Merchant-directed
Customer and order information is processed to provide services configured and requested by the merchant.
Data processing
This overview explains the expected roles, data categories, purposes, safeguards, subprocessors, retention practices, and privacy assistance involved in providing the Reveu Shopify application.
Processing principles
Reveu aims to process personal information only where it is needed to provide merchant-selected features, support the service, protect the platform, or meet legal obligations.
Customer and order information is processed to provide services configured and requested by the merchant.
Information should not be used for unrelated purposes simply because it is technically available.
Access is intended to be limited to authorised systems, providers, and people who require it for legitimate work.
Privacy, uninstall, and merchant-data cleanup workflows are included in the application design.
When a merchant uses Reveu to collect reviews, send review requests, display storefront content, import reviews, or operate conversion tools, Reveu may process information on the merchant’s behalf.
Normally determines why customer and store information is used and which Reveu features are enabled.
Processes information required to provide and secure the configured application services.
Provides the commerce platform, application interfaces, store administration, and relevant merchant data.
May provide hosting, storage, communications, monitoring, or other supporting infrastructure.
01
This page provides general information about how Reveu expects to process personal information when providing its Shopify application.
It is intended to help prospective merchants understand the application’s data-processing model before launch.
This page does not currently:
The final processing terms may be updated as Reveu completes infrastructure decisions, launch testing, provider selection, and merchant agreements.
02
A Shopify merchant will normally act as the controller for personal information relating to its customers, orders, fulfilments, products, customer communications, submitted reviews, and storefront activity.
The merchant determines matters such as:
Reveu expects to act as a processor where it handles personal information on behalf of a merchant to provide merchant- selected application functionality.
Reveu may act as an independent controller for limited information it determines how and why to use for its own legitimate operations.
This may include:
Reveu’s controller activities are described further in the Privacy Policy.
03
Depending on the features enabled by a merchant, Reveu may perform operations such as:
04
Personal information processed through Reveu may relate to:
05
Depending on the application features used, information may include:
Store identity, Shopify domain, administrator details, application configuration, theme settings, and support communications.
Name, email address, customer or order references, and information required to send or validate review requests.
Product, order, fulfilment, purchase, delivery, and communication-preference information relevant to review collection.
Ratings, titles, written comments, images, submission dates, verification details, replies, reports, and helpful votes.
Product names, handles, IDs, variants, SKUs, images, and other information used to match and display reviews.
Request data, event records, application errors, security information, browser details, and operational diagnostics.
Reveu is not designed for merchants or customers to submit passwords, payment-card details, authentication codes, health information, government identifiers, or unnecessary special-category personal information.
06
Reveu expects to process merchant-controlled information for purposes including:
Reveu does not intend to sell merchant customer information to third parties.
07
Reveu expects to process merchant-controlled personal information only on documented instructions, except where applicable law requires different processing.
Merchant instructions may be communicated through:
Reveu may refuse an instruction where it would be technically impossible, unsafe, unlawful, inconsistent with Shopify requirements, or outside the agreed service.
08
Reveu applies technical and organisational measures intended to protect personal information against unauthorised access, disclosure, alteration, loss, or destruction.
Current and planned measures include:
Further details are available on the Security page.
09
Reveu may use service providers to support hosting, storage, email delivery, security, monitoring, networking, and related application operations.
Provider categories may include:
The public website currently uses Google Firebase and Cloud Firestore for waitlist and contact-form submissions.
Shopify provides the underlying commerce platform and relevant application interfaces. Shopify’s precise legal role may depend on the processing activity and its relationship with the merchant.
Reveu will publish or make available a confirmed application subprocessor list before the Shopify application becomes generally available. The list should identify the provider, service purpose, and relevant processing location.
10
Some infrastructure or service providers may process information outside the United Kingdom.
Where an international transfer is restricted by applicable data-protection law, Reveu expects to use an appropriate legal mechanism and supplementary safeguards where required.
Depending on the destination and provider, mechanisms may include:
Confirmed transfer locations and mechanisms should be included in the final subprocessor information and Data Processing Agreement.
11
Application data should be retained only for as long as needed to provide the service, follow merchant instructions, protect the application, resolve disputes, or meet applicable legal obligations.
Retention may depend on:
Reveu includes workflows intended to remove relevant merchant, customer, review, media, and configuration information after applicable privacy requests or application uninstall events.
Information may be retained where deletion is technically delayed by secure backups or where continued retention is legally required. Any retained information should remain protected and should not be used for unrelated purposes.
12
Where a merchant acts as controller, individuals should normally direct requests about their store information to that merchant.
Subject to the final DPA and applicable law, Reveu expects to provide reasonable assistance with requests involving:
Reveu may need to verify that a request comes from the relevant merchant or an authorised person before taking action.
Requests involving information controlled directly by Reveu may be sent to hello@reveu.me.
13
If Reveu becomes aware of a confirmed personal-data breach affecting information processed for a merchant, Reveu expects to provide the merchant with relevant information without undue delay, subject to applicable law and the final DPA.
Information may include:
Reveu may also work with relevant providers, legal advisers, regulators, or law-enforcement authorities where appropriate.
14
A person may contact Reveu if they believe Reveu has handled their personal information in a way that does not comply with applicable data-protection law.
Complaints may be submitted by email or through the Reveu contact form by selecting “Privacy and data.”
Reveu will:
Where the complaint relates primarily to information controlled by a Shopify merchant, Reveu may direct the person to that merchant or work with the merchant to investigate the issue.
15
Before general application availability, Reveu intends to provide processing terms covering matters such as:
This page will be updated when the final merchant terms, DPA, infrastructure arrangements, and subprocessor information are available.