Privacy Policy
Last updated: 26 August 2026
1.Who we are
Revealu (“we”) provides a service that shows website owners which organisations visit their website. This policy explains what data we process, why, and what rights you have. It covers both our own website/app and the tracking script our customers install on their websites.
2.Two roles: controller and processor
We process data in two distinct roles:
- Account data (of Revealu users): we are the data controller.
- Visitor data (of visitors to our customers' websites): the customer is the data controller and we act as processor on their behalf. Visitors with questions about tracking on a specific website should contact the owner of that website.
3.Account data we collect
- name and email address (to create and secure your account);
- password — stored only as a bcrypt hash, never in plain text;
- your organisation name and the websites you configure;
- optionally: your office address, if you enable distance-based sorting.
Legal basis: performance of the agreement (providing the Service). We do not sell account data and we do not use it for advertising.
4.Visitor data the tracker processes
When the tracking script runs on a customer's website, it processes:
- the visitor's IP address — used server-side to look up the organisation registered for that network. Each visit keeps a salted hash of the IP; the raw IP is currently retained for the duration of the service's development phase, so recognition improvements can be re-tested on past traffic. A fixed retention period will be set before general availability. Legal basis: our legitimate interest in accurate, improving company identification;
- technical context: pages viewed, referrer, browser and device type, screen size, language, time zone and country;
- a short-lived, daily-rotating fingerprint used to group pageviews into a visit (cookieless mode, the default) — nothing is stored on the visitor's device;
- optionally, if the website owner uses the identify function after e.g. a form submission: the company domain derived from a business email address. Only the domain is stored, never the address itself.
The purpose is company-level identification only. The Service is not designed to identify or profile individual natural persons, and consumer ISP networks are deliberately filtered out.
5.Our own business email (open and click tracking)
Revealu sends business email to organisations and places a tracking pixel and rewritten links in those messages. This is our own processing, for our own database — it is not a feature our customers use and it does not involve their data. When a recipient opens such a message or follows such a link, we process:
- the IP address the request came from, stored both as a salted hash and — for the duration of the service's development phase — in raw form;
- the user agent, the country and the time of the open or click, and which link was followed;
- the recipient's business email address and name, as used to send the message.
The purpose is company-level identification: only the domain part of the recipient's address is ever linked to the IP address, so that the network an organisation uses becomes known to us and later anonymous visitors from it can be recognised as that organisation. Requests we can attribute to a mail provider's image proxy, to a mail security scanner or to a datacenter are recorded but never used for identification.
For this processing Revealu is the controller — we choose the recipients and send the messages ourselves. Our legal basis is our legitimate interest in building an accurate company-recognition database (Art. 6(1)(f) GDPR). We note that the placing of a tracking pixel in email may additionally require consent under ePrivacy rules (in the Netherlands, Art. 11.7a Telecommunications Act); we assess this per campaign. You may object to this processing at any time via the contact details below, and an IP address registered on our opt-out page is not recorded here at all.
Every message we send carries an unsubscribe link, and the standard List-Unsubscribe header so your mail client can offer its own unsubscribe button. Using either stops all further messages from us to that address; we keep only the fact that the address unsubscribed, precisely so we cannot mail it again.
6.Where data is stored and who helps us
We use the following subprocessors to run the Service:
- Vercel (application hosting);
- Supabase (database hosting, EU region);
- IP intelligence providers (such as ipapi.is) and public registry services (RDAP/RIPE, reverse DNS, Dutch Chamber of Commerce and geocoding services) — these receive an IP address or company name solely to perform the lookup;
- an email delivery provider (Resend) or the customer’s own SMTP mail server, where email is sent through the Service.
Data is transmitted over encrypted connections (HTTPS/TLS).
7.Retention
- account data: for as long as your account exists; deleting the account deletes it;
- visitor analytics data: for as long as the customer's account and websites exist, or until the customer deletes it (leads can be deleted individually, including all underlying visits);
- IP-to-company cache entries: up to 30 days, after which they are refreshed.
- raw visitor IP addresses: currently for the duration of the service's development phase, to allow recognition improvements to be re-tested on past traffic; a fixed retention period will be set before general availability. The visit itself is kept for analytics either way;
- email opens and clicks, and the IP-to-domain pairs derived from them: under the same development-phase rule as raw visitor IP addresses. These pairs are what allows a recognition decision to be reviewed and corrected afterwards.
8.Your rights (GDPR)
You have the right to access, rectify, erase and receive the personal data we hold about you, to restrict or object to processing, and to withdraw consent where processing is based on consent. To exercise these rights, contact us (section 10). You also have the right to lodge a complaint with the Dutch supervisory authority, the Autoriteit Persoonsgegevens.
For visitor data on a customer's website, direct your request to that website's owner (the controller); we will assist them where required. You can also stop your network from being identified on any Revealu-enabled site via our opt-out page.
9.Changes
We may update this policy from time to time. The current version is always available on this page; the date above shows when it was last changed.
10.Contact
Privacy questions or requests? Reach the Revealu team via the contact option in your dashboard, or via the website owner who operates Revealu if you are a visitor of a customer's site. See also our Terms of Service and Disclaimer.
