revisit

    Privacy Policy

    Last updated: 3 September 2026

    This is a translation of the Spanish original, provided for convenience. In the event of any discrepancy, the Spanish version prevails.

    1. Data controller

    • Identity: REVISIT XMD, S.L. (hereinafter, "Revisit")
    • Registered address: C/ Holanda, 1, 08917 Badalona (Barcelona), Spain
    • Tax ID (NIF): B93872174
    • Contact email: hola@revisit.es

    2. Data we collect

    Depending on your relationship with Revisit, we process different categories of personal data:

    2.1. Website visitors

    • Data provided through the contact form: name, business name, telephone and email address.

    2.2. Business customers (tenants)

    • Company data: trading name, email, telephone, address, website, logo.
    • User data (business staff): name, email, password (stored encrypted), avatar.
    • Service configuration data: opening hours, loyalty programme, rewards, marketing campaigns.
    • Google OAuth credentials (stored encrypted) for the Google Business Profile integration.

    2.3. The businesses' own end customers

    Businesses using Revisit record data about their own customers. In this case the business acts as data controller and REVISIT XMD, S.L., through the Revisit platform, as data processor under Article 28 GDPR.

    • Identifying data: name, email, telephone, dialling code.
    • Demographic data (optional): date of birth, gender, postcode, acquisition channel.
    • Activity data: visits, points, stamps, average ticket, lifetime value (LTV), customer status.
    • Wallet data: wallet token, Google Wallet object identifier.
    • Interaction data: reviews, reward redemptions, review requests sent.
    • Marketing consent: recorded expressly and separately.

    3. Purpose of processing

    • Providing the loyalty service contracted by the businesses.
    • Managing the commercial relationship with business customers.
    • Handling contact requests and technical support.
    • Sending commercial communications about Revisit (only with prior consent).
    • Improving the service through aggregated and anonymised statistical analysis.
    • Complying with applicable legal obligations.

    4. Legal basis for processing

    • Performance of a contract (Art. 6(1)(b) GDPR): to provide the service to businesses that contract Revisit.
    • Consent (Art. 6(1)(a) GDPR): to send commercial communications and for the processing of end customer data by the businesses.
    • Legitimate interest (Art. 6(1)(f) GDPR): to improve the service, perform aggregated statistical analysis and prevent fraud or misuse.
    • Legal obligation (Art. 6(1)(c) GDPR): to comply with tax, commercial and data protection obligations.

    5. Recipients and data processors

    Personal data may be disclosed to the following recipients or data processors:

    • OVH SAS (Gravelines, France, EU): infrastructure and server hosting provider where all platform data is stored.
    • Google LLC (United States): for Google Wallet functionality and the Google Business Profile integration. Transfer covered by the EU-US Data Privacy Framework.
    • Automation engine (hosted at OVH, France, EU): workflow automation system used to process events and send notifications.

    No data is disclosed to third parties except where legally required or strictly necessary to provide the service.

    6. Use of Google API data (Limited Use requirements)

    Revisit accesses information through Google APIs (Google Wallet, Google Business Profile and Sign in with Google) solely to deliver the functions the business contracts: issuing and updating the customer's loyalty card in Google Wallet, displaying and replying to the business's reviews on its Google Business Profile, and allowing the owner to access their management panel.

    Revisit's use and transfer of information received from Google APIs will adhere to the Google API Services User Data Policy, including its Limited Use requirements (Limited Use). Specifically:

    • We only use data obtained from Google APIs to provide or improve user-facing features within Revisit.
    • We do not sell data obtained from Google APIs.
    • We do not use that data for advertising purposes, including personalised advertising, nor for creditworthiness or lending purposes.
    • We do not allow humans to read that data, except: (a) with the user's express consent, (b) for security purposes (for example, investigating abuse), (c) to comply with applicable law, or (d) where the data is aggregated and anonymised and used for internal operations in accordance with applicable policies.

    7. International data transfers

    Revisit's main infrastructure is located in the European Union (OVH, Gravelines, France).

    The integration with Google services (Wallet and Business Profile) may involve data transfers to the United States. Those transfers are covered by the EU-US Data Privacy Framework, approved by the European Commission's adequacy decision of 10 July 2023, and by the Standard Contractual Clauses (SCCs) where applicable.

    8. Data retention

    • Lead and contact form data: 12 months from the request, unless a contractual relationship is formalised.
    • Business customer data: for the entire duration of the contractual relationship, plus the applicable legal retention periods (tax and commercial obligations).
    • End customer data: for as long as the business keeps its Revisit account active, or until the end customer requests deletion from the relevant business.
    • After service termination: data is kept blocked for the legally required periods and securely deleted once they have elapsed.

    9. Data subject rights

    Under the GDPR and the Spanish Data Protection Act (LOPDGDD), you may exercise the following rights:

    • Access (Art. 15 GDPR): to know what personal data of yours we are processing.
    • Rectification (Art. 16 GDPR): to correct inaccurate or incomplete data.
    • Erasure (Art. 17 GDPR): to request deletion of your data when it is no longer necessary.
    • Restriction of processing (Art. 18 GDPR): to request that processing be restricted in certain circumstances.
    • Portability (Art. 20 GDPR): to receive your data in a structured, commonly used, machine-readable format and transmit it to another controller.
    • Objection (Art. 21 GDPR): to object to the processing of your data in certain cases.
    • Withdrawal of consent: where processing is based on your consent, you may withdraw it at any time without affecting the lawfulness of prior processing.

    To exercise any of these rights, send an email to hola@revisit.es stating the right you wish to exercise and enclosing a copy of your identity document. We will respond within one month of receiving the request, extendable by a further two months for complex or numerous requests, with prior notice to the data subject.

    End customers of the businesses should address their requests to the relevant business, which is the controller of their data. If you need assistance, however, you can contact us at hola@revisit.es.

    10. Data processor

    REVISIT XMD, S.L., through the Revisit platform, acts as data processor with respect to end customer data that businesses enter into the platform. Every business that contracts Revisit accepts a Data Processing Agreement (DPA) under Article 28 GDPR, which sets out:

    • The controller's instructions for processing the data.
    • The applicable technical and organisational security measures.
    • Confidentiality obligations for staff with access to the data.
    • The conditions for engaging sub-processors.
    • Assistance to the controller in meeting its obligations (data subject rights, impact assessments, breach notification).
    • The return or deletion of data at the end of the contractual relationship.

    11. Security measures

    Revisit applies appropriate technical and organisational measures to safeguard personal data, including:

    • Passwords encrypted with secure hashing algorithms (bcrypt).
    • All communications encrypted using HTTPS/TLS.
    • OAuth tokens and sensitive credentials stored encrypted and never exposed in API responses.
    • OTP verification for end customer registration.
    • Role and permission system with data isolation per tenant (business).
    • Regular backups.
    • Restricted access to production servers and systems.

    12. Complaints

    If you believe the processing of your personal data does not comply with applicable law, you have the right to lodge a complaint with the Spanish Data Protection Agency (AEPD):

    • Website: www.aepd.es
    • Address: C/ Jorge Juan, 6, 28001 Madrid, Spain