
- Contact-form inquiries — for as long as they are relevant to a sales process or an existing engagement.
- Technical server logs — for a short period, per the providers' policies.
You may request earlier deletion at any time, as set out in the rights section.
11. Mailing and marketing messages
Submitting the contact form lets us get back to you about that inquiry. We will not send you marketing material by email, SMS or any other means without explicit prior consent, as required by section 30A of the Israeli Communications Law (Telecommunications and Broadcasting), 5742-1982. If you consent to receive updates, you can withdraw that consent at any time with an opt-out message, and we will stop immediately.
12. Your rights
Under the Israeli Privacy Protection Law, 5741-1981, and its regulations, you may:
- Access the information kept about you. We will respond to an access request within 30 days at most.
- Request correction or deletion of information that is inaccurate, incomplete or out of date.
- Request removal from direct mailing and deletion of the information used for it.
- Complain to the Privacy Protection Authority if you believe your privacy has been violated — details at www.gov.il/he/departments/the_privacy_protection_authority.
A customer who left contact details in private feedback can approach the business directly or us, and we will see to deletion on our side as well.
13. Data security
We apply security measures in line with the Privacy Protection (Data Security) Regulations, 5777-2017, including: encrypted traffic (HTTPS) on every page; admin sign-in by one-time email link, with no passwords, against an allow-list of approved addresses only; and row-level access control in the database, so a business sees its own data only. No system is completely immune, but in the event of a severe security incident we will act under the regulations, including reporting to the Privacy Protection Authority and notifying those affected as required.
14. Minors
The service is not designed to collect information from minors, and we do not knowingly collect personal information from children. The review page requires no details at all. A parent or guardian who believes a minor has given us details is welcome to contact us and we will delete them.
15. Changes to this policy
If we change what we collect or how we use it, we will update this document and the date at its top. A material change for the worse will be published prominently on the site before it takes effect.
16. Contact
For any question, request or complaint about privacy, contact us through the contact form on the site. We keep a record of every inquiry and the response given.