Version 2026-09-15
Makeways (Private) Limited (“Revolo”, “we”, “us”), a company registered in Pakistan, operates the Revolo customer app, the Revolo Staff app, and the Revolo merchant web portal (together, the “Service”).
This policy explains what personal information we collect, why we collect it, who we share it with, how long we keep it, and what you can ask us to do about it. It is written to be read by people, not lawyers.
This policy covers two kinds of people, and some sections apply to only one:
An important structural point. Revolo is a platform used by many independent businesses. When you order from or join a business on Revolo, that business receives your information too and decides for itself how to use it. We control the platform; each merchant controls what it does with its own customer list.
Customers
Merchant users
What the Staff app collects, and what it deliberately does not.
Location — please read this carefully. Revolo is location-first: the app ranks branches by how close they are to you. There are four distinct ways location is collected, and they are not equivalent:
Everything else we collect automatically
What we do not collect automatically.
Biometric data. None. We do not collect or process biometrics.
We use your information for these purposes and no others:
To provide the Service
To communicate with you
To keep the Service safe
To improve the Service and give merchants insight
To meet legal obligations — keep financial records for the period tax law requires, respond to lawful requests from authorities, and establish or defend legal claims.
What we will not do. We will not sell your personal information. We will not share it with advertising networks or data brokers. We will not use your order notes, chat messages or location history to build an advertising profile of you. If we ever want to use your information for a new purpose not listed above, we will tell you and ask first.
| What we do | Basis we rely on |
|---|---|
| Run your account, take your order, run the loyalty programme | Necessary to perform our contract with you |
| Transactional email (verification, password reset, security alerts) | Necessary to perform our contract; also our legitimate interest in account security |
| Foreground location for branch ranking | Your consent (the device permission prompt), withdrawable in your device settings |
| Background location and proximity offers | Your consent (the background-location permission prompt), withdrawable in your device settings; proximity offers can also be switched off in notification settings |
| Check-in and visit history | Necessary to perform our contract (it is how you earn points) |
| Offer notifications | Your consent |
| Date of birth for birthday offers | Your consent — it is optional |
| Security, rate limiting, fraud prevention | Our legitimate interest in protecting the Service and its users |
| Merchant analytics | Our and the merchant’s legitimate interest in running the business |
| Keeping financial records | Legal obligation |
Withdrawing consent. Where we rely on your consent you can withdraw it at any time. Turning off location permission in your device settings stops location collection immediately.
When you join a business, order from it, book with it or check in at it, that business sees your name, email, phone number, member ID, loyalty balance and tier, your orders and bookings with them, your reviews of them, and your messages to them. Staff at that business see this in the Staff app when they serve you. A merchant sees only its own customers; it cannot see your activity at any other business.
| Provider | What it does | What it receives | Where |
|---|---|---|---|
| Railway | Hosts our servers, database and job queue | All platform data at rest | Outside Pakistan |
| Vercel | Hosts this web portal | Portal traffic; sets the session cookies | Global edge — outside Pakistan |
| Google (Places API) | Address search and autocomplete | The address text you type, and nothing else — no name, no account, no identifier | Outside Pakistan |
| Safepay | Card payments | Amount, currency and an order reference — not your name, email or phone. You enter card details on Safepay’s own page | Pakistan |
| Resend | Sends transactional email | Your email address, and the content of that email | Outside Pakistan |
| Expo → Apple / Google | Delivers push notifications | Your device’s push token and the notification text | Outside Pakistan |
| Cloudflare R2 | Encrypted nightly database backups | A full copy of the database | Outside Pakistan |
| Sentry | Crash reports — disabled by default | When enabled: the crash and an anonymous user ID — no IP address, no request headers, no cookies, no URL query strings | Outside Pakistan |
We do not sell, rent or trade personal information. We have no advertising partners and no data-broker relationships. Nothing in the product is funded by monetising your data.
Your personal information is stored and processed outside Pakistan. Our servers, database, backups, email delivery and push delivery all run on infrastructure hosted abroad, principally in the United States and on global edge networks. Card payments are the exception: Safepay operates in Pakistan and your card details are handled there, never by us.
| What | How long |
|---|---|
| Login sessions | Expired sessions are purged 30 days after they expire (about 60 days in total) |
| Email verification and password-reset links | Deleted 7 days after they expire |
| Encrypted database backups | 30 days, then destroyed |
| Your account and everything else we hold about you — orders, loyalty history, visits, location records, chat, reviews, notifications and uploads | For as long as your account exists, or until you ask us to delete it (see §8) |
One exception you should know about. Our financial ledger — the record of points and money moving — is deliberately built so entries cannot be altered or deleted, because an auditable financial record has to be tamper-proof. Ledger entries reference your customer ID. If you ask us to delete your account, we will remove your identity everywhere else, but the ledger entry itself must survive for the period tax and audit law requires.
In the app, at any time, you can correct your name, phone number, date of birth, city, interests, profile picture and saved addresses. You can turn notifications on or off per category, including proximity offers, and you can revoke location permission from your device settings.
By contacting us, you can ask for a copy of the personal information we hold about you, ask us to change your email address, ask us to delete your account and data (subject to §7), or ask us to stop a particular use of your information. Email privacy@revolo.app from the address on your account. We will verify it is you and respond within 30 days.
We will never charge you for exercising a right, and we will never treat you worse for having done so — no worse pricing, no reduced points, no degraded service.
The mobile apps do not use cookies. They store a small amount of data in your device’s secure storage: your login tokens, your chosen location, your shopping cart, and your light/dark theme preference. Signing out erases the tokens and the cart.
This web portal uses exactly two cookies, both first-party and both strictly necessary:
| Cookie | Purpose | Lifetime |
|---|---|---|
rv_rt | Holds your session token so you stay signed in. HttpOnly, Secure, SameSite=Lax, scoped to the session endpoint only | 30 days |
rv_sess | Contains only the value 1, so the site knows a session exists. Holds no secret and no identifier | 30 days |
There are no analytics cookies, no advertising cookies and no third-party trackers, which is why you are not seeing a consent banner. If we ever add a non-essential cookie we will ask for your consent first, and this section will change.
No system is perfectly secure, and we do not claim otherwise. If a breach puts your information at risk we will investigate, contain it, and notify you and the relevant authority without undue delay.
The Service is not intended for children, and we do not knowingly collect their personal information. If you believe a child has given us personal information, contact privacy@revolo.app and we will delete the account and its data.
Privacy enquiries and rights requests: privacy@revolo.app
Postal Address: Makeways PVT LTD, 82-J1, 4th Floor, Johar Town, Lahore, Pakistan
More ways to reach us: Contact
We respond within 30 days. Please come to us first if something is wrong — we would rather fix it. If you are not satisfied, you may complain to the relevant supervisory authority; matters under the Prevention of Electronic Crimes Act 2016 go to the FIA Cyber Crime Wing.
We ask you to accept this policy before you can use Revolo, and we record that you did.
| Surface | When you are asked |
|---|---|
| Customer app | At registration. You tick a box confirming you have read this policy; the account is not created until you do |
| Merchant web portal | At business signup, on the last step before the account is created |
| Staff app | Your employer creates your account. You are asked the first time you sign in, and you cannot reach the POS until you accept |
What we store when you accept: your user ID, the version of this policy you accepted, the time you accepted it, and which of the three surfaces you accepted it on. We do not record your IP address as part of that.
We keep previous versions and will provide one on request.
Links to other services. The app links out to maps, WhatsApp, SMS and our payment provider’s page. Once you leave Revolo, that service’s own privacy policy governs. When you tap “Directions”, we hand the branch’s coordinates to your device’s map app.
Governing law. This policy is governed by the laws of Pakistan.