← Back to Dashboard

RevoVend Privacy Policy

Overview

This Privacy Policy explains how RevoVend collects, uses, and shares information when you use our application and services. By using RevoVend, you consent to the data practices described in this policy.

Information We Collect

Account data (name, email, phone, role), profile details (business name, EIN/DUNS, location, photos), event listings and unmanned table preferences, table configuration details (base table sizes and pricing, electricity availability and pricing, miscellaneous add-on items with descriptions and prices, marketing packages with social media platform selections), multi-photo uploads for events (up to 3 photos per event, compressed and stored in cloud storage), contractor applications, messages, purchase history, shipping labels and tracking numbers, inventory counts and loss reports, quality control photos, payment and wallet transaction history, BNPL payment metadata (provider selection, billing address, approval status - no payment credentials), tax documents (W-9, 1099), background check results, training materials (content, PDFs, videos, quiz questions/answers), training progress and certification data (quiz scores, attempts, acknowledgments, completion timestamps), survey responses, job alert preferences, referral activity, Pro Tier subscription status, penalty and incident records, QR code check-in data, appeal submissions and evidence, table marketplace checkout activity and abandonment tracking, fee override application history, cold calling data (phone numbers, call logs, recordings, outcomes, notes, do-not-call requests), accounting export requests (date ranges, format selections, download timestamps - no exported file content), newsletter subscriber data (email addresses, signup dates, subscription status), newsletter send history (subject, recipient groups, delivery statistics, timestamps), Event Materials product orders (product selections, checkout links accessed, purchase timestamps), AI Help Assistant conversations (messages, support ticket submissions, AI responses, conversation history), security and authentication data (two-factor authentication setup, 2FA verification attempts, audit logs for sensitive actions, rate limiting logs, login attempt records), image compression metadata (original and compressed sizes, MIME types), device information, usage analytics, and payment-related metadata processed by third-party providers (Stripe, Klarna, Afterpay, Affirm, MailerSend, Riya AI, OpenAI). We do not store full payment card details or BNPL account credentials.

How We Use Information

To operate and improve the platform; facilitate role-based messaging; conduct manual cold calling for proposal outreach; process table purchases including electricity add-ons and miscellaneous items, manage marketing package sales and fulfillment, generate marketplace listings from table configurations, process bookings and contractor payments; manage inventory tracking and fund releases; calculate and apply tiered deductions for inventory losses; process host appeals and business owner decisions; calculate host risk scores and track incident history; enforce contractor penalty policies and suspensions; verify contractor identity via QR codes; deliver training materials and certifications; manage Pro Tier qualifications; send job alerts and notifications; track referrals and ambassador activities; generate post-event surveys and feedback scores; process tax documents and 1099 forms; maintain do-not-call lists and telemarketing compliance; compress and store event photos in cloud storage; send targeted email newsletters to user segments; manage Event Materials product catalog and process product orders; provide AI-powered help assistance and support ticket management; enforce two-factor authentication for account security; maintain audit logs of sensitive actions for security monitoring; implement rate limiting to prevent abuse; detect and prevent fraud; provide customer support; comply with legal obligations; and improve our services through analytics.

Automated Decision-Making

RevoVend uses automated systems to: 1) Calculate tiered deductions for inventory losses (11-35% loss = 25% deduction, 36-75% = 50%, 76-100% = 75%). 2) Compute host risk scores (0-100 scale) based on total incidents, average loss percentage, and recent loss history. 3) Apply contractor penalty points and trigger automatic suspensions at 20 active points. 4) Determine Pro Tier eligibility based on performance metrics or subscription status. 5) Auto-approve inventory fund releases for losses ≤10% when enabled by business owners. You have the right to appeal automated decisions through our appeal process.

Sharing

We share data with: 1) Service providers for payments (Stripe), email (MailerSend via info@revovend1.com), SMS and voice calling (Twilio for manual cold calling), optional post-event voice calls (Riya AI), storage (Cloudflare R2), and analytics. 2) Business owners can view: contractor applications, backgrounds, training progress, penalty history, QR check-in confirmations, inventory counts, and cold call history/outcomes for their proposals. 3) Business owners and admins can view: host risk scores, incident history, and loss patterns for proposal review. 4) Event hosts can view: contractor profiles, check-in status, inventory discrepancies, and fund release status. 5) Proposal callers (W-8BEN contractors) can view: phone numbers and contact information from assigned proposals for calling purposes only. 6) Public profile fields and event listings you choose to post may be visible to other users based on role permissions. 7) We may share information to comply with law, protect rights, or in connection with a business transfer.

Inventory & Fund Release Data

We collect and process: shipping label uploads with tracking numbers, contractor and host inventory counts (beginning/end of event), stock unit quantities, quality control photos, loss percentage calculations, tiered deduction determinations, host appeal submissions with evidence and notes, business owner review decisions, payment withholding and release records, and final disbursement amounts. This data is used to: facilitate transparent inventory management, calculate fair deductions, process appeals, protect all parties from losses, maintain platform integrity, and comply with financial recordkeeping requirements.

Host Risk Tracking

We automatically track and calculate host risk scores based on inventory loss incidents. Data collected includes: event IDs, loss percentages, deduction amounts, incident dates, appeal outcomes, and resolution notes. Risk scores (0-100) are calculated using: total incident count (max 30 points), average loss percentage (max 40 points), and recent incidents within 6 months (max 30 points). Risk levels are categorized as: Low (<25), Medium (25-49), High (50-74), or Critical (75+). Business owners and admins can access this data when reviewing proposals or monitoring host performance. Hosts can appeal incidents or request score recalculations through proper channels.

Contractor Data

We collect and process: applications with work history and experience, background check results and identity verification, W-9 tax forms and 1099 records, training module progress and quiz scores, Pro Tier qualification status (performance or subscription-based), penalty records (no-shows, late arrivals, early departures, poor performance), active penalty points and suspension status, QR code check-in confirmations (arrival, midpoint, end-of-event), Phone Payment Acknowledgment records (acknowledgment timestamp, consent confirmation, application ID association), survey responses and ratings, wallet balances and prepaid card transactions, job alert preferences and notification history, and referral activity. This data is used for: hiring decisions, payment processing, compliance, performance evaluation, access control, and platform safety.

Phone Payment Processing Acknowledgment

CONTRACTOR PAYMENT PROCESSING CONSENT: Before contractors can be hired for jobs requiring payment processing, they must complete the Phone Payment Acknowledgment form. We collect and process the following acknowledgment data: acknowledgment completion status (acknowledged/not acknowledged), acknowledgment timestamp (date and time of acceptance), application ID association (linking acknowledgment to specific job applications), acknowledgment IP address and device information for verification purposes, acknowledgment form content viewed by contractor. PAYMENT PROCESSING OPTIONS DATA: We record contractor understanding of two payment methods: 1) Self-Checkout (Preferred): Acknowledgment that contractors understand customers use self-checkout terminals without contractor handling of payment cards. 2) NFC Tap-to-Pay (If Available): Acknowledgment that contractors understand: personal phone may be used for contactless NFC payments if device supports it and event requires it, wireless transactions only (no manual card entry, no photos, no touching cards), included in compensation without additional fees, security requirements and PCI-DSS compliance obligations. DATA USAGE: Phone Payment Acknowledgment data is used to: verify contractor consent before hiring for payment-processing roles, protect contractors by documenting they understand security guidelines, protect business owners by confirming contractors agreed to payment processing terms, demonstrate compliance with payment security standards and regulations, resolve disputes regarding payment processing expectations or security violations. BUSINESS OWNER VISIBILITY: Business owners can view contractor Phone Payment Acknowledgment status when reviewing applications for jobs requiring payment processing. Acknowledgment status is displayed as: "Acknowledged" with timestamp, "Not Acknowledged" (contractor must complete before being hired for payment-processing jobs). RETENTION: Phone Payment Acknowledgment records are retained for 7 years for compliance with payment processing regulations and dispute resolution. Contractors cannot withdraw acknowledgment once submitted, but can decline jobs requiring payment processing. SECURITY: Acknowledgment data is stored securely with audit trail protection to prevent tampering or unauthorized modifications. All access to acknowledgment records is logged for security monitoring.

Training Materials & Certification Data

We collect and process training material interactions and completion data including: training material views and time spent on materials, quiz attempts and scores (100% required for quiz-required materials, maximum 3 attempts), acknowledgment timestamps for acknowledgment-required materials, review-only material access history, quiz question answers and correctness, completion status and certification dates, training material assignments by business owners, and material effectiveness analytics. TRAINING MATERIAL TYPES: 1) Quiz-Required: Contractors must pass a 5-question quiz with 100% accuracy, maximum 3 attempts. All attempts and scores are tracked. 2) Acknowledgment-Required: Contractors must read and acknowledge understanding. Completion timestamp recorded. 3) Review-Only: Optional reference materials with no completion requirement but access tracked for analytics. DATA USAGE: Training data is used to: verify contractor readiness for events, provide business owners with contractor qualification visibility, improve training material effectiveness, ensure compliance with event-specific requirements, and determine event access permissions. Business owners can view contractor training progress for their assigned materials. Incomplete training may result in event access denial and payment withholding per platform policies.

QR Code Check-In System

We generate secure JWT-based QR codes for contractor event verification. Data includes: contractor ID, event ID, role verification, timestamps, and authorization tokens. DUAL CHECK-IN METHODS: We collect data from two verification workflows: 1) CAMERA-BASED SCANNING: Hosts use camera-enabled devices to scan QR codes via @yudiel/react-qr-scanner library integrated in Vendor Management dashboard. Camera data collected includes: temporary camera access permissions (requested per-scan, not stored permanently), QR code scan results and decoded token values, real-time validation results (success/error states), contractor check-in confirmation timestamps, automatic UI refresh triggers for contractor status updates. Camera permissions are browser-managed and revoked immediately after scan completion. No camera feed recording or image storage occurs. 2) URL-BASED WORKFLOW: Contractors share check-in URLs containing encoded tokens. Hosts access URLs via browser for manual validation. URL access logs include: timestamp of URL access, IP address of accessing device, validation success/failure, contractor check-in confirmation. Business owners and event hosts scan QR codes to confirm: contractor identity, event authorization, arrival/midpoint/end-of-event check-ins. All scans are logged with timestamps, scan method (camera vs URL), device information, and validation results for accountability and payment verification. SECURITY MEASURES: QR codes expire after event completion and cannot be reused. Backend validates: role permissions (only authorized hosts/business owners can scan), event ownership (hosts can only scan for their events), token authenticity (JWT signature verification), timing constraints (check-ins within valid event timeframes). Failed scan attempts are logged for security monitoring and fraud prevention.

Fees, Payments, and Records

We record all transactions to apply platform fees: 15% host commission for Local Vendor bookings (may be reduced to 10% as one-time waiver), 5% host fee on table sales, inventory management fees with tiered deductions when applicable, Pro Tier subscriptions ($25/month), proposal fees for paid proposals, contractor penalty deductions, and processing fees. Transaction records include: amounts, fee breakdowns, deduction calculations, appeal decisions, payment methods, disbursement dates, escrow holds and releases, wallet balances, prepaid card transactions, checkout abandonment tracking, fee override applications and approvals, automated discount notifications, BNPL payment method metadata (provider name, approval status, no account credentials), and tax reporting data. Records are retained for reconciliation, dispute resolution, tax compliance, and audit purposes.

Accounting Export & Financial Data

EXPORT FEATURE: Business owners can export transaction data as CSV files through our RevoTools Accounting Export feature. This tool allows users to download payment records for integration with accounting software such as QuickBooks, Xero, FreshBooks, and other financial management systems. DATA INCLUDED IN EXPORTS: Exported CSV files contain: transaction dates (formatted for accounting software compatibility), transaction descriptions (event-based identifiers), transaction amounts (numeric format without currency symbols), payment methods used (card, Klarna, Afterpay, Affirm, etc.), customer email addresses (when provided during checkout), reference IDs (Stripe payment intent IDs, charge IDs, or transaction IDs), transaction status (completed transactions only). WHAT IS NOT INCLUDED: We do NOT include in accounting exports: full credit card numbers or payment credentials, customer names or personal details beyond email, BNPL account credentials or payment plan details, pending or failed transaction data, internal RevoVend processing notes, business owner personal information. NO SERVER STORAGE: CSV files are generated dynamically when you request an export and are downloaded directly to your device. We do not store exported CSV files on our servers. Once downloaded, you are solely responsible for the security, storage, and proper handling of the exported data. DATA FILTERING: Users can filter exports by: custom date ranges (start and end dates are inclusive of all transactions on those dates), transaction types (RevoTools payments, table splits, proposal payments, or all transactions), accounting format (Standard, QuickBooks 3-column, QuickBooks 4-column, Xero). USER RESPONSIBILITY: You are responsible for: 1) Securing downloaded CSV files on your device and preventing unauthorized access. 2) Properly disposing of or encrypting exports containing sensitive financial information. 3) Complying with data protection regulations when sharing exports with accountants, CPAs, or tax professionals. 4) Verifying the accuracy of exported data before importing into accounting systems. 5) Maintaining your own backup copies for record-keeping purposes. INTENDED USE: Accounting exports are designed for legitimate business purposes including: tax preparation and filing, financial reconciliation, bookkeeping and accounting, audit compliance, sharing with authorized financial professionals. Misuse of exported data for fraudulent purposes, unauthorized disclosure, or identity theft is strictly prohibited and may result in account termination and legal action. DATA ACCURACY: Exported data reflects the transaction records as stored in our system at the time of export. We make reasonable efforts to ensure accuracy but are not responsible for: errors in merchant data entry during transactions, discrepancies between export data and actual bank deposits (timing differences), third-party payment processor delays or adjustments, currency conversion or exchange rate variations. RETENTION: While we do not store exported CSV files, the underlying transaction data used to generate exports is retained for 7 years in compliance with financial recordkeeping requirements and tax regulations (see Data Retention section).

Survey & Feedback Data

We collect post-event surveys from hosts and contractors to generate Business Owner Feedback Scores (0-100%). Survey data includes: communication clarity ratings, shipment tracking confirmation, product completeness assessments, professionalism scores, payment promptness ratings, work-again confidence levels, and improvement suggestions. Aggregated scores are displayed on business owner profiles. Individual survey responses are confidential but may be shared in anonymized form for platform improvements.

Job Alerts & Notifications

We process job alert preferences including: desired job types, location preferences (local/nationwide), hourly rate ranges, and notification channels (email/push). When matching jobs are posted, we send automated notifications and track: alert triggers, notification delivery status, contractor engagement, and application submissions. You can manage alert preferences and opt-out at any time through your account settings.

Multi-Photo Upload & Cloud Storage

EVENT PHOTO UPLOADS: Event hosts can upload up to 3 photos per event to enhance event listings and provide visual context for business owners and contractors. Photo data we collect and process includes: original uploaded images (in various formats: JPG, PNG, WEBP, etc.), compressed versions automatically generated to 500KB or less for efficient storage and loading, image metadata (file names, MIME types, upload timestamps, file sizes before and after compression), temporary blob URLs for client-side preview during upload process, cloud storage file paths and access URLs. STORAGE LOCATION: All event photos are stored in Google Cloud Storage via Replit App Storage with secure access controls. Photos are associated with specific event records and accessible only to: the event host who uploaded them, business owners booking tables at the event, contractors assigned to the event, admins for moderation purposes. COMPRESSION & QUALITY: We automatically compress images client-side before upload to reduce storage costs and improve platform performance. Compression maintains visual quality while reducing file size. Original images are not retained after compression. DATA RETENTION: Event photos are retained for the lifetime of the event listing plus 2 years for historical records and dispute resolution. Photos may be deleted earlier if: the event host deletes the event, the event host requests photo removal, the account is deleted (subject to legal retention requirements), photos violate content policies. SHARING & VISIBILITY: Event photos are visible to authenticated platform users viewing the event listing based on role permissions. Photos are NOT publicly visible to unauthenticated users or search engines. Photos are never shared with third parties for marketing purposes without explicit consent.

Newsletter Management System

ADMIN NEWSLETTER TOOL: RevoVend admins can send targeted email newsletters to user segments through our Newsletter Management system. Data collected includes: newsletter subscriber emails (from landing page signups), newsletter send records (subject lines, HTML email content, send dates and times), recipient group selections (all users, business owners, contractors, event hosts, ambassadors, landing page subscribers), delivery statistics (success counts, failure counts, bounce rates), newsletter history and campaign tracking. SUBSCRIBER DATA: Landing page email subscribers who sign up through our public website consent to receive periodic newsletters and platform updates. Subscriber data includes: email address, signup date, subscription status (active/unsubscribed), signup source (landing page, account creation, profile settings). TARGETED SENDING: Newsletters can be sent to specific user segments based on roles, allowing admins to communicate relevant information to the appropriate audience. All sends are tracked for delivery confirmation and troubleshooting. EMAIL CONTENT: Newsletter emails are sent via MailerSend from info@revovend1.com and may include: platform updates and new features, policy changes and important notices, community highlights and success stories, educational content and best practices, event promotions and opportunities. OPT-OUT RIGHTS: All newsletter recipients can unsubscribe by: clicking the unsubscribe link in any newsletter email, updating email preferences in account settings (for registered users), emailing info@revovend1.com with an unsubscribe request. Landing page subscribers who have not created accounts can unsubscribe via the email link. We honor opt-out requests immediately and will not send further newsletters to unsubscribed addresses. RETENTION: Newsletter send history is retained for 3 years for analytics and compliance. Subscriber data is retained until unsubscribe request or account deletion.

Event Materials Catalog & Product Orders

PRODUCT CATALOG: RevoVend maintains an Event Materials catalog featuring business productivity products such as thermal printers, receipt paper rolls, branded t-shirts, table covers, stickers, and other event-related materials. Product catalog data includes: product names, descriptions, and specifications, product images and visual assets, pricing information, Stripe checkout link URLs, admin management records (product creation, updates, deletions). ORDER PROCESSING: When users click product checkout links, we track: product selections and interest, timestamp of checkout link access, redirect to Stripe-hosted checkout pages. IMPORTANT: We do NOT process payments directly for Event Materials. All payments are handled exclusively by Stripe through their secure checkout system. We do not collect or store: payment card numbers or credentials, billing addresses (stored only by Stripe), order confirmation details, shipment tracking for Event Materials. STRIPE INTEGRATION: Event Materials purchases are conducted through Stripe payment links. Stripe collects and processes all payment and shipping information per their privacy policy (stripe.com/privacy). We receive only high-level confirmation when purchases are completed. USAGE DATA: We may use Event Materials interaction data to: understand which products are most popular, improve product offerings and descriptions, optimize catalog organization, provide better recommendations to users. THIRD-PARTY PROCESSING: Stripe acts as an independent payment processor and merchant for Event Materials sales. Your payment and shipping information is subject to Stripe's privacy policy and data practices, not RevoVend's direct control.

AI Help Assistant & Support Tickets

AI-POWERED SUPPORT: RevoVend offers an AI Help Assistant powered by OpenAI GPT-4 models to provide instant answers to user questions about platform features, policies, and troubleshooting. Conversation data we collect includes: user messages and questions submitted to the AI assistant, AI-generated responses and suggestions, conversation timestamps and session IDs, chat history and conversation threading, support ticket submissions for complex issues requiring human review, user feedback on AI response helpfulness (if provided). DATA USAGE: AI conversation data is used to: provide immediate assistance and answer questions, improve AI response accuracy and helpfulness, identify common user pain points and confusion, prioritize feature documentation and improvements, train and refine AI models for better support quality, escalate complex issues to human support staff when needed. OPENAI INTEGRATION: User messages are sent to OpenAI's API for processing and response generation. OpenAI processes this data per their privacy policy (openai.com/privacy) and data usage policies. We do not share personally identifiable information with OpenAI beyond what's necessary for conversation context. AI responses are generated based on RevoVend documentation and policies, not stored user data. LIMITATIONS: The AI Help Assistant is a support tool and may occasionally provide incorrect or incomplete information. Users should verify critical information through official documentation or contact human support for definitive answers. AI conversations do not constitute legal advice or binding commitments. RETENTION: AI conversation history is retained for 90 days for quality assurance and improvement purposes, then automatically deleted. Support tickets escalated to human review are retained per our standard support retention policies (3 years). PRIVACY CONTROLS: Users can request deletion of their AI conversation history by contacting info@revovend1.com. Conversation data is not used for marketing purposes or shared with third parties except as required for AI processing (OpenAI).

Enhanced Security Features

TWO-FACTOR AUTHENTICATION (2FA): Users can enable 2FA for enhanced account security. 2FA data we collect includes: 2FA setup status (enabled/disabled), verification method preferences, 2FA verification attempt logs (success/failure, timestamps, IP addresses), backup code generation and usage records. 2FA data is used exclusively for account security and authentication purposes. AUDIT LOGGING: We maintain detailed audit logs of sensitive account actions for security monitoring and fraud prevention. Audit logs record: account changes (email updates, password resets, profile modifications), permission changes and role assignments, sensitive data access (tax documents, payment information, contractor records), administrative actions by platform admins, security events (failed login attempts, suspicious activity, rate limit violations). Audit logs include: action type and description, user ID and role performing the action, timestamp and IP address, affected resources or records, success/failure status. RATE LIMITING: To prevent abuse and protect platform integrity, we implement rate limiting on API requests and sensitive actions. Rate limiting data includes: request counts and frequency per user/IP address, rate limit violation records, temporary restriction periods, IP addresses subject to rate limiting. Rate limiting applies to: login attempts (to prevent brute force attacks), API requests (to prevent DoS attacks), sensitive operations (password resets, fund transfers), bulk actions (mass messaging, proposal sending). SECURITY DATA RETENTION: Audit logs are retained for 7 years for compliance, security analysis, and dispute resolution. 2FA data is retained while the feature is enabled and for 90 days after disabling for security review. Rate limiting data is retained for 30 days for pattern analysis and abuse detection. SECURITY INCIDENT RESPONSE: In the event of a security breach or unauthorized access, audit logs and security data may be used for: incident investigation and forensics, determining scope of compromise, notifying affected users as required by law, implementing additional security measures, cooperating with law enforcement if necessary. ACCESS CONTROL: Audit logs and security data are accessible only to: authorized platform administrators with security responsibilities, automated security monitoring systems, law enforcement with valid legal process. This data is never used for marketing purposes or shared with third parties except as required by law.

Cold Calling System

RevoVend operates a browser-based cold calling system for proposal outreach. Data collected includes: phone numbers provided in external proposals, call logs (duration, timestamp, outcome), call recordings (if applicable and permitted by law), caller ID information, call notes and dispositions, attempt history and frequency, do-not-call list entries, and call queue assignments. Calls are manually placed by W-8BEN contractors (not automated dialers) using Twilio WebRTC technology through their web browser. Call recordings may be made for quality assurance, training, and dispute resolution with proper notification where required by law. RETENTION POLICY: Call recordings and detailed notes are retained for 30 days, after which they are automatically deleted. Basic call logs (date, time, outcome, phone number) are retained for 7 years for legal compliance and business records. Do-not-call list entries are retained indefinitely to honor opt-out requests. You may request to be added to our do-not-call list at any time by: 1) Declining during a call and requesting removal, 2) Contacting info@revovend1.com with subject "Do Not Call Request", or 3) Replying to any follow-up communication with removal request. Phone numbers marked as "Declined" are automatically blocked from future calls. We comply with all applicable telemarketing regulations including TCPA, TSR, and state-specific do-not-call laws.

SMS Communications & Opt-In

LANDING PAGE OPT-IN: When you submit your phone number through our landing page, you consent to receive SMS text messages from RevoVend about our services, updates, and platform features. Message frequency may vary. Message and data rates may apply. Reply STOP to opt-out at any time. Reply HELP for support. We will not share your phone number with third parties for their marketing purposes. Your opt-in consent is stored securely and can be withdrawn at any time. PLATFORM USER SMS: We use Twilio to send SMS text messages to opted-in platform users who provide their phone number. SMS is used exclusively for transactional messages to existing users: 1) Phone number verification codes for account security, 2) Contractor gig confirmations with Google Calendar links when hired for events, 3) Booking confirmations for table reservations, 4) Event updates and schedule changes, 5) Payment reminders for overdue balances. We DO NOT send SMS to non-users for marketing/promotional purposes or for proposal solicitations. By providing your phone number, you consent to receive these transactional SMS messages. Standard message and data rates may apply. You can opt-out of SMS communications at any time by updating your notification preferences in account settings or replying STOP to any message. Opting out may limit certain platform features that require SMS verification.

Riya AI Voice Calls (Post-Event Follow-Ups Only)

IMPORTANT LIMITATION: Riya AI automated voice calling is used EXCLUSIVELY for optional post-event follow-up communications. We DO NOT use Riya AI or any automated calling system for proposal outreach, sales calls, or initial business development contacts. PERMITTED USES: Post-event survey invitations, post-event feedback collection, follow-up questions after completed events, thank-you calls after event participation. PROPOSAL OUTREACH: All proposal-related calls are conducted manually by human W-8BEN contractors through our browser-based cold calling system using Twilio WebRTC (see Cold Calling System section). NO ROBOCALLS FOR PROPOSALS: We do not use autodialers, predictive dialers, or AI voice systems for proposal solicitations to comply with TCPA regulations. OPT-OUT: You may opt-out of Riya AI post-event calls by updating your notification preferences or contacting info@revovend1.com.

Referral & Ambassador Programs

We track: host job referrals (platform contractors or new persons), referral invitations and responses, application submissions from referrals, hiring outcomes, referral credits earned, and ambassador referral links and conversions. Referral data is used to: facilitate hiring, award credits, track ambassador performance, and improve our referral programs.

Data Retention

We retain data for as long as necessary to: provide services, comply with legal obligations, resolve disputes, and enforce agreements. Specific retention periods: Account data - duration of account plus 7 years for tax/legal compliance. Transaction records - 7 years for financial and tax reporting. Cold call recordings and detailed notes - 30 days (then automatically deleted). Basic cold call logs (date, time, outcome) - 7 years for compliance and business records. Do-not-call lists - retained indefinitely for compliance. Penalty points - 30 days (then automatically expire). Host risk incidents - retained indefinitely for safety and pattern analysis. Survey responses - 3 years. Training certifications - duration of employment plus 3 years. Appeal records - 5 years. Inactive accounts - deleted after 3 years of inactivity with 60-day notice. You may request data deletion subject to legal retention requirements.

Your Choices

You can: update your profile and preferences, manage notification settings and job alerts, request to be added to our do-not-call list, request access to your data, request data corrections, appeal automated decisions (deductions, penalties, risk scores), opt-out of surveys and feedback requests, disable QR code generation (may limit event access), and request account deletion (subject to legal retention). Some data may be retained for legal, security, accounting, or safety purposes even after account deletion.

Security

We use industry-standard security measures including: encrypted data transmission (SSL/TLS), secure password hashing (bcryptjs), JWT-based authentication, role-based access controls, secure QR code generation with expiring tokens, encrypted storage of sensitive data, regular security audits, and third-party security certifications (Stripe PCI compliance). FINANCIAL DATA PROTECTION: We implement additional safeguards for financial information: 1) Payment card details are processed and stored exclusively by Stripe (PCI-DSS Level 1 certified) - we never store full card numbers on our servers. 2) BNPL payment processing is handled entirely by the respective providers (Klarna, Afterpay, Affirm) - we do not store BNPL account credentials. 3) Accounting exports are generated on-demand with encrypted transmission (HTTPS) and are not stored on our servers after download. 4) Transaction data access is restricted by role-based permissions - only authorized business owners can export their own transaction data. 5) All financial API communications use encrypted channels and authenticated requests. ACCOUNT PROTECTION: We strongly recommend that users: enable strong, unique passwords for their accounts, secure downloaded accounting exports with encryption or password protection, store financial exports in secure locations with restricted access, use secure file sharing methods when providing exports to accountants or CPAs, regularly review account activity for unauthorized access, immediately report any suspected security breaches to info@revovend1.com. USER RESPONSIBILITY FOR EXPORTS: Once you download an accounting export CSV file, you assume full responsibility for its security. We recommend: storing files in encrypted folders or drives, password-protecting files before email transmission, using secure cloud storage with access controls, permanently deleting exports when no longer needed, avoiding storage on shared or public computers. No method of transmission or storage is 100% secure. We cannot guarantee absolute security but maintain reasonable safeguards appropriate to the sensitivity of the data. In the event of a data breach affecting financial information, we will notify affected users in accordance with applicable data breach notification laws.

DATA SECURITY AND USER RESPONSIBILITY

SHARED SECURITY RESPONSIBILITY: Users are solely responsible for maintaining the confidentiality and security of their account credentials and must immediately notify RevoVend Eco LLC of any suspected unauthorized access, security breach, or misuse of their account. While RevoVend implements industry-standard security measures including SSL/TLS encryption, PCI DSS compliance, and multi-factor authentication options, users acknowledge that no system is completely secure and assume responsibility for their own data protection practices. USER SECURITY OBLIGATIONS: You agree to: (a) Create and maintain strong, unique passwords for your account; (b) Enable two-factor authentication (2FA) when available, especially for accounts with administrative privileges or financial access; (c) Immediately report any suspected security breaches, unauthorized access, or account compromise to info@revovend1.com; (d) Secure any downloaded data, including accounting exports, tax documents, and transaction records; (e) Use secure networks when accessing the platform and avoid public Wi-Fi for sensitive operations; (f) Keep your devices, browsers, and operating systems updated with the latest security patches; (g) Never share your account credentials with others or allow unauthorized access to your account. PLATFORM SECURITY MEASURES: RevoVend implements: (a) SSL/TLS encryption for all data transmission between your device and our servers; (b) PCI DSS compliance through Stripe for all payment card processing; (c) Secure password hashing using bcryptjs to protect your credentials; (d) JWT-based authentication with token expiration and refresh mechanisms; (e) Role-based access controls limiting data access based on user roles; (f) Audit logging of sensitive actions for security monitoring and fraud detection; (g) Rate limiting to prevent brute force attacks and abuse; (h) Regular security audits and penetration testing. LIMITATION OF LIABILITY FOR SECURITY: While we implement robust security measures, RevoVend is not liable for security breaches resulting from: (a) User negligence in protecting account credentials; (b) Sharing of passwords or account access with unauthorized parties; (c) Failure to report suspected breaches promptly; (d) Use of weak passwords or failure to enable 2FA; (e) Compromise of user devices, browsers, or operating systems; (f) Phishing attacks or social engineering targeting users; (g) Third-party service provider breaches beyond our control. INCIDENT REPORTING: If you suspect a security breach, unauthorized access, or account compromise, immediately: (1) Change your password; (2) Enable 2FA if not already active; (3) Contact us at info@revovend1.com with subject "Security Incident"; (4) Provide details of the suspected breach, including date, time, and circumstances; (5) Review your account activity and transaction history for unauthorized actions. We will investigate all reported security incidents and take appropriate action to protect your account and data.

Children

The service is not intended for individuals under 13 (or the minimum age in your jurisdiction). We do not knowingly collect data from children. If we learn we have collected data from a child, we will delete it promptly. Contractors must be 18+ or have parental consent where required by law.

International Transfers

Your information may be transferred to and processed in the United States and other jurisdictions where our service providers operate. These jurisdictions may have different data protection laws than your country. By using RevoVend, you consent to such transfers. We implement appropriate safeguards such as standard contractual clauses and Privacy Shield frameworks where applicable.

Third-Party Services

We integrate with: Stripe (payments, Connect payouts, Issuing cards, Event Materials product checkout), Klarna, Afterpay/Clearpay, and Affirm (Buy Now, Pay Later payment options), MailerSend (email notifications and newsletter distribution via info@revovend1.com), Twilio (SMS and WebRTC voice calling for manual cold calling system), Riya AI (optional post-event follow-up voice calls only - NOT used for proposal outreach), Google Cloud Storage via Replit App Storage (event photo storage and file uploads), Neon (database hosting), OpenAI (AI Help Assistant, cost estimation, wage analysis, and AI-powered photo extraction), Indeed/Joveo (job posting). BNPL PAYMENT PROVIDERS: When you select Klarna, Afterpay/Clearpay, or Affirm as your payment method, we share the following information with the selected provider: purchase amount, billing address, email address, phone number (if provided), transaction details. This data sharing is necessary for payment processing, credit checks, and fraud prevention. Each BNPL provider has its own privacy policy governing their use of your information: Klarna Privacy Policy (klarna.com/us/privacy), Afterpay Privacy Policy (afterpay.com/privacy), Affirm Privacy Policy (affirm.com/privacy). We do not store your BNPL account credentials or payment method details. OPENAI INTEGRATION: User messages submitted to the AI Help Assistant are processed by OpenAI GPT-4 models per OpenAI's privacy policy (openai.com/privacy). We share only necessary conversation context and do not include sensitive personal information (payment details, tax documents, passwords) in AI requests. OpenAI's data retention and usage policies apply to AI-processed content. GOOGLE CLOUD STORAGE: Event photos and file uploads are stored in Google Cloud Storage with access controls. Google processes this data per their privacy policy (cloud.google.com/terms/cloud-privacy-notice). We implement appropriate security measures including authentication, encryption, and access logging. PROPOSAL OUTREACH: Proposal outreach is conducted via manual browser-based calls by W-8BEN contractors using Twilio WebRTC, not automated AI systems. These services have their own privacy policies. We are not responsible for their practices. Review their policies before using RevoVend features that involve these services.

California Privacy Rights

California residents have rights under CCPA/CPRA to: know what personal information we collect, access your data, request deletion (subject to exceptions), opt-out of sale (we do not sell data), correct inaccurate data, and limit use of sensitive information. To exercise these rights, contact us at info@revovend1.com. We will verify your identity before processing requests.

Changes to this Policy

We may update this policy from time to time. Material changes will be communicated via email or in-app notification. Changes take effect upon posting unless otherwise stated. Continued use after changes means you accept the updated policy. We encourage you to review this policy periodically.

Contact

Questions about privacy? Contact us at info@revovend1.com or through our support page. For data subject requests, include "Privacy Request" in the subject line with your account email and specific request details.

Last updated: November 23, 2025