Privacy Policy | RevWize
RevWize Privacy Policy dated August 20, 2026, for website visitors, registered users, and visitors to public business profiles.
REVWIZE · LEGAL DOCUMENTS
Privacy Policy
for website visitors, registered users of the web application, and visitors to public business profiles
| Provider | PebbleByte GmbH, Mittelgasse 4/13, 1060 Vienna, Austria |
|---|---|
| Scope | Public privacy information for revwize.com, the RevWize web application, and public business profiles |
As of: August 20, 2026
1. Controller
PebbleByte GmbH
Mittelgasse 4/13, 1060 Vienna, Austria
Phone: +43 676 59 40 027
Email: office@pebblebyte.com
2. Scope and Data Protection Roles
This Privacy Policy distinguishes between three main groups of data subjects. PebbleByte’s role depends on the context in which RevWize is used:
Website visitors and visitors to public RevWize pages: Anyone who accesses revwize.com or a publicly accessible business profile may generate technical connection and security data. PebbleByte generally processes this data as controller for the technical provision of these pages.
Registered users and Business Customers: PebbleByte is the controller for registration, login, customer accounts, contract performance, billing, support, security, and abuse prevention. This applies in particular to owners, employees, and other authorized users of a Business Customer.
End customers of a Business Customer: As soon as a person provides personal data to the respective business through a public business profile, a QR form, a check-in, a loyalty function, or a campaign, or receives an SMS from that business, the respective Business Customer generally determines the purposes and legal bases of this processing. PebbleByte processes the relevant end-customer data as processor pursuant to Art. 28 GDPR and the DPA. Affected end customers should primarily contact the respective business regarding this data and their rights.
3. Website, Public Business Profiles, and Technical Provision
When revwize.com, the RevWize web application, or a publicly accessible business profile is accessed, the data processed may include the IP address, date and time, requested URL, referrer, browser, operating system, device data, transmission status, and security and error logs. This serves to deliver content, operate the service technically, analyze errors, and detect and defend against attacks.
PebbleByte is generally the controller for this technical provision. The legal basis is Art. 6 para. 1 lit. f GDPR; the legitimate interests are secure, stable, and economical operation, error analysis, abuse prevention, and evidence of technical processes. Where provision is necessary for pre-contractual measures or contract performance, Art. 6 para. 1 lit. b GDPR also applies.
Merely accessing a public business profile does not yet result in a person being processed as an end customer on behalf of the business shown. The rules in Section 8 apply to this end-customer data only when personal data is entered through the profile, a check-in is performed, a loyalty or voucher function is used, or a comparable interaction is initiated.
4. Business Customers, Registered Users, and Customer Accounts
For inquiries, registration, and use, we process in particular the company name, address, VAT identification number or other business identifier, names and contact details of contact persons, login and authorization data, selected plan, credits, term, contract and payment status, and communication and support data.
Processing serves pre-contractual measures, contract conclusion, account provision, authentication, service management, and customer support. The legal basis is Art. 6 para. 1 lit. b GDPR where the data subject is personally the contracting party. For contact persons of a company, we rely on Art. 6 para. 1 lit. f GDPR; the legitimate interests are efficient B2B communication, performance of the contract with the company, and secure user administration.
Required information in the registration or checkout process is necessary for concluding the contract and providing the service. Without it, we cannot provide an account or contract. Voluntary information is marked accordingly.
5. Billing, Payment, and Legal Obligations
For offers, invoices, payments, and accounting, we process business, contact, invoice, transaction, tax, and payment-status data. The legal bases are Art. 6 para. 1 lit. b GDPR for contract processing and Art. 6 para. 1 lit. c GDPR for statutory accounting, tax, and documentation obligations.
For payments by Business Customers, we may use Stripe Payments Europe Limited, 1 Grand Canal Street Lower, Grand Canal Dock, Dublin, D02 H210, Ireland, and/or Mollie B.V., Keizersgracht 126, 1015 CW Amsterdam, Netherlands. The payment service provider used receives the data required for payment processing and may be an independent controller for certain purposes, particularly regulatory and security purposes. Payment data is generally entered directly in the payment environment provided by the respective payment service provider. End-customer payments are not part of this processing within RevWize Business Customer billing.
6. Support, Communication, and Abuse Prevention
For support inquiries, we process contact data, inquiry content, attachments, technical diagnostic information, and processing histories. The legal basis is Art. 6 para. 1 lit. b GDPR; for general contact persons and for improving security and support, Art. 6 para. 1 lit. f GDPR also applies.
To detect attacks, account misuse, payment fraud, and unauthorized messaging patterns, we process login, usage, messaging, and security logs to the extent required. The legal basis is Art. 6 para. 1 lit. f GDPR; the legitimate interests are protecting users and end customers, system security, preventing harm, and enforcing legal rights.
7. Cookies, Local Storage, and Usage Analytics
RevWize currently does not use cookies. In particular, we currently do not use analytics or marketing cookies and do not store persistent user identifiers in the browser for usage analytics.
For technical and product-related usage analytics, we use PostHog, provided by PostHog Inc., 2261 Market Street #4008, San Francisco, CA 94114, USA, in the PostHog Cloud EU. The analytics data is processed and stored on PostHog’s EU infrastructure in Frankfurt, Germany. The analytics operates without cookies and without persistent identifiers; session-related values are held only in the browser’s memory. Under our configuration, no names, email addresses, account IDs, or end-customer identifiers are transmitted to PostHog as analytics identifiers. Recognition across multiple browser sessions is therefore not intended.
Where personal technical data arises in this context, processing for the analysis and improvement of stability, usability, and features is based on Art. 6 para. 1 lit. f GDPR. Our legitimate interest lies in improving and securing the service in a data-minimizing manner. If cookies or other non-essential persistent technologies are used in the future, this Privacy Policy will be updated accordingly and any required consent will be obtained before their use.
8. End-Customer Data in RevWize
Business Customers can process personal data of their end customers through RevWize, including contact data, consent and opt-out data, message and delivery data, QR check-ins, stamp-card balances, points, rewards, vouchers, redemptions, tags, segments, campaign assignments, and end-customer-related usage and change logs. Such data may arise in particular through public business profiles, QR forms, check-ins, or campaigns of the Business Customer.
The respective Business Customer determines the purposes and legal bases for this end-customer data and is generally the controller. PebbleByte does not process this data for its own marketing purposes, but as processor solely for technical provision, storage, SMS delivery, security, and in accordance with the documented instructions of the Business Customer.
When data is entered, a QR-code check-in is performed, or a comparable interaction takes place on a public business profile, the privacy information displayed there must identify the respective business as controller and transparently explain how the data is used. RevWize may provide a technical template for this purpose; the Business Customer is responsible for completeness, content, and the legal basis.
Where consent is required, a one-time review request and ongoing promotional SMS should be selectable separately. Consent options must not be preselected and consent must be easy to withdraw at any time. Withdrawals and opt-outs are documented on behalf of the Business Customer and observed for the relevant purpose.
9. Recipients and Service Providers
We disclose personal data only where this is necessary for the purposes described, a legal basis exists, and appropriate agreements and safeguards are in place. Recipients may include:
- Hetzner Online GmbH, Industriestr. 25, 91710 Gunzenhausen, Germany, for hosting, databases, storage, and backups of the website, web application, public business profiles, and the data processed in them;
- ONLINECITY.IO ApS, Buchwaldsgade 50, 5000 Odense C, Denmark (GatewayAPI service), for sending SMS and processing delivery statuses on behalf of the respective Business Customer;
- Stripe Payments Europe Limited, 1 Grand Canal Street Lower, Grand Canal Dock, Dublin, D02 H210, Ireland, for payment processing for Business Customers;
- Mollie B.V., Keizersgracht 126, 1015 CW Amsterdam, Netherlands, for payment processing for Business Customers;
- PostHog Inc., 2261 Market Street #4008, San Francisco, CA 94114, USA, using PostHog Cloud EU in Frankfurt, Germany, for data-minimizing usage analytics in the cookie-free configuration without persistent identification described above;
- Tax advisers, legal advisers, banks, insurers, courts, and authorities where required or legally mandated.
Where service providers act as processors, agreements pursuant to Art. 28 GDPR are concluded. The subprocessors approved for end-customer data must be listed by name in Annex 2 to the DPA.
10. Data Transfers Outside the EEA
We prefer processing within the European Economic Area. Where a provider processes data outside the EEA or accesses it from there, this occurs only if the requirements of Art. 44 et seq. GDPR are met, in particular on the basis of an adequacy decision or standard contractual clauses and, where required, additional technical and organizational measures.
11. Retention Period
| Data category | Retention period or criterion |
|---|---|
| Website and security logs | Only for as long as required for operation, error analysis, and security; generally up to 30 days, and for security incidents until they have been resolved and any legal enforcement has concluded |
| Prospect inquiries | Until the inquiry has been completed; thereafter generally no more than three years where required for evidence or potential claims |
| Account and contract data | For the duration of the contract and thereafter until the applicable limitation and documentation periods have expired |
| Invoice, payment, and tax data | In accordance with statutory retention obligations, generally seven years in Austria; correspondingly longer where proceedings are ongoing |
| Support data | Until the matter has been resolved and thereafter according to necessity, contractual relevance, security relevance, and potential claims |
| End-customer data processed on behalf of a customer | In accordance with the Business Customer’s instructions and the DPA; after the contract ends, generally 30 days for export, followed by deletion from production systems and overwriting of backups in the regular cycle |
| PostHog/analytics data | According to the configured retention period; no persistent identifiers or cookies are stored in the browser for analytics. |
12. Sources of Data
We obtain data directly from data subjects, from the company for which they work, from RevWize functions they use, from payment and technical service providers, and, for end-customer data, from the respective Business Customer or through its public business profiles, QR forms, check-ins, and campaigns. Publicly accessible business registers may be consulted to verify business information.
13. Rights of Data Subjects
Subject to the statutory requirements, data subjects have rights to access, rectification, erasure, restriction, data portability, and objection, as well as the right to withdraw consent at any time with effect for the future. Withdrawal does not affect the lawfulness of processing carried out before the withdrawal.
Objections to processing based on Art. 6 para. 1 lit. f GDPR may be sent to office@pebblebyte.com, stating the particular situation. Direct marketing may be objected to at any time without giving reasons.
If a request concerns end-customer data that PebbleByte processes only on behalf of a customer, the respective business is the primary point of contact. Where possible, PebbleByte forwards requests and supports the controller.
14. Automated Decisions
As controller, PebbleByte does not make decisions based solely on automated processing that produce legal effects concerning data subjects or similarly significantly affect them. Segmentations and campaign logic within RevWize are configured by the Business Customer and executed on its behalf.
15. Data Security
We implement risk-oriented technical and organizational measures, including TLS-encrypted transmission, authentication, role-based access, logging of security-relevant events, maintenance and update processes, backup and recovery procedures, confidentiality obligations, and incident and deletion processes.
16. Right to Lodge a Complaint
Data subjects may lodge a complaint with a data protection supervisory authority. The competent Austrian authority is:
Austrian Data Protection Authority
Barichgasse 40–42, 1030 Vienna
Email: dsb@dsb.gv.at
Website: https://www.dsb.gv.at
Phone: +43 1 52 152-0
17. Changes
We amend this Privacy Policy where legal, technical, or organizational changes require it. The current version is available at revwize.com. Material changes will be communicated in an appropriate manner.
Contact
PebbleByte GmbH
Mittelgasse 4/13, 1060 Vienna, Austria
Email: office@pebblebyte.com
Phone: +43 676 59 40 027
Website: https://revwize.com