Last updated 16 August 2026

Privacy notice

Who is responsible

Revue is responsible for business account, registration, security and subscription information. Each business decides why and how its customer, booking, order, staff and voucher information is used; Revue processes that information to provide the connected services on the business’s behalf.

Information we process

Business account information may include business name, category, usernames, email addresses, roles, permissions, device licences, login security records and Stripe customer or subscription references. Booking information may include a customer’s name, contact details, date and time, party size, notes, assigned resources and visit history. POS and operational information may include menus, tables, orders, payments recorded by method, printer routing, stock, staff activity and reports. Voucher information may include purchaser and recipient contact details, value, balance, expiry, redemption history and wallet-pass references. Operational records may include request identifiers, delivery status, browser or device error details and administrator support actions. Stripe handles card information directly; Revue does not store raw card details.

Why we use it

We use information to provide and secure enabled Revue services, synchronise authorised devices, deliver bookings and vouchers, administer subscriptions, support users, prevent abuse, maintain records and meet legal obligations. Business account processing is generally necessary to perform the service contract or for legitimate security and operational interests. Each business is responsible for identifying the appropriate basis for its customers’ information and any sensitive information it requests.

Sharing

Information is shared only where needed to operate the service, including with the relevant business, Stripe for checkout and billing, configured email and wallet-pass providers, and services that host or support Revue. Revue products share information only inside the same business account when those products are connected. One business cannot access another business’s records. We may also disclose information where required by law or to protect users and the service.

Retention and security

Pending registration details normally expire within two hours if checkout is not completed. One-time account links expire after 24 hours. Active account, booking, order and voucher data is kept for the service period and according to the business’s instructions, operational needs and applicable record-keeping requirements. Financial and redemption records may be retained where required for tax, fraud prevention or legal obligations. Operational and delivery logs are retained only as long as needed for security, support and reliability. We use tenant isolation, access controls, hashed passwords, revocable sessions, audited support access, restricted origins and transport security, but no online system can guarantee absolute security.

Support access and service logs

Authorised Revue.day administrators may open a time-limited support session when needed to diagnose or configure a business workspace. These actions are logged. Client and server errors may be recorded with a request identifier, business reference, route and technical stack information; passwords, session tokens and payment card data are deliberately excluded.

Your choices and rights

Depending on the circumstances, you may have rights to access, correct, erase, restrict or object to processing of your information, and to data portability. Customers should normally contact the relevant business first about a booking, order or voucher. Business account and Revue privacy enquiries can be sent to privacy@revue.day. Business owners can also start account deletion from the account deletion page.

You may also complain to the UK Information Commissioner’s Office at ico.org.uk.

Local storage, analytics and checkout

Revue web tools use browser storage for secure sign-in sessions and interface preferences. Native apps may use protected device storage for authorised sessions, settings and resilient offline operation. Google Tag Manager is initialised with analytics and advertising storage denied. Optional analytics can run only after a visitor chooses to allow it; advertising storage remains denied, the preference is stored in the browser and analytics remains denied when a browser sends a Do Not Track signal. Stripe may use its own cookies and technologies during secure checkout under Stripe’s privacy information.