How Relvino collects, uses, and protects personal information
Relvino, formerly doing business as "RubyPoints"
Effective Date: June 1, 2026 | Version: 1.1 | Last Updated: October 2, 2026
This Privacy Policy explains how Relvino, the DBA for RubyPoints Corp, a Delaware corporation (“Relvino,” “we,” “us”), collects, uses, discloses, and protects personal information in connection with the Relvino consumer app, browser extension, websites, pixels, and related services (the “Service”). It applies both to shoppers who use our consumer products and to personal information we process through pixels and plugins on participating retailers’ websites.
Two roles. For our consumer app and rewards program, Relvino generally acts as a controller (or “business”) that decides how personal information is used. When we process shopper data on behalf of a retailer through that retailer’s pixel or integration, we generally act as a processor / service provider under that retailer’s instructions and our Data Processing Agreement. This Policy focuses on our controller activities; processor activities are governed primarily by the relevant retailer’s privacy notice and our DPA.
We work with both anonymous and identified traffic. Depending on how you interact with the Service, we collect the following categories:
When you use the Service or the extension, we and our service providers may collect technical details such as IP address, device and browser type, operating system, and approximate geolocation derived from IP address, and we use cookies and similar technologies (see Section 8).
We do not intentionally collect “sensitive personal information” as defined under the CPRA and similar U.S. state laws (for example, precise geolocation, government ID numbers, racial or ethnic origin, religious beliefs, health data, or contents of consumer communications where Relvino is not the intended recipient), except to the limited extent coarse location (city, state, ZIP) or similar fields are described above. We do not use or disclose sensitive personal information for purposes that require a right to limit under the CPRA, other than as reasonably necessary to provide the Service you request. If our practices change, we will update this Policy and provide any required notice or choice.
We use personal information to:
Where the EU or UK GDPR applies, we rely on these legal bases: performance of a contract (operating your account and Rewards); your consent (marketing email/SMS and certain cookies), which you may withdraw at any time; our legitimate interests (securing and improving the Service, attribution and measurement, and fraud prevention), balanced against your rights; and compliance with legal obligations.
We use automated processing, including AI, in parts of the decisioning and content pipeline — specifically to select the channel and send timing, rank templates, and generate message content such as subject lines and body copy.
Personal contact information (email, phone, name, address) is never sent to our AI models. The AI operates only on behavioral and transactional context — browsing activity, order history, derived segments, and coarse location (city, state, ZIP code). This lets the AI optimize messaging without access to identifying contact details.
Additional safeguards include:
These processes do not produce legal or similarly significant effects about you. Where you have a right to object to automated decision-making or to request human review, you may contact us as described in Section 14.
We do not sell personal information. We share information only as follows:
“Sale” and “sharing.” We do not sell personal information, and we do not share it for cross-context behavioral advertising, as those terms are defined under U.S. state privacy laws. When we process shopper data for a retailer, we act as that retailer’s service provider and use it only to provide our services to that retailer. We may use information that has been de-identified or aggregated, so that it cannot reasonably be linked to any individual, to improve our services. If our practices change, we will update this Policy and provide any required notice and opt-out choices.
We protect personal information using administrative, technical, and physical safeguards, including:
No system is perfectly secure, and we cannot guarantee absolute security. If your data is hosted or processed outside your country (including in the United States), we use appropriate safeguards for cross-border transfers, such as the EU Standard Contractual Clauses where required.
We and our providers use cookies, the browser extension, pixels, and similar technologies to operate the Service, recognize returning shoppers, attribute activity, and measure performance. You can manage cookies through your browser settings and can disable or uninstall the extension at any time. Some features may not function without them. Where required, we obtain consent for non-essential cookies.
Depending on your state of residence (for example, under the California Consumer Privacy Act as amended by the CPRA, and comparable laws in states such as Virginia, Colorado, Connecticut, Texas, and others), you may have the right to:
To exercise these rights, use the controls in your account or the unsubscribe/STOP mechanisms for communications, or contact us as described in Section 14. We will verify your request and may ask for information to confirm your identity. You may use an authorized agent where the law permits. We will respond to verifiable consumer requests within 45 days (with possible extensions as permitted by law). If we deny a request, and your state law provides an appeal right, you may appeal by emailing privacy@relvino.com with the subject line “Privacy Request Appeal,” and we will inform you in writing of the outcome within the time required by applicable law.
If you are in the EEA or UK, you may have rights to access, rectify, erase, restrict, or object to processing, to data portability, and to withdraw consent. To exercise these rights, contact us as described in Section 14. Where Relvino acts as a processor for a retailer, please direct requests to that retailer; we will assist them as required. You may also lodge a complaint with your supervisory authority.
We retain personal information only as long as needed for the purposes described here, then delete or de-identify it under our Data Retention Policy, which applies an automatic hot-to-cold storage model:
See the retention schedule table below for current periods. Criteria for retention include last activity, legal/compliance needs (including suppression and consent records), and the operational usefulness of the data type.
Deletion and redaction. We process deletion and redaction events (including GDPR webhooks from commerce platforms such as Shopify). On a Delete event, the shopper record is marked deleted and all future messaging is blocked. On a Redact event, contact fields (email, phone) are cleared, the record is marked redacted, and all future messaging is blocked. Once a record is marked deleted or redacted, we treat it as permanently ineligible for any outbound messaging.
The Service is not directed to children under 13, and we do not knowingly collect personal information from children under 13 (COPPA). We also do not knowingly “sell” or “share” personal information of consumers under 16. If you believe a child has provided us information, contact us and we will delete it.
We may update this Policy from time to time. We will post the updated version with a new “Last Updated” date and, for material changes, notify you by email or through a prominent notice within the Service before the changes take effect.
For privacy questions or to exercise your rights, contact us at: