Privacy Policy
Last updated: 3 June 2026
RevisitAI ("we", "our", "us") provides a customer comeback and retention platform for clinics and salons. This Privacy Policy explains what personal information we collect, how we use it, and the choices you have. By using RevisitAI you agree to the practices described here.
1. Information we collect
- Account data — your name, business name, email, phone, and password when you sign up.
- Workspace data — customer records you create (names, phone numbers, appointment history, notes, WhatsApp opt-in), and the business profile you configure.
- Payment data — handled by Razorpay; we store a payment reference and amount, never your card or UPI details.
- Messaging metadata — when you send a WhatsApp message via Gupshup we log delivery status, recipient phone, and template name.
- Technical data — IP address, browser type, and access logs needed to secure the service.
2. How we use the data
- To operate and improve the RevisitAI service for your workspace.
- To send WhatsApp messages on your instruction via Gupshup.
- To process payments via Razorpay and provide receipts.
- To detect abuse, debug issues, and respond to support requests.
- To comply with applicable laws (including the Information Technology Act, 2000 and the Digital Personal Data Protection Act, 2023 in India).
3. Sharing
We share the minimum data needed with the following sub-processors:
- Supabase — database hosting and authentication (EU/US regions).
- Vercel — application hosting (global edge).
- Razorpay — payment processing (India).
- Gupshup — WhatsApp Business API delivery (India).
We do not sell your data. We do not share it with advertisers.
4. Your customers' data
When you store information about your own customers (patients, clients) in RevisitAI, you are the data controller and we are the data processor. You must have a lawful basis (typically consent or contract) to collect that data and to send them WhatsApp messages. You are responsible for honoring their opt-out requests; we provide an opt-out flag on every customer record.
5. Your rights
You can at any time:
- Export all your workspace data from Settings → Workspace → Export.
- Delete your entire workspace from Settings → Workspace → Danger Zone.
- Update business or personal details from Settings.
- Request a copy of any audit log via support.
6. Data retention
We keep your workspace data for as long as your account is active. When you delete your workspace, all customer records, appointments, messages, and payments are permanently removed within 30 days. Backups expire on a rolling 35-day window.
7. Security
We use Row Level Security in Postgres to isolate every workspace's data. All traffic is TLS-encrypted. Webhook endpoints verify HMAC signatures. We follow industry-standard practices but no system is perfectly secure — please use a strong, unique password and enable two-factor authentication when offered.
8. International transfers
Your data is stored on Supabase infrastructure. By using the service you consent to the transfer of your data to the region you select during signup, subject to standard contractual safeguards.
9. Changes
We may update this policy from time to time. Material changes will be announced by email to the workspace owner at least 14 days before they take effect.
10. Contact
Email privacy@revisit.ai with any questions, data access requests, or grievances. For India-specific complaints, contact our Grievance Officer at grievance@revisit.ai.