Security
Data Processing Agreement
Last updated: August 5, 2026
This Data Processing Agreement (“DPA”) is a legally binding part of the RevCollect Terms of Service (“Terms”) and governs how RevCollect (“we,” “our,” or “us”) processes Personal Data on behalf of you (“you” or “your”) as our customer. By using the Services, you agree to this DPA.
02. Definitions
We collect various types of information in connection with the services we provide, including:
Personal Information: Such as your name, email address, phone number, and billing details.
Account Information: Details like your username, password, business details, and your preferences related to our services.
Usage Information: Data about how you interact with our website and platform, including IP addresses, device information, and browser types.
Third-Party Information: Information from third-party services that integrate with RevCollect, such as QuickBooks or other accounting systems you connect.
03. Scope and Roles
We collect various types of information in connection with the services we provide, including:
Personal Information: Such as your name, email address, phone number, and billing details.
Account Information: Details like your username, password, business details, and your preferences related to our services.
Usage Information: Data about how you interact with our website and platform, including IP addresses, device information, and browser types.
Third-Party Information: Information from third-party services that integrate with RevCollect, such as QuickBooks or other accounting systems you connect.
04. Term and Termination
We may share your information with third parties under the following circumstances:
Service Providers: We may share information with third-party vendors who perform services on our behalf, such as payment processing and data analysis.
Legal Requirements: We may disclose your information if required by law or in response to valid requests by public authorities.
Business Transfers: In the event of a merger, acquisition, or sale of all or a portion of our assets, your information may be transferred as part of that transaction.
05. Processing Instructions
We implement a range of security measures to protect your personal information from unauthorized access, use, or disclosure. These measures include encryption, secure access controls, and regular security reviews.
06. Processor Personnel
We implement a range of security measures to protect your personal information from unauthorized access, use, or disclosure. These measures include encryption, secure access controls, and regular security reviews.
07. Disclosure to Third Parties and Data Subject Rights
If you are located outside the country where RevCollect operates, please note that your data may be transferred to and processed in countries that may have different data protection laws. Where required by applicable law, we will implement appropriate safeguards to ensure your data is adequately protected.
08. Technical and Organizational Measures (TOMs)
Depending on applicable laws, you may have rights including:
Access: Request access to the personal data we hold about you.
Correction: Request corrections to inaccurate or incomplete data.
Deletion: Request deletion of your personal data, subject to certain conditions.
Opt-Out: Unsubscribe from marketing communications by following instructions in those messages or contacting us directly.
To exercise any of these rights, please contact us at the details below.
09. Assistance with Data Protection Impact Assessments
We implement a range of security measures to protect your personal information from unauthorized access, use, or disclosure. These measures include encryption, secure access controls, and regular security reviews.
10. Information Rights and Audit
We may update this Privacy Policy from time to time. When we make material changes, we will post the updated policy on our Site and update the effective date. Your continued use of the Site and Services after changes indicates your acceptance of the updated policy.
11. Personal Data Breach Notification
If you have any questions about this privacy policy or our privacy practices, please contact us at:
Email: admin@revcollect.ai
12. SUBPROCESSING
If you have any questions about this privacy policy or our privacy practices, please contact us at:
Email: admin@revcollect.ai
13. International Data Transfers
If you have any questions about this privacy policy or our privacy practices, please contact us at:
Email: admin@revcollect.ai
14. Deletion or Return of Personal Data
If you have any questions about this privacy policy or our privacy practices, please contact us at:
Email: admin@revcollect.ai
15. CCPA Undertaking (California Residents)
If you have any questions about this privacy policy or our privacy practices, please contact us at:
Email: admin@revcollect.ai
16. Miscellaneous
In case of conflict, this DPA overrides the Terms. SCCs override any conflicting part of this DPA.
Notices may be delivered via email to the contacts in Appendix I.
Amendments must be in writing and signed by both parties.
If any provision is invalid, the remainder remains in effect.
No fees are charged for fulfilling DPA obligations unless expressly stated.
17. Appendix II – Technical and Organisational Security Measures
We have implemented and shall maintain a security program in accordance with industry standards. We have implemented and will maintain appropriate TOMS to protect Customer Data from a Personal Data Breach. Reach out to us at admin@revcollect.ai for our security policy document.
18. Appendix III – List of Sub-processors
Customer authorizes RevCollect to engage the following Subprocessors:
| Entity Name | Nature and Purpose of Processing | Location of Processing |
|---|---|---|
| Supabase, Inc. | Database, authentication, and backend infrastructure | United States |
| Loops.so | Transactional and product email delivery | United States |
| GitHub, Inc. | Source code hosting and CI/CD | United States |
| Vercel, Inc. | Application hosting and edge delivery | United States |
| Google LLC | Website analytics (Google Analytics) and workspace email | United States |
| Cloudflare, Inc. | DNS, CDN, and network security | United States |
| Stripe, Inc. | Payment processing | United States |
| Functional Software, Inc. (Sentry) | Error monitoring and application observability | United States |
| Intuit Inc. (QuickBooks) | Accounting / invoicing integration (customer-connected) | United States |
| Xero Limited | Accounting / invoicing integration (customer-connected) | United States / New Zealand |
Customer may connect additional accounting, invoicing, or ERP systems of a similar nature; those connections are authorized to the extent needed to deliver the Services, and RevCollect will update this list when a new standing subprocessor or standard integration is added.
19. Appendix IV: UK SCCs
This UK SCCs shall stand included as an addendum to the EU SCCs set implemented under Clause 12.1 (a) of this DPA.
Part 1: Tables
For data transfers from the United Kingdom that are subject to the UK SCCs, the UK SCCs will be deemed entered into (and incorporated into this Data Processing Addendum by this reference) and completed as follows:
(a) In Table 1 of the UK SCCs, the Parties’ details and key contact information shall be as set forth in Schedule A.A.
(b) In Table 2 of the UK SCCs, information about the version of the Approved EU SCCs, modules and selected clauses which this UK SCC is appended to shall be as set forth in Clauses 11.1 and 12.1(a)(i), (ii), (iii), (iv) of this DPA.
(c) In Table 3 of the UK SCCs:
i Annex 1A: List of Parties: Parties are as set forth in Appendix I.A.
ii Annex 1B: Description of Transfer: Description of Transfer is as set forth in Appendix I.B.
iii Annex II: Technical and organisational measures including technical and organisational measures to ensure the security of the data: TOMs are as set forth in Appendix II.
iv Annex III: List of Sub processors: Sub processors are as set forth in Appendix I.B.
(d) In Table 4 of the UK SCCs, both the data importer and the data exporter may end the UK SCCs in accordance with the terms of the UK SCCs.
Part 2: Mandatory Clauses
Mandatory Clauses of the Approved Addendum, being the template Addendum B.1.0 issued by the ICO and laid before Parliament in accordance with s119A of the Data Protection Act 2018 on 2 February 2022, as it is revised under Section 18 of those Mandatory Clauses.