Privacy Policy
Last updated: 2026-10-05
This policy describes which personal data we process when operating RevReach (https://revreach.app), for what purposes and on what legal basis. It applies to the website, the Platform and our interfaces.
1. Controller
Luca Martini, Planeggerstraße 57c, 82110 Germering, Germany
Email: support@revreach.app, data protection: support@revreach.app
We are currently not required to appoint a data protection officer (section 38 of the German Federal Data Protection Act, BDSG). Please send any data protection enquiries to the address above.
2. Visiting the website and server logs
When you visit the website, our hosting provider processes technically necessary data: IP address, time, URL accessed, referrer, browser and operating system. This is necessary to deliver the website and to fend off attacks (Art. 6(1)(f) GDPR, legitimate interest in secure operation). Logs are deleted after 30 days at the latest unless they are needed to investigate a security incident.
3. Cookies and local storage
We only use strictly necessary cookies:
| Name | Purpose | Duration |
|---|---|---|
| sb-…-auth-token | Sign-in and session | until you sign out, at most for the duration of the session |
| yt_oauth | Protects the YouTube connection against forgery (CSRF) | 10 minutes |
| ansicht | Remembers whether you are viewing the website as a Creator or an App Provider (only after you click the toggle) | 1 year |
| sprache | Remembers the language you have chosen for the website (German or English), after you click the DE/EN switch or open an English address (/en/…) | 1 year |
| beta_zugang | Remembers that a valid invitation code for the closed beta was entered in this browser (only during a closed beta) | 90 days |
| signup_intent | Remembers your chosen role and the time of your consent while you sign up with Google or Apple | 15 minutes |
| sb-…-auth-token-code-verifier | Security value for signing in with Google or Apple (PKCE) | until sign-in is complete |
| social_oauth | Protects the TikTok and Instagram connections against forgery (CSRF) | 10 minutes |
This storage is permitted without consent because it is strictly necessary to provide the service you have expressly requested (section 25(2) no. 2 of the German Telecommunications Digital Services Data Protection Act, TDDDG). We do not use any analytics, advertising or tracking tools and do not embed any fonts or scripts from third parties.
4. Account
For an account, we process your email address, password (as a hash only), name, role, the time of your consent to the Terms of Service and your settings. The legal basis is the performance of the user agreement (Art. 6(1)(b) GDPR). Sign-in is handled by our database service provider (Supabase).
Language: Your settings include the language of your account (German or English). When you register, we take it from the language in which you are using the website, and we update it when you switch using the DE/EN switch. We use it to send you emails in that language and to generate Partnership Agreements in the appropriate language: in German if both sides use German, otherwise in English. The legal basis is the performance of the user agreement (Art. 6(1)(b) GDPR).
Signing in with Google or Apple: If you choose this option, you are redirected to Google (Google Ireland Ltd.) or Apple (Apple Distribution International Ltd., Ireland). Once you have given your approval, we receive your email address, your name, an identifier for your account and, in the case of Google, possibly a link to your profile picture. With Apple, you can choose an anonymous relay address instead of your email address. We only use this data to create your account and sign you in (Art. 6(1)(b) GDPR). The data that Google or Apple process themselves in this context is governed by their own privacy policies.
5. Data of App Providers
We process company and billing details, information about the app, public store data (name, icon, screenshots, rating from Apple's App Store interface) and the RevenueCat API key. The key is stored encrypted with AES-256-GCM and only used server-side to retrieve metrics (revenue, subscriptions, trials). Legal basis: Art. 6(1)(b) GDPR; for billing details, additionally Art. 6(1)(c) GDPR (tax obligations).
6. Data of Creators, channels and posts
For Creators, we process profile information (handle, description, topics, languages, country), your preferred terms (e.g. minimum revenue share, retainer, posts per month), which appear in your public profile and to App Providers, and the channels you add. You can add a channel in two ways:
- Add manually (all platforms): profile link, handle, followers and average views as stated by you. We display these figures as stated by the Creator. To check that the profile belongs to you, our team may view the public verification code in your profile description.
- Connect (YouTube, TikTok, Instagram): With your permission, we read the figures directly from the platform and update them daily. We do not post anything and do not read any private messages or any data about your viewers.
The purpose is to demonstrate your reach to App Providers and to provide evidence of the agreed posts. Legal basis: Art. 6(1)(b) GDPR. We store access and refresh tokens in encrypted form (AES-256-GCM). You can disconnect a channel at any time under “Channels”; we then revoke access, where the platform offers this, and delete the channel and post data retrieved via the interface. We delete data that we can no longer update after 30 days at the latest.
YouTube API Services
With your consent in Google's sign-in window (permission “youtube.readonly”), we read: channel ID, channel name, handle, profile picture, country, number of subscribers, views and videos, as well as the title, description, publication time, views, likes and comments of your latest videos and of the videos assigned to a partnership. When you connect, the YouTube Terms of Service and the Google Privacy Policy apply. You can also revoke access in your Google account settings.
TikTok
Via TikTok Login Kit and TikTok's Display API (for users in the EEA: TikTok Technology Limited, Ireland), we read, with the permissions “user.info.basic”, “user.info.profile”, “user.info.stats” and “video.list”: identifier, display name, username, profile picture and profile link, number of followers and videos, as well as your public videos with title, description, thumbnail, publication time, views, likes, comments and shares. TikTok's Privacy Policy applies. You can also revoke access in your TikTok account settings.
Via the Instagram API with Instagram Login (Meta Platforms Ireland Limited), we read, for business and creator accounts and with the permissions “instagram_business_basic” and “instagram_business_manage_insights”: account identifier, username, name, profile picture, number of followers and posts, your posts with caption, type, link, thumbnail, time, likes and comments, as well as views and shares of your latest posts and of the posts assigned to a partnership. Instagram's Privacy Policy applies. You can also revoke access in the Instagram settings under “Apps and websites”.
Posts per partnership
For each partnership, we store the posts that you add, import from a connected channel or that we recognise automatically from your code in the description: link, platform, title, thumbnail, publication date, metrics and your confirmation of the ad disclosure. The App Provider of the partnership can see this information. We also show how many code redemptions were counted in the seven days after a post (without reference to individual users). The purpose is to provide evidence of the contractual performance and to evaluate the partnership for both sides; legal basis: Art. 6(1)(b) GDPR.
7. Tax and reporting data (DAC7)
For payouts to Creators, we process name or company name, address, date of birth (for individuals), tax identification number, tax number, VAT identification number and, where applicable, commercial register number. As a platform operator, we are obliged under the German Platform Tax Transparency Act (PStTG) to report this data and the remuneration paid to the German Federal Central Tax Office (Bundeszentralamt für Steuern) once a year, which may exchange it with the tax authorities of your country of residence. Legal basis: Art. 6(1)(c) GDPR in conjunction with the PStTG. We retain the data for ten years after the end of the reporting period (section 22 PStTG).
8. Agreements, billing and messages
We store the Partnership Agreements between App Providers and Creators together with the acceptance log (time, IP address, browser) in order to be able to prove that the agreement was concluded (Art. 6(1)(b) and (f) GDPR). We store bookings, self-billing invoices and invoices for the performance of the contract and because of retention obligations under commercial and tax law (Art. 6(1)(c) GDPR, section 147 of the German Fiscal Code (AO), section 257 of the German Commercial Code (HGB)). We store messages between partners for as long as the partnership exists and delete them three years after it ends.
9. Payments via Stripe
App Providers' payment methods and Creators' payout accounts are captured directly by Stripe; we only see the type and the last digits. Stripe verifies the identity of Creators and prevents fraud. In doing so, Stripe partly acts as an independent controller; for details, see the Stripe Privacy Policy. Legal basis: Art. 6(1)(b) and (c) GDPR.
10. Data of app users (processing on behalf of App Providers)
When App Providers connect RevenueCat to RevReach, we receive pseudonymous customer IDs of the app users, the creator code entered and purchase data (product, price, currency, country, store, timestamps). We process this data on behalf of the respective App Provider, who is the controller, on the basis of our data processing agreement. Creators only see aggregated figures. We store purchase events without a creator code only as anonymous daily counters.
11. Emails
We send confirmation and notification emails (Art. 6(1)(b) GDPR). You can switch off notifications in the settings; emails relating to security and your account remain active. We do not send newsletters.
12. Reports and complaints
When you submit a report via the reporting form, we process your details in order to review the report and inform you of the outcome (Art. 6(1)(c) GDPR in conjunction with Art. 16 DSA). We delete them two years after the case has been closed.
13. Public code check
When an app checks a creator code with us, we briefly process the IP address in memory to limit misuse. It is not stored.
14. Recipients and processors
| Service provider | Purpose | Location and safeguards |
|---|---|---|
| Netlify, Inc. (USA) | Delivery of the website and execution of server functions | Delivery via servers distributed worldwide, server functions in the USA; transfers based on the standard contractual clauses in Netlify's data processing agreement |
| Supabase, Inc. (USA) | Database, sign-in and file storage | US region (Ohio); transfer based on the standard contractual clauses in Supabase's data processing agreement |
| Stripe Payments Europe, Ltd., 1 Grand Canal Street Lower, Grand Canal Dock, Dublin, D02 H210, Ireland | Payment processing, identity verification and payouts | EU; transfers to Stripe, Inc. (USA) based on the EU-US Data Privacy Framework and standard contractual clauses |
| Resend, Inc. (USA) | Sending notification emails | USA; standard contractual clauses |
| Google (YouTube API Services) | Retrieval of your channel and video figures after your approval | Google Ireland Ltd. / Google LLC, independent controller |
| Google (sign-in) | Sign-in with your Google account, if you choose this option | Google Ireland Ltd., independent controller |
| Apple (sign-in) | Sign-in with your Apple ID, if you choose this option | Apple Distribution International Ltd. (Ireland), independent controller |
| TikTok | Retrieval of your profile and video figures after your approval | TikTok Technology Ltd. (Ireland), independent controller |
| Meta (Instagram) | Retrieval of your profile and post figures after your approval | Meta Platforms Ireland Ltd., independent controller |
We have concluded agreements under Art. 28 GDPR with all processors. Transfers to third countries only take place on the basis of an adequacy decision (such as the EU-US Data Privacy Framework) or of standard contractual clauses adopted by the European Commission. Your contractual partners on the Platform receive the data required for the partnership (e.g. name and address in the agreement).
15. Storage period
We delete data as soon as it is no longer required for the purpose. We delete accounts without partnerships immediately on request. We delete cached posts from connected channels after 30 days, and metrics retrieved via interfaces that are no longer updated also after 30 days. We retain posts from a partnership until three years after it ends (limitation period, section 195 BGB). We retain booking and billing data for eight to ten years (section 147 AO, section 257 HGB) and reporting data under the PStTG for ten years. During this time, the data is restricted and used only to comply with these obligations.
16. Your rights
- Access (Art. 15 GDPR) and data portability (Art. 20 GDPR): you can download a complete export in the settings.
- Rectification (Art. 16), erasure (Art. 17) and restriction of processing (Art. 18 GDPR).
- Objection to processing based on legitimate interests (Art. 21 GDPR).
- Withdrawal of consent given, with effect for the future (Art. 7(3) GDPR), for example by disconnecting a connected channel.
- Complaint to a supervisory authority (Art. 77 GDPR), for example the authority responsible for us: Bayerisches Landesamt für Datenschutzaufsicht (BayLDA), Promenade 18, 91522 Ansbach, https://www.lda.bayern.de.
17. Obligation to provide data, automated decision-making
Without account and contract data, we cannot provide the Platform; without tax and reporting data, we are not permitted to pay out any remuneration. We do not make automated decisions within the meaning of Art. 22 GDPR. The attribution of purchases to Creators and the calculation of the revenue share follow fixed rules described in the agreement.
18. Security
Transmissions are TLS-encrypted. We additionally store secrets such as API keys and access tokens in encrypted form. Access to database rows is technically restricted to the respective authorised accounts; bookings are stored immutably.
19. Changes
We update this policy when our processing or the legal situation changes. The version published here applies.