Privacy Policy

How RevuKit handles your data

Last updated: February 26, 2026

This Privacy Policy explains how RevuKit collects, uses, stores, and shares personal data when you use our website, dashboard, widgets, and related services.

Personal data we collect

  1. Account and identity data: email address, authentication identifiers, premium ID, and subscription status.
  2. Business integration data: business name, Google place ID, and connected domain metadata.
  3. Usage and technical data: page interactions, API events, browser/device information, IP-derived security signals, and abuse-prevention telemetry.
  4. Support data: messages and account requests sent to our support channels.
  5. Instagram Feed plugin data: public Instagram handles, profile URLs, feed IDs, public profile metadata, public post metadata, media URLs, sync timestamps, owner or subscription identifiers, and runtime request metadata needed to create, sync, validate, and render Instagram feeds in Framer.

Lawful bases (GDPR)

  1. Contract: providing widgets, account features, and paid subscription services you request.
  2. Legitimate interests: service security, fraud prevention, reliability, and product operations.
  3. Consent: optional analytics cookies and related analytics processing.
  4. Legal obligations: tax, accounting, and lawful requests.

Cookies and similar technologies

We use strictly necessary cookies/storage for sign-in, security, and core functionality. Optional analytics cookies are disabled by default and only enabled after consent. See the detailed register in our Cookie Policy.

For websites that embed RevuKit widgets, the site owner is responsible for obtaining any required visitor consent before loading third-party widgets or similar technologies in regulated regions.

Third-party review and social feed data

To render widgets for our customers, we process limited publicly available review profile data (for example reviewer name and avatar) from third-party platforms. We use this data only to provide the requested widget service and do not resell it.

For the RevuKit Instagram Feed plugin for Framer, users enter a public Instagram handle or profile URL. RevuKit uses that input to retrieve publicly available Instagram profile and post data, create a feed record, and keep the inserted Framer component updated after the Framer site is published. RevuKit does not ask for Instagram login credentials and does not access private Instagram accounts.

How we share data

We share data with subprocessors and providers only as needed to operate RevuKit, including payment processing, hosting, authentication, analytics (when consented), and anti-abuse services.

  1. Stripe (billing and subscription management).
  2. Google Firebase (authentication, database, storage, and analytics when consented).
  3. Google reCAPTCHA (security and abuse prevention).
  4. Vercel and related cloud infrastructure providers.
  5. Data retrieval providers, including Apify, for retrieving publicly available Instagram feed data requested by users.

We do not sell personal data.

Instagram Feed plugin runtime processing

Framer sites that use the RevuKit Instagram Feed component make runtime requests to RevuKit endpoints, including feed item and media proxy endpoints, so the published site can load the latest synced feed data rather than relying only on insertion-time data. These requests may include feed IDs, requested media URLs, site or embed origin metadata, IP- derived rate-limit signals, response status, and error details needed for security, abuse prevention, diagnostics, and service reliability.

International transfers

Where personal data is transferred outside your jurisdiction, we rely on appropriate safeguards such as contractual protections and equivalent transfer mechanisms where required.

Retention

We keep personal data only as long as necessary for service delivery, security, legal obligations, and dispute management. Typical retention includes temporary widget cache windows and account records tied to subscription and support history.

Instagram feed records and public feed snapshots are kept while the feed is active or needed to provide the requested widget service. Temporary logs, cache entries, and media proxy diagnostics are retained only as needed for security, troubleshooting, abuse prevention, and normal operational purposes.

Your privacy rights

Depending on your location, you may have rights to access, correct, delete, restrict, object to processing, and request portability of your personal data. You may also withdraw consent for optional analytics at any time.

Contact and complaints

Contact us at support@revukit.com for privacy requests. You may also lodge a complaint with your local data protection authority where applicable.