Introduction and scope
This policy applies to two groups of people: merchants who use ReviveCart to run their store, and the end customers, the shoppers, who interact with a merchant's store where ReviveCart's products are running. If you're a merchant, this covers the account and business data we collect from you directly. If you're a shopper, this covers the data that flows through ReviveCart on a merchant's behalf when you browse or check out on their site, even though you never signed up with us yourself.
ReviveCart operates several product surfaces that each touch data differently: Sage, an AI agent that runs sales, support, and customer operations across WhatsApp, SMS, email, and voice; Pulse, which reads behavioral signals on a merchant's storefront; and Flux, our payment rail for merchant payouts. Each is described in more detail below. This policy is effective March 1, 2026. If you have questions about how it applies to you, email us at privacy@revivecart.com.
Information we collect
Merchant account data. When a merchant and their team members sign up, we collect names, email addresses, login and session data, IP address, and browser or device information. We also collect product usage data: which features a merchant uses, how often, and how their store is configured.
Merchant KYC and financial data. Flux, our payment rail, requires identity and banking verification before a merchant can accept payouts. This includes government ID numbers, bank account and routing numbers, business details, and tax ID. Full ID numbers and full bank account details are passed directly to our third-party payment processor and are never stored by ReviveCart. On our side, we retain only the last four digits of these identifiers, enough to reference an account without exposing the full value.
End-customer and shopper data. On a merchant's behalf, Sage collects shopper names, phone numbers, email addresses, cart contents, and order history in order to run sales and support conversations. Pulse collects IP address, device and browser information, session and click-stream data, and product interaction events as a shopper browses a merchant's storefront. This data is collected for the merchant, not for ReviveCart's own separate use.
How we use information
We use the information above to operate the products merchants sign up for: running Sage's AI-driven sales and support conversations, powering Pulse's behavioral analytics, and processing payouts through Flux. Financial and identity information collected during onboarding is used specifically for fraud and compliance screening, including OFAC sanctions screening and know-your-customer checks required of anyone moving money through a payment rail.
We also use account and usage data to improve ReviveCart itself: understanding which features work, diagnosing issues, and building new capabilities. We use merchant contact information to communicate about the account, including service updates, billing, and security notices. Where the law requires it, we use information to meet legal, regulatory, or audit obligations, including responding to lawful requests from authorities.
Data retention
KYC identifiers are never retained beyond the last four digits described above; the full values live only with our payment processor. Behavioral and analytics data collected through Pulse is retained at the event level for 24 months, after which it's aggregated into summary metrics or deleted. Aggregated data, which no longer identifies an individual shopper, may be kept longer for trend reporting.
Account data, including merchant team member information and usage history, is retained for the life of the account. After a merchant closes their account, we keep a limited set of records for a reasonable period afterward to meet legal, tax, and audit obligations, then delete or anonymize what remains.
Your rights
Depending on where you're located, you may have the right to access the personal data we hold about you, correct it if it's inaccurate, or request that it be deleted. These rights apply in full where laws like the GDPR or CCPA require them, and we extend the same basic access, correction, and deletion process more broadly as a matter of practice.
To exercise any of these rights, email privacy@revivecart.com. If you're a shopper whose data reached us through a merchant's use of Sage or Pulse, we'll still process your request directly, though we may need to confirm details with the merchant to locate the right records. We'll respond within the timeframe applicable law requires, and sooner where we can.
Security
We encrypt data in transit between a shopper's browser, a merchant's store, and ReviveCart's systems, and we apply access controls internally so that only team members who need it can reach sensitive data. Access to KYC and payout information is particularly restricted, consistent with what's described above.
The most sensitive financial identifiers, full government ID numbers and full bank account details, are never persisted by ReviveCart in the first place; they pass through to our third-party payment processor at the point of collection. That design choice limits our own exposure and, by extension, the exposure of anyone whose data we handle, even in the event of a breach elsewhere in our systems.
International data transfers
ReviveCart serves merchants across the United States, Canada, the European Economic Area, and the United Kingdom, and data may be transferred between and processed in these regions as part of running the platform. Where a transfer moves data out of a region with its own data protection framework, such as the EEA or UK, we rely on recognized transfer mechanisms, including standard contractual clauses, to keep that data protected to the standard the originating region requires.
Children's privacy
ReviveCart is a business tool for merchants and is not directed at children. We don't knowingly collect personal data from children under the age applicable law sets as the threshold for parental consent, generally 13 in the United States and 16 in parts of the EEA and UK. If we learn that a child's data has reached us in a way that requires removal, we'll delete it.
Changes to this policy
We may update this policy from time to time as ReviveCart's products change or as privacy law evolves. When a change is material, we'll notify merchants by email or through the console before it takes effect. Continuing to use ReviveCart after a change takes effect means the updated policy applies.
Contact us
Questions about this policy, or requests related to your personal data, can be sent to privacy@revivecart.com. You can also reach us by mail at ReviveCart, 2810 North Church Street, Wilmington, DE 19802.