Privacy Policy
Last updated: [LAST UPDATED DATE]
Controller / company: [COMPANY LEGAL NAME], [REGISTERED ADDRESS] (“Resurve”, “we”, “us”).
Contact: [CONTACT EMAIL]
Governing law (provisional): [GOVERNING LAW — provisional: laws of Mauritius]
This Privacy Policy explains how Resurve collects, uses, shares, and protects personal information when you use:
resurve.netand{handle}.resurve.net(customer and marketing surfaces);dashboard.resurve.net(business operator portal);affiliate.resurve.net(affiliate portal);ops.resurve.net(staff tools);- related apps, emails, WhatsApp/in-app notifications, and APIs.
Everyday language summaries are for convenience only and are not legally binding.
1. Who this policy covers
Which means: Businesses, customers, affiliates, and visitors are covered — roles differ.
- Business users — owners, staff, and admins on the business portal.
- Customers — people who browse storefronts, book, pay, or create customer accounts.
- Affiliates — people using the affiliate program.
- Visitors — people on marketing pages who have not signed up.
- Staff — Resurve internal users (separate employment/ops rules may also apply).
2. Information we collect
Which means: We collect account data, booking/ops data, payment references (not full card data when the PSP handles cards), device/usage data, and communications.
2.1 You provide
- Identity and contact: name, email, phone, address, business legal name, BRN/licence docs where onboarding requires them.
- Account credentials and profile details.
- Storefront Materials: listings, photos, policies, FAQs.
- Booking and operating-file details: dates, locations, assignments, documents/evidence you or your customers upload.
- Support and feedback messages.
- Affiliate profile and payout details where applicable.
2.2 Automatic collection
- Device, browser, IP, approximate location, language.
- Usage logs, pages viewed, feature events, performance diagnostics.
- Cookies and similar technologies (see Cookie Policy).
- Security and fraud signals.
2.3 Payments
- Payment state and provider references (authorised, failed, refunded, deposit held/released, cash/Juice confirmed, etc.).
- Cardholder data is typically handled by the PSP/acquirer under their terms. Resurve aims not to store full PAN/CVV. PCI responsibilities follow who stores/processes/transmits Account Data.
2.4 From others
- PSP/acquirer webhooks and settlement metadata when provided.
- Auth providers (e.g. Google) if you choose social login.
- Affiliates or businesses who refer you (attribution fields).
- Public or partner sources where lawful for onboarding or risk checks.
3. Lead provenance and storefront modes
Which means: We record whether a customer came from a business’s own link or from Resurve marketplace discovery.
- Landing on
{handle}.resurve.netis typically attributed asbusiness_link. - Landing on indexed marketplace paths on
resurve.netis typically attributed asmarketplace. - Provenance may persist through checkout onto the operating file for analytics, monetization programs (future), and trust rules (for example cross-marketing of related verticals without same-vertical competitor spam on locked demand).
4. How we use information
Which means: We use data to run accounts, checkout, the operating system, automation, notifications, security, and improvement of Resurve.
- Provide and improve the Services (handles, storefronts, booking, POS, fleet/ops modules, analytics).
- Process payments states and coordinate with PSPs.
- Send transactional and product messages by email, in-app, and (where opted in) WhatsApp — every email should also create an actionable in-app notification where that channel is enabled.
- Onboarding, verification, and compliance (market × vertical documents).
- Security, fraud prevention, abuse detection (including AUP enforcement).
- Support, dispute handling, and audit trails on operating files.
- Marketing of Resurve to businesses/affiliates where allowed; customer marketing follows consent and channel rules.
- Research and product analytics with safeguards.
- Legal obligations and enforcement of Terms.
5. Legal bases (where applicable)
Where GDPR/UK GDPR or similar regimes apply, we rely on bases such as contract performance, legitimate interests (securing and improving the platform, B2B marketing where allowed), consent (certain cookies, WhatsApp marketing, non-essential tracking), and legal obligation. Exact bases depend on your location and the processing.
6. How we share information
Which means: We share with processors who help us run Resurve, with PSPs, and when you enable integrations — not sell personal data as a product.
We may share with:
- Infrastructure and processors (hosting, email, messaging, analytics, error reporting such as Linear-bound pipelines, auth).
- PSPs / acquirers for payment processing.
- Businesses — customer booking and operating-file data needed to fulfil the service the customer requested.
- Customers — business identity and booking/payment status they need.
- Affiliates — limited attribution/commission data as needed for the program.
- Third-party apps you enable (your instruction).
- Authorities when required by law or to protect rights and safety.
- Corporate transactions (merger/acquisition) under appropriate safeguards.
We do not sell personal information in the conventional “data broker” sense. Some advertising or analytics tools may be “sharing”/targeted advertising under certain US state laws — see Cookie Policy and your preference controls when available.
7. International transfers
Which means: Data may be processed in countries other than where you live.
We may use vendors in multiple regions. Where required, we use appropriate transfer mechanisms (for example standard contractual clauses) and vendor diligence.
8. Retention
Which means: We keep data as long as needed for the Services, law, and disputes — then delete or anonymise.
Retention varies by record type (accounts, operating files, financial references, support tickets, logs). Evidence and financial history may be retained longer for audit and legal reasons.
9. Security
Which means: We use reasonable technical and organisational measures; no system is perfectly secure.
Measures include access controls, encryption in transit where appropriate, least-privilege staff access on ops tools, and monitoring. You must protect your own passwords and staff access.
10. Your rights
Which means: Depending on where you live, you may access, correct, delete, or object to certain processing.
Contact [CONTACT EMAIL]. We may need to verify identity. Businesses acting as controllers for their customer data may need to handle customer requests directly for data they control; we will assist under our DPA where applicable.
11. Children
The Services are not directed to children under 16 (or higher age where required). Do not create accounts for children in violation of local law.
12. Businesses as controllers
When you are a business using Resurve, you may be an independent controller (or similar) for your customer relationships. You must provide required notices on your storefront, honour consumer rights, and only upload lawful Materials. Where Resurve processes Your Customer Personal Data as a processor, our DPA (when executed/posted) applies.
13. Automated decisions and AI
Where we use automated tools (fraud checks, recommendations, Sidekick-like assistants if offered), we design them to support operators and customers. Significant legal effects will include human review pathways where required by law.
14. Changes
We may update this Policy. Material changes will be notified as described in the Terms (email or Account notice when practicable). Continued use after the effective date means you acknowledge the update.
15. Contact
[COMPANY LEGAL NAME]
[REGISTERED ADDRESS]
[CONTACT EMAIL]