Effective and last updated: 3 September 2026
The short version
- ReviGo keeps the business and order information needed to provide and support the service.
- Redirect analytics exclude raw IP addresses, raw browser strings, destination URLs, and public card tokens.
- An enabled review gateway temporarily records the selected rating and resulting journey state.
- ReviGo does not sell personal information or use advertising trackers on the public website.
- People can ask about access, correction, deletion, or another applicable privacy right.
1. Who is responsible
- Responsible service provider
- ReviGo Limited Liability Company, trading as ReviGo
- Address
- Libya. The full service address is stated on each quote, order confirmation, or invoice.
- Privacy contact
- hello@revigo.ly
ReviGo is responsible for information in its customer, order, payment, support, security, and redirect systems. A Customer and a third-party destination platform remain independently responsible for information they collect or publish through their own systems.
2. Who this notice covers
This notice covers:
- business owners, contacts, branch staff, and authorized representatives;
- people who enquire, order, pay, request support, or communicate with ReviGo;
- people who tap or scan a ReviGo product; and
- people connected to suspected misuse or a security event.
ReviGo is designed for businesses and general customers, not for children to create accounts or provide personal information. A person under the legal age to contract should not place an order without an authorized adult or business representative.
3. Business and contact information
ReviGo may process:
- business name, type, city, branch name, and branch address;
- contact name, role, phone number, email, and preferred contact channel;
- authorized-contact status and records of confirmed instructions;
- notes voluntarily provided for delivery, design, setup, or support; and
- communication dates and relevant message content.
This information normally comes from the Customer or its representative. It may also come from a branch contact, delivery provider, payment record, or public business information when reasonably needed to verify the order.
4. Orders, cards, subscriptions, and payments
ReviGo may keep:
- quotes, accepted order details, quantities, designs, costs, prices, and delivery status;
- internal place, branch, card, route, destination, QR, and replacement records;
- service period, expiry, renewal cycle, subscription status, and reminder history;
- amounts paid, payment method category, payment date, receipt number, and balance status; and
- refund, credit, repair, replacement, dispute, and cancellation records.
ReviGo does not need to store a full bank-card number in its customer management system. A bank, wallet, or other payment provider handles information required by its own payment method and privacy terms.
4.1 Customer Telegram access
When a business representative activates the ReviGo customer bot, ReviGo may keep the Telegram user ID, available username and profile names, the name entered during onboarding, assigned business and branches, access role, activation grant, join and last-seen times, access status, and the version and time of legal acceptance. Telegram processes the underlying account and messages under its own terms.
This information authenticates the representative, limits them to authorized business records, supports revocation and seat capacity, provides requested service information, and creates security and accountability records.
5. Website enquiries
The public website does not require an account. Information typed into an order or contact experience is prepared in the browser for the visitor to send through the selected contact channel. ReviGo receives it only when the visitor chooses to send it.
WhatsApp, email, telephone, and other communication providers process information under their own terms. Do not send passwords, full payment-card details, public card tokens, or unrelated sensitive information.
6. NFC and QR redirect events
When somebody requests a ReviGo route, the server must process ordinary network information long enough to validate and answer the request. A privacy-minimized event may then record:
- event time and internal link or physical-card references;
- whether the request used NFC, QR, or another supported route type;
- whether the route redirected or was unavailable;
- a broad device class: mobile, tablet, desktop, bot, prefetch, or unknown;
- automated-traffic and link-preview classification flags; and
- a rotating one-way visitor bucket for approximate unique counts and abnormal-traffic detection.
The visitor bucket is derived from the request's network address using a secret cryptographic process and a rotating time period. The raw address is not written into the redirect analytics event, and the bucket is not designed to reveal the original address or identify a named person.
7. Information excluded from redirect analytics
The redirect analytics boundary is designed not to retain the raw IP address, full raw browser user-agent, full requested URL, business alias, destination URL, or public card token. ReviGo does not receive the text, rating, profile, account identity, or other content a visitor submits after reaching a third-party destination.
7.1 Review gateway and announcement information
If a Customer enables the ReviGo review gateway, ReviGo creates a short-lived session associated with the relevant business route. It may contain an internal session identifier, business and route references, selected rating, configured journey, resulting outcome, whether the destination was opened, and creation, update, and expiry times. The active session is designed to expire after approximately twenty minutes.
ReviGo may retain separate funnel events showing that the gateway was viewed, a rating was submitted, a recovery journey completed, or a destination was opened. These events can include the rating, outcome, event time, internal card or link reference, and privacy-minimized visitor bucket. ReviGo does not currently request free-text feedback, a name, phone number, or email address from an ordinary gateway visitor.
A gateway may display an announcement or promotion supplied by the business. ReviGo does not use the visitor bucket to build a named advertising profile, sell audiences, or disclose one business's visitor information to another business. If campaign-click measurement is introduced, this notice and the applicable customer-facing information must be updated before collection.
8. Security and audit information
ReviGo may keep limited information about:
- invalid, malformed, or repeated route attempts using privacy-safe fingerprints;
- administrator authentication, sensitive changes, and audit events;
- service errors, delivery failures, health checks, and security alerts; and
- evidence reasonably needed to investigate misuse, protect systems, or resolve a dispute.
Security records are not used to identify ordinary card visitors for marketing.
9. Why ReviGo processes information
Depending on the context, ReviGo uses information to:
- prepare, form, perform, and document an order or service agreement;
- produce, program, deliver, activate, renew, repair, replace, or support a product;
- authenticate instructions and maintain accurate customer and financial records;
- measure route use and provide aggregate operational analytics;
- detect abuse, protect credentials, investigate incidents, and defend legal rights;
- meet accounting, tax, court, regulatory, or other applicable legal duties;
- respond to an enquiry or privacy request; and
- send service, expiry, renewal, safety, or incident communications.
ReviGo relies on the agreement, requested pre-contract steps, consent where required, applicable legal duties, and proportionate operational or security needs where permitted. ReviGo will seek a new permission before using personal information for an unrelated purpose that requires consent.
10. Processing methods and locations
Information may be collected through electronic messages, the Telegram administration interface, ReviGo servers, database records, payment or delivery confirmations, support interactions, and automatic redirect security processes.
ReviGo uses cloud database, hosting, domain, communication, and security systems selected for the service. These systems may process information in Libya or in another country. When information must be transferred outside Libya, ReviGo considers the data's nature, purpose, duration, destination country, applicable protections, provider controls, and technical security measures.
11. Who may receive information
Information may be disclosed only as reasonably needed to:
- authorized ReviGo personnel and service operators;
- hosting, database, domain, messaging, payment, delivery, backup, and security providers;
- professional advisers working under confidentiality duties;
- the Customer and its verified authorized contacts for their own records;
- a competent authority, court, or investigator when lawfully required; or
- a successor in a properly managed sale, merger, or transfer subject to appropriate protection.
ReviGo does not sell personal information, rent contact lists, or disclose card-visitor information to data brokers.
12. Retention
ReviGo keeps each category only for as long as reasonably needed for the stated purpose, the customer relationship, security, accounting, dispute handling, backup recovery, and applicable law.
- Unsuccessful enquiries may be deleted when no longer useful for follow-up.
- Customer, order, payment, subscription, and receipt records may be retained for the relationship and the applicable accounting or legal period.
- Redirect events may be aggregated or deleted when detailed operational and security analysis is no longer required.
- Review gateway sessions expire automatically after their short operational window; associated funnel events may remain for aggregate reporting, abuse prevention, and dispute handling.
- Customer-bot memberships remain while access is active and may be retained after revocation where needed for security, audit, or dispute records.
- Security and audit evidence may be retained longer when an incident, claim, or legal duty justifies it.
- Backup copies may remain for a limited recovery cycle before being overwritten.
ReviGo periodically reviews retention and may anonymize or aggregate information instead of keeping identifiable detail.
13. Security
ReviGo uses measures appropriate to the information and risk, including access controls, restricted database roles, hashed public credentials, request validation, rate limits, audit records, privacy-minimized analytics, backups, and operational monitoring.
No connected service can promise absolute security. ReviGo investigates suspected incidents, limits access, rotates or disables affected credentials, restores service where possible, and provides legally required notice when an incident materially affects protected information.
14. Cookies and browser storage
ReviGo's public website currently does not use advertising trackers, behavioral advertising cookies, or public website customer-account cookies. The ordinary redirect response does not need client-side analytics scripts or a behavioral ReviGo tracking cookie.
When the review gateway is enabled, ReviGo uses a short-lived, essential, secure session cookie so the rating journey cannot be separated from its validated route. It is used for operation and security rather than cross-site advertising and expires with the gateway session.
Essential hosting and security systems still process ordinary request information needed to deliver and protect the website. A third-party destination or communication service may set its own cookies after the visitor chooses to open it. Its notice applies there.
15. Privacy choices and requests
Subject to identity verification and applicable law, a person may ask ReviGo to explain, access, correct, update, or delete personal information, withdraw a consent, or raise an objection. ReviGo may retain information needed for an active agreement, payment record, security investigation, legal obligation, or legal claim and will explain a refusal where appropriate.
A rotating visitor bucket is intentionally not connected to a named person, so ReviGo may be unable to locate a particular card visitor's event without collecting additional information that ReviGo otherwise does not need.
16. Updates and complaints
ReviGo reviews this notice when information use, technology, providers, or applicable requirements change. Material new uses will be communicated before they begin where required. A person should first contact ReviGo so the concern can be investigated, without affecting any right to contact a competent authority.
Questions
Talk to ReviGo
For policy questions, service concerns, or privacy requests, email hello@revigo.ly. Please include the business name and relevant order or card reference when available.
- Service provider
- ReviGo Limited Liability Company, trading as ReviGo
- Address
- Libya. The full service address is stated on each quote, order confirmation, or invoice.
- Phone
- +218919619666