Privacy Policy
Effective August 28, 2026
This Privacy Policy explains how Relvato Inc ("Relvato", "we", "us") collects, uses, shares and protects personal data when you use the Relvato website, dashboard, WordPress plugin and related services (together, the "Service"). By using the Service you agree to this Policy.
Information we collect
Account information — your name and email address, and organization details, handled through our authentication provider when you sign up.
Sites and verification data — the sites you connect, your check (“journey”) configuration, and the results of the checks we run: pass/fail status, timings, error messages, and screenshots or page-structure snapshots captured during a check. For checks you enable on a WordPress or WooCommerce site, our plugin also reports your installed plugin and theme names and versions and store settings (for example checkout type and currency) — only for the checks you turn on. Relvato never handles a real customer's password: authenticated checks use a dedicated verification user whose credential is short-lived and rotated by the plugin.
Real-user performance data — if you enable the Real-user Web Vitals (RUM) beacon, we collect anonymous, cookieless performance timings from your site's visitors (such as loading and responsiveness metrics). This data carries no page URLs and no personal data, and is sampled (roughly 15% of page views).
Payment information — if you subscribe to a paid plan, payments are processed by our payment provider. We do not store your full card details.
Usage and technical data — logs, IP address, browser and device information, collected to operate and secure the Service.
How we use information
To provide and operate the Service — run your checks, show results, and send alerts when something fails.
To manage your account and process billing.
To secure the Service, prevent abuse, and debug problems.
To improve the Service and develop new features.
To communicate with you about the Service, including important service or security notices.
Legal bases (EEA/UK)
Where the GDPR or UK GDPR applies, we process personal data on these legal bases: performance of our contract with you; our legitimate interests in operating, securing and improving the Service; your consent (where required, for example optional communications); and compliance with legal obligations.
Sharing and sub-processors
We do not sell your personal data. We share it with third-party service providers (“sub-processors”) who help us run the Service — hosting, storage, authentication, payments, and AI features. Our current sub-processors, their purpose and their data location are listed at /trust, which we keep up to date.
We may also disclose information if required by law, to protect our rights or users' safety, or in connection with a merger or acquisition (with notice where required).
Where your data is processed
Relvato runs its compute in the European Union, while some data is stored in the United States. Where personal data is transferred internationally, we rely on appropriate safeguards such as the European Commission's Standard Contractual Clauses. See the data-location details for each provider on our sub-processors page.
Data retention
We keep account and configuration data for as long as your account is active and as needed to provide the Service. Check artifacts such as per-run screenshots are pruned over time. We may retain limited data as required for legal, accounting or security purposes. You can ask us to delete your data as described below.
Your rights
Depending on where you live, you may have rights to access, correct, delete, port, or restrict the processing of your personal data, and to object to certain processing. If you are in California, you have rights under the CCPA/CPRA, including to know and to delete, and we do not sell or share personal data as those terms are defined there.
To exercise any right, contact us at contact@relvato.com. We will respond within the timeframe required by applicable law. You may also lodge a complaint with your local data protection authority.
Security
We use technical and organizational measures to protect personal data, including encryption in transit and at rest, managed encryption keys, access controls, and the principle of least privilege. No method of transmission or storage is completely secure, but we work to protect your data and to respond promptly to incidents.
Cookies
We use only the cookies necessary to run the dashboard, such as keeping you signed in. The optional Real-user Web Vitals beacon is cookieless and stores nothing on your visitors' devices.
Children
The Service is not directed to children and is not intended for anyone under 16. We do not knowingly collect personal data from children.
Changes to this Policy
We may update this Policy from time to time. We will post the updated version here and update the effective date; material changes will be communicated where appropriate.
Contact
Relvato Inc is the controller of the personal data described here. For any privacy question or request, contact us at contact@relvato.com.