Legal

Privacy Policy

Last updated: September 22, 2026

This policy explains what personal data we process at Revenight, what for, who we share it with, how long we keep it and how you can exercise your rights. It covers three groups of people: visitors to our website, the venues that use Revenight and their staff, and those venues’ guests.

1. Summary

  • We do not sell personal data.
  • PostHog analytics and the Meta advertising pixel only run on our website if you accept them in the cookie notice.
  • Separately from cookies, when you request a demo or buy a subscription, our server sends Meta your email address (and, for a demo, your phone number) as a hash, to measure our ads. Section 3 explains how.
  • If you are a guest of a bar, club or restaurant that uses Revenight, that venue is responsible for your data. We process it on the venue’s behalf and never for our own purposes (section 6).
  • We work with service providers, several of them in the United States, with safeguards for those transfers (sections 8 and 9).
  • You can see, correct or delete your data, or object to how we use it, by writing to hello@revenight.com.

2. Who we are

Revenight is a service of Journey AI & Automation (“Revenight”, “we”, “us”), available at revenight.com. We are the controller for the data of visitors to our website, of the venues we contact and of the venues that use Revenight.

For any privacy matter, write to hello@revenight.com.

Guests’ data is different: each venue is the controller of its guests’ data, and we process that data on its behalf as a processor (section 6).

3. If you visit our website or request a demo

  • Browsing. When you load a page, Vercel, our hosting provider, records technical data such as your IP address, your browser and the page you requested. We use it to run the site, protect it from abuse and fix errors. Legal basis: our legitimate interest in a secure, working website.
  • Analytics, only if you accept. With PostHog we measure which pages are visited, for how long, on which device and browser, and an approximate location that PostHog derives from the IP address. If you are signed in, PostHog links that activity to your user ID and email address and records actions inside the app, such as logging a night, sometimes with figures from that night (total revenue, attendance or score). We do not record your sessions and we have turned off automatic event capture: we only record page views and the specific actions we chose to measure. Legal basis: your consent.
  • Advertising and measurement with Meta, only if you accept. The Meta Pixel records the pages you visit, the button clicks Meta detects on its own, and when you click a link to book a demo or submit the demo form. To do this, Meta receives your IP address, your browser details and the page address, stores its cookies in your browser and may link this information to your Facebook or Instagram account. We use it to measure and optimize our ads. We are joint controllers with Meta for collecting this data and sending it to Meta; what Meta does with it afterwards is governed by its privacy policy. Legal basis: your consent.
  • Demo form. If you request a demo, you give us your name, email address, WhatsApp number, your venue’s name and type, and your city. We use them to reply, prepare the demo and follow up, and we send you a confirmation email. Submitting the form opens our Cal.com calendar with your name, email and the other details already filled in. Legal basis: taking steps at your request before a possible contract, and our legitimate interest for the follow-up.
  • Booking the demo on Cal.com. Cal.com runs our calendar. When you book, it processes the details you give it (name, email, phone number and notes) and sends us the booking: those details, the date and time, the campaign parameters in the link and the page you came from. We keep them to organize the meeting and to learn which channels bring us demos. Legal basis: handling your request, and our legitimate interest in knowing where demos come from.
  • Conversion measurement with Meta. Only if you accept advertising cookies in the banner. In that case, when you submit the demo form, our server notifies Meta (through its Conversions API) and sends it your email address and phone number as a hash, a code that cannot be reversed but that Meta can match against its users’ data, together with your IP address, your browser details, the page you submitted the form from and Meta’s cookies. If a venue subscribes with that permission given, we send Meta the payer’s email address, also as a hash, with the amount, currency and plan. If you do not accept advertising cookies, we send nothing to Meta. It tells us whether our ads bring in demos and customers. Legal basis: your consent, which you can withdraw at any time from “Cookie preferences” at the bottom of the site.
  • Our Instagram account. We publish on our own account and read its statistics, which are aggregate figures, through Meta’s Instagram API. If you comment on our posts, we read your username and comment and may reply with the help of AI (section 7). Legal basis: our legitimate interest in running our account.

4. If we contact you to introduce Revenight

We look for venues that Revenight could help and write to them or call them to introduce it. For that we keep business contact details that the venue itself publishes, for example on its website, its social media or its Google Maps listing: the venue’s name and type, its address, website, email and phone number, its rating and number of reviews, the contact person if one is listed, and our notes from follow-ups and calls. We use AI to research each venue and score how good a fit it is, and we record when we wrote to it and, where possible, whether our emails were opened or their links clicked.

Legal basis: our legitimate interest in introducing our service to other businesses. If you do not want to hear from us again, reply to any of our emails or write to hello@revenight.com. We will stop, and keep only what we need to make sure we do not contact you again.

5. If your venue uses Revenight

If you have a Revenight account, or work at a venue that has one, we process:

  • Account: your email address, your password (stored as a hash, so nobody can read it), your name if you give it to us, and your language.
  • Your venue: name, city, type, currency, time zone and language; what you set up for the WhatsApp assistant and the door (opening hours, address, house rules, WhatsApp number, reply-to email and door PIN); and your logo and brand.
  • Every night: revenue by type, costs, attendance, reservations, no-shows, walk-ins, waste, comps, payment methods, the manager’s rating, notes and incidents, and what we calculate from them: the 0-100 score, insights and briefings.
  • Files you upload: POS closing reports, spreadsheets with past nights and guest lists to import into the Circle.
  • Billing: Stripe takes payment and stores your card, billing address and tax or VAT number. We store the customer and subscription IDs, the plan, its status and renewal date, and your credit history. We never see your full card number.
  • Signing documents: if you sign a proposal or contract online, we keep your name, email address, signature, the date, your IP address and browser details, together with a fingerprint (hash) of the document, as proof of the signature.
  • Communication and support: the emails you send us and the ones we send you (welcome, getting started, daily and weekly summaries of your nights, and reservation notices). For the welcome sequence, our automations receive your user ID, email address and name.
  • Our business relationship: notes from our meetings with you and the history of the relationship, which we use to prepare proposals and support you.

What we use it for and on what legal basis:

  • Providing the service you signed up for: storing and analyzing your nights, calculating the score, generating briefings, running the assistant, the door and the Circle, and sending you service emails. Basis: the contract.
  • Charging and invoicing. Basis: the contract and our tax and accounting obligations.
  • Keeping the platform secure, spotting errors and finding out when something breaks. We log server errors with PostHog and email alerts to our team, and each venue’s nightly summary (name, score, revenue and the day’s focus) is also posted to an internal Telegram chat so we can check the service is working. Basis: our legitimate interest.
  • Understanding how the app is used so we can improve it, with PostHog, only if you accepted analytics. Basis: your consent.
  • Measuring our campaigns with Meta (section 3), only if you accepted advertising cookies. Basis: your consent.
  • Being able to prove a signature or defend ourselves against a claim. Basis: our legitimate interest.

What you write in a night’s notes is sent to the AI for the briefing (section 7). In notes and other free-text fields, avoid personal data you do not need, especially health data (for example, a guest’s allergies).

6. If you are a guest of a venue that uses Revenight

If you joined a venue’s Circle through its QR code, booked through its WhatsApp or were checked in at its door with Revenight, that venue is the controller of your data. Revenight is its processor: we process your data only on the venue’s behalf, following its instructions and under a data processing agreement (Article 28 GDPR). We do not use it for our own purposes, we do not combine it across venues and we do not sell it. We do not load our analytics or advertising on the venue’s Circle page or on the unsubscribe page.

Depending on what the venue uses, Revenight may store:

  • Contact details: name, phone number (WhatsApp) and email address.
  • Preferences: the day and month of your birthday (the form does not ask for the year), your language, and whether you live in the city or are visiting.
  • Permissions and proof: whether you agreed to receive news by email or WhatsApp, each channel separately, with the date, the version and exact text you agreed to and where you did it (the QR form or the WhatsApp conversation). If it was on the form, we also keep a hash of your IP address (not the address itself) and your browser details.
  • Reservations and visits: the date, time, party size, status and notes of your reservations; your arrivals recorded at the door, how many times you have been and when your first and last visits were.
  • Venue notes: notes and tags written by the venue’s staff.
  • WhatsApp conversations: the messages you exchange with the venue’s assistant.
  • Messages: which messages the venue sent you, whether they were delivered, whether you opened the email or clicked a link, bounces and spam complaints, and whether you later booked or visited, to measure the result.
  • Unsubscribes: the date you unsubscribed, so you are not contacted again.

The venue uses this data to manage your reservations and reply to you on WhatsApp, recognize you at the door and, only if you agreed, send you news and offers on the channel you chose, including messages on your birthday or when you have not been in for a while. Emails come from a Revenight address under the venue’s name. For this we work with Supabase, Vercel, Resend, Meta (WhatsApp), Anthropic and n8n (section 8). We do not pass data received through WhatsApp or other Meta platforms to data brokers or advertising networks.

To unsubscribe, use the link in any email or reply STOP on WhatsApp. To see, correct or delete your data, or for any other right, contact the venue. If you write to us at hello@revenight.com, we will pass your request to the venue and help it respond.

The venue decides how long it keeps your data. When a venue stops using Revenight, we delete its data or return it, as the agreement says.

7. Artificial intelligence

We use Anthropic’s models (Claude) for specific tasks and only send what each one needs:

  • Briefings and the morning summary: the venue’s name, city and type, the figures for the night and previous nights, its capacity, and the notes the staff wrote. We do not send the venue’s guest data, except whatever the staff wrote in those notes.
  • Reading files: the POS closing reports and spreadsheets you upload, to extract the figures.
  • Importing a guest list: if we do not recognize the file’s columns, we send only the headers and three sample rows, which may include those three people’s names, emails or phone numbers. Never the whole list.
  • WhatsApp assistant: the guest’s message, the conversation so far and the venue’s information, to draft the reply.
  • Our own sales activity: public details of venues we want to contact, to research them and prepare emails and call scripts; a client’s company details and meeting notes, to draft its proposal; and comments on our Instagram account, to reply to them.

Under Anthropic’s commercial terms, what it receives through its API is not used to train its models. We do not use your data to train any model either.

8. Service providers we share data with

We work with these providers to run the service. Each one receives only the data it needs for its job and, when it processes data on our behalf, it does so under a data processing agreement.

  • Supabase (United States, servers in Oregon): database, authentication and file storage for the whole platform, including venues’ guest data.
  • Vercel (United States): hosting for the website and apps, and technical logs of visits.
  • Stripe (United States and other countries): payments, subscriptions and invoices.
  • Resend (United States): sending emails, both ours and those venues send to their guests, and tracking delivery, opens and clicks.
  • PostHog (United States): website and app analytics, only with your consent, and server error logging.
  • Meta (Ireland and United States): the Pixel and Conversions API to measure our advertising, the WhatsApp Business Platform that venues’ assistants run on, and the Instagram API for our own account.
  • Anthropic (United States): the AI models in section 7.
  • Cal.com (United States): the calendar for booking demos.
  • n8n: our automations and the WhatsApp assistant. It is software we host on a server we manage ourselves, so data does not pass through the company that makes it.
  • Telegram (outside the European Economic Area): internal messages to our team, such as each venue’s nightly summary or the list of venues we are about to contact.

Our use of Meta’s platforms is governed by the Meta Platform Terms, its Developer Policies and the WhatsApp Business Messaging Policy. We will also disclose data to authorities or courts when the law requires it. We do not sell personal data.

9. International transfers

Several of these providers are in the United States or process data outside the European Economic Area. In those cases the transfer relies on the EU-U.S. Data Privacy Framework, where the provider is certified, or on the standard contractual clauses approved by the European Commission, with any additional measures needed. Write to hello@revenight.com if you would like more detail about these safeguards.

10. How long we keep data

  • Account and venue: for as long as you have an account. If you cancel your subscription, the data stays in your account until you delete it or ask us to. When you delete it, we immediately erase your user and your venue with its nights, scores, insights and briefings, and the rest of the associated data within 30 days at most. Backups may hold a copy for a limited time until they are replaced.
  • Billing: for as long as tax and commercial law requires (in Spain, generally six years). Stripe keeps its own records under its own obligations.
  • Demo requests and Cal.com bookings: up to two years from our last contact, unless you become a customer.
  • Sales contacts: until you ask us not to write again and, at most, two years from our last contact. If you object, we keep only the minimum to avoid contacting you again.
  • Analytics and error logs: up to 24 months.
  • Vercel technical logs: a few days.
  • Document signatures: for the life of the contract and afterwards for as long as claims arising from it can be brought.
  • Guest data: as the venue decides (section 6).
  • Cookies: see section 12.

11. Your rights

You can ask us at any time for:

  • Access: to know what data we hold about you and get a copy.
  • Rectification: to correct data that is inaccurate or incomplete.
  • Erasure: to delete your data, for example when it is no longer needed for the purpose it was collected for.
  • Objection: to stop using your data where we rely on our legitimate interest, and always for direct marketing.
  • Restriction: to keep your data stored but unused while a complaint about it is resolved.
  • Portability: to receive the data you gave us in a structured format, where we process it under a contract or with your consent, or to have us send it to another company.
  • Withdrawing consent: at any time, without affecting what we did with it before.

To exercise them, write to hello@revenight.com and tell us what you need. If we need to confirm your identity, we will ask for as little as possible. We will reply within one month; for complex requests that can be extended by two more months, and we will tell you if so. If you have an account, you can delete it yourself from Settings → Danger Zone → Delete Account, and our data deletion page explains each case. If we process your data on a venue’s behalf (section 6), contact the venue; if you write to us, we will pass your request on.

We do not make decisions based solely on automated processing that produce legal effects on you or affect you in a similarly significant way.

If you think we have not handled your data properly, you can complain to the Spanish Data Protection Agency (www.aepd.es) or to the data protection authority in your country, such as PRODHAB in Costa Rica. If you like, write to us first and we will try to sort it out.

12. Cookies and similar technologies

We use cookies and your browser’s local storage. Essential ones do not need your permission. Analytics and advertising only start if you click “Accept all” in the cookie notice.

Essential

  • Session (sb-…-auth-token, Supabase cookies): keep you signed in to Revenight. They last up to 400 days or until you sign out.
  • Language (rn-lang, cookie and local storage): remembers the language you chose. Lasts one year.
  • Your cookie choice (rn-cookie-consent, local storage): kept until you change it or clear the site’s data.

Analytics, only with your consent

  • PostHog (ph_…_posthog, local storage): recognizes your browser to measure how the website and app are used. Kept until you clear the site’s data.

Advertising and measurement, only with your consent

  • Meta Pixel (_fbp and, if you arrive from an ad, _fbc): let Meta recognize your browser and attribute visits and demo requests to our ads. They last about 90 days. If you are signed in to Facebook or Instagram, Meta may also use its own cookies.

To change your mind, click (it is also at the bottom of every page) and pick another option. If you accept, analytics and advertising start right away. If you withdraw consent, we immediately delete what PostHog and the Meta Pixel stored in this browser (the ph_… keys, _fbp and _fbc) and reload the page so they stop working. Facebook’s and Instagram’s own cookies are managed by Meta in its settings.

We do not load analytics or advertising, or show this notice, on each venue’s Circle page or on the unsubscribe page. The only thing counted there is how many times the Google review and Instagram buttons are tapped, when the venue has added them: a number per venue and per night, with no cookies and no record of who tapped.

13. Security

The whole website and the apps use encrypted connections (HTTPS). The database enforces row-level security, so each account can only reach its own venue’s data. Passwords are stored as hashes, as are the IP addresses that prove a consent, and connections with our providers are authenticated with signatures or secret keys. Inside Revenight, only people who need the data to provide the service can access it.

No system is infallible. If a security breach affects your data, we will notify the authority and, where required, you, within the legal deadlines. If it affects data we process on a venue’s behalf, we will tell the venue without delay.

14. Children

Revenight is a service for businesses and is not aimed at anyone under 18; you must be an adult to have an account. We do not knowingly collect children’s data for our own purposes. If you think a child has given us their data, write to us and we will delete it. Each venue decides who it admits to its Circle and its reservations, and is responsible for that.

15. Changes to this policy

We may update this policy when the service or the law changes. When we do, we will change the date at the top and, if the change is significant and you have an account, we will email you before it takes effect.

16. Contact

For any question about this policy or your data, write to hello@revenight.com.