Privacy Policy
Last updated: 19 August 2026
1. Who we are
This Privacy Policy explains how Revotech OÜ ("Revotech", "we", "us", "our") processes personal data when you visit the Salesreach website, contact us about becoming a merchant partner, or receive messages through the Salesreach messaging service operated on behalf of a Shopify merchant.
| Legal name | Revotech OÜ |
| Registry code | 17332344 |
| Registered address | Ahaste tee 4, Ahaste küla, 88306 Pärnu linn, Pärnu maakond, Estonia |
| Product / brand | Salesreach |
| Privacy contact | support@salesreach.net |
| Sales enquiries | sales@salesreach.net |
Revotech OÜ is the data controller for personal data collected through the Salesreach marketing website and for prospective merchant leads.
When we deliver WhatsApp or SMS messages on behalf of a Shopify merchant, we generally act as a data processor for that merchant's end-customer data. The merchant remains the data controller for its customers' personal data. Section 8 below describes that processing.
We have not appointed a Data Protection Officer (DPO). Under the GDPR, Revotech OÜ is not currently required to designate a DPO based on the nature and scale of our processing. For privacy enquiries, contact support@salesreach.net. For sales and partnership enquiries, contact sales@salesreach.net.
2. Scope of this policy
This policy applies to:
- Website visitors — anyone who browses the Salesreach marketing site or submits our contact form.
- Prospective merchant leads — businesses that enquire about partnering with Salesreach.
- End-customers of merchant clients — shoppers who opt in to receive WhatsApp or SMS messages from a merchant through Salesreach's messaging infrastructure (described in Section 8).
This policy does not govern third-party websites linked from our site (including merchant Shopify stores). Those sites are operated by their respective controllers and have their own privacy policies.
3. Personal data we collect
3.1 Marketing website and contact form
When you submit our "Get in contact" form, we collect:
- Email address — so we can reply to your enquiry.
- Phone number (including country dialling code) — so we can reach you about Salesreach.
- Technical data — IP address, browser type, device information, and timestamps, collected automatically through our hosting infrastructure for security and abuse prevention.
We do not require you to create an account to use the marketing website.
3.2 Merchant onboarding (future)
If you become a Salesreach merchant partner, we will additionally collect business contact details, Shopify store information, billing details, and messaging configuration data necessary to operate the service. We will provide supplementary privacy information at onboarding where required.
3.3 End-customer messaging data (on behalf of merchants)
When a merchant uses Salesreach to message its customers, we process data the merchant provides or that is generated through the service, including:
- Customer name and phone number
- Order and cart information (e.g. products purchased, order numbers)
- Messaging consent records (timestamp, opt-in method, opt-in text shown)
- Message content sent and received (including replies such as STOP or HELP)
- Delivery and read status metadata from messaging providers
We process this data only on the merchant's documented instructions and as described in our agreement with the merchant.
4. Why we use your data and our legal bases
Under the GDPR, we must have a lawful basis for each processing activity.
| Processing activity | Purpose | Legal basis (GDPR Art. 6) |
|---|---|---|
| Contact form submissions | Responding to partnership and sales enquiries about Salesreach | Legitimate interests (Art. 6(1)(f)) — pursuing business development for a B2B SaaS product. You may object (see Section 10). Enquiries are handled via sales@salesreach.net. |
| Security logs and bot mitigation | Protecting the website and contact form from abuse | Legitimate interests (Art. 6(1)(f)) — ensuring security and integrity of our systems |
| End-customer messaging | Delivering opted-in WhatsApp/SMS messages on a merchant's behalf | Consent (Art. 6(1)(a)) — collected by the merchant from the end-customer at checkout or equivalent opt-in point. The merchant is responsible for obtaining valid consent. |
| Merchant contract performance | Operating Salesreach for onboarded merchants | Contract (Art. 6(1)(b)) — necessary to perform our agreement with the merchant |
| Legal compliance | Responding to lawful requests; maintaining consent and opt-out records for telecom regulations | Legal obligation (Art. 6(1)(c)) and legitimate interests (Art. 6(1)(f)) |
We do not use contact-form data for automated decision-making or profiling that produces legal or similarly significant effects.
5. SMS and WhatsApp messaging disclosures
This section applies to end-customers who opt in to receive messages through a merchant's use of Salesreach.
Program name: Salesreach Messaging (delivered on behalf of the merchant whose store you interacted with)
Types of messages you may receive: Order confirmations and shipping updates; cart-abandonment reminders; post-purchase product recommendations and upsell offers related to products you viewed or purchased. Messages are sent over WhatsApp and/or SMS.
Message frequency: Message frequency varies by your interactions with the merchant. You may receive up to 4 messages per month, and sometimes fewer depending on your orders and cart activity.
Cost disclosure: Message and data rates may apply. Check with your mobile carrier for details about your plan.
Opt-out: Reply STOP (or UNSUBSCRIBE, CANCEL, END, or QUIT) to any SMS message to cancel future SMS messages from that merchant's program. Reply STOP in WhatsApp to unsubscribe from WhatsApp messages. You will receive a one-time confirmation that you have been unsubscribed. After opting out, you may still receive messages already in transit.
Help: Reply HELP (or INFO) to any message for assistance, or contact the merchant directly using the contact details on their store.
Consent: You opt in by checking an unchecked consent box at the merchant's Shopify checkout (or equivalent opt-in point shown by the merchant). Consent is not a condition of purchase unless the merchant explicitly states otherwise in compliance with applicable law.
AI-generated content: Some messages may be drafted by an AI assistant operating under a named persona (e.g. "Jake from [Brand]"). The first message in a new conversation identifies the sender as an AI shopping assistant for that merchant, in compliance with applicable automated-messaging disclosure laws.
Mobile data sharing — required disclosure
We do not share, sell, rent, or provide your mobile phone number, SMS opt-in data, WhatsApp opt-in data, or messaging consent records to third parties or affiliates for their own marketing or promotional purposes.
We share mobile and messaging data only with service providers that help us deliver the messaging service (such as Twilio and Meta/WhatsApp), under written data-processing agreements and solely to provide the service — not for those providers' independent marketing. See Section 6.
6. Who we share data with
We do not sell personal data.
We share personal data with the following categories of recipients, only as needed:
| Recipient | Role | Data shared | Location |
|---|---|---|---|
| Vercel, Inc. | Website hosting and serverless infrastructure | Contact form data, technical logs | United States / global CDN |
| Neon, Inc. (Vercel Postgres) | Database hosting for lead storage | Contact form submissions | United States / EU (region-dependent) |
| Twilio, Inc. | SMS and WhatsApp message delivery | Phone numbers, message content, delivery metadata | United States |
| Meta Platforms, Inc. | WhatsApp Business Platform | Phone numbers, message content, delivery metadata | United States / Ireland |
| Professional advisers | Legal, accounting, compliance | As necessary | Estonia / EU |
| Authorities | Law enforcement or regulators, when legally required | As required by law | Varies |
When we process end-customer data for a merchant, the merchant also has access to its own customers' data through the Salesreach service.
International transfers
Some of our service providers are located outside the European Economic Area (EEA), primarily in the United States. Where we transfer personal data outside the EEA, we rely on appropriate safeguards under GDPR Chapter V, including:
- Standard Contractual Clauses (SCCs) approved by the European Commission, incorporated into our agreements with processors; and/or
- Adequacy decisions where applicable (e.g. transfers to countries the European Commission has deemed adequate).
You may request a copy of the relevant safeguards by contacting us at support@salesreach.net.
7. How long we keep data
| Data category | Retention period |
|---|---|
| Contact form leads | 24 months from submission, unless a business relationship continues (then for the duration of the relationship plus 24 months) |
| Security and server logs | 90 days, unless needed for an active security investigation |
| End-customer messaging data (processor role) | For the duration of the merchant's agreement with us, plus 5 years thereafter for consent and opt-out audit records (to meet telecom and GDPR accountability requirements; German-market merchants may require longer retention — we configure per merchant jurisdiction where applicable) |
| Opt-out / STOP records | Indefinitely while the phone number remains in our suppression list, to honour unsubscribe requests |
When retention periods expire, we delete or anonymise data unless a longer period is required by law.
8. End-customer data — controller / processor roles
When you purchase from a Shopify merchant that uses Salesreach:
- The merchant decides why and how your data is used for marketing and messaging. The merchant is the data controller.
- Revotech OÜ (Salesreach) processes your phone number, order context, and message content on the merchant's instructions to deliver the messaging service. We are a data processor.
To exercise your GDPR rights regarding messaging data, you may contact the merchant directly (they are your primary contact as controller). You may also contact us at support@salesreach.net and we will forward your request to the relevant merchant or assist as required by law.
9. Cookies and similar technologies
The Salesreach marketing website uses strictly necessary cookies and similar technologies required for hosting, security, and basic site operation. These do not require consent under the ePrivacy Directive because they are essential to provide the service you request.
If we add analytics (e.g. Vercel Analytics) or marketing cookies in the future, we will update this policy and implement a consent mechanism before collecting non-essential data.
You can control cookies through your browser settings. Disabling essential cookies may affect site functionality.
10. Your rights under the GDPR
If you are in the European Economic Area (EEA) or UK, you have the following rights regarding personal data we control:
| Right | What it means |
|---|---|
| Access (Art. 15) | Request a copy of the personal data we hold about you |
| Rectification (Art. 16) | Ask us to correct inaccurate data |
| Erasure (Art. 17) | Ask us to delete your data in certain circumstances |
| Restriction (Art. 18) | Ask us to limit how we use your data |
| Data portability (Art. 20) | Receive data you provided in a structured, machine-readable format |
| Objection (Art. 21) | Object to processing based on legitimate interests (including contact-form follow-up) |
| Withdraw consent (Art. 7(3)) | Where processing is based on consent, withdraw it at any time without affecting prior lawful processing |
To exercise any of these rights, email support@salesreach.net. We will respond within one month, extendable by two further months for complex requests as permitted by the GDPR.
We may need to verify your identity before fulfilling a request. There is no fee unless your request is manifestly unfounded or excessive.
Right to lodge a complaint
If you believe we have not handled your personal data properly, you have the right to lodge a complaint with the Estonian Data Protection Inspectorate:
Andmekaitse Inspektsioon (AKI)
Tatari 39, 10134 Tallinn, Estonia
Website: https://www.aki.ee/en
Email: info@aki.ee
You may also complain to the supervisory authority in your country of residence or habitual residence.
11. Security
We implement appropriate technical and organisational measures to protect personal data, including:
- Encryption in transit (HTTPS/TLS) for all web traffic
- Access controls limiting staff access to personal data on a need-to-know basis
- Hashed credentials and environment-variable secrets for production systems
- Processor due diligence and data-processing agreements with sub-processors
No method of transmission or storage is completely secure. If you believe your interaction with us has been compromised, contact us immediately.
12. Children
Salesreach is a B2B service directed at Shopify merchants. Our marketing website and messaging service are not directed at children under 16. We do not knowingly collect personal data from children. If you believe a child has provided us data, contact us and we will delete it.
13. Changes to this policy
We may update this Privacy Policy from time to time. When we make material changes, we will update the "Last updated" date at the top and, where appropriate, provide additional notice on our website. Continued use of the website after changes constitutes acknowledgment of the updated policy.
For end-customers receiving messages, material changes affecting messaging practices will be communicated through the merchant or via an updated policy link where required by law.
14. Contact us
For any questions about this Privacy Policy or our data practices:
Revotech OÜ
Ahaste tee 4, Ahaste küla, 88306 Pärnu linn, Pärnu maakond, Estonia
Privacy & support: support@salesreach.net
Sales: sales@salesreach.net