Privacy Policy
How we collect, use, and protect your information.
RevvWorks Privacy Policy
Updated August 11, 2026
Previous version: June 2, 2026
1. General Information Regarding This Privacy Policy
Welcome, and thank you for your interest in RevvWorks.
Who We Are: “RevvWorks,” “Revv.Works,” “we,” “our,” or “us” refers to RevvWorks Inc., a corporation based in Ontario, Canada.
This document explains how RevvWorks collects, uses, and shares your personal information when you use our Services. When we say “Services,” we mean everything we provide, including consulting, support, our websites (https://revv.works and its subdomains), and our software applications.
This Privacy Policy document, together with the Terms of Service and any additional terms you may agree to with us, form a binding legal agreement between you and RevvWorks. Collectively, this legal agreement is referred to as the “Terms.”
By using our Service, you agree to the collection and use of your information as described in this policy.
2. Acceptance
By using any of our Services, you agree to the Terms, including the collection and use of your information as described in this policy.
If you don’t agree with the Terms, please don’t use our Services.
3. What is Personal Data?
Personal Data is information about an individual who can be identified. It can include information you give us directly (like your name or contact details) and information collected automatically when you use our services (like website usage data). Anonymous data that cannot be linked to an individual is generally not considered personal data.
4. Information We Collect
We collect and process personal data from individuals associated with the businesses we serve, such as business owners, CEOs and managers. The types of information we collect include:
- Contact Information: Your name, email address, and phone number, which you provide when you sign up for our services, join a waiting list, or book a meeting.
- Business-Related Information: As part of our service to help businesses improve, we collect information on strategic plans, financial data, operational processes, sales, and staffing. While this information is about the business, it may contain personal data about individuals connected to the business.
- Information from Interactions: We may collect information about how you interact with our website and services (Usage Data). This can include device information or IP address. Our website uses a privacy-focused analytics service to measure aggregate traffic; see Section 10.
- Information from Systems You Connect or Upload: If you connect a business system to the Services, or upload an export from one, we receive the data that the integration or file contains. See Section 5.
- Information from Third Parties: We may receive information about you from other sources if you use third-party services integrated with ours or interact with us through platforms where others provide your data.
If you provide personal data about someone else, you must confirm that you have their permission or are otherwise allowed to give us that information.
5. Data From Business Systems You Connect or Upload
The Services are designed to work with the business systems you already use. You may connect an integration, upload an export file, or have a system send reports to an intake address we provide, from systems such as accounting, scheduling, booking, and practice-management software. However the data reaches us, we receive what that system contains, which may include personal information about your own customers, clients, patients, members, staff, or vendors.
Data minimization. Our Services are built for business and operational analysis, not for care of your end customers, and we ask you to send us only the data the Services actually need. Where a file you upload contains directly identifying columns that the Services do not require, our import process removes them before the data is stored.
Sensitive information. We do not seek personal health information or other sensitive categories of personal information, and we ask that you not send them to us beyond what the Services require. We do not use data from connected systems to provide clinical care or to make decisions about your end customers.
Your responsibility. If you are a health information custodian, or are otherwise subject to sector-specific privacy law such as Ontario’s Personal Health Information Protection Act (PHIPA), you are responsible for determining what you may lawfully send us and for obtaining any notices and consents required from the individuals concerned. This mirrors Section 11 of our Terms of Service. If you believe you have sent us information the Services do not need, contact us at privacy@revv.works and we will work with you to delete it.
6. Messaging Channels
Some Services can be used through third-party messaging channels, including the WhatsApp Business Platform operated by Meta. Access to these channels is limited to people who hold a RevvWorks account and who accepted these Terms and this Privacy Policy when their account was created.
We do not operate a channel between you and the public. These channels are not a way for you to message your own customers, and we do not receive messages from members of the public through them.
When you use a messaging channel, the content of your messages, together with the phone number and profile information that the channel makes available, passes through that provider’s infrastructure. The provider handles that information under its own terms and privacy policy in addition to this one, so you should review them before using the channel. If you give a member of your team access, they will need their own RevvWorks account, and you are responsible for making sure they understand that their messages are processed as described here.
7. How We Use Your Information
We use your personal data for specific purposes:
- Providing and Improving Services: To deliver our services as described in our Terms of Service, which include helping improve business strategy, operations, and revenue. This involves using the business-related information you provide.
- Improving and Developing Our Services: To improve the accuracy and capability of the Services, we use Business-Related Information to test and refine our models, algorithms, and features, and to develop new ones. When we use your information for general improvement and development (as distinct from providing the Services directly to you) we do so only on an aggregated and/or anonymized basis, meaning it is processed in a way that does not identify your specific business or any individuals within it to other users or the public. Our legitimate interest in this processing is to provide a continually improving and innovative service. Section 8 separately explains what happens when your data is processed by third-party AI providers as part of delivering the Services to you.
- Communication: To maintain contact with you, respond to your inquiries, and communicate with you about our services. This includes sending communications to individuals who opt into our waiting lists or who book meetings with us.
- Service Operation: To manage your account, provide customer support, and improve our website and applications.
- Security and Fraud Prevention: To ensure the safety and security of our services and users, and to prevent fraudulent or illegal activities.
- Business Operations: For internal business purposes such as data analysis, usage trends, and evaluating the effectiveness of our services.
We process your personal data only as legally allowed, primarily to fulfill our contract with you, pursue legitimate business interests (including, for example, internal R&D; CRM and customer retention; audit / compliance), or with your consent.
8. AI Processing
Parts of the Services use artificial intelligence provided by third parties. This is separate from the improvement and development described in Section 7: to answer your questions and generate results, the Services send relevant content to these providers as part of normal operation, and that content is not aggregated or anonymized first. Specifically:
- Anthropic receives the content of your conversations with our AI features, including any business data contained in them, in order to generate responses.
- Cohere receives text drawn from your business data in order to generate embeddings, which are numeric representations used for search and retrieval within the Services.
- Serper.dev receives web search queries generated from your requests.
- Firecrawl receives the addresses of public web pages we retrieve on your behalf, such as your own public website, and returns their content.
Training. These providers do not use the content we send them to train their models. Where a provider allows model training by default, we have turned it off for our account. We do not currently hold zero-retention agreements with these providers, which means they may retain submitted content for a limited period under their standard terms — for example, for security, abuse monitoring, and legal compliance. Serper.dev and Firecrawl operate on public web content and search queries rather than on your stored business records.
Accuracy. AI-generated output may be inaccurate or incomplete. Section 12 of our Terms of Service sets out your responsibility to review it before relying on it.
9. How We Share Your Information
We do not sell your personal information, and we do not share it in exchange for money or other valuable consideration. We do not disclose your confidential business information to third parties except as described in this policy or as legally required. We may share your personal data in the following situations:
- With Service Providers and Sub-processors: We use third-party companies to help us operate and deliver the Services. Section 10 lists them. These providers are required by contract to process your data securely and only for the purposes we specify.
- With Affiliates: We may share information with our affiliates, who must adhere to this Privacy Policy.
- Business Transfers: If RevvWorks is involved in a merger, acquisition, or sale of assets, your personal data may be transferred to the relevant parties involved in the transaction. This is subject to confidentiality agreements and applicable data protection law.
- With Your Consent: We may share your information with other third parties when you give us explicit consent to do so.
- Legal Requirements: We may disclose your personal data if required by law or in response to valid requests by public authorities. Section 9 of our Terms of Service describes how we handle legal demands, including our practice of notifying you where we are permitted to do so.
10. Service Providers and Sub-processors
There are two kinds of third parties involved in the Services, and they work differently:
- Providers you connect. Integrations you choose to link, or files you choose to upload, from systems such as accounting, scheduling, booking, and practice-management software. You control whether these are connected, and your use of them is governed by your agreement with that provider. See Section 5.
- Providers we choose (sub-processors). Companies we engage to run the Services. You do not select these, so we identify them here. Where they process personal information on our behalf, they do so under contracts requiring appropriate security and confidentiality safeguards, and RevvWorks remains accountable for that information under PIPEDA.
The list below is current as of August 11, 2026.
Application and infrastructure
| Provider | What it does for us | Primary processing location |
|---|---|---|
| Render.com | Hosts our primary application database | United States |
| Fly.io | Application hosting | Canada |
| Google Cloud (Cloud Storage, BigQuery, Looker Studio) | File and artifact storage, analytics warehouse, customer dashboards | Canada and United States |
| Cloudflare | Hosts and delivers revv.works; delivers and protects app.revv.works; bot protection on our website forms | Global edge network |
AI and data retrieval
| Provider | What it does for us | Primary processing location |
|---|---|---|
| Anthropic | AI models that generate responses and analysis | United States |
| Cohere | Text embeddings for search and retrieval | United States |
| Serper.dev | Web search results | United States |
| Firecrawl | Retrieval of public web page content | United States |
Communication and business operations
| Provider | What it does for us | Primary processing location |
|---|---|---|
| Resend | Sends transactional and notification email, and receives report emails sent to our intake addresses | United States |
| WhatsApp Business Platform (Meta) | Messaging channel for account holders (see Section 6) | United States |
| Stripe | Payment processing | United States |
| Attio | Customer relationship management; receives enquiry and sign-up form submissions from revv.works | United States |
Monitoring and analytics
| Provider | What it does for us | Primary processing location |
|---|---|---|
| Rollbar | Application error monitoring; payloads are scrubbed of personal information before they are sent | United States |
| Slack | Internal alerting to our own team; payloads are scrubbed of personal information before they are sent | United States |
| Umami Cloud | Aggregate website analytics for revv.works | European Union |
| PostHog | Product analytics within the application | United States |
Cookies and similar technologies. We do not use advertising cookies or cross-site tracking cookies, and we do not run a cookie consent banner because we do not set any cookie that would require one.
Our website analytics service, Umami, does not use cookies. It records aggregate page views, and stores a single flag in your browser’s local storage only if you choose to opt out.
When you are signed in to our application, it sets a session cookie that keeps you logged in as you move from page to page. That cookie is required for the application to work, is not readable by scripts running in your browser, and is not used for analytics or advertising.
Cloudflare, which delivers and protects both our website and our application, may also set cookies that are strictly necessary for security, such as telling automated traffic apart from real visitors. These are set for security purposes only, and are not used to track you across other websites or to build a profile of you.
We may add or replace sub-processors as the Services change. When we do, we will update this section and the date above.
11. International Data Transfers
RevvWorks is based in Ontario, Canada, and stores and processes personal information in Canada and the United States.
Our application servers run in Canada.
Files which you upload and those the Services generate are stored in Google Cloud Storage in the country you choose for your organization when you set up your account, either Canada or the United States. That choice applies to stored files only.
Your account records, the data drawn from the systems you connect, and the reports and analyses the Services produce are held in our primary application database, which is currently hosted in the United States.
Information is subject to the laws of the country it is held in, including access by that country’s courts, law enforcement, and regulators. Most of the providers listed in Section 10 are United States companies, and information they hold may be subject to United States legal process whichever country it is stored in. Section 9 of our Terms of Service sets out how we respond to legal demands for your information.
We protect information transferred to these providers through contracts requiring appropriate security and confidentiality safeguards, and we review a provider’s security practices before adopting it. Under PIPEDA, RevvWorks remains accountable for personal information transferred to a service provider for processing, and a comparable level of protection must be maintained while it is in that provider’s hands.
12. Data Retention
We will keep your personal data only for as long as necessary to fulfill the purposes for which we collected it, or as required by law. When data is no longer needed for legal or business purposes, we will delete it securely.
You can ask us to delete data you have provided or uploaded by contacting privacy@revv.works. Some copies may persist for a limited period in encrypted backups before they are overwritten on their normal cycle.
13. Security of Your Information
We take security seriously. While we do our best to protect your personal information, internet transmissions aren’t entirely secure, and any transmission is at your own risk. Once received, we use strict security measures to keep your data safe.
14. If There Is a Data Breach
If personal information in our care is lost, or is accessed, used, or disclosed without authorization, we will:
- investigate and take steps to contain the incident;
- assess whether the breach creates a real risk of significant harm to any affected individual;
- where that risk exists, report the breach to the Office of the Privacy Commissioner of Canada and notify affected individuals, as PIPEDA requires, and notify any other regulator where the law requires it;
- notify the affected account holder without undue delay after we confirm the breach, with the information reasonably available to us at the time so you can meet your own notification obligations; and
- keep a record of breaches of security safeguards, as PIPEDA requires.
15. Children’s Privacy
We do not knowingly collect personal information from anyone under the age of 13. If we learn that we have inadvertently collected personal information from a person under 13, we will take steps to delete the information as soon as possible.
16. Links to Other Services
Our website and services may contain links to external sites or services that are not operated by us. We are not responsible for third-party content or privacy practices.
17. Your Privacy Rights
Depending on where you live, you may have certain rights regarding your personal data. These rights may include:
- Access: The right to request a copy of the personal data we hold about you.
- Correction: The right to request that we correct any inaccurate personal information that we maintain about you.
- Deletion: The right to request the deletion of your personal data in certain circumstances. Please note that legal obligations may prevent us from deleting all data immediately.
- Opt-out of Marketing: The right to ask us to stop sending you direct marketing communications. You can usually do this through account settings or by contacting us.
- Withdraw Consent: Where we process your data based on your consent, you have the right to withdraw that consent at any time.
- Object to Processing: The right to object to our processing of your data if based on legitimate interests.
To protect your information, we may need to verify your identity before processing your request.
If you are dissatisfied with how we have handled your personal information or your request, you may complain to the Office of the Privacy Commissioner of Canada.
A note for our business customers: where we hold personal information about your customers, clients, patients, members, or staff because you provided it to us, we act on your behalf. If one of those individuals contacts us directly with a request, we will generally refer them to you and support you in responding.
18. Changes to This Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in our practices or legal requirements. When we do, we’ll post the updated policy here, change the “Updated” date at the top, and keep the prior version available (see the “Previous version” link at the top of this page).
If we make significant or material changes, we will notify you, for example, by email or by posting a prominent notice on our website before the changes take effect.
19. Contact Us
If you have any questions, comments, or requests regarding this Privacy Policy or our handling of your personal data, please contact our privacy team at:
RevvWorks Inc.
6244-2100 Bloor St. West
Toronto, ON, M6S 5A5 Canada
Email: privacy@revv.works
You can also use this contact information to exercise your privacy rights.