← Revolo

Privacy Policy

Version 2026-09-15

Makeways (Private) Limited (“Revolo”, “we”, “us”), a company registered in Pakistan, operates the Revolo customer app, the Revolo Staff app, and the Revolo merchant web portal (together, the “Service”).

This policy explains what personal information we collect, why we collect it, who we share it with, how long we keep it, and what you can ask us to do about it. It is written to be read by people, not lawyers.

This policy covers two kinds of people, and some sections apply to only one:

An important structural point. Revolo is a platform used by many independent businesses. When you order from or join a business on Revolo, that business receives your information too and decides for itself how to use it. We control the platform; each merchant controls what it does with its own customer list.

1. Information we collect

1.1 Information you give us

Customers

  • Account details — first name, last name, email address, phone number, and a password.
  • Your member ID — we generate a short code for you (for example RV-7F3K9) that identifies you at the counter. Staff can look you up by it.
  • Date of birth — optional. We use it only to send you a birthday offer.
  • Profile picture — optional. If you upload one, we strip the embedded metadata (including any GPS coordinates your camera recorded) before storing the image.
  • Interests and preferences — if you choose to set them.
  • Saved addresses — a label, the address text, and its exact coordinates.
  • Order content — what you ordered, for which table or pickup time, and any special requests or item notes you type. Please avoid typing medical information into these free-text fields.
  • Reservation details — date, time, party size, and any notes.
  • Reviews — a star rating and free-text comment tied to an order.
  • Support messages — anything you write to a merchant in in-app chat, and any attachments.
  • Referrals — if you refer a friend, we store the email address you give us for them.
  • Split-bill participants — when you split a bill, we store the names of the people you split with. If you pick someone from your phone’s contacts, we receive their name only. We do not receive or store their phone number — it stays on your device and is used only to open your own SMS or WhatsApp app with a link you choose to send.

Merchant users

  • Name, work email, phone number, and role.
  • Your assigned business, branch, and permissions.
  • Multi-factor authentication settings and recovery codes.
  • For business owners: your business’s payment settlement details, including bank account information.

What the Staff app collects, and what it deliberately does not.

  • It asks for the camera, and nothing else. The camera decodes customer and table QR codes on the device. No image or video is captured, transmitted or stored.
  • It does not request location, contacts, or your photo library. There is no GPS, no geofencing and no visit tracking of staff.
  • It records what you do to customer accounts. When you award points, redeem a voucher, refund an order or seat a table, the action is recorded against your staff account, and your activity is visible to your employer.
  • It shows you other people’s personal data. Serving a customer displays their name, email, phone number, member ID, points balance and tier. Your employer is responsible for what its staff do with it.
  • Your account is created by your employer, not by you. You do not sign up.

1.2 Information we collect automatically

Location — please read this carefully. Revolo is location-first: the app ranks branches by how close they are to you. There are four distinct ways location is collected, and they are not equivalent:

  • Your chosen location. When you set your location (by GPS or by searching an address), we store the coordinates, the address text and the city on your profile so the app can rank branches next time.
  • Nearby-branch lookups. When the app loads your home feed, it sends your coordinates to us so we can compute distances.
  • Check-in. When you check in at a business, the app compares your position to the branch on your device and sends us only the result — that you were within range. We record the visit itself: which business, which branch, which day, and whether it was confirmed by GPS or by scanning a QR code. This builds a history of places you have physically been.
  • Background geofencing (Android). If you grant background location permission, the app asks the operating system to wake it when you enter or leave the area around a branch of a business you have joined. When that happens — including when the app is closed — your coordinates are sent to us and stored, so we can send you a nearby-offer notification. The area is set by the merchant, at least 100 metres across.

Everything else we collect automatically

  • Security and abuse-prevention data. We process your IP address to rate-limit requests, block brute-force login attempts, and detect stolen session tokens. Your IP address is not stored in our database; it lives briefly in a short-lived counter, and may appear in server logs when a security event fires.
  • Session records — so you can stay signed in, and so we can end a session if a token is stolen.
  • Loyalty activity — points earned and spent, tier, challenge progress, badges, and vouchers issued or redeemed.
  • Notifications we have sent you and whether you opened them.

What we do not collect automatically.

  • No advertising identifiers — no IDFA, no Android Advertising ID. We do not track you across other companies’ apps or websites.
  • No product analytics — no Google Analytics, Firebase Analytics, Segment, Mixpanel, Amplitude, PostHog or comparable tool in the apps, the portal, or the server.
  • No advertising or attribution SDKs, and no social-network SDKs.
  • No device fingerprinting — we do not record your browser user-agent string, screen characteristics, or installed fonts.
  • No microphone or motion-sensor data.

1.3 Information from other sources

  • Merchants. When a merchant’s staff awards you points in store, that transaction and the identity of the staff member who did it are recorded on your account.
  • Payments. Our payment provider tells us whether a payment succeeded and gives us a reference. It does not give us your card number.
  • Nobody else. We do not buy data, and we do not receive personal data from data brokers, advertising networks or social platforms.

Biometric data. None. We do not collect or process biometrics.

2. How we collect information

  • Directly from you — registration, your profile, orders, bookings, reviews, chat messages, and the address search box.
  • Automatically from your device — GPS position when you allow it, geofence events in the background when you allow it, and your camera when you scan a QR code (the code is decoded on your device; no image or video is ever sent to us or stored).
  • From merchants — in-store point awards and voucher redemptions performed by staff.
  • From our payment provider — the outcome of a payment.

3. How we use information

We use your information for these purposes and no others:

To provide the Service

  • Create and secure your account, and keep you signed in.
  • Show you branches near you, ranked by distance, with accurate open/closed status.
  • Take, route and track your orders and reservations; run the live table session when you scan a table QR code.
  • Calculate, credit and redeem loyalty points, tiers, challenges and vouchers; validate a voucher at the counter as unused, unexpired, and belonging to that business.
  • Let you and the merchant talk to each other in support chat.
  • Process payments through our provider and reconcile them.

To communicate with you

  • Send transactional email you need: email verification, password resets, and security notices when your password or two-factor settings change.
  • Send push notifications about your order status, reservations and loyalty activity.
  • Send offer notifications, including offers triggered by your physical proximity to a branch, which you can switch off in your notification settings.
  • Send you a birthday offer, if you gave us your date of birth.

To keep the Service safe

  • Rate-limit traffic, detect brute-force login attempts, and detect reuse of a stolen session token so we can end every session in that family.
  • Enforce the daily cap on points earned, and prevent duplicate or fraudulent redemptions.

To improve the Service and give merchants insight

  • Merchants see analytics about their own business — order volumes, popular items, redemption rates, and member counts. A merchant sees the customers of its own business, not the customers of any other business on the platform.
  • We look at aggregate platform behaviour to decide what to build next.

To meet legal obligations — keep financial records for the period tax law requires, respond to lawful requests from authorities, and establish or defend legal claims.

What we will not do. We will not sell your personal information. We will not share it with advertising networks or data brokers. We will not use your order notes, chat messages or location history to build an advertising profile of you. If we ever want to use your information for a new purpose not listed above, we will tell you and ask first.

4. Our legal basis for using your information

What we doBasis we rely on
Run your account, take your order, run the loyalty programmeNecessary to perform our contract with you
Transactional email (verification, password reset, security alerts)Necessary to perform our contract; also our legitimate interest in account security
Foreground location for branch rankingYour consent (the device permission prompt), withdrawable in your device settings
Background location and proximity offersYour consent (the background-location permission prompt), withdrawable in your device settings; proximity offers can also be switched off in notification settings
Check-in and visit historyNecessary to perform our contract (it is how you earn points)
Offer notificationsYour consent
Date of birth for birthday offersYour consent — it is optional
Security, rate limiting, fraud preventionOur legitimate interest in protecting the Service and its users
Merchant analyticsOur and the merchant’s legitimate interest in running the business
Keeping financial recordsLegal obligation

Withdrawing consent. Where we rely on your consent you can withdraw it at any time. Turning off location permission in your device settings stops location collection immediately.

5. Who we share your information with

5.1 Merchants on the platform

When you join a business, order from it, book with it or check in at it, that business sees your name, email, phone number, member ID, loyalty balance and tier, your orders and bookings with them, your reviews of them, and your messages to them. Staff at that business see this in the Staff app when they serve you. A merchant sees only its own customers; it cannot see your activity at any other business.

5.2 Service providers

ProviderWhat it doesWhat it receivesWhere
RailwayHosts our servers, database and job queueAll platform data at restOutside Pakistan
VercelHosts this web portalPortal traffic; sets the session cookiesGlobal edge — outside Pakistan
Google (Places API)Address search and autocompleteThe address text you type, and nothing else — no name, no account, no identifierOutside Pakistan
SafepayCard paymentsAmount, currency and an order reference — not your name, email or phone. You enter card details on Safepay’s own pagePakistan
ResendSends transactional emailYour email address, and the content of that emailOutside Pakistan
Expo → Apple / GoogleDelivers push notificationsYour device’s push token and the notification textOutside Pakistan
Cloudflare R2Encrypted nightly database backupsA full copy of the databaseOutside Pakistan
SentryCrash reports — disabled by defaultWhen enabled: the crash and an anonymous user ID — no IP address, no request headers, no cookies, no URL query stringsOutside Pakistan

5.3 Other recipients

  • Legal authorities, where we are compelled by a valid legal process, or where disclosure is necessary to protect someone’s safety.
  • A buyer, if the business is sold or merged — you will be told before your data moves, and this policy continues to apply until you are given notice of a new one.

5.4 We do not sell your information

We do not sell, rent or trade personal information. We have no advertising partners and no data-broker relationships. Nothing in the product is funded by monetising your data.

6. Sending information outside Pakistan

Your personal information is stored and processed outside Pakistan. Our servers, database, backups, email delivery and push delivery all run on infrastructure hosted abroad, principally in the United States and on global edge networks. Card payments are the exception: Safepay operates in Pakistan and your card details are handled there, never by us.

7. How long we keep your information

WhatHow long
Login sessionsExpired sessions are purged 30 days after they expire (about 60 days in total)
Email verification and password-reset linksDeleted 7 days after they expire
Encrypted database backups30 days, then destroyed
Your account and everything else we hold about you — orders, loyalty history, visits, location records, chat, reviews, notifications and uploadsFor as long as your account exists, or until you ask us to delete it (see §8)

One exception you should know about. Our financial ledger — the record of points and money moving — is deliberately built so entries cannot be altered or deleted, because an auditable financial record has to be tamper-proof. Ledger entries reference your customer ID. If you ask us to delete your account, we will remove your identity everywhere else, but the ledger entry itself must survive for the period tax and audit law requires.

8. Your rights and choices

In the app, at any time, you can correct your name, phone number, date of birth, city, interests, profile picture and saved addresses. You can turn notifications on or off per category, including proximity offers, and you can revoke location permission from your device settings.

By contacting us, you can ask for a copy of the personal information we hold about you, ask us to change your email address, ask us to delete your account and data (subject to §7), or ask us to stop a particular use of your information. Email privacy@revolo.app from the address on your account. We will verify it is you and respond within 30 days.

We will never charge you for exercising a right, and we will never treat you worse for having done so — no worse pricing, no reduced points, no degraded service.

9. Cookies and tracking

The mobile apps do not use cookies. They store a small amount of data in your device’s secure storage: your login tokens, your chosen location, your shopping cart, and your light/dark theme preference. Signing out erases the tokens and the cart.

This web portal uses exactly two cookies, both first-party and both strictly necessary:

CookiePurposeLifetime
rv_rtHolds your session token so you stay signed in. HttpOnly, Secure, SameSite=Lax, scoped to the session endpoint only30 days
rv_sessContains only the value 1, so the site knows a session exists. Holds no secret and no identifier30 days

There are no analytics cookies, no advertising cookies and no third-party trackers, which is why you are not seeing a consent banner. If we ever add a non-essential cookie we will ask for your consent first, and this section will change.

10. How we protect your information

  • Passwords are hashed with bcrypt. We cannot read your password, and neither can anyone who steals the database.
  • Encryption in transit. Everything uses HTTPS. A release build of either app refuses to start against an unencrypted server.
  • Short-lived access tokens (15 minutes) with rotating refresh tokens stored only as a hash. If a stolen token is replayed, we detect it and end every session in that lineage at once.
  • Two-factor authentication for merchant and administrator accounts, with the secret encrypted at rest and single-use recovery codes stored only as keyed hashes.
  • Step-up authentication — sensitive administrative actions require you to re-authenticate.
  • Login throttling and account lockout against brute-force attempts.
  • Upload safety. Uploaded images are identified by their actual contents, not their filename; SVG files are refused; EXIF metadata is stripped before storage.
  • Log redaction. Passwords, tokens, cookies, authorisation headers and secrets are stripped from server logs.
  • Access control. Every API route is governed by an explicit permission policy, and merchants are isolated from one another’s data.
  • Encrypted nightly backups, retained 30 days.

No system is perfectly secure, and we do not claim otherwise. If a breach puts your information at risk we will investigate, contain it, and notify you and the relevant authority without undue delay.

11. Children

The Service is not intended for children, and we do not knowingly collect their personal information. If you believe a child has given us personal information, contact privacy@revolo.app and we will delete the account and its data.

12. Contact us, and how to complain

Privacy enquiries and rights requests: privacy@revolo.app
Postal Address: Makeways PVT LTD, 82-J1, 4th Floor, Johar Town, Lahore, Pakistan
More ways to reach us: Contact

We respond within 30 days. Please come to us first if something is wrong — we would rather fix it. If you are not satisfied, you may complain to the relevant supervisory authority; matters under the Prevention of Electronic Crimes Act 2016 go to the FIA Cyber Crime Wing.

13. Accepting this policy

We ask you to accept this policy before you can use Revolo, and we record that you did.

SurfaceWhen you are asked
Customer appAt registration. You tick a box confirming you have read this policy; the account is not created until you do
Merchant web portalAt business signup, on the last step before the account is created
Staff appYour employer creates your account. You are asked the first time you sign in, and you cannot reach the POS until you accept

What we store when you accept: your user ID, the version of this policy you accepted, the time you accepted it, and which of the three surfaces you accepted it on. We do not record your IP address as part of that.

14. Changes to this policy

  • Minor changes — we will update the version shown at the top.
  • Material changes — anything that meaningfully changes what we collect, why, or who we share it with — we will tell you at least 30 days before it takes effect, by email and in-app, and ask you to accept the new version.
  • If you do not agree to a material change, you may close your account.

We keep previous versions and will provide one on request.

15. Other terms

Links to other services. The app links out to maps, WhatsApp, SMS and our payment provider’s page. Once you leave Revolo, that service’s own privacy policy governs. When you tap “Directions”, we hand the branch’s coordinates to your device’s map app.

Governing law. This policy is governed by the laws of Pakistan.


Privacy Policy · Terms of Service · Contact