Privacy Policy
What we hold, why, for how long, and who else sees it — for this website and for the products. Guest data belongs to the hotel; we only ever process it on their instruction.
Effective 13 August 2026 · Last updated 13 August 2026
Who we are
WEBER BG EOOD (EIK 205090014), 6 Preslav St, Ruse 7000, Bulgaria, trading as Revio. For anything on this page, write to privacy@reviosoft.app and a person will answer.
The two halves of this policy
Revio touches personal data in two very different roles, and conflating them would be misleading.
| Data | Our role | What that means |
|---|---|---|
| Guests of a hotel that uses Revio | Processor | The hotel decides what happens to it. We act on their instructions and nothing else. Guests should ask the hotel first — we will help the hotel answer. |
| Hotel staff accounts, and visitors to this website | Controller | We decide, so this policy is the answer, and you can hold us to it directly. |
Part one — this website
What we collect
- What you type into the demo form: your name, work email, property name, room count if you give it, which products interest you, and anything you write in the message box.
- How you found us, if you arrived from a campaign: the campaign parameters in the link you clicked. This is attached to your enquiry so we know which advert to keep paying for.
- Anonymous analytics, only if you accept cookies: pages viewed, roughly where in the world you are, and which buttons get clicked. IP addresses are anonymised. If you decline, none of this runs at all.
Why, and on what legal basis
- To reply to your enquiry and run the sales conversation — our legitimate interest in responding to someone who asked us to, and steps towards a contract.
- Analytics — your consent, which you give or withhold on the cookie banner.
- Sales follow-up email — your consent, given on the form. Every message has an unsubscribe link that works immediately.
How long we keep it
Enquiries that do not become customers: 24 months, then deleted. Analytics: 14 months. Ask us to delete an enquiry sooner and we will, same week.
Part two — the products
Hotel staff accounts (we are the controller)
- Name, work email, role and permissions, and which property you belong to.
- A hash of your password. It is not reversible: nobody at Revio can read your password, and we will never ask you for it.
- Sign-in and security events — when you signed in, from roughly where, when your password changed, when sessions were revoked. This exists so that an account compromise can be investigated, and so a departing employee’s access can be proven to have ended.
Basis: performance of our contract with your employer, and our legitimate interest in keeping the platform secure. Retention: for as long as the account exists, and security events for 12 months after that.
Guest data (the hotel is the controller)
Reservations, guest names and contact details, stay history, preferences and notes, folio lines and invoices, and — where a card is used — a payment token and the last four digits, never a card number.
We process this only to run the service for the hotel. We do not sell it, share it for anyone else’s marketing, or use it to train machine-learning models. The terms are in our Data Processing Agreement.
If you are a guest and want your data corrected or deleted, contact the hotel you stayed at — they decide, and we act on their instruction. If you cannot reach them, write to privacy@reviosoft.app and we will help you get to the right person.
One thing we deliberately made narrower
A hotel’s booking page can recognise a returning guest. That check happens only after a guest submits their own details, never as a live lookup while they type — because a public page that answers “does this email exist” is a tool for finding out who has stayed somewhere. Any guest can switch recognition off entirely, and that setting is respected by staff screens too.
Who else touches it
Only the companies we need to run the service. Each is bound by contract, each is listed with what it can actually see, and we tell customers before we add one.
- Railway — Application hosting, the Postgres database and object storage for uploaded images. European Union.
- Channex.io — Connectivity to Booking.com, Expedia and other channels. European Union / United Kingdom.
- Stripe — Card guarantees on direct bookings, and card payments where a property enables them. Ireland / United States (EU Standard Contractual Clauses).
- Resend — Transactional email — booking confirmations, invitations, password resets. United States (EU Standard Contractual Clauses).
- Google Analytics 4 — Anonymous traffic analytics on this marketing website only. United States (EU Standard Contractual Clauses).
The maintained list, with the exact data each one can see, is at /subprocessors.
Where your data lives
The platform runs in the European Union — application, database and uploaded images. Where a sub-processor operates outside the EU, the transfer relies on the European Commission’s Standard Contractual Clauses, and the sub-processor page says which ones those are.
How it is protected
- Every row of data carries the hotel that owns it, and the database itself refuses to return anyone else’s — so a bug in our application cannot leak your data.
- Encrypted in transit, and backed up nightly with a restore procedure we have run and timed.
- Passwords hashed; integration credentials encrypted at rest and never shown to a hotel.
- Sessions can be revoked everywhere at once, and a password change ends every other session immediately.
More detail, including what we do not have, is on our security page.
Your rights
Under the GDPR you can ask us to:
- tell you what we hold about you, and give you a copy;
- correct it if it is wrong;
- delete it, where we have no overriding obligation to keep it;
- stop processing it, or object to processing based on legitimate interest;
- hand it to you in a portable format;
- withdraw consent at any time, without affecting what happened before.
Write to privacy@reviosoft.app. We answer within 30 days and usually much sooner. There is no charge.
If we get it wrong you can complain to the Bulgarian Commission for Personal Data Protection, or to the supervisory authority where you live. We would rather you told us first, but that right is yours either way.
Cookies
This website sets no analytics or marketing cookies until you accept them. The products set only what is strictly necessary to keep you signed in. Details are on the Cookie Policy page.
Automated decisions
We do not make automated decisions with legal or similarly significant effects about anyone, and we do not profile guests.
Children
The products are business software and are not directed at children. Where a hotel records a child as part of a booking, that data is the hotel’s and is covered by their own policy.
Changes
If we change this policy in a way that matters, we will email account holders rather than quietly editing the page. The date at the top always reflects the current version.
Questions about anything on this page go to legal@reviosoft.app, and we will answer them in writing. If a clause here would stop you signing, tell us — most of it is negotiable and we would rather know.