Privacy
Privacy Policy
This Privacy Policy describes how personal data is processed when Revora is used.
Last updated: 3 September 2026
1. Controller
Christopher Heaviside
Heaviside Solutions
Roßschwemme 14
6200 Jenbach, Österreich
Email: revora.konakt@gmail.com
Phone: +43 676 6603474
2. Data processed by Revora
Depending on how Revora is used, the following categories of data may in particular be processed:
- account and profile data such as name, email address and authentication information
- workspace and team data, roles and invitations
- item and inventory data such as title, brand, category, size, condition, color, material, descriptions and internal notes
- purchase prices, listing prices and sale prices, together with operational metrics calculated from them
- storage locations, shelf and box information and QR assignments
- images, documents and file references stored by the user
- sales and shipping data, potentially including recipient name, shipping carrier, tracking number and shipping-label reference
- technical usage, security and log data such as IP address, timestamps, browser or request information
- subscription, plan and billing status
3. Purposes and legal bases
Personal data is processed in particular to provide Revora, authenticate accounts, manage workspaces, perform functions requested by the user, process subscriptions, provide support and operate the application securely.
Where processing is necessary to provide an account or perform a Revora contract, it is carried out in particular for pre-contractual measures and contract performance under Article 6(1)(b) GDPR.
Statutory retention obligations or required records are processed on the basis of Article 6(1)(c) GDPR. Technical security measures, abuse prevention and ensuring stable operation may be based on legitimate interests under Article 6(1)(f) GDPR.
4. Registration and authentication
Revora uses Supabase Auth for registration, email confirmation, sign-in, password recovery and other authentication functions.
This may involve processing in particular the email address, authentication identifier, security-relevant session information and technical data required for the relevant authentication process.
5. Database and application data – Supabase
Revora uses Supabase for database and authentication infrastructure. The primary Revora Supabase location was selected within the European Union.
Regardless of the primary location, additional processing may occur in connection with infrastructure, support, security or subprocessors. Where required, the applicable data-protection transfer mechanisms are used.
6. Hosting and analytics – Vercel and PostHog
The Revora web application is delivered through Vercel. Technical connection and log data required for provision, delivery, security and error analysis may be processed when pages are accessed.
Revora uses Vercel Web Analytics for selected public pages. Only public paths specifically approved for that purpose are evaluated. URL query parameters and URL fragments are removed before transmission. Authenticated and sensitive application areas are excluded from this public reach measurement.
Revora additionally uses PostHog for narrowly limited reach and product analytics. Only explicitly defined analytics events are used.
On public pages, Revora may in particular record from which selected page area a visitor opened an explicitly instrumented registration button.
Within the authenticated application, coarse product milestones may additionally be recorded after successfully completed actions. These may include successful registration, workspace creation or workspace joining, item or storage-location creation, completion of the intended QR workflow, reaching the defined core activation milestone and successful qualification for the Founding Beta program.
The PostHog integration is configured for data minimization. Automatic event capture, automatic page-view and page-leave events, rage-click capture, automatic performance and error capture, Session Recording and automatic use of remotely supplied feature configuration are disabled.
The browser integration uses only volatile memory. Revora does not use PostHog cookies, Local Storage or Session Storage for this purpose. No PostHog person profiles are created in the browser, and authenticated users are not linked through browser identification to previous public-page visits.
Server-side product milestones use only pseudonymized technical identifiers generated by Revora. These are derived from internal user or workspace identifiers and are not transmitted to PostHog as a name or email address. These events are also configured so that no PostHog person profiles are created from them.
Through these custom analytics events, Revora does not transmit in particular names, email addresses, postal addresses, free-form item descriptions, complete business objects, invitation or authentication tokens, API keys, payment secrets, bank data or complete payment information.
The purpose of this limited analysis is to understand, in a data-minimizing manner, public paths to registration, workspace setup and use of the core workflows central to Revora, and to further develop the product accordingly.
The technical PostHog production configuration is enabled. The specific data-protection classification and legal basis for this analytics processing are subject to a separate legal review; technical activation does not replace that legal review.
7. Email delivery – Resend
Resend is used as the technical email infrastructure for transactional emails, in particular authentication emails, contract confirmations and contract-related system messages. This may involve processing in particular the recipient address, message content, delivery status and technical sending information.
Open tracking and click tracking are disabled for the Revora email infrastructure currently in use.
8. Payments and subscriptions – Stripe
For paid Revora plans, Stripe is used for Checkout, payment processing, subscription management, payment methods, tax calculation, invoices, receipts and transaction-related support.
For paid Revora plans, Stripe is used for technical payment and subscription processing. Stripe Tax processes the checkout information required for tax calculation based on the tax registrations configured for Revora.
Where Stripe determines the purposes and means of its own payment, tax or transaction services, such processing takes place under its own data-protection responsibility and in accordance with the privacy information provided by Stripe.
Revora does not itself store full payment-card details. Revora receives and stores in particular technical references such as customer, subscription and price identifiers, together with subscription and payment status, where required for plan provision, contract evidence and support.
9. Marketplace Companion and import features
The Revora Marketplace Companion is a browser extension that connects supported item pages on Vinted, eBay, Kleinanzeigen and Depop with the user's Revora account.
When the Marketplace Companion is opened and used on a supported item page, listing data required for the Revora workflow may be read from the page currently open. Depending on the marketplace and availability, this may include in particular platform, external item identifier, listing URL, title, description, price and currency, brand, category, size, condition, color, material, images and listing status.
This data is used to identify the current marketplace item, compare its Revora status, display the associated information in the Marketplace Companion and perform import and workflow actions requested by the user. This includes in particular adding an item to Revora as well as sales, packing, shipping and completion actions.
Where required for matching or an action initiated by the user, the necessary marketplace and item data is transmitted to the Revora API and associated with the authenticated Revora account or workspace.
For authentication in the Marketplace Companion, the email address and password are sent to Supabase Auth to verify the login credentials. The password is not stored permanently by the extension. After successful authentication, the authentication and session information required for the session, including access and refresh tokens and the email address of the authenticated account, is held in extension storage.
To the extent technically supported, Revora restricts access to this session information to trusted extension contexts. Session-bound extension storage may be used as a fallback. In addition, the display state of the Revora panel, for example open, minimized or closed, may be stored locally.
The browser extension does not use remotely loaded executable JavaScript or WebAssembly code. The executable code of the Marketplace Companion is delivered with the extension package. Network access to Revora and Supabase is used to transmit data and API responses, not to load remote code.
Requested host permissions are limited to the supported marketplace domains and the Revora and Supabase domains required for Revora API access and authentication. These permissions are used exclusively for the described marketplace and reselling workflow.
User data processed through the Marketplace Companion is not sold and is not used for advertising, profiling outside the Revora purpose, creditworthiness checks or lending decisions. Data is used or disclosed only where necessary for the described Revora functions, authentication, security, support or legal obligations.
Information processed or obtained through the Marketplace Companion is used in accordance with the Chrome Web Store User Data Policy, including its Limited Use requirements.
Users should import or store only data that they are legally permitted to process. Vinted, eBay, Kleinanzeigen and Depop remain responsible for their own services, websites and data processing.
10. Data relating to other persons
Revora may contain functions in which users store data relating to other persons, for example recipient information within a shipping process.
The respective user is responsible for entering into Revora only personal data that is necessary for the intended workflow and for which a lawful basis for processing exists.
11. Cookies and local storage technologies
Revora uses technically necessary storage and session technologies, in particular for sign-in, authentication, security and provision of the application requested by the user.
Revora does not use its own advertising or marketing cookies. Where Vercel Web Analytics is enabled, the limited reach measurement described in section 6 takes place only for the public pages named there.
The browser configuration intended for PostHog stores analytics state only in the volatile memory of the currently open page. No PostHog cookies, Local Storage or Session Storage are used for this purpose.
If Revora introduces persistent analytics storage in the future or any additional tracking or marketing technology that is not technically necessary, the legal basis and, where applicable, any required consent will be reviewed and implemented separately before activation.
12. Affiliate and external links
Public Revora content pages may contain labelled affiliate links or other external links to third parties.
When an external website is opened, the privacy terms of the respective third party apply. Further information about commercial disclosure is provided in the Affiliate Notice.
13. Retention period
Data is generally stored only for as long as necessary for the relevant purpose, provision of the account or contract, handling of support matters or compliance with statutory retention obligations.
In the event of a request to delete an account, account, workspace, contract and, where applicable, billing-related data are reviewed separately. Data that must mandatorily continue to be retained will not be deleted before the applicable retention obligation expires.
14. Recipients and international data transfers
Data is disclosed to service providers or other recipients only where required for the purposes described or where a legal basis exists. These recipients include in particular Supabase, Vercel, PostHog, Resend and Stripe.
Where data is processed outside the European Economic Area, this takes place only in compliance with the applicable requirements for international data transfers.
15. Rights of data subjects
Subject to the requirements of the GDPR, data subjects have in particular rights of access, rectification, erasure, restriction of processing, data portability and objection.
Requests may be sent to revora.konakt@gmail.com.
Where the statutory requirements are met, data subjects also have the right to lodge a complaint with a competent data-protection supervisory authority.
16. Changes to this Privacy Policy
This Privacy Policy will be updated if Revora's functions, service providers or legal bases materially change.