RevenueOS Privacy Policy
Version 1.0 · Effective Date: July 8, 2026
Draft prepared for counsel review — not yet final
Contents
- Who We Are and What This Policy Covers
- If You Received an Email Sent Through RevenueOS
- Personal Data We Collect
- Why We Process Personal Data and Our Legal Bases
- Records We Keep as Legal Evidence
- How Long We Keep Personal Data
- Your Privacy Rights
- Automated Decision-Making
- The Pooled Intelligence Program
- How We Share Personal Data
- Security and Breach Notification
- International Data Transfers
- Cookies and Similar Technologies
- US State Privacy Rights
- Children and Sensitive Data
- Changes to This Policy
- How to Contact Us
- Annex I: Categories of Personal Data
- Annex II: Security Measures
- Annex III: Service Providers
1. Who We Are and What This Policy Covers
1.1 Who we are. RevenueOS Inc. ("RevenueOS," "we," "us," or "our") is a Delaware corporation with its notice address at RevenueOS Inc., [registered / notice address]. We operate the website at www.revenueos.app and the RevenueOS outbound experimentation, measurement, and attribution platform (together, the "Services"). You can reach us about anything in this policy at legal@revenueos.app.
1.2 Our two roles. We handle personal data in two distinct capacities, and your rights run differently in each. First, we are a controller for the data described in this policy: information about visitors to our website, the people who create and use RevenueOS accounts, billing contacts, recipients of our own communications, service telemetry, and the legal-evidence records described in Section 5. Second, we are a processor for Customer Data and Prospect Data — the data our business customers submit to the platform to run their own outbound programs. Processor-side processing is governed by our Data Processing Addendum (the "DPA"), available at www.revenueos.app/dpa, not by this policy. Where this policy and the DPA could be read to conflict about Customer Data or Prospect Data, the DPA controls.
1.3 What this policy does not cover. This policy does not describe the privacy practices of our customers. If a RevenueOS customer has your information, that customer's own privacy notice governs — see Section 2. Our Terms of Service, available at www.revenueos.app/terms, govern the commercial relationship with our customers; this policy is consistent with them and does not modify them.
1.4 European and UK applicability. Our Services are targeted at businesses in the United States, and we have no establishment in the European Union or the United Kingdom. Whether the limited circumstances in which our controller-side processing touches EU or UK individuals require the appointment of a representative under Article 27 of the EU or UK GDPR is under review by our counsel. We have not appointed a representative as of the effective date; if we appoint one, we will name them in an update to this policy.
2. If You Received an Email Sent Through RevenueOS
2.1 The sender is our customer. RevenueOS is a measurement platform used by business-to-business sales teams. If you received an outbound email from a company using RevenueOS, that company — not RevenueOS — decided to contact you, wrote or approved the message, and sent it through its own mailboxes and sending tools. That company is the controller (or is acting for its own client, who is) of your personal data. RevenueOS processes your data only on that company's behalf and under its instructions, as a processor.
2.2 What we hold about you. On behalf of the sender, we may process: your business contact details (such as name, business email address, company, and title); records of messages sent to you and your engagement with them (sends, opens, replies, bounces, and opt-outs); and experiment-assignment and outcome records used to measure which messaging performs better. This data comes to us from the company that contacted you — from its own records and systems and any data providers it uses — not from any collection of ours. We do not use this data for our own purposes, we do not sell it, and we do not contact you on our own behalf.
2.3 Where to send your requests. Please direct requests to access, correct, delete, or stop the use of your data — and opt-out requests — to the company that contacted you; its identity appears in the message you received. If you send a request to us instead, we will forward it to the relevant customer without undue delay and will assist that customer in fulfilling it as described in the DPA. The sender remains responsible for responding to you within the deadlines that apply to it.
3. Personal Data We Collect
3.1 Website visitors. When you visit www.revenueos.app we set a small number of strictly necessary first-party cookies: ro_consent_v1, which remembers your cookie choices, and cookies set by our authentication provider, Clerk, that are required to establish and secure sessions. We deploy no marketing or advertising pixels of any kind. Where analytics is enabled for a deployment, we load Google Analytics only if you have granted analytics consent, and only with IP anonymization turned on; as of the effective date, no analytics loader is enabled on the public site. We honor the Global Privacy Control (GPC) signal: if your browser sends it, our consent banner defaults analytics and marketing consent to off, and no analytics loads without your affirmative consent; GPC does not override a choice you have already saved, which you can change at any time. Our servers also keep standard technical logs (IP address, user-agent string, request metadata) for security and diagnostics.
3.2 Accounts. When you create or use a RevenueOS account, our authentication provider, Clerk, processes your name, email address, IP address, sign-in timestamps, and session and device information on our behalf. We use this to create your account, keep it secure, and let your organization manage its members and roles.
3.3 Billing. Our payment processor, Stripe, collects and processes payment information when your organization pays for the Services. We receive billing contact details, plan and subscription information, and transaction records; we do not store full payment card numbers.
3.4 Customer Data and Prospect Data (processor role). Our customers submit data to the platform to run their outbound programs, including Prospect contact and engagement data and campaign content. We process this data solely as a processor under the DPA. The categories, purposes, safeguards, subprocessors, and deletion commitments for this data are set out in the DPA at www.revenueos.app/dpa; Section 2 above explains how to exercise your rights if you are a Prospect.
3.5 Usage data and telemetry. We collect technical logs and telemetry about how the Services are accessed and perform — request logs, feature-usage events, error diagnostics, and performance measurements. This data is about the operation of the Services; it excludes the content of Customer Data.
3.6 Legal-evidence records. When someone accepts our Terms of Service or makes a consent decision with legal effect, we record it, including the IP address and user-agent string of the accepting session. Section 5 describes these records and their unusual retention in full.
3.7 What we do not collect. We do not buy personal data from data brokers, we do not collect advertising identifiers, and we do not run marketing pixels or cross-site tracking on our website.
4. Why We Process Personal Data and Our Legal Bases
4.1 To perform our contract. We process account, billing, and support data to provide the Services your organization signed up for: creating and administering accounts, operating the platform, sending transactional email (such as receipts, security notices, and service messages), invoicing, and providing support. Legal basis where the GDPR applies: performance of a contract.
4.2 With your consent. We process the following only with consent: analytics cookies (Section 13); participation of a customer's data in the Pooled Intelligence Program (Section 9); and marketing communications where you have opted in. You can withdraw any consent at any time (Section 7), and withdrawal does not affect the lawfulness of processing before withdrawal.
4.3 For our legitimate interests. We process limited personal data for legitimate interests we have specifically identified: securing the Services and our users' accounts; preventing fraud and abuse of the platform; and service telemetry and diagnostics that keep the Services reliable and let us fix defects. We have balanced these interests against your rights, we limit the data involved to what these purposes need, and you may object as described in Section 7.
4.4 To comply with legal obligations. We retain tax, billing, and accounting records for statutory periods, and we respond to valid legal process, as required by law.
5. Records We Keep as Legal Evidence
5.1 Terms-acceptance records. When you accept our Terms of Service on behalf of your organization, we record: the version of the Terms accepted, a cryptographic hash of the document text exactly as it was published to you, the date and time of acceptance, your IP address, and your browser's user-agent string.
5.2 Consent-ledger records. When your organization makes a consent decision with legal effect — most importantly, opting into or withdrawing from the Pooled Intelligence Program (Section 9) — we record the decision, who made it, and when, in an append-only consent ledger.
5.3 These records survive account deletion. The records in Sections 5.1 and 5.2 are retained even after your account is deleted or an erasure request is granted. We keep them as evidence for the establishment, exercise, or defence of legal claims, as permitted by GDPR Article 17(3)(e), and to demonstrate that consent was given, as GDPR Article 7(1) requires of us. They are immutable by design — the ledgers are append-only and cannot be edited — and we use them for no other purpose. This is the one deliberate exception to erasure, and we disclose it here so it never surprises you.
6. How Long We Keep Personal Data
6.1 General rule. We keep personal data only as long as we need it for the purposes described in this policy, and then delete or anonymize it — except where a statutory retention period applies.
6.2 Concrete retention windows. When an account is deleted or an erasure request is granted:
- Proposals, invoices, and signed documents: the personal fields (names, email addresses, billing addresses, signer IP addresses, notes) are anonymized immediately, and the underlying business records are retained for approximately seven years to satisfy tax and accounting law.
- Your user profile: anonymized immediately — email, name, phone, and IP address are removed; a non-identifying record skeleton remains for contract and legal retention.
- Cookie-preference consent events and PII access logs: deleted.
- Marketing interaction records: deleted.
- Service telemetry containing IP addresses or user-agent strings: kept only as long as needed for security monitoring and diagnostics and then deleted or anonymized; we review these logs on a rolling basis.
- Terms-acceptance records and the Pooled Intelligence consent ledger: retained as described in Section 5.
- Routine backups: copies may persist in encrypted backups until their scheduled destruction.
6.3 After your organization's subscription ends. Consistent with our Terms of Service, Customer Data remains available for export for thirty days after termination and is then deleted in accordance with the DPA, except for backup copies pending scheduled destruction, data retained to comply with law, and the aggregate statistics described in Section 9.
6.4 EU and UK enhancements. For data subject to EU or UK law, we apply two additional erasure enhancements: analytics events are deleted immediately on erasure rather than retained under a legitimate-interest claim, and user-agent strings and internal notes are anonymized.
7. Your Privacy Rights
7.1 The rights you have. Depending on where you live, you may have the right to: access the personal data we hold about you and receive a copy; correct inaccurate data; delete your data; restrict or object to certain processing; receive your data in a portable format; withdraw any consent at any time; and not be discriminated against for exercising any of these rights.
7.2 How to make a request. There are two ways: email us at legal@revenueos.app, or — if you hold a RevenueOS account — use the privacy tools in your account settings, which support access and export requests directly; to request deletion of your data, email legal@revenueos.app and we will action it through our data-subject-request process. If you are a Prospect (someone a RevenueOS customer contacted), Section 2.3 explains why your request should go to the sender, and what we do if it reaches us instead.
7.3 Identity verification. We verify requests before acting on them — for account holders, through the authenticated account itself; for email requests, by matching the request to the data we hold and asking for reasonable additional confirmation where needed. We only use verification information to verify the request.
7.4 Timing. We respond within 30 days of receiving a verifiable request. Where a request is complex or numerous, that period is extendable as applicable law permits, and we will tell you within the initial period if we need an extension and why.
7.5 Appeals. If we deny your request in whole or in part, we will explain why and tell you how to appeal. To appeal, reply to our decision or write to legal@revenueos.app with the word "Appeal" in the subject line; a person other than the original decision-maker will review the appeal and respond within the period applicable law requires. If your appeal is denied, we will tell you how to contact your supervisory authority or state attorney general.
7.6 Complaints. You may complain directly to us at legal@revenueos.app about how we have handled your personal data. We will acknowledge your complaint within 30 days and investigate it without undue delay, and we will tell you the outcome. You also have the right, at any time, to lodge a complaint with a data protection supervisory authority — in the EU, the authority in your member state; in the UK, the Information Commissioner's Office; in the US, your state attorney general.
7.7 Withdrawing consent. You can change your cookie choices at any time as described in Section 13.4. An organization's owner or administrator can withdraw from the Pooled Intelligence Program at any time in the product's legal settings (Section 9.4).
8. Automated Decision-Making
8.1 No legally significant automated decisions. We do not make decisions based solely on automated processing that produce legal effects concerning individuals or similarly significantly affect them.
8.2 What our statistics actually do. The platform's statistical outputs — experiment estimates, posterior probabilities, and rankings — describe the performance of messaging strategies for our business customers. They evaluate messages, not people: they do not score, profile, or make decisions about any individual's eligibility, access, or treatment.
9. The Pooled Intelligence Program
9.1 Opt-in only. The Pooled Intelligence Program is our optional cross-customer statistics program. A customer's data contributes to it only if that customer's owner or administrator explicitly opts in, and a customer that has never decided is not in the program. The decision is recorded in the consent ledger described in Section 5.
9.2 What is pooled. The program computes aggregate Bayesian posteriors / sufficient statistics: for each messaging angle, per-customer success and trial counts are combined into a single population-level statistical parameter. No names, no email addresses, no message content, no per-recipient records, and no customer identity ever enter the pooled output.
9.3 Safeguards. A pooled statistic is published for an angle only when at least five distinct participating customers contribute to it; below that floor, no population signal is released. Calibrated statistical noise (differential privacy) is applied to every release. These parameters are strongly protected, but we do not call them "anonymous": we treat them as regulated data, apply the safeguards above, and never attempt to reverse them to any customer or individual.
9.4 Withdrawal. A participating customer can withdraw at any time, effective prospectively: we stop deriving new pooled statistics from that customer's data going forward. Statistics already computed are aggregate, noise-protected parameters from which an individual customer's contribution cannot be isolated or extracted, and they may continue to be used as our Terms of Service describe.
10. How We Share Personal Data
10.1 Service providers. We share personal data with the service providers that run the platform — currently spanning identity and authentication, database hosting, payments, email-event processing, application hosting, AI inference, and caching, as summarized in Annex III. The canonical, vendor-level subprocessor list, including each vendor's location and transfer mechanism, is maintained in the DPA at www.revenueos.app/dpa, and we update it there under the DPA's notice process rather than duplicating it here.
10.2 Corporate events. If we are involved in a merger, acquisition, financing, or sale of assets, personal data may be transferred as part of that transaction, subject to this policy and to notice where required by law.
10.3 Legal reasons. We disclose personal data where required by valid legal process, or where necessary to protect the rights, safety, or property of RevenueOS, our customers, or others — and we will challenge overbroad demands where we reasonably can.
10.4 No sale. WE DO NOT SELL PERSONAL INFORMATION, AND WE DO NOT SHARE PERSONAL INFORMATION FOR CROSS-CONTEXT BEHAVIORAL ADVERTISING.
11. Security and Breach Notification
11.1 How we protect personal data. We maintain administrative, technical, and organizational safeguards designed to protect personal data, including encryption of data in transit, platform-provided encryption at rest, logical tenant isolation, role-based access controls, and audit logging of privileged operations. Annex II summarizes these measures; the DPA carries the binding version for Customer Data.
11.2 If something goes wrong. If we become aware of a breach of security leading to the accidental or unlawful destruction, loss, alteration, or unauthorized disclosure of or access to personal data, we will notify affected customers without undue delay, will notify regulators and affected individuals where applicable law requires, and will provide the information reasonably needed to assess and respond to the incident. This commitment stands on its own and applies regardless of which regulatory regime governs the incident.
12. International Data Transfers
12.1 Where we process. RevenueOS operates from the United States, and personal data is processed and stored in the United States.
12.2 Transfers of EU personal data. Where we process personal data protected by EU law, the DPA incorporates the European Commission's 2021 Standard Contractual Clauses — Module Two (controller to processor) and, where the Customer is itself a processor for its own clients, Module Three (processor to processor). If the European Commission adopts updated Standard Contractual Clauses applicable to these transfers, the updated clauses automatically supersede the incorporated set as the DPA provides.
12.3 Transfers of UK personal data. For personal data protected by UK law, the DPA incorporates the UK International Data Transfer Addendum to the EU Standard Contractual Clauses (or the ICO's International Data Transfer Agreement, as applicable).
12.4 Data Privacy Framework. Where a service provider of ours is certified under the EU-U.S. Data Privacy Framework, we may take that certification into account; we rely on Standard Contractual Clauses in any event.
12.5 Copies. You may request a copy of the transfer safeguards that apply to your data (redacted of commercial terms) by writing to legal@revenueos.app.
13. Cookies and Similar Technologies
13.1 Cookies we set. Our actual cookie inventory is deliberately small:
- ro_consent_v1 — a necessary first-party cookie that stores your cookie choices (analytics on or off, marketing on or off) and when you made them. It lasts about twelve months.
- Authentication cookies — session and client cookies set by our authentication provider, Clerk, when our authentication layer loads and when you sign in. These are necessary to establish and secure sessions and to keep you signed in securely.
- Google Analytics cookies — set only where analytics is enabled for the deployment AND you have granted analytics consent, and always with IP anonymization. As of the effective date, analytics is not enabled on the public site.
- Payment cookies — if you use payment surfaces, our payment processor, Stripe, sets cookies necessary for payment processing and fraud prevention.
13.2 What we do not set. We deploy no marketing or advertising pixels. The consent banner includes a marketing category so that your preference is recorded, but granting it currently loads nothing — no marketing script exists in the product. If we ever add one, we will update this policy first.
13.3 Browser storage. We use browser localStorage for two non-tracking values: ro_consent_queue (a temporary offline queue that holds your consent choices if our server is briefly unreachable, so they are not lost) and ros-specimen-expiry (a timestamp the public landing page uses to rotate a display specimen; it identifies no one).
13.4 Your controls. The consent banner appears until you decide. You can change your choices afterwards at any time: from the privacy settings link available in the application, or — from any page, including our public pages — by clearing the ro_consent_v1 cookie in your browser, which brings the banner back the next time you visit; you can also write to legal@revenueos.app and we will reset your choices. Your choices are stored in the ro_consent_v1 cookie and recorded server-side so we can demonstrate them. We honor the Global Privacy Control: if your browser sends the GPC signal, our consent banner defaults analytics and marketing to off, and no analytics loads without your affirmative consent; GPC does not override a choice you have already saved, which you can change at any time.
14. US State Privacy Rights
14.1 Scope. This section applies to residents of US states with comprehensive privacy laws. Because those laws now generally cover personal information collected in a business-to-business context, they apply to the account, billing, visitor, and telemetry data this policy describes.
14.2 Categories we collect and disclose. In the categories those laws use: identifiers (name, email address, IP address); commercial information (subscription and transaction records); internet and network activity (usage logs and telemetry); and professional information (company, title). Annex I maps these to the collection surfaces in Section 3. We disclose these categories only to the service providers in Annex III, for business purposes, under contracts restricting their use.
14.3 No sale, no sharing, no targeted advertising. We do not sell personal information, we do not share it for cross-context behavioral advertising, and we do not process it for targeted advertising. We also do not process personal information for profiling in furtherance of decisions that produce legal or similarly significant effects (Section 8).
14.4 Deidentified data. The pooled statistical parameters described in Section 9 are maintained in deidentified, aggregate form and are not reasonably linkable to any individual: we maintain them as aggregate, noise-protected statistical parameters, and we publicly commit not to attempt to reidentify them.
14.5 Universal opt-out. We do not sell or share personal information or process it for targeted advertising, so the opt-outs that universal opt-out signals invoke are already the permanent state of our processing in every state that recognizes such a signal — and everywhere else too. In addition, when your browser sends the Global Privacy Control signal, our consent banner defaults analytics and marketing consent to off (Section 13.4).
14.6 Exercising your rights; appeals. State-law rights to know, access, correct, delete, and obtain a copy of your personal information are exercised through the two methods in Section 7.2, on the timing in Section 7.4. If we deny a request, the appeal process in Section 7.5 applies; if your appeal is denied, you may contact your state attorney general.
14.7 Rhode Island. Rhode Island's law provides no cure period and defines "sale" broadly. Our practices do not involve the sale of personal information under any state's definition, including Rhode Island's.
14.8 Data brokers. We are not a data broker, we are not required to register as one, and we do not sell personal information.
14.9 Automated decision-making technology. We do not use automated decision-making technology to make significant decisions concerning individuals, as described in Section 8.
15. Children and Sensitive Data
15.1 Children. The Services are business software and are not directed to individuals under 16. We do not knowingly collect personal data from anyone under 16; if you believe we have, contact legal@revenueos.app and we will delete it.
15.2 Sensitive data. The Services are not intended to process sensitive or special-category data (such as health, biometric, or precise-geolocation data), and we instruct our customers not to submit it to the platform.
16. Changes to This Policy
16.1 Versioning. This policy is versioned, and the version and effective date appear at the top. We keep prior versions available on request.
16.2 Notice of material changes. If we make a material change, we will notify you before it takes effect — through the Services, by email, or both — and the new version will apply from its stated effective date. Non-material clarifications may take effect on posting.
17. How to Contact Us
17.1 Contact. For privacy questions, requests, appeals, and complaints: legal@revenueos.app, or by mail to RevenueOS Inc., [registered / notice address]. Legal notices under our Terms of Service follow the notice provisions there.
Annex I: Categories of Personal Data
Controller-side personal data, by collection surface (Section 3):
- Website visitors — cookie-choice records (the ro_consent_v1 cookie); server logs including IP address and user-agent string; where enabled and consented, IP-anonymized analytics data.
- Account holders — name, email address, IP address, sign-in timestamps, session and device information, organization membership and role.
- Billing contacts — billing name and contact details, plan and subscription records, transaction history (full payment card numbers are held by our payment processor, not by us).
- Communications — messages you send us and our transactional email to you.
- Usage data and telemetry — request logs, feature-usage events, error diagnostics, and performance measurements about the operation of the Services.
- Legal-evidence records — Terms-acceptance records (version, document hash, timestamp, IP address, user-agent string) and consent-ledger records (Section 5).
Processor-side data (Customer Data and Prospect Data — categories only; the DPA governs): Prospect business contact details; message and engagement events; experiment-assignment and outcome records; campaign content.
Annex II: Security Measures
A summary of our technical and organizational measures; the binding version for Customer Data lives in the DPA:
- Encryption of data in transit (TLS) and platform-provided encryption of data at rest.
- Logical tenant isolation, so one customer's data is partitioned from another's.
- Role-based access controls and least-privilege credentials for personnel and systems.
- Audit logging of privileged operations; audit records are additionally sealable through KMS-backed signing that operates over cryptographic hash values only and receives no personal-data content.
- Append-only, immutable ledgers for Terms-acceptance and consent records (Section 5).
- Consent-gated loading of analytics: no analytics script executes before consent, and the loader fails closed if the consent check fails.
- Deliberate minimization of third parties: no marketing pixels, no advertising SDKs, no data-broker feeds.
- Encrypted backups with scheduled destruction, and documented erasure and anonymization procedures (Section 6).
Annex III: Service Providers
We use service providers in the following functions to operate the Services: identity and authentication; database hosting; payments; email-event processing; application hosting; AI inference; and caching.
The canonical subprocessor list — naming each vendor, its function, its location, and the transfer mechanism that applies — is maintained in the DPA at www.revenueos.app/dpa and is updated there under the DPA's subprocessor-notice process. We do not duplicate the vendor-level list here, so that there is exactly one authoritative version.
— End of Privacy Policy —
RevenueOS Inc. · Version 1.0 · Last updated July 8, 2026