Salesreach
TermsPrivacy

Privacy Policy

Last updated: 19 August 2026

1. Who we are

This Privacy Policy explains how Revotech OÜ ("Revotech", "we", "us", "our") processes personal data when you visit the Salesreach website, contact us about becoming a merchant partner, or receive messages through the Salesreach messaging service operated on behalf of a Shopify merchant.

Legal nameRevotech OÜ
Registry code17332344
Registered addressAhaste tee 4, Ahaste küla, 88306 Pärnu linn, Pärnu maakond, Estonia
Product / brandSalesreach
Privacy contactsupport@salesreach.net
Sales enquiriessales@salesreach.net

Revotech OÜ is the data controller for personal data collected through the Salesreach marketing website and for prospective merchant leads.

When we deliver WhatsApp or SMS messages on behalf of a Shopify merchant, we generally act as a data processor for that merchant's end-customer data. The merchant remains the data controller for its customers' personal data. Section 8 below describes that processing.

We have not appointed a Data Protection Officer (DPO). Under the GDPR, Revotech OÜ is not currently required to designate a DPO based on the nature and scale of our processing. For privacy enquiries, contact support@salesreach.net. For sales and partnership enquiries, contact sales@salesreach.net.

2. Scope of this policy

This policy applies to:

  1. Website visitors — anyone who browses the Salesreach marketing site or submits our contact form.
  2. Prospective merchant leads — businesses that enquire about partnering with Salesreach.
  3. End-customers of merchant clients — shoppers who opt in to receive WhatsApp or SMS messages from a merchant through Salesreach's messaging infrastructure (described in Section 8).

This policy does not govern third-party websites linked from our site (including merchant Shopify stores). Those sites are operated by their respective controllers and have their own privacy policies.

3. Personal data we collect

3.1 Marketing website and contact form

When you submit our "Get in contact" form, we collect:

  • Email address — so we can reply to your enquiry.
  • Phone number (including country dialling code) — so we can reach you about Salesreach.
  • Technical data — IP address, browser type, device information, and timestamps, collected automatically through our hosting infrastructure for security and abuse prevention.

We do not require you to create an account to use the marketing website.

3.2 Merchant onboarding (future)

If you become a Salesreach merchant partner, we will additionally collect business contact details, Shopify store information, billing details, and messaging configuration data necessary to operate the service. We will provide supplementary privacy information at onboarding where required.

3.3 End-customer messaging data (on behalf of merchants)

When a merchant uses Salesreach to message its customers, we process data the merchant provides or that is generated through the service, including:

  • Customer name and phone number
  • Order and cart information (e.g. products purchased, order numbers)
  • Messaging consent records (timestamp, opt-in method, opt-in text shown)
  • Message content sent and received (including replies such as STOP or HELP)
  • Delivery and read status metadata from messaging providers

We process this data only on the merchant's documented instructions and as described in our agreement with the merchant.

4. Why we use your data and our legal bases

Under the GDPR, we must have a lawful basis for each processing activity.

Processing activityPurposeLegal basis (GDPR Art. 6)
Contact form submissionsResponding to partnership and sales enquiries about SalesreachLegitimate interests (Art. 6(1)(f)) — pursuing business development for a B2B SaaS product. You may object (see Section 10). Enquiries are handled via sales@salesreach.net.
Security logs and bot mitigationProtecting the website and contact form from abuseLegitimate interests (Art. 6(1)(f)) — ensuring security and integrity of our systems
End-customer messagingDelivering opted-in WhatsApp/SMS messages on a merchant's behalfConsent (Art. 6(1)(a)) — collected by the merchant from the end-customer at checkout or equivalent opt-in point. The merchant is responsible for obtaining valid consent.
Merchant contract performanceOperating Salesreach for onboarded merchantsContract (Art. 6(1)(b)) — necessary to perform our agreement with the merchant
Legal complianceResponding to lawful requests; maintaining consent and opt-out records for telecom regulationsLegal obligation (Art. 6(1)(c)) and legitimate interests (Art. 6(1)(f))

We do not use contact-form data for automated decision-making or profiling that produces legal or similarly significant effects.

5. SMS and WhatsApp messaging disclosures

This section applies to end-customers who opt in to receive messages through a merchant's use of Salesreach.

Program name: Salesreach Messaging (delivered on behalf of the merchant whose store you interacted with)

Types of messages you may receive: Order confirmations and shipping updates; cart-abandonment reminders; post-purchase product recommendations and upsell offers related to products you viewed or purchased. Messages are sent over WhatsApp and/or SMS.

Message frequency: Message frequency varies by your interactions with the merchant. You may receive up to 4 messages per month, and sometimes fewer depending on your orders and cart activity.

Cost disclosure: Message and data rates may apply. Check with your mobile carrier for details about your plan.

Opt-out: Reply STOP (or UNSUBSCRIBE, CANCEL, END, or QUIT) to any SMS message to cancel future SMS messages from that merchant's program. Reply STOP in WhatsApp to unsubscribe from WhatsApp messages. You will receive a one-time confirmation that you have been unsubscribed. After opting out, you may still receive messages already in transit.

Help: Reply HELP (or INFO) to any message for assistance, or contact the merchant directly using the contact details on their store.

Consent: You opt in by checking an unchecked consent box at the merchant's Shopify checkout (or equivalent opt-in point shown by the merchant). Consent is not a condition of purchase unless the merchant explicitly states otherwise in compliance with applicable law.

AI-generated content: Some messages may be drafted by an AI assistant operating under a named persona (e.g. "Jake from [Brand]"). The first message in a new conversation identifies the sender as an AI shopping assistant for that merchant, in compliance with applicable automated-messaging disclosure laws.

Mobile data sharing — required disclosure

We do not share, sell, rent, or provide your mobile phone number, SMS opt-in data, WhatsApp opt-in data, or messaging consent records to third parties or affiliates for their own marketing or promotional purposes.

We share mobile and messaging data only with service providers that help us deliver the messaging service (such as Twilio and Meta/WhatsApp), under written data-processing agreements and solely to provide the service — not for those providers' independent marketing. See Section 6.

6. Who we share data with

We do not sell personal data.

We share personal data with the following categories of recipients, only as needed:

RecipientRoleData sharedLocation
Vercel, Inc.Website hosting and serverless infrastructureContact form data, technical logsUnited States / global CDN
Neon, Inc. (Vercel Postgres)Database hosting for lead storageContact form submissionsUnited States / EU (region-dependent)
Twilio, Inc.SMS and WhatsApp message deliveryPhone numbers, message content, delivery metadataUnited States
Meta Platforms, Inc.WhatsApp Business PlatformPhone numbers, message content, delivery metadataUnited States / Ireland
Professional advisersLegal, accounting, complianceAs necessaryEstonia / EU
AuthoritiesLaw enforcement or regulators, when legally requiredAs required by lawVaries

When we process end-customer data for a merchant, the merchant also has access to its own customers' data through the Salesreach service.

International transfers

Some of our service providers are located outside the European Economic Area (EEA), primarily in the United States. Where we transfer personal data outside the EEA, we rely on appropriate safeguards under GDPR Chapter V, including:

  • Standard Contractual Clauses (SCCs) approved by the European Commission, incorporated into our agreements with processors; and/or
  • Adequacy decisions where applicable (e.g. transfers to countries the European Commission has deemed adequate).

You may request a copy of the relevant safeguards by contacting us at support@salesreach.net.

7. How long we keep data

Data categoryRetention period
Contact form leads24 months from submission, unless a business relationship continues (then for the duration of the relationship plus 24 months)
Security and server logs90 days, unless needed for an active security investigation
End-customer messaging data (processor role)For the duration of the merchant's agreement with us, plus 5 years thereafter for consent and opt-out audit records (to meet telecom and GDPR accountability requirements; German-market merchants may require longer retention — we configure per merchant jurisdiction where applicable)
Opt-out / STOP recordsIndefinitely while the phone number remains in our suppression list, to honour unsubscribe requests

When retention periods expire, we delete or anonymise data unless a longer period is required by law.

8. End-customer data — controller / processor roles

When you purchase from a Shopify merchant that uses Salesreach:

  • The merchant decides why and how your data is used for marketing and messaging. The merchant is the data controller.
  • Revotech OÜ (Salesreach) processes your phone number, order context, and message content on the merchant's instructions to deliver the messaging service. We are a data processor.

To exercise your GDPR rights regarding messaging data, you may contact the merchant directly (they are your primary contact as controller). You may also contact us at support@salesreach.net and we will forward your request to the relevant merchant or assist as required by law.

9. Cookies and similar technologies

The Salesreach marketing website uses strictly necessary cookies and similar technologies required for hosting, security, and basic site operation. These do not require consent under the ePrivacy Directive because they are essential to provide the service you request.

If we add analytics (e.g. Vercel Analytics) or marketing cookies in the future, we will update this policy and implement a consent mechanism before collecting non-essential data.

You can control cookies through your browser settings. Disabling essential cookies may affect site functionality.

10. Your rights under the GDPR

If you are in the European Economic Area (EEA) or UK, you have the following rights regarding personal data we control:

RightWhat it means
Access (Art. 15)Request a copy of the personal data we hold about you
Rectification (Art. 16)Ask us to correct inaccurate data
Erasure (Art. 17)Ask us to delete your data in certain circumstances
Restriction (Art. 18)Ask us to limit how we use your data
Data portability (Art. 20)Receive data you provided in a structured, machine-readable format
Objection (Art. 21)Object to processing based on legitimate interests (including contact-form follow-up)
Withdraw consent (Art. 7(3))Where processing is based on consent, withdraw it at any time without affecting prior lawful processing

To exercise any of these rights, email support@salesreach.net. We will respond within one month, extendable by two further months for complex requests as permitted by the GDPR.

We may need to verify your identity before fulfilling a request. There is no fee unless your request is manifestly unfounded or excessive.

Right to lodge a complaint

If you believe we have not handled your personal data properly, you have the right to lodge a complaint with the Estonian Data Protection Inspectorate:

Andmekaitse Inspektsioon (AKI)
Tatari 39, 10134 Tallinn, Estonia
Website: https://www.aki.ee/en
Email: info@aki.ee

You may also complain to the supervisory authority in your country of residence or habitual residence.

11. Security

We implement appropriate technical and organisational measures to protect personal data, including:

  • Encryption in transit (HTTPS/TLS) for all web traffic
  • Access controls limiting staff access to personal data on a need-to-know basis
  • Hashed credentials and environment-variable secrets for production systems
  • Processor due diligence and data-processing agreements with sub-processors

No method of transmission or storage is completely secure. If you believe your interaction with us has been compromised, contact us immediately.

12. Children

Salesreach is a B2B service directed at Shopify merchants. Our marketing website and messaging service are not directed at children under 16. We do not knowingly collect personal data from children. If you believe a child has provided us data, contact us and we will delete it.

13. Changes to this policy

We may update this Privacy Policy from time to time. When we make material changes, we will update the "Last updated" date at the top and, where appropriate, provide additional notice on our website. Continued use of the website after changes constitutes acknowledgment of the updated policy.

For end-customers receiving messages, material changes affecting messaging practices will be communicated through the merchant or via an updated policy link where required by law.

14. Contact us

For any questions about this Privacy Policy or our data practices:

Revotech OÜ
Ahaste tee 4, Ahaste küla, 88306 Pärnu linn, Pärnu maakond, Estonia
Privacy & support: support@salesreach.net
Sales: sales@salesreach.net

SalesreachTerms · Privacy