Privacy Policy

Last updated: October 2, 2026

How Relvino collects, uses, and protects personal information

Relvino, formerly doing business as "RubyPoints"

Effective Date: June 1, 2026 | Version: 1.1 | Last Updated: October 2, 2026

This Privacy Policy explains how Relvino, the DBA for RubyPoints Corp, a Delaware corporation (“Relvino,” “we,” “us”), collects, uses, discloses, and protects personal information in connection with the Relvino consumer app, browser extension, websites, pixels, and related services (the “Service”). It applies both to shoppers who use our consumer products and to personal information we process through pixels and plugins on participating retailers’ websites.

Two roles. For our consumer app and rewards program, Relvino generally acts as a controller (or “business”) that decides how personal information is used. When we process shopper data on behalf of a retailer through that retailer’s pixel or integration, we generally act as a processor / service provider under that retailer’s instructions and our Data Processing Agreement. This Policy focuses on our controller activities; processor activities are governed primarily by the relevant retailer’s privacy notice and our DPA.

1. Information We Collect

We work with both anonymous and identified traffic. Depending on how you interact with the Service, we collect the following categories:

1.1 Identifiers

  • Pseudonymous identifiers — an anonymous shopper or device ID used to correlate events and attribute activity, and, where available, a commerce-platform customer ID (for example, a Shopify customer ID).
  • Contact information — email address and/or mobile phone number, used only where you are eligible to receive messages.

1.2 Profile and Account Information

  • Profile attributes — first and last name and general location (city, state, ZIP code) used for personalization and localization when available.
  • Consent and account state — your marketing consent per channel (email/SMS), suppression flags (such as “do not contact”), and account status (active, deleted, or redacted).

1.3 Activity and Commerce Information

  • Behavioral and transactional data — page views, product views, cart activity, and checkout events, used for attribution and measurement.
  • Derived attributes — segments we infer for personalization, such as customer-value tier or engagement level (for example, “high-value returning customer”).

1.4 Technical Information

When you use the Service or the extension, we and our service providers may collect technical details such as IP address, device and browser type, operating system, and approximate geolocation derived from IP address, and we use cookies and similar technologies (see Section 8).

1.5 Sensitive Personal Information

We do not intentionally collect “sensitive personal information” as defined under the CPRA and similar U.S. state laws (for example, precise geolocation, government ID numbers, racial or ethnic origin, religious beliefs, health data, or contents of consumer communications where Relvino is not the intended recipient), except to the limited extent coarse location (city, state, ZIP) or similar fields are described above. We do not use or disclose sensitive personal information for purposes that require a right to limit under the CPRA, other than as reasonably necessary to provide the Service you request. If our practices change, we will update this Policy and provide any required notice or choice.

2. How We Collect Information

  • Directly from you — when you create an account, install the extension, or provide your email or phone number and consent preferences.
  • Automatically — through our app, browser extension, and pixels as you browse and shop at participating retailers.
  • From retailers and commerce platforms — including verified webhooks from platforms such as Shopify. Inbound webhooks are signature-verified before processing and spoofed or tampered requests are rejected.

3. How We Use Information

We use personal information to:

  • Operate the rewards and discount program, including attributing qualifying activity and calculating Rewards;
  • Decide if, when, and what to communicate to you — selecting the channel and timing, ranking message templates, and generating message content based on brand guidelines and shopper context;
  • Personalize and localize content using profile attributes (inserted through placeholders, as described in Section 5);
  • Send transactional and — with your consent — marketing communications by email and SMS;
  • Measure performance and attribution (opens, clicks, conversions) and improve the Service;
  • Maintain security, prevent fraud and abuse, and enforce our Terms; and
  • Comply with legal obligations, including consent, suppression, and messaging-law requirements.

4. Legal Bases for Processing (EEA/UK)

Where the EU or UK GDPR applies, we rely on these legal bases: performance of a contract (operating your account and Rewards); your consent (marketing email/SMS and certain cookies), which you may withdraw at any time; our legitimate interests (securing and improving the Service, attribution and measurement, and fraud prevention), balanced against your rights; and compliance with legal obligations.

5. Automated Decision-Making and AI Safeguards

We use automated processing, including AI, in parts of the decisioning and content pipeline — specifically to select the channel and send timing, rank templates, and generate message content such as subject lines and body copy.

Personal contact information (email, phone, name, address) is never sent to our AI models. The AI operates only on behavioral and transactional context — browsing activity, order history, derived segments, and coarse location (city, state, ZIP code). This lets the AI optimize messaging without access to identifying contact details.

Additional safeguards include:

  • AI outputs follow a strict format and are validated and sanitized before use, including URL and HTML safety checks;
  • Personalization uses placeholders (for example, {{first_name}}) rather than embedding real names in AI-generated content, and a safety layer detects and corrects any hard-coded names that could indicate cross-recipient mix-ups; and
  • Logging and monitoring redact contact PII (emails and phone numbers) before any AI input or output is stored.

These processes do not produce legal or similarly significant effects about you. Where you have a right to object to automated decision-making or to request human review, you may contact us as described in Section 14.

6. How We Share Information

We do not sell personal information. We share information only as follows:

  • Retailers. With participating retailers in connection with attribution, Rewards, and — where we act as their processor — under their instructions.
  • Service providers / processors. With vendors that help us operate the Service, such as cloud hosting, and email and SMS delivery partners, who are bound by contract to protect the data and use it only to provide their services.
  • Compliance and safety. When required by law, to respond to legal process, or to protect the rights, safety, and security of Relvino, our users, and the public.
  • Business transfers. In connection with a merger, acquisition, financing, or sale of assets, subject to this Policy.
  • Categories disclosed for a business purpose. In the preceding 12 months we may have disclosed the categories in Section 1 (identifiers; profile/account information; activity and commerce information; and technical information) to the categories of recipients listed above for the business purposes described in Sections 3 and 6.

“Sale” and “sharing.” We do not sell personal information, and we do not share it for cross-context behavioral advertising, as those terms are defined under U.S. state privacy laws. When we process shopper data for a retailer, we act as that retailer’s service provider and use it only to provide our services to that retailer. We may use information that has been de-identified or aggregated, so that it cannot reasonably be linked to any individual, to improve our services. If our practices change, we will update this Policy and provide any required notice and opt-out choices.

7. Data Storage, Security, and Transfers

We protect personal information using administrative, technical, and physical safeguards, including:

  • Encryption. The subscriber database (identity, contact information, consent state, suppression flags, account status), the outbound message queue, and dispatch logs are encrypted at rest. All data moving between Relvino, commerce platforms, and delivery partners is encrypted in transit using TLS.
  • Consent-first delivery. Our systems default to “no consent = no send.” Before any scheduled message is sent, the dispatch layer re-checks consent, suppression, and account status, and blocks messages to recipients who have opted out, been suppressed, or are no longer active.
  • Access controls. Production systems use role-based access controls; access to shopper PII is restricted to authorized personnel and subject to audit logging.
  • Secrets management. Credentials for external services (API keys, webhook secrets, delivery-partner tokens) are kept in a dedicated secrets manager and are never stored in our codebase.

No system is perfectly secure, and we cannot guarantee absolute security. If your data is hosted or processed outside your country (including in the United States), we use appropriate safeguards for cross-border transfers, such as the EU Standard Contractual Clauses where required.

8. Cookies and Similar Technologies

We and our providers use cookies, the browser extension, pixels, and similar technologies to operate the Service, recognize returning shoppers, attribute activity, and measure performance. You can manage cookies through your browser settings and can disable or uninstall the extension at any time. Some features may not function without them. Where required, we obtain consent for non-essential cookies.

9. Your U.S. State Privacy Rights

Depending on your state of residence (for example, under the California Consumer Privacy Act as amended by the CPRA, and comparable laws in states such as Virginia, Colorado, Connecticut, Texas, and others), you may have the right to:

  • Know and access the categories and specific pieces of personal information we have collected;
  • Correct inaccurate personal information;
  • Delete personal information, subject to exceptions;
  • Opt out of “sale” or “sharing” / targeted advertising and of certain profiling;
  • Not be discriminated against for exercising your rights;
  • Limit the use and disclosure of sensitive personal information, where that right applies; and
  • Appeal our decision if we deny your request, where your state law provides an appeal right (for example, Virginia, Colorado, Connecticut, Texas, and similar laws).

To exercise these rights, use the controls in your account or the unsubscribe/STOP mechanisms for communications, or contact us as described in Section 14. We will verify your request and may ask for information to confirm your identity. You may use an authorized agent where the law permits. We will respond to verifiable consumer requests within 45 days (with possible extensions as permitted by law). If we deny a request, and your state law provides an appeal right, you may appeal by emailing privacy@relvino.com with the subject line “Privacy Request Appeal,” and we will inform you in writing of the outcome within the time required by applicable law.

10. Your EEA/UK Rights

If you are in the EEA or UK, you may have rights to access, rectify, erase, restrict, or object to processing, to data portability, and to withdraw consent. To exercise these rights, contact us as described in Section 14. Where Relvino acts as a processor for a retailer, please direct requests to that retailer; we will assist them as required. You may also lodge a complaint with your supervisory authority.

11. Data Retention

We retain personal information only as long as needed for the purposes described here, then delete or de-identify it under our Data Retention Policy, which applies an automatic hot-to-cold storage model:

See the retention schedule table below for current periods. Criteria for retention include last activity, legal/compliance needs (including suppression and consent records), and the operational usefulness of the data type.

  • Subscriber records (identity, contact, consent, suppression, status): 2 years from last activity; inactive subscribers are automatically removed after the window expires
  • Message queue (scheduled outbound messages): 90 days
  • Dispatch logs (send attempts, delivery outcomes, engagement events): 180 days
  • Behavioral and transactional data described in Section 1.3 (page views, cart activity, derived segments): 180 days

Deletion and redaction. We process deletion and redaction events (including GDPR webhooks from commerce platforms such as Shopify). On a Delete event, the shopper record is marked deleted and all future messaging is blocked. On a Redact event, contact fields (email, phone) are cleared, the record is marked redacted, and all future messaging is blocked. Once a record is marked deleted or redacted, we treat it as permanently ineligible for any outbound messaging.

12. Children’s Privacy

The Service is not directed to children under 13, and we do not knowingly collect personal information from children under 13 (COPPA). We also do not knowingly “sell” or “share” personal information of consumers under 16. If you believe a child has provided us information, contact us and we will delete it.

13. Changes to This Policy

We may update this Policy from time to time. We will post the updated version with a new “Last Updated” date and, for material changes, notify you by email or through a prominent notice within the Service before the changes take effect.

14. Contact Us

For privacy questions or to exercise your rights, contact us at:

  • Email: privacy@relvino.com
  • Mail: Relvino, the DBA for RubyPoints Corp, a Delaware corporation, 23807 Aliso Creek Rd, Suite 100, Laguna Niguel, California 92677