Privacy Policy
How Revyr Labs handles product, licensing, and support data.
Last Updated: June 13, 2026
Data controller
Revyr Labs, LLC, a sole proprietorship owned and operated by Alejandro Ramirez, is the data controller for personal information collected through this website and Ferqon Server. For privacy-related questions, contact privacy@revyrlabs.com.
1. Information We Collect
Account Information:
- Email address (optional, for license management)
- Name (optional, provided via Clerk authentication)
License Data:
- License key (generated upon purchase)
- Activation status and device count
- Device fingerprint (SHA-256 hash of machine hardware ID, stored as machine_hash for license binding)
Payment Information:
- Processed via Stripe; we do not store full card numbers
- Billing address and email for tax compliance (processed by Stripe)
Security and Fraud Prevention:
- IP address (logged for security events, fraud detection, and rate limiting)
- Device fingerprint (browser/user-agent based, for session security)
- User agent and request metadata for error troubleshooting
Error Monitoring:
- Error logs, stack traces, and browser context via Sentry (for debugging and stability)
- PII is automatically redacted before transmission
- No session replay or screen recording
Website Analytics:
- We use Vercel Analytics to understand website traffic
- Vercel Analytics does not use cookies or track individual users
- Analytics collect anonymized page views, referrers, and general location (country level)
- We also track aggregate business events (for example, plan type, purchase amount, and signup method) without personal identifiers
Contact Form and Sales Inquiries:
- Contact form: name, email, and message
- Pricing estimate form: company name, work email, fleet size, tier of interest, message, and optional UTM/page source data
- IP address and device fingerprint are collected for security and rate limiting and are truncated in support/sales communications
2. How We Collect Information
- Voluntary Submission: Account registration, contact form submissions, and pricing estimate requests
- License Validation: When activating or deactivating licenses
- Payment Processing: Through Stripe's secure payment system
- Security Logging: IP address and device fingerprint logged during API requests for fraud prevention, rate limiting, and abuse detection
- Error Monitoring: Sentry captures error logs, stack traces, and browser context (URL, user agent, breadcrumbs) when application errors occur; PII is redacted before transmission
- Marketing Source Data: When submitting a pricing estimate, UTM parameters and page path are collected for sales attribution and follow-up
3. Lawful Basis for Processing (GDPR)
- Contract: Processing necessary to provide the license and services you purchase
- Legitimate Interest: Security logging (IP addresses, device fingerprints) for fraud prevention and system security
- Legitimate Interest: Error monitoring via Sentry for application stability and debugging
- Consent: Account registration (when you choose to create an account)
4. Use of Information
- License Management: Activating, deactivating, and tracking licenses
- Support: Responding to technical inquiries
- Security: Detecting and preventing license abuse, fraud, and unauthorized access
- Improvement: Analyzing support patterns and error logs to improve documentation and stability
- Analytics: Understanding website traffic to improve our services
5. Data Storage and Security
- Encryption: License keys and account data encrypted at rest in Supabase
- Secure Hosting: All data stored on secure, access-controlled infrastructure (Supabase, Vercel)
- Access Controls: Strict access controls for administrative access to user data
- IP Anonymization: IP addresses are truncated (last octet removed) before long-term storage where feasible
6. Third-Party Services
Payment Processing: Stripe processes all payments. Credit card information never touches our servers. Stripe's privacy policy governs payment data.
Authentication: Clerk handles user authentication and session management. Clerk's privacy policy governs authentication data.
Database: Supabase hosts our database. Supabase's privacy policy governs data storage.
Email: Resend delivers transactional emails. Resend's privacy policy governs email delivery.
Error Monitoring: Sentry captures error logs, stack traces, and browser context. PII is automatically redacted before transmission. Sentry's privacy policy governs error data.
Hosting and Analytics: Vercel hosts the website and provides analytics. Vercel's privacy policy governs hosting and analytics data.
CDN: Cloudflare provides content delivery and DDoS protection. Cloudflare's privacy policy governs CDN data.
Rate Limiting: Upstash provides rate limiting and caching. Upstash's privacy policy governs rate limit data.
7. Website Analytics
Privacy-First Analytics:
- We use Vercel Analytics to understand website traffic and improve our services
- No Cookies: Vercel Analytics does not use cookies or track individual users
- No Personal Data: Analytics only collect anonymized page views, referrers, and general location (country level)
- No Cross-Site Tracking: Analytics are limited to this website only
Data Collected:
- Page URLs visited
- Approximate geographic location (country/region)
- Browser and device type
- Referrer source (how you found us)
- Page load times (for performance optimization)
Data Not Collected:
- Personal identifiers (name, email, IP address)
- Individual user sessions
- Cross-site browsing history
- Personal behavioral profiles
8. Cookies and Tracking
- Essential Cookies: Required for website functionality (authentication, session management)
- No Third-Party Analytics: We do not use Google Analytics or similar cookie-based tracking
- No Marketing Cookies: No advertising or retargeting cookies
- Session Replay: We do not use session replay or screen recording
9. Data Sharing
We do not sell or rent your personal data. We share your data only with service providers who process it on our behalf and under contract, and where required by law.
- Payment Processors: Stripe for transaction processing
- Service Providers: Subprocessors listed in our Subprocessors page (Stripe, Clerk, Supabase, Resend, Sentry, Vercel, Cloudflare, Upstash)
- Legal Requirements: When required by law, court order, or to protect our rights and safety
10. International Transfers
Data is stored within secure infrastructure that may be located outside your country (primarily United States). All transfers comply with applicable data protection laws, including the use of Standard Contractual Clauses (SCCs) for EU data transfers where required.
11. Your Rights
- Access: View your account information and licenses
- Correction: Update your email address and account details
- Deletion: Request account deletion (license management only)
- Portability: Export your license information
- Objection: Object to certain processing activities (where legally permitted)
- Restriction: Request restriction of processing (where legally permitted)
- Withdrawal of Consent: Withdraw consent where processing is based on consent at any time
- Complaint: Lodge a complaint with a data protection supervisory authority in your jurisdiction
To exercise these rights, contact privacy@revyrlabs.com. We will respond within 30 days. For complex requests, we may extend this period by up to two additional months and will inform you of the extension within the first 30 days.
12. GDPR and CCPA Compliance
- Data Minimization: Collect only necessary information
- Transparency: Clear disclosure of data practices
- User Rights: Access, correction, deletion, portability, objection, and restriction rights
- Security: Appropriate technical and organizational measures
- Lawful Basis: Processing based on contract, legitimate interest, or consent
CCPA Rights: California residents have the right to know the categories of personal information we collect, the right to request deletion of personal information, the right to correct inaccurate personal information, and the right to non-discrimination for exercising these rights. Revyr Labs does not sell or share personal information for cross-context behavioral advertising. To exercise CCPA rights, contact privacy@revyrlabs.com.
13. Children's Privacy
Revyr Labs services are not intended for users under 16. We do not knowingly collect information from children under 16. If we become aware that we have collected personal information from a child under 16, we will take steps to delete that information.
14. Data Retention
- License Data: Retained for license management purposes for 7 years (tax and legal compliance)
- Account Data: Retained until account deletion request
- Support Requests and Sales Inquiries: Retained for 2 years, then deleted
- Consent Records: Retained for 7 years after account deletion for legal defensibility
- Security Logs (IP, device fingerprint): Retained for 90 days, then deleted
- Error Logs (Sentry): Retained for 30 days, then deleted
- Analytics Data (Vercel): Retained for 30 days by Vercel Analytics, then automatically deleted
15. Data Breach Notification
In the event of a data breach affecting your personal information, we will notify you within 72 hours of becoming aware of the breach, in accordance with applicable law. Notification will be sent to the email address associated with your account.
16. Changes to This Policy
We may update this privacy policy as needed. Changes will be posted on our website with an updated effective date. Material changes will be notified via email to registered users.
17. Contact Information
For privacy-related questions, contact privacy@revyrlabs.com.