Privacy Policy
Last updated: June 27, 2026
RevPass Privacy Policy
RevPass LLC ("RevPass," "we," "us," or "our") provides a B2B revenue workflow platform for quote generation, order-form generation, approval routing, electronic acceptance, electronic signature facilitation, CRM validation, Salesforce synchronization, MSA drift detection, AI-assisted extraction and analysis, Slack workflow actions, booking handoff, analytics, support, security, and related services.
This Privacy Policy explains how we collect, use, disclose, and protect personal information in connection with our websites, applications, platform, integrations, communications, marketing, support, billing, and related services (collectively, the "Services").
RevPass is located at 708 Heartland Trl, 3rd Floor, Madison, WI 53717. You can contact us at privacy@revpass.io or legal@revpass.io.
1. Scope and roles
This Privacy Policy applies to personal information that RevPass processes in its own capacity as a business, controller, or similar role, such as account administration, website use, marketing, billing, support, security, and business communications.
When RevPass processes Customer Data on behalf of a business customer through the Services, RevPass generally acts as that customer's processor, service provider, contractor, or subprocessor. In that case, the business customer controls the processing, and the applicable customer agreement and Data Processing Addendum govern RevPass's processing. If your personal information appears in a customer's Salesforce records, order forms, MSAs, contracts, quotes, approvals, Slack workflows, signature records, or related business documents, you should contact that customer directly to exercise privacy rights or ask questions about its processing.
This Privacy Policy does not apply to third-party websites, applications, platforms, or services that we do not control, including Salesforce, Slack, DocuSign, Stripe, Google, or other connected systems used by customers.
2. Personal information we collect
Depending on how you interact with RevPass, we may collect the following categories of personal information.
Account and contact information
We may collect names, business email addresses, business phone numbers, job titles, company names, workspace names, domain information, user roles, authentication identifiers, and similar account information.
Customer Data processed through the Services
Customers and authorized users may upload, submit, generate, or sync Customer Data through the Services. Customer Data may include CRM records, account records, opportunity records, contact records, quotes, order forms, MSAs, contracts, signed PDFs, approval records, pricing data, billing terms, contract terms, signature metadata, IP addresses, timestamps, audit trail data, and related business records.
Connected system data
If a customer connects Salesforce, Slack, DocuSign, email, storage, billing, ERP, identity, or other systems, we may process the data authorized by the customer through the applicable OAuth scopes, API permissions, field mappings, settings, and user actions. This may include CRM records, Slack user and message metadata, DocuSign envelope and signer metadata, files, workflow actions, and integration logs.
Electronic signature and acceptance data
If a customer uses RevPass native acceptance links or an e-signature integration, we may process signer names, business email addresses, IP addresses, timestamps, acceptance records, envelope identifiers, document identifiers, signed documents, signing status, and audit trail metadata.
AI-assisted processing data
The Services may process deal context, CRM fields, contract text, MSA text, order-form text, quote data, validation rules, extracted terms, customer instructions, and related metadata through AI-assisted features to provide extraction, summarization, classification, opportunity matching, MSA term analysis, MSA drift detection, natural-language validation rules, nudge drafting, Slack responses, and other workflow functionality.
Payment and billing information
We may collect billing contacts, invoice information, subscription details, payment status, tax information, transaction identifiers, and limited payment metadata. Payment card information is processed by our payment processor and is not intended to be stored directly by RevPass.
Communications and support information
We may collect information you provide when you contact us, request a demo, submit a form, participate in sales or support communications, respond to surveys, attend meetings, or otherwise communicate with us. This may include message content, attachments, contact details, company information, support tickets, troubleshooting information, and call or meeting notes.
Website, device, and usage information
We may collect information about how you interact with our websites and Services, including IP address, browser type, device type, operating system, referring URLs, pages viewed, features used, dates and times of activity, log data, diagnostic data, performance data, and security event data.
Cookies and similar technologies
We may use cookies, pixels, local storage, analytics tools, and similar technologies to operate our websites and Services, remember preferences, authenticate users, understand usage, improve performance, secure the Services, and support marketing or sales operations. See Section 9 for more information.
3. Sources of personal information
We may collect personal information from:
you directly;
your employer or organization;
authorized users of the Services;
Salesforce and other customer-connected systems;
Slack, DocuSign, Google, Stripe, and other integrations or service providers;
forms, emails, meetings, support requests, and sales communications;
website and product usage;
cookies and similar technologies;
public sources, business directories, or lead sources where permitted by law.
4. How we use personal information
We may use personal information to:
provide, operate, maintain, and improve the Services;
create, authenticate, administer, and secure accounts;
process customer instructions, workflows, approval policies, autonomy settings, and integrations;
connect to Salesforce, Slack, DocuSign, Google, Stripe, and other systems as authorized;
generate quotes, order forms, approvals, acceptance workflows, and booking handoff materials;
extract, summarize, classify, validate, compare, and analyze documents and CRM records;
perform MSA term extraction and MSA drift detection;
provide AI-assisted outputs and automated workflow functionality;
sync authorized data to Salesforce or other connected systems;
send transactional emails, workflow notifications, security notices, product updates, and administrative messages;
process subscriptions, invoices, billing, and payments;
provide customer support, troubleshooting, and training;
monitor usage, performance, availability, and security;
detect, prevent, and respond to fraud, abuse, security incidents, and technical issues;
enforce agreements and protect legal rights;
comply with legal, regulatory, tax, accounting, and security obligations;
conduct analytics, benchmarking, product development, and business planning;
send marketing communications where permitted by law.
5. AI and automation
RevPass uses AI-assisted and automated features to help customers operate revenue workflows, including contract and PDF extraction, opportunity matching, quote and order-form generation, validation against Salesforce or other CRM records, MSA term extraction, MSA drift detection, natural-language validation rules, approval recommendations, Slack responses, nudge messages, booking handoff preparation, Salesforce synchronization, and other functionality.
RevPass does not use Customer Data to train, fine-tune, or improve generative artificial intelligence or machine-learning models for the benefit of other customers or third parties, and does not permit its AI subprocessors to train their general-purpose models on Customer Data, in each case except for aggregated or de-identified data as permitted under this Privacy Policy and the applicable customer agreement.
AI-assisted outputs may be incomplete, inaccurate, outdated, misleading, or unsuitable for a customer's intended purpose. Customers are responsible for reviewing and approving outputs, validation results, MSA drift results, Salesforce updates, booking handoffs, and related actions before relying on them.
RevPass does not make automated decisions about individuals on its own behalf that produce legal or similarly significant effects. Customers control how they configure and use automation, including whether actions are notification-only, proposed for approval, or automatically executed within customer-configured guardrails.
6. How we disclose personal information
We may disclose personal information to the following categories of recipients.
Service providers and subprocessors
We disclose personal information to vendors that help us provide, secure, support, and operate the Services, including hosting providers, database providers, object storage providers, AI providers, email providers, billing providers, authentication providers, monitoring providers, and support providers. Our current security and subprocessor information is available at https://revpass.io/security.
Customer-authorized connected systems
At a customer's instruction, we may disclose or transmit personal information to Salesforce, Slack, DocuSign, ERP systems, billing systems, storage systems, identity providers, or other connected systems. Customers are responsible for their connected-system permissions, field mappings, OAuth scopes, workflows, and downstream processing.
Customers and authorized users
If you use the Services on behalf of a customer, information associated with your account, activity, approvals, workflows, signatures, audit trails, or support requests may be visible to that customer and its authorized users.
Professional advisors
We may disclose information to lawyers, auditors, accountants, insurers, banks, consultants, and other professional advisors where necessary for business, legal, accounting, or compliance purposes.
Legal, security, and compliance recipients
We may disclose information to comply with law, subpoenas, court orders, legal process, regulatory requests, law enforcement requests, or government requests; to protect rights, safety, and security; to enforce agreements; to investigate fraud or abuse; or to respond to security incidents.
Business transfers
We may disclose or transfer information in connection with a merger, acquisition, financing, corporate reorganization, bankruptcy, sale of assets, due diligence process, or similar business transaction.
7. Aggregated and de-identified data
We may create and use aggregated, anonymized, or de-identified data derived from use of the Services for analytics, benchmarking, product improvement, research, security, reporting, and business purposes, provided that such data does not identify a customer, user, counterparty, or individual and cannot reasonably be re-identified.
We do not attempt to re-identify aggregated, anonymized, or de-identified data except to test or validate de-identification measures or as permitted by law.
8. Customer Data and the Data Processing Addendum
For most Customer Data processed inside the Services, RevPass acts as a processor, service provider, contractor, or subprocessor on behalf of the customer. Our use of that data is governed by the applicable customer agreement and Data Processing Addendum.
If you are a customer end user, signer, approver, prospect, customer contact, Salesforce contact, Slack user, or other individual whose personal information is processed by a RevPass customer, the customer is generally responsible for responding to your privacy request. We will assist the customer as required by our agreement and applicable law.
9. Cookies and similar technologies
We may use cookies and similar technologies to:
operate and secure our websites and Services;
authenticate users and maintain sessions;
remember settings and preferences;
measure website and product usage;
improve performance and reliability;
understand marketing effectiveness;
prevent fraud and abuse.
You can usually control cookies through your browser settings. If you block cookies, some features may not work correctly.
Some browsers offer "Do Not Track" signals. There is not yet a consistent industry standard for responding to those signals. Where legally required, we will honor legally recognized opt-out preference signals, such as Global Privacy Control, in connection with activities that qualify as a sale, sharing, or targeted advertising under applicable law. We do not currently sell personal information or share personal information for cross-context behavioral advertising.
10. Data retention
We retain personal information for as long as reasonably necessary to provide the Services, maintain accounts, comply with legal obligations, resolve disputes, enforce agreements, maintain security, prevent fraud or abuse, support business operations, and fulfill the purposes described in this Privacy Policy.
Retention periods depend on the type of information, the customer agreement, account status, legal requirements, operational needs, backup lifecycle, security needs, and dispute or audit requirements.
Customer Data is retained and deleted in accordance with the applicable customer agreement and Data Processing Addendum. Backup copies may remain for a limited period in accordance with our normal backup lifecycle.
11. Security
We use reasonable administrative, technical, and organizational safeguards designed to protect personal information against unauthorized access, disclosure, alteration, and destruction.
Our safeguards may include encryption in transit, encryption at rest where supported, application-layer encryption for certain connected credentials, access controls, role-based permissions, logging, monitoring, audit trails, vulnerability management, secure development practices, vendor review, backups, and incident response processes.
No system is perfectly secure. Customers and users are responsible for securing their own accounts, devices, credentials, OAuth grants, connected systems, user permissions, and configurations.
12. International transfers
RevPass is based in the United States, and personal information may be processed in the United States and other countries where we or our service providers operate. These countries may have data protection laws different from those in your jurisdiction.
Where required, we use appropriate safeguards for international transfers, such as Standard Contractual Clauses, the UK Addendum, or other lawful transfer mechanisms.
13. Your privacy rights
Depending on where you live and the nature of our processing, you may have rights to:
request access to personal information;
request correction of inaccurate personal information;
request deletion of personal information;
request portability of personal information;
object to or restrict certain processing;
opt out of sale, sharing, targeted advertising, or certain profiling where applicable;
limit use of sensitive personal information where applicable;
withdraw consent where processing is based on consent;
appeal a denied privacy request where applicable;
complain to a data protection authority.
To exercise rights, contact privacy@revpass.io. We may need to verify your identity and authority before responding.
If your request relates to personal information controlled by a RevPass customer, we may direct you to that customer or process your request on the customer's instructions.
We will not discriminate against you for exercising privacy rights.
14. California privacy notice
This section applies to California residents where the California Consumer Privacy Act, as amended by the California Privacy Rights Act, applies to RevPass's processing of personal information.
Categories collected, sources, purposes, and disclosures
In the past twelve months, we may have collected and disclosed for business purposes the following categories of personal information:
| Category | Examples | Sources | Purposes | Disclosed to |
| Identifiers | Name, business email, business phone, IP address, account ID, Salesforce ID, Slack ID, DocuSign ID | You, customers, authorized users, connected systems, service providers | Account administration, Services delivery, integrations, support, security, communications | Service providers, subprocessors, connected systems, customers, legal/compliance recipients |
| Customer records information | Business contact details, billing contact details, account details | You, customers, billing systems, forms | Billing, contracting, support, customer management | Service providers, payment processors, professional advisors |
| Commercial information | Subscription plan, invoices, transaction metadata, product usage, deal workflow metadata | You, customers, payment processors, Services usage | Billing, analytics, support, product operation | Service providers, payment processors, professional advisors |
| Internet or electronic network activity | Log data, device data, browser data, pages viewed, features used, authentication events | Website, Services, cookies, logs, service providers | Security, analytics, troubleshooting, product improvement | Hosting, analytics, monitoring, security providers |
| Professional or employment-related information | Job title, company, role, department, approval role | You, customers, CRM records, connected systems | Account management, workflow routing, approvals, support | Service providers, customers, connected systems |
| Geolocation data | Approximate location inferred from IP address | Website, Services, logs | Security, fraud prevention, analytics, localization | Hosting, analytics, security providers |
| Audio, electronic, or visual information | Support call recordings or meeting notes if recorded or provided | You, meetings, support communications | Support, training, sales, quality assurance | Service providers, professional advisors |
| Inferences | Usage trends, account health, workflow analytics, security signals | Services usage, logs, analytics | Product improvement, customer support, security, business planning | Service providers, customers in account-level reporting |
| Sensitive personal information | Account login information, credentials or tokens where applicable | You, connected systems, authentication providers | Authentication, security, integration operation | Service providers, connected systems as instructed |
| Contents of communications or documents | Support messages, uploaded documents, contracts, order forms, MSAs, signed PDFs | You, customers, authorized users, connected systems | Services delivery, extraction, validation, MSA drift detection, support | Service providers, AI providers, storage providers, connected systems as instructed |
Sale and sharing
We do not currently sell personal information or share personal information for cross-context behavioral advertising as those terms are defined under the CCPA.
Sensitive personal information
We do not use or disclose sensitive personal information for purposes that would require a right to limit under the CCPA, unless we provide required notice and choice.
California rights
California residents may have the right to request access, portability, correction, deletion, disclosure of categories collected and disclosed, opt out of sale or sharing, limit certain uses of sensitive personal information, and not be discriminated against for exercising rights.
To exercise rights, contact privacy@revpass.io. Authorized agents may submit requests on behalf of California residents where permitted by law. We may require proof of authorization and verification of identity.
15. Other U.S. state privacy rights
Residents of certain U.S. states may have rights under applicable state privacy laws, including rights to access, correct, delete, obtain a copy of personal information, opt out of targeted advertising, sale, or certain profiling, and appeal a denied request.
To exercise rights, contact privacy@revpass.io. If we deny your request and your state law provides an appeal right, you may appeal by replying to our decision email or contacting privacy@revpass.io with "Privacy Appeal" in the subject line.
16. EEA, UK, and Swiss privacy notice
If you are located in the European Economic Area, United Kingdom, or Switzerland, this section applies where RevPass acts as a controller for your personal data.
Controller
RevPass LLC is the controller for the processing described in this Privacy Policy where we determine the purposes and means of processing. Our contact information is:
RevPass LLC
708 Heartland Trl, 3rd Floor
Madison, WI 53717
privacy@revpass.io
legal@revpass.io
Legal bases
We may process personal data based on:
performance of a contract, such as providing the Services and managing accounts;
legitimate interests, such as securing the Services, improving the product, supporting customers, preventing fraud, and conducting B2B sales and marketing;
consent, such as for certain marketing communications or cookies where required;
legal obligations, such as tax, accounting, compliance, and regulatory requirements.
Rights
Depending on the circumstances, you may have rights to access, rectify, erase, restrict, object to processing, data portability, withdraw consent, and lodge a complaint with a supervisory authority.
To exercise rights, contact privacy@revpass.io.
International transfers
Where required, we use appropriate safeguards for transfers of personal data outside the EEA, UK, or Switzerland, including Standard Contractual Clauses, the UK Addendum, or other lawful mechanisms.
17. Marketing choices
You may unsubscribe from marketing emails by using the unsubscribe link in the email or contacting us at privacy@revpass.io.
Even if you opt out of marketing emails, we may still send transactional, security, legal, billing, support, and service-related communications.
18. Children's privacy
The Services are intended for business use and are not directed to children. We do not knowingly collect personal information from children under 13 or from children under the age threshold applicable in your jurisdiction. If you believe a child has provided personal information to us, contact privacy@revpass.io.
19. Changes to this Privacy Policy
We may update this Privacy Policy from time to time. If we make material changes, we will provide notice by posting the updated policy, sending email, providing notice through the Services, or using another reasonable method.
The updated Privacy Policy will be effective as of the "Last Updated" date unless stated otherwise.
20. Contact us
For privacy questions or requests, contact:
RevPass LLC
708 Heartland Trl, 3rd Floor
Madison, WI 53717
privacy@revpass.io
legal@revpass.io