Privacy Policy
How Revindi Media collects, uses, protects and shares information — including data accessed through Google APIs.
Last updated: September 21, 2026
On this page
1. Who We Are
Revindi Media (“Revindi”, “we”, “us”, or “our”) builds and operates done-for-you automation systems for local service businesses — appointment scheduling, lead capture and CRM routing, email and SMS follow-up, review management, payment workflows and client onboarding.
We operate remotely and serve businesses throughout the United States. This policy explains what we do with personal information, both on this website and inside the automation systems we build and run for our clients.
It covers revindi.com and the automation services we deliver to clients.
2. Information We Collect
a) Website visitors
This website does not run advertising trackers, analytics pixels or third-party marketing scripts, and it does not set cookies for anonymous visitors. We do not operate a contact form; enquiries reach us by phone or email, which you choose to initiate.
Our hosting provider automatically records standard server logs (IP address, timestamp, page requested, browser user-agent) for security, abuse prevention and reliability. Fonts on this site are served by Google Fonts, which receives your IP address as part of delivering them — see our Cookie Policy.
b) Clients and prospective clients
When you enquire about or purchase our services, we collect the information you give us:
- Name, business name, email address and phone number
- Details about your business, its workflows and the problems you want automated
- Account and billing records, including the plan you are on and payment history
- Correspondence with us by email, phone, message or during calls
- Credentials and authorisations you grant us so we can build and operate your systems (see Section 5)
We do not collect payment card numbers directly. Card details are handled by our payment processor.
c) Data we process on behalf of clients
To run your automations we necessarily handle data belonging to your customers — for example a caller name and number, an appointment request, an invoice, or the contents of an email thread. For that data you are the controller and Revindi is the processor: we act on your instructions, use it only to operate the systems you asked us to build, and do not repurpose it.
3. How We Use Information
- To deliver, configure, operate, monitor and support the automation systems you engage us to build
- To respond to enquiries, provide quotes and communicate about your account
- To invoice you and keep accurate financial records
- To secure our systems, investigate abuse and troubleshoot faults
- To meet legal, tax and accounting obligations
- To send service updates about work we are doing for you
We do not sell personal information. We do not share it with data brokers, and we do not use client data or end-customer data to serve advertising.
4. Legal Bases for Processing
Where the UK GDPR, EU GDPR or comparable law applies, we rely on:
| Basis | Where we rely on it |
|---|---|
| Contract | Delivering the services you have engaged us to provide, and billing for them |
| Legitimate interests | Securing our infrastructure, preventing abuse, maintaining server logs, and responding to enquiries you initiate |
| Consent | Any optional marketing communications; withdrawable at any time |
| Legal obligation | Tax, accounting and records-retention requirements |
Where we process end-customer data on a client behalf, the client determines the legal basis and is responsible for having one.
5. Google User Data
Several of our automations connect to Google Workspace and Gmail. We connect to our own Google accounts and, where a client authorises it, to the client Google account. Access is always granted through the standard Google OAuth consent flow — we never ask for, store, or accept a Google account password.
What we access
We request the narrowest OAuth scopes that the automations you enable actually require. Depending on which workflows you turn on, this can include reading messages and their metadata so a workflow can be triggered or populated, sending or drafting messages on your behalf, and organising mail with labels. If a workflow does not need a scope, we do not request it.
What we use it for
Google user data is used for one purpose only: to operate the specific automation workflows you asked us to build. Typical examples are detecting an inbound enquiry and creating a CRM record, sending a templated follow-up or appointment reminder from your address, and filing correspondence against the right customer.
How it is stored and for how long
| Item | Our practice |
|---|---|
| OAuth tokens | Stored encrypted in the credential store of our automation platform, accessible only to the workflow that needs them and to authorised Revindi personnel |
| Message content | Processed in transit to execute a workflow. We do not build an archive or a copy of your mailbox |
| Derived records | Only the fields a workflow must retain to work — for example a contact name, an email address or an appointment time written into your CRM, which remains in your systems under your control |
| Retention | Held only while your engagement is active. On termination, tokens are revoked and any residual Google-derived data held by us is deleted within 30 days |
Who it is shared with
Google user data is not shared with any third party, other than the infrastructure providers strictly required to run your workflows (listed in Section 7), and only to the extent needed to operate them. It is never transferred for any independent purpose of theirs.
Limited Use commitment
Revindi Media use and transfer of information received from Google APIs to any other app adheres to the Google API Services User Data Policy, including its Limited Use requirements.
Specifically, and without qualification, we confirm that Google user data is:
- Never sold to anyone, under any circumstances
- Never used for advertising — including retargeting, personalised advertising, or ad measurement
- Never used to train generalised AI or machine-learning models. We do not feed Google user data into the training, fine-tuning or improvement of any generalised model, whether our own or that of a third party
- Never used for any purpose beyond operating the user-facing features you explicitly enabled
- Only read by a human where you have given explicit consent for a specific issue, where required for security or to comply with law, or where the data has been aggregated and anonymised
How to revoke our access
You can withdraw our access to your Google account at any time, without contacting us first:
- Go to Google Account → Third-party apps & services
- Select the Revindi connection
- Choose Remove access
Revoking access stops all data flow immediately. Any automation depending on that connection will stop working, so please tell us if you want the workflow rebuilt another way.
How to delete Google data we hold
Email contact@revindi.com with the subject line “Google data deletion” and tell us which Google account is involved. We will revoke the stored tokens, delete Google-derived data we hold, and confirm in writing within 30 days. Deletion also happens automatically when an engagement ends.
6. Cookies and Tracking
This website sets no cookies for anonymous visitors and runs no analytics or advertising trackers. Cookies are only set if you log in to the site as an administrator. Full detail is in our Cookie Policy.
7. Service Providers
We keep our supply chain deliberately small. The categories of provider who may handle personal information on our behalf are:
| Category | Purpose |
|---|---|
| Website hosting | Serving revindi.com and retaining standard server logs |
| Web fonts | Google Fonts serves typefaces on this site and receives visitor IP addresses |
| Workflow automation | Running the automations we build, including securely storing the credentials you authorise |
| Google Workspace / Gmail APIs | Executing the mail-related steps of your workflows, under Section 5 |
| Email and messaging delivery | Sending the email and SMS your workflows generate |
| Payment processing | Taking payment and issuing invoices; card data is handled by the processor, not by us |
Providers act on our documented instructions and are bound by confidentiality. We do not authorise them to use your data for their own purposes. If you need the current named list of subprocessors for a due-diligence review, email us and we will provide it.
8. Sharing and Selling
We do not sell personal information and we do not share it for cross-context behavioural advertising. We disclose information only:
- To the service providers described above, to deliver what you asked for
- To you, or to anyone you direct us to
- Where we are legally required to — a court order, lawful request, or to establish or defend a legal claim
- To protect the rights, safety or property of Revindi, our clients or the public
- To a successor entity in a merger or acquisition, under equivalent confidentiality obligations
9. Data Retention
| Data | Retained for |
|---|---|
| Enquiries that do not become clients | Up to 24 months, then deleted |
| Client account and project records | Duration of the engagement, then up to 7 years where needed for tax, accounting or legal-claim purposes |
| OAuth tokens and Google-derived data | Duration of the engagement; deleted within 30 days of termination |
| Server logs | A rolling short-term window held by our host for security and diagnostics |
| End-customer data inside your systems | Under your control, per your own retention policy |
10. Your Rights
Depending on where you live, you may have the right to:
- Access the personal information we hold about you
- Correct information that is inaccurate or incomplete
- Delete your information, subject to legal retention obligations
- Port your data to another provider in a machine-readable format
- Object to or restrict processing based on legitimate interests
- Withdraw consent at any time, without affecting processing already carried out
- Opt out of any sale or sharing of personal information — note that we do neither
- Be free from discrimination for exercising any of these rights
Exercise any of these by emailing contact@revindi.com. We respond within 30 days and will not charge you for a reasonable request. We may need to verify your identity before acting. If we process your data on behalf of one of our clients, we will refer your request to them and support them in answering it.
If you are in the EEA or UK and believe we have handled your data unlawfully, you may complain to your local supervisory authority.
11. Deleting Your Data
To request deletion, email contact@revindi.com with the subject line “Data deletion request”, telling us which account or business the request relates to. We will confirm what has been deleted, and identify anything we must retain by law and why. Google-specific deletion is covered in Section 5.
12. Security
We protect information with encryption in transit (TLS), encrypted storage of credentials and OAuth tokens, access restricted to personnel who need it, least-privilege OAuth scopes, and hardened, monitored hosting. No system is perfectly secure, but if a breach affects your personal information we will notify you and any regulator as required by law.
13. Children
Our services are sold to businesses and are not directed to children under 16. We do not knowingly collect their personal information. If you believe a child has provided us data, contact us and we will delete it.
14. Changes to This Policy
We may update this policy as our services or the law change. The “Last updated” date at the top always reflects the current version. Material changes affecting how we handle your data will be communicated to active clients directly.
Contact Us
Questions about this policy, your data, or a Google data deletion request:
contact@revindi.comRevindi Media · Remote · Serving businesses nationwide (United States)
