Legal

Privacy Policy

Last updated: June 27, 2026

RevPass Privacy Policy

RevPass LLC ("RevPass," "we," "us," or "our") provides a B2B revenue workflow platform for quote generation, order-form generation, approval routing, electronic acceptance, electronic signature facilitation, CRM validation, Salesforce synchronization, MSA drift detection, AI-assisted extraction and analysis, Slack workflow actions, booking handoff, analytics, support, security, and related services.

This Privacy Policy explains how we collect, use, disclose, and protect personal information in connection with our websites, applications, platform, integrations, communications, marketing, support, billing, and related services (collectively, the "Services").

RevPass is located at 708 Heartland Trl, 3rd Floor, Madison, WI 53717. You can contact us at privacy@revpass.io or legal@revpass.io.

1. Scope and roles

This Privacy Policy applies to personal information that RevPass processes in its own capacity as a business, controller, or similar role, such as account administration, website use, marketing, billing, support, security, and business communications.

When RevPass processes Customer Data on behalf of a business customer through the Services, RevPass generally acts as that customer's processor, service provider, contractor, or subprocessor. In that case, the business customer controls the processing, and the applicable customer agreement and Data Processing Addendum govern RevPass's processing. If your personal information appears in a customer's Salesforce records, order forms, MSAs, contracts, quotes, approvals, Slack workflows, signature records, or related business documents, you should contact that customer directly to exercise privacy rights or ask questions about its processing.

This Privacy Policy does not apply to third-party websites, applications, platforms, or services that we do not control, including Salesforce, Slack, DocuSign, Stripe, Google, or other connected systems used by customers.

2. Personal information we collect

Depending on how you interact with RevPass, we may collect the following categories of personal information.

Account and contact information

We may collect names, business email addresses, business phone numbers, job titles, company names, workspace names, domain information, user roles, authentication identifiers, and similar account information.

Customer Data processed through the Services

Customers and authorized users may upload, submit, generate, or sync Customer Data through the Services. Customer Data may include CRM records, account records, opportunity records, contact records, quotes, order forms, MSAs, contracts, signed PDFs, approval records, pricing data, billing terms, contract terms, signature metadata, IP addresses, timestamps, audit trail data, and related business records.

Connected system data

If a customer connects Salesforce, Slack, DocuSign, email, storage, billing, ERP, identity, or other systems, we may process the data authorized by the customer through the applicable OAuth scopes, API permissions, field mappings, settings, and user actions. This may include CRM records, Slack user and message metadata, DocuSign envelope and signer metadata, files, workflow actions, and integration logs.

Electronic signature and acceptance data

If a customer uses RevPass native acceptance links or an e-signature integration, we may process signer names, business email addresses, IP addresses, timestamps, acceptance records, envelope identifiers, document identifiers, signed documents, signing status, and audit trail metadata.

AI-assisted processing data

The Services may process deal context, CRM fields, contract text, MSA text, order-form text, quote data, validation rules, extracted terms, customer instructions, and related metadata through AI-assisted features to provide extraction, summarization, classification, opportunity matching, MSA term analysis, MSA drift detection, natural-language validation rules, nudge drafting, Slack responses, and other workflow functionality.

Payment and billing information

We may collect billing contacts, invoice information, subscription details, payment status, tax information, transaction identifiers, and limited payment metadata. Payment card information is processed by our payment processor and is not intended to be stored directly by RevPass.

Communications and support information

We may collect information you provide when you contact us, request a demo, submit a form, participate in sales or support communications, respond to surveys, attend meetings, or otherwise communicate with us. This may include message content, attachments, contact details, company information, support tickets, troubleshooting information, and call or meeting notes.

Website, device, and usage information

We may collect information about how you interact with our websites and Services, including IP address, browser type, device type, operating system, referring URLs, pages viewed, features used, dates and times of activity, log data, diagnostic data, performance data, and security event data.

Cookies and similar technologies

We may use cookies, pixels, local storage, analytics tools, and similar technologies to operate our websites and Services, remember preferences, authenticate users, understand usage, improve performance, secure the Services, and support marketing or sales operations. See Section 9 for more information.

3. Sources of personal information

We may collect personal information from:

you directly;

your employer or organization;

authorized users of the Services;

Salesforce and other customer-connected systems;

Slack, DocuSign, Google, Stripe, and other integrations or service providers;

forms, emails, meetings, support requests, and sales communications;

website and product usage;

cookies and similar technologies;

public sources, business directories, or lead sources where permitted by law.

4. How we use personal information

We may use personal information to:

provide, operate, maintain, and improve the Services;

create, authenticate, administer, and secure accounts;

process customer instructions, workflows, approval policies, autonomy settings, and integrations;

connect to Salesforce, Slack, DocuSign, Google, Stripe, and other systems as authorized;

generate quotes, order forms, approvals, acceptance workflows, and booking handoff materials;

extract, summarize, classify, validate, compare, and analyze documents and CRM records;

perform MSA term extraction and MSA drift detection;

provide AI-assisted outputs and automated workflow functionality;

sync authorized data to Salesforce or other connected systems;

send transactional emails, workflow notifications, security notices, product updates, and administrative messages;

process subscriptions, invoices, billing, and payments;

provide customer support, troubleshooting, and training;

monitor usage, performance, availability, and security;

detect, prevent, and respond to fraud, abuse, security incidents, and technical issues;

enforce agreements and protect legal rights;

comply with legal, regulatory, tax, accounting, and security obligations;

conduct analytics, benchmarking, product development, and business planning;

send marketing communications where permitted by law.

5. AI and automation

RevPass uses AI-assisted and automated features to help customers operate revenue workflows, including contract and PDF extraction, opportunity matching, quote and order-form generation, validation against Salesforce or other CRM records, MSA term extraction, MSA drift detection, natural-language validation rules, approval recommendations, Slack responses, nudge messages, booking handoff preparation, Salesforce synchronization, and other functionality.

RevPass does not use Customer Data to train, fine-tune, or improve generative artificial intelligence or machine-learning models for the benefit of other customers or third parties, and does not permit its AI subprocessors to train their general-purpose models on Customer Data, in each case except for aggregated or de-identified data as permitted under this Privacy Policy and the applicable customer agreement.

AI-assisted outputs may be incomplete, inaccurate, outdated, misleading, or unsuitable for a customer's intended purpose. Customers are responsible for reviewing and approving outputs, validation results, MSA drift results, Salesforce updates, booking handoffs, and related actions before relying on them.

RevPass does not make automated decisions about individuals on its own behalf that produce legal or similarly significant effects. Customers control how they configure and use automation, including whether actions are notification-only, proposed for approval, or automatically executed within customer-configured guardrails.

6. How we disclose personal information

We may disclose personal information to the following categories of recipients.

Service providers and subprocessors

We disclose personal information to vendors that help us provide, secure, support, and operate the Services, including hosting providers, database providers, object storage providers, AI providers, email providers, billing providers, authentication providers, monitoring providers, and support providers. Our current security and subprocessor information is available at https://revpass.io/security.

Customer-authorized connected systems

At a customer's instruction, we may disclose or transmit personal information to Salesforce, Slack, DocuSign, ERP systems, billing systems, storage systems, identity providers, or other connected systems. Customers are responsible for their connected-system permissions, field mappings, OAuth scopes, workflows, and downstream processing.

Customers and authorized users

If you use the Services on behalf of a customer, information associated with your account, activity, approvals, workflows, signatures, audit trails, or support requests may be visible to that customer and its authorized users.

Professional advisors

We may disclose information to lawyers, auditors, accountants, insurers, banks, consultants, and other professional advisors where necessary for business, legal, accounting, or compliance purposes.

Legal, security, and compliance recipients

We may disclose information to comply with law, subpoenas, court orders, legal process, regulatory requests, law enforcement requests, or government requests; to protect rights, safety, and security; to enforce agreements; to investigate fraud or abuse; or to respond to security incidents.

Business transfers

We may disclose or transfer information in connection with a merger, acquisition, financing, corporate reorganization, bankruptcy, sale of assets, due diligence process, or similar business transaction.

7. Aggregated and de-identified data

We may create and use aggregated, anonymized, or de-identified data derived from use of the Services for analytics, benchmarking, product improvement, research, security, reporting, and business purposes, provided that such data does not identify a customer, user, counterparty, or individual and cannot reasonably be re-identified.

We do not attempt to re-identify aggregated, anonymized, or de-identified data except to test or validate de-identification measures or as permitted by law.

8. Customer Data and the Data Processing Addendum

For most Customer Data processed inside the Services, RevPass acts as a processor, service provider, contractor, or subprocessor on behalf of the customer. Our use of that data is governed by the applicable customer agreement and Data Processing Addendum.

If you are a customer end user, signer, approver, prospect, customer contact, Salesforce contact, Slack user, or other individual whose personal information is processed by a RevPass customer, the customer is generally responsible for responding to your privacy request. We will assist the customer as required by our agreement and applicable law.

9. Cookies and similar technologies

We may use cookies and similar technologies to:

operate and secure our websites and Services;

authenticate users and maintain sessions;

remember settings and preferences;

measure website and product usage;

improve performance and reliability;

understand marketing effectiveness;

prevent fraud and abuse.

You can usually control cookies through your browser settings. If you block cookies, some features may not work correctly.

Some browsers offer "Do Not Track" signals. There is not yet a consistent industry standard for responding to those signals. Where legally required, we will honor legally recognized opt-out preference signals, such as Global Privacy Control, in connection with activities that qualify as a sale, sharing, or targeted advertising under applicable law. We do not currently sell personal information or share personal information for cross-context behavioral advertising.

10. Data retention

We retain personal information for as long as reasonably necessary to provide the Services, maintain accounts, comply with legal obligations, resolve disputes, enforce agreements, maintain security, prevent fraud or abuse, support business operations, and fulfill the purposes described in this Privacy Policy.

Retention periods depend on the type of information, the customer agreement, account status, legal requirements, operational needs, backup lifecycle, security needs, and dispute or audit requirements.

Customer Data is retained and deleted in accordance with the applicable customer agreement and Data Processing Addendum. Backup copies may remain for a limited period in accordance with our normal backup lifecycle.

11. Security

We use reasonable administrative, technical, and organizational safeguards designed to protect personal information against unauthorized access, disclosure, alteration, and destruction.

Our safeguards may include encryption in transit, encryption at rest where supported, application-layer encryption for certain connected credentials, access controls, role-based permissions, logging, monitoring, audit trails, vulnerability management, secure development practices, vendor review, backups, and incident response processes.

No system is perfectly secure. Customers and users are responsible for securing their own accounts, devices, credentials, OAuth grants, connected systems, user permissions, and configurations.

12. International transfers

RevPass is based in the United States, and personal information may be processed in the United States and other countries where we or our service providers operate. These countries may have data protection laws different from those in your jurisdiction.

Where required, we use appropriate safeguards for international transfers, such as Standard Contractual Clauses, the UK Addendum, or other lawful transfer mechanisms.

13. Your privacy rights

Depending on where you live and the nature of our processing, you may have rights to:

request access to personal information;

request correction of inaccurate personal information;

request deletion of personal information;

request portability of personal information;

object to or restrict certain processing;

opt out of sale, sharing, targeted advertising, or certain profiling where applicable;

limit use of sensitive personal information where applicable;

withdraw consent where processing is based on consent;

appeal a denied privacy request where applicable;

complain to a data protection authority.

To exercise rights, contact privacy@revpass.io. We may need to verify your identity and authority before responding.

If your request relates to personal information controlled by a RevPass customer, we may direct you to that customer or process your request on the customer's instructions.

We will not discriminate against you for exercising privacy rights.

14. California privacy notice

This section applies to California residents where the California Consumer Privacy Act, as amended by the California Privacy Rights Act, applies to RevPass's processing of personal information.

Categories collected, sources, purposes, and disclosures

In the past twelve months, we may have collected and disclosed for business purposes the following categories of personal information:

CategoryExamplesSourcesPurposesDisclosed to
Identifiers Name, business email, business phone, IP address, account ID, Salesforce ID, Slack ID, DocuSign ID You, customers, authorized users, connected systems, service providers Account administration, Services delivery, integrations, support, security, communications Service providers, subprocessors, connected systems, customers, legal/compliance recipients
Customer records information Business contact details, billing contact details, account details You, customers, billing systems, forms Billing, contracting, support, customer management Service providers, payment processors, professional advisors
Commercial information Subscription plan, invoices, transaction metadata, product usage, deal workflow metadata You, customers, payment processors, Services usage Billing, analytics, support, product operation Service providers, payment processors, professional advisors
Internet or electronic network activity Log data, device data, browser data, pages viewed, features used, authentication events Website, Services, cookies, logs, service providers Security, analytics, troubleshooting, product improvement Hosting, analytics, monitoring, security providers
Professional or employment-related information Job title, company, role, department, approval role You, customers, CRM records, connected systems Account management, workflow routing, approvals, support Service providers, customers, connected systems
Geolocation data Approximate location inferred from IP address Website, Services, logs Security, fraud prevention, analytics, localization Hosting, analytics, security providers
Audio, electronic, or visual information Support call recordings or meeting notes if recorded or provided You, meetings, support communications Support, training, sales, quality assurance Service providers, professional advisors
Inferences Usage trends, account health, workflow analytics, security signals Services usage, logs, analytics Product improvement, customer support, security, business planning Service providers, customers in account-level reporting
Sensitive personal information Account login information, credentials or tokens where applicable You, connected systems, authentication providers Authentication, security, integration operation Service providers, connected systems as instructed
Contents of communications or documents Support messages, uploaded documents, contracts, order forms, MSAs, signed PDFs You, customers, authorized users, connected systems Services delivery, extraction, validation, MSA drift detection, support Service providers, AI providers, storage providers, connected systems as instructed

Sale and sharing

We do not currently sell personal information or share personal information for cross-context behavioral advertising as those terms are defined under the CCPA.

Sensitive personal information

We do not use or disclose sensitive personal information for purposes that would require a right to limit under the CCPA, unless we provide required notice and choice.

California rights

California residents may have the right to request access, portability, correction, deletion, disclosure of categories collected and disclosed, opt out of sale or sharing, limit certain uses of sensitive personal information, and not be discriminated against for exercising rights.

To exercise rights, contact privacy@revpass.io. Authorized agents may submit requests on behalf of California residents where permitted by law. We may require proof of authorization and verification of identity.

15. Other U.S. state privacy rights

Residents of certain U.S. states may have rights under applicable state privacy laws, including rights to access, correct, delete, obtain a copy of personal information, opt out of targeted advertising, sale, or certain profiling, and appeal a denied request.

To exercise rights, contact privacy@revpass.io. If we deny your request and your state law provides an appeal right, you may appeal by replying to our decision email or contacting privacy@revpass.io with "Privacy Appeal" in the subject line.

16. EEA, UK, and Swiss privacy notice

If you are located in the European Economic Area, United Kingdom, or Switzerland, this section applies where RevPass acts as a controller for your personal data.

Controller

RevPass LLC is the controller for the processing described in this Privacy Policy where we determine the purposes and means of processing. Our contact information is:

RevPass LLC

708 Heartland Trl, 3rd Floor

Madison, WI 53717

privacy@revpass.io

legal@revpass.io

Legal bases

We may process personal data based on:

performance of a contract, such as providing the Services and managing accounts;

legitimate interests, such as securing the Services, improving the product, supporting customers, preventing fraud, and conducting B2B sales and marketing;

consent, such as for certain marketing communications or cookies where required;

legal obligations, such as tax, accounting, compliance, and regulatory requirements.

Rights

Depending on the circumstances, you may have rights to access, rectify, erase, restrict, object to processing, data portability, withdraw consent, and lodge a complaint with a supervisory authority.

To exercise rights, contact privacy@revpass.io.

International transfers

Where required, we use appropriate safeguards for transfers of personal data outside the EEA, UK, or Switzerland, including Standard Contractual Clauses, the UK Addendum, or other lawful mechanisms.

17. Marketing choices

You may unsubscribe from marketing emails by using the unsubscribe link in the email or contacting us at privacy@revpass.io.

Even if you opt out of marketing emails, we may still send transactional, security, legal, billing, support, and service-related communications.

18. Children's privacy

The Services are intended for business use and are not directed to children. We do not knowingly collect personal information from children under 13 or from children under the age threshold applicable in your jurisdiction. If you believe a child has provided personal information to us, contact privacy@revpass.io.

19. Changes to this Privacy Policy

We may update this Privacy Policy from time to time. If we make material changes, we will provide notice by posting the updated policy, sending email, providing notice through the Services, or using another reasonable method.

The updated Privacy Policy will be effective as of the "Last Updated" date unless stated otherwise.

20. Contact us

For privacy questions or requests, contact:

RevPass LLC

708 Heartland Trl, 3rd Floor

Madison, WI 53717

privacy@revpass.io

legal@revpass.io