Consulter cette politique en français
Privacy Policy
Version 2026-07 · Last updated: July 12, 2026
This Privacy Policy explains how Revyn Media ("we", "us") collects, uses and protects personal information when you visit revynengine.com, sign up for Revyn Engine, or use the Revyn Engine platform. We are headquartered in Alberta, Canada (First Edmonton Place, 10665 Jasper Avenue, Edmonton, AB T5J 3S9, Canada) and serve venues in Canada, the United States, and — as we expand — the European Union and the United Kingdom. This policy is written to meet PIPEDA and Alberta's Personal Information Protection Act (PIPA), US state privacy laws (including the CCPA/CPRA), and the EU and UK GDPR.
Who is responsible for your data
For information you give us directly — a trial signup, a sales inquiry, your operator account — we act as the data controller (in Canadian terms, the organization accountable for it). For guest data that venues manage inside the platform (bookings, waivers, customer profiles, conversations), the venue is the controller and we act as a data processor on the venue's documented instructions, under the Data Processing Addendum that forms part of our Terms of Service. Guests seeking access to or deletion of data held by a venue should contact that venue first; the platform gives venues the tools to fulfil those requests, and we assist where needed.
Our designated Privacy Officer — the individual accountable for personal information under PIPEDA and Alberta PIPA, the Person in Charge of the Protection of Personal Information under Quebec's Law 25, and our privacy contact for GDPR purposes — can be reached at support@revynengine.com or by mail at Revyn Media, First Edmonton Place, 10665 Jasper Avenue, Edmonton, AB T5J 3S9, Canada.
Information we collect
- Contact and account data — name, email, company name and phone number when you request a trial, demo access or contact sales; login credentials, roles and security settings (such as multi-factor authentication enrollment) when you use the platform.
- Platform content — data venues store in the platform: bookings, customer profiles, waivers (including waivers for minors, signed by a parent or guardian), messages and campaign content.
- Payment data — subscription billing and guest payments are processed by Stripe. Card numbers never touch our systems.
- Usage and device data — server logs and security audit records (IP addresses in security logs are stored hashed where feasible), and privacy-respecting first-party analytics events, collected subject to the consent choices you make in our consent banner where required by your region.
- Referral attribution — if you arrive via a referral link, the referral code and any campaign parameters in the URL, so we can credit the person or venue who referred you. See "Cookies and analytics" for how and when this is stored.
Why we process it, and on what legal basis
Where the GDPR or UK GDPR applies, every processing purpose rests on a recorded lawful basis:
- Contract — providing the platform and website, operating bookings, check-in, payments and messaging you or your venue initiate.
- Consent — analytics and marketing cookies in opt-in regions, and marketing communications, which you can withdraw at any time as easily as you gave them.
- Legitimate interests — securing the platform (fraud and abuse prevention, security logging and alerting), improving the service, responding to sales inquiries, and running our referral program (crediting the person or venue who referred you, using the minimum information needed to do so).
- Legal obligation — retaining financial records, signed waivers and consent/audit trails, and responding to lawful requests.
We do not sell personal information, and we do not "share" it for cross-context behavioural advertising as those terms are defined in the CCPA/CPRA — so there is nothing for a "Do Not Sell or Share" link to opt you out of. Because we do not sell or share personal information, universal opt-out signals such as Global Privacy Control do not change how we process your data, and we treat them as consistent with the choices we already apply. We also do not use personal information for automated decisions that produce legal or similarly significant effects.
Cookies and analytics
Our consent banner adapts to your region: in the EU, UK and other opt-in jurisdictions, analytics and marketing technologies stay off until you enable them; in North America the banner acts as a preference centre where you can turn categories off at any time. Our web analytics are first-party and cookieless, and analytics events are deleted after 14 months. Records of your consent choices are kept for 7 years, because privacy law requires us to be able to prove them.
Referral cookie. If you follow a referral link, we read the referral code straight
from the URL to attribute your signup — that alone requires no cookie. Where you've enabled the
"Marketing" category in the consent banner (or, in opt-out regions, until you turn it off), we also
set one first-party cookie, rvn_ref, so the referral is still credited if you come back
and sign up later. It holds only the referral code and any campaign parameters, is never shared with
a third party, is not used for advertising, expires automatically after 90 days, and
is deleted immediately if you decline or withdraw marketing consent.
Who we share data with (sub-processors)
We share personal data only with the service providers needed to run the platform, each bound by a data-protection agreement and holding independent security certifications (SOC 2 / ISO 27001 / PCI-DSS as applicable):
- Cloudflare — hosting, compute, storage, CDN and security (global network; primary data storage in North America)
- Stripe — subscription billing and guest payments
- Twilio — SMS and voice messaging
- Mailgun (Sinch) — transactional email
- HighLevel — optional CRM/marketing integration, where a venue connects it
- AI providers — where a venue enables optional AI agent features, conversation content is processed by the AI service providers disclosed to that venue at activation
The current sub-processor register is available on request from support@revynengine.com, and venues are notified before we add a new sub-processor. We may also disclose information where required by law — and where the law allows, we notify the affected venue before responding to a legal demand for its data.
International transfers
Our platform runs on Cloudflare's network with primary data storage in North America. Canada holds a European Commission adequacy decision for data protected by PIPEDA, and transfers to our US-based sub-processors take place under their EU Standard Contractual Clauses (and the UK Addendum or International Data Transfer Agreement, as applicable) together with their published security certifications. If you are in the EU or UK, this is the mechanism that protects your data when it leaves your jurisdiction. For Quebec residents, we complete a privacy impact assessment before communicating personal information outside Quebec and rely on these same contractual and security safeguards, which we have assessed as providing adequate protection under Law 25.
Retention
We keep personal information only as long as needed for the purposes above, under a documented, automatically enforced retention schedule. Representative periods: message bodies are deleted after 2 years; call logs after 1 year; game-session history is anonymized after 5 years; analytics events are deleted after 14 months; referral attribution (the cookie and the stored referral code) expires after 90 days; consent records and processing audit logs are kept 7 years to meet legal accountability duties; signed waivers and payment records are retained for the limitation and tax periods the law requires. When a venue closes its account, its data is deleted or anonymized after a wind-down window, except where law requires longer retention.
Your rights
Wherever you are, you can ask us to access, correct, export or delete your personal information by emailing support@revynengine.com. We verify each request, respond within the timeline your law sets (30 days under PIPEDA and the GDPR, 45 days under the CCPA/CPRA, extendable only as the law allows), and never discriminate against you for exercising your rights. Region-specific rights include:
- Canada (PIPEDA / Alberta PIPA) — access and correction, withdrawal of consent, and the right to complain to our Privacy Officer, the Office of the Privacy Commissioner of Canada, or the Office of the Information and Privacy Commissioner of Alberta.
- EU / UK (GDPR) — access, rectification, erasure, restriction, portability, objection (including to direct marketing, which we always honour), withdrawal of consent, and the right to lodge a complaint with your supervisory authority (in the UK, the ICO).
- Quebec (Law 25) — access, correction, withdrawal of consent, and the right to data portability; the right to be informed of, and to request that we cease, any use of your information for automated profiling; and the right to complain to the Commission d'accès à l'information (CAI). We do not use technology that identifies, locates or profiles you without your consent, and analytics/marketing technologies stay off by default for Quebec visitors until you enable them.
- United States (CCPA/CPRA and other state laws) — to know, access, correct, delete and port your personal information; we do not sell or share it, so no opt-out is needed. If we refuse a request, you may appeal by replying to our decision and we will have a different reviewer answer within the statutory appeal window, with a reference to your state Attorney General if you remain unsatisfied.
For guest data held by a venue, we forward the request to the venue (the controller) and support its response with the platform's built-in export, correction and erasure tooling.
Security
Every account is protected by multi-factor authentication at login. Data is encrypted in transit (TLS 1.2+) and at rest, with an additional application-layer encryption envelope on sensitive values. Access is role-based, re-verified on every request, and recorded in tamper-resistant audit logs that are also streamed to independent storage. Our controls are aligned to the CSA Cloud Controls Matrix v4, we self-assess against it annually, and our incident-response procedure commits us to notifying affected venues without undue delay — and regulators and individuals within the timelines that apply, including the GDPR's 72-hour rule. See Security & Compliance for details.
Children
This website and the platform's operator accounts are for adults (18+), and we do not knowingly collect personal information from children through this site. Waiver records for minors are created and consented to by a parent or legal guardian at the venue's direction, are treated as sensitive data, and are used only for that purpose.
Changes and contact
We may update this policy from time to time; material changes will be noted on this page with a new "last updated" date, and venues will be notified for changes that affect how we process their guests' data. Questions or complaints? Email support@revynengine.com or info@revynengine.com, or write to our Privacy Officer at Revyn Media, First Edmonton Place, 10665 Jasper Avenue, Edmonton, AB T5J 3S9, Canada. If we cannot resolve your concern, you may contact the privacy regulator for your region, as listed under "Your rights".