Legal

Privacy Policy

How Revisit Business collects, uses and protects information — for the businesses that run on it, and for their customers.

Effective 13 September 2026 · Version 1.0

In short

We sell software to small businesses, not advertising. We collect what the product needs to run your workspace, we never sell personal information, and we never process card payments. When a business uses Revisit to serve its own customers, that business decides what is collected and why — we only hold it on their behalf. The sections below set out the detail, and they, not this summary, are the policy.

Who we are and what this covers

Revisit Business ("Revisit", "we", "us") provides a business-management platform for small businesses: a workspace for products and services, customers, orders and appointments, payments recorded against those orders, staff roles, advisories, and an optional public site for the business. It runs on the web, on Android and iOS, and on desktop, from one codebase.

This policy covers the Revisit apps, the Revisit marketing site, the public sites we host for businesses that use Revisit, and the API behind all of them. It does not cover a third-party service you choose to open from inside the product — WhatsApp, your mail app, your phone dialler, a map — each of which has its own policy.

The two roles we play

This is the most important section in the policy

For information about the business itself and the people who log in — the account holder and their staff — Revisit is the controller: we decide what is collected and why. For information a business records about its own customers — names, contact details, appointments, order history, advisories — the business is the controller and Revisit is only the processor. We hold and protect that data, and we act on the business's instructions with it. We do not decide what goes into it, we do not use it for our own purposes, and we do not sell it.

If you are a customer of a business that uses Revisit and you want your records changed or deleted, ask that business first — they control the record. See "If you are a customer of a business using Revisit" below for what we will do if you come to us instead.

Information we collect

From the business and its staff

  • Account details — name, email address, phone number, username and password, and a profile photo if one is uploaded.
  • Business details — trading name, contact details, address, logo, and the branding and copy shown on a public site we host for the business.
  • Roles and permissions — which staff account holds which role, and what each role is permitted to view, create, update or delete.
  • Subscription and support records — which features are enabled for the workspace, and the enquiries sent to us during onboarding or support.

Recorded by the business about its customers

The business decides what to enter here. In the product, the fields available are:

  • Customer record — name, email address, phone number, address, gender, an optional photo, and whether the record is a guest.
  • Activity — appointments and orders, the services or products on them, quantities and prices, sessions, status history, and the notes the business adds.
  • Payment ledger — amounts due and received, part payments, and whether each was taken as cash or card. See "What we do not collect" below.
  • Advisories — the advisories, instructions or prescriptions a business issues to a customer, where the business uses that feature.

Collected automatically

  • Device and app data — device or browser type, operating system, app version, language, and a device or installation identifier.
  • Usage data — which screens and features are opened and when, as aggregate usage events.
  • Diagnostics — when something goes wrong, the error, a stack trace, and the state of the app around it, so the fault can be traced.
  • Server logs — the request, the time, an IP address and the response, kept for security and troubleshooting.

What we do not collect

  • Card and bank details — Revisit does not process payments and has no payment gateway. An order records the amount and whether it was settled in cash or by card; no card number, expiry, CVV or bank detail is requested, transmitted or stored by us.
  • The content of your messages and calls — the product opens WhatsApp, your mail client or your phone dialler with a message prefilled. The conversation happens in that app, between you and the other person. We do not receive, store or read it.
  • Advertising identifiers — we do not run advertising, we do not embed advertising or social-media trackers, and we do not build advertising profiles.
  • Background location or continuous device access — the camera and photo-library permissions are requested only when you choose a profile picture, and only the image you select is read.

How we use information

  • To provide the service — to create and secure accounts, keep you signed in, enforce role permissions, and run the workspace features the business has enabled.
  • To host public sites — to publish the business's own public site with the content and branding it has given us.
  • To support you — to answer enquiries, onboard a new business, and investigate faults reported to us.
  • To protect the platform — to detect abuse, prevent unauthorised access, and keep audit and security logs.
  • To improve the product — to understand which features are used, in aggregate, and to fix crashes and errors.
  • To comply with the law — to meet obligations that apply to us, and to establish, exercise or defend legal claims.

Where the law requires a legal basis, ours is: performance of our contract with the business; our legitimate interest in operating, securing and improving the platform; consent, where you have given it (for example for a device permission); and compliance with a legal obligation. Customer records are processed on the instructions of the business that entered them.

We do not sell personal information, and we do not use customer records held for one business to serve any other business.

Public sites and what is visible on them

A business using Revisit can have a public site — its services, opening hours, address, phone number and the content it chooses to publish. That page is open to anyone on the internet and is intended to be. No customer record, order, payment or advisory is ever published on it.

A visitor to a public site can read it without an account, and we do not require one. If a visitor starts a WhatsApp chat or dials the number from that page, they are contacting the business directly; that exchange does not pass through Revisit.

Health and other sensitive information

Some businesses using Revisit are clinics, and the advisories they issue can amount to health information about an identified person. Where that happens, the clinic is the controller of those records and is responsible for the lawful basis, any consent required, and the professional obligations that attach to them. We hold that data on the clinic's behalf, under the same protections described in this policy, and we do not access it except where strictly necessary to operate the service or when the clinic asks us to.

Revisit is not a medical records system

The platform has not been certified against any healthcare records standard, and we make no claim that it satisfies HIPAA or any comparable national health-data regime. A business subject to one of those regimes should confirm that this product meets its obligations before recording regulated data in it.

Diagnostics and cookies

  • Sentry — crash and error reports, which can include an error message, a stack trace and limited context about what the app was doing. Our Sentry project is hosted in the European Union.

We do not use advertising cookies or third-party tracking pixels. On the web, we use browser storage for the things the app cannot work without: your session token, the "remember me" choice, and interface preferences such as the theme. On mobile and desktop, session tokens are held in the operating system's secure store (Keychain on Apple platforms, Keystore on Android). Clearing site data or logging out removes them.

Who we share information with

We share personal information only in these situations:

  • Service providers — hosting, storage and error reporting, as named above. They act on our instructions and may not use the data for their own purposes.
  • Within your workspace — each business sees only its own workspace. Within it, what a staff account can see is decided by the role the business gave it.
  • Legal reasons — where we must comply with a law, a court order or a lawful request from an authority, or to protect the rights, safety or property of a person or of the platform.
  • A change in our business — if the business is ever sold, merged or reorganised, data may transfer with it. Notice will be given before any such transfer takes effect, and this policy continues to apply to the data until it is replaced.

Where data is stored

The platform's API and database run on Microsoft Azure (East US region). Uploaded images are held in Azure Blob Storage and served through links that are signed and expire — an image link stops working roughly a day after it is issued, so a copied URL does not stay open indefinitely. Error reports go to Sentry in the European Union.

This means data may be processed outside the country where you or your customers are. Where such a transfer needs a safeguard, we rely on the terms our providers offer for international transfers.

How long we keep it

  • Workspace and customer records — kept while the workspace is active, and for a reasonable wind-down period after it closes so that records can be exported or restored if the closure was a mistake.
  • Account details — deleted when the account is deleted, apart from what we must keep for legal or accounting reasons.
  • Logs and error reports — kept on a rolling short-term basis — typically weeks to months, depending on the provider's retention settings — and then discarded.

Deletion inside the app may first mark a record inactive rather than erase it, so that an accidental deletion can be undone. On a confirmed deletion request, we remove the data from our live systems, and backups age out on their own cycle.

How we protect information

  • In transit — traffic between the apps and our API is encrypted in transit (HTTPS/TLS).
  • Authenticated access — access requires an authenticated session token, and every request is checked against the role permissions of the account making it.
  • Separation — a business's data is scoped to that business's workspace.
  • Uploads — image links are signed and time-limited rather than public.

No system is perfectly secure, and we cannot guarantee that data transmitted to us is never intercepted. Keep your password to yourself, give staff the narrowest role that lets them do their job, and tell us immediately if you think an account has been compromised.

Your rights and choices

Depending on where you live, you may have the right to ask for a copy of your personal information, to have it corrected, to have it deleted, to object to or restrict how we use it, to receive it in a portable form, and to withdraw a consent you gave. You can also complain to your local data-protection authority.

Much of this you can do yourself in the app: edit your profile, update or delete a customer record, or change what a role can access. For anything else, write to us at mashood.murtaza@gmail.com. We will verify that the request comes from the account holder before acting, and we will respond within a month, or tell you why we need longer.

If you are a customer of a business using Revisit

Your records belong to the business you visited — the clinic, salon, workshop or shop that entered them. They decide what is kept and for how long, so the fastest route to having something corrected or removed is to ask them directly.

If you contact us instead, we will pass the request to that business and tell you we have done so. We will not change or delete another business's records without their instruction, unless the law requires us to.

Children

Revisit is a tool for businesses and is not directed at children. We do not knowingly create accounts for anyone under 18. A business may legitimately record a minor as its own customer — a child patient at a dental clinic, for example — and where it does, that business is responsible for obtaining any consent its law requires from a parent or guardian.

Changes to this policy

We will update this policy when the product or the law changes. The effective date and version at the top of the page always say which text is current. For a change that materially affects how we handle personal information, we will give notice in the app or by email before it takes effect. Continuing to use Revisit after that date means the updated policy applies.

Contact us

Questions about this policy, or a request about your data, can go to mashood.murtaza@gmail.com, or to +92 332 468 1053 by phone or WhatsApp. We read every message ourselves — Revisit is a small team.