Privacy Policy

Last updated [DATE]

This policy explains what personal data [LEGAL ENTITY NAME](“Revenant,” “we,” “us”) collects when you use revenantbot.com and the Revenant service (the “Service”), why, who processes it for us, how long we keep it, and the choices you have. We are the controller of this data. Questions: [email protected].

In short

  • We collect what we need to run your seat: your application, account, payments, your Skinport connection and what the bot does for you.
  • We do not sell your data, show ads, or use advertising or cross-site tracking cookies.
  • Card numbers go to Stripe, never to us. Your card security code (CVV) is stored encrypted, only on the bot server.
  • We keep a record of what you agreed to and your sign-ins, partly to answer payment disputes.
  • You can ask for a copy of your data or for it to be deleted at [email protected].

1. What we collect

1.1 When you join the waitlist. Your email address, the plan you are interested in, how you heard about us (if you tell us), the time you signed up, and a one-way hash of your IP address (used to limit abuse; it cannot be turned back into the address).

1.2 Email opens. The invitation email to apply contains a small tracking image. When your email app loads it, we record the time of the first and latest open and how many times it was opened. Blocking images in your email app prevents this.

1.3 When you apply. Your email; your Steam profile link and the public information we read from it on Steam (SteamID, display name, avatar, profile visibility and account age); the capital range, experience and Plan you choose; the note you write; and a one-way hash of your IP address.

1.4 Record of your agreement. When you submit your application we store the version of the Terms of Service you accepted, the exact wording of every box you ticked, the date and time, your IP address and your browser (user agent). This is the record of your agreement described in Section 1.2 of the Terms of Service.

1.5 Payments.Payments are handled by Stripe. You enter your card details on Stripe's page, not ours, and Stripe stores them. We receive and keep your Stripe customer and payment-method identifiers, the status, amount and date of each payment, and your subscription status, which tells us your next charge date and whether you have cancelled. Stripe may share the card's brand, last four digits and expiry date with us.

1.6 Your account. Username, email, password (stored only as a one-way hash, never in readable form), membership Plan, account status, preferences such as your display currency, your onboarding progress, and the name of the assistant assigned to you.

1.7 Sign-ins and security. For each sign-in session: the time, your IP address and your browser or device. We use this to keep you signed in, to alert you about new sign-ins, to protect accounts, and as evidence of use if a payment is disputed.

1.8 Your Skinport connection. To buy for you, the bot signs into your Skinport account. To do that we store, on our bot servers: your Skinport sign-in email and password and the signed-in session; your card security code (CVV), encrypted; and the details Skinport shows about your account (username, avatar, country, currency, number of linked Steam accounts, two-factor and trusted status, and the last four digits of saved cards). Personal details on your Skinport account, such as name, date of birth and address, are stored only in encrypted form. We also assign a dedicated network address (proxy) that the bot uses for your account.

1.9 Trading activity. The items you put on your Hit List, the purchases the bot makes or attempts for you, prices paid, market and estimated sale prices, estimated profit, order identifiers, outcomes and failure reasons, and logs of what the bot did and when.

1.10 Notifications. If you link Discord, Telegram or email alerts, the identifier needed to reach you there (your Discord user ID, Telegram chat ID or email address).

1.11 Support.What you send us by email or through the dashboard's help requests, and our replies.

2. Cookies and similar technologies

We use only what the Service needs to work and stay secure. There are no advertising or cross-site tracking cookies.

  • Sign-in cookies (access_token, refresh_token): keep you signed in. Removed when you sign out or they expire (up to 30 days).
  • Admin cookies (admin_session, rv_onboarding_preview, CF_Authorization): used only for our staff.
  • Security cookies set by Cloudflare to filter bots and attacks.
  • Local storage in your browser for preferences such as light or dark theme and display currency. It never leaves your device.

Cloudflare may also provide us with aggregate, cookie-free page-view statistics.

3. Why we use it

  • To provide the Service you signed up for: reviewing applications, running your seat, the bot's purchases, notifications and support (performance of our contract with you).
  • To bill you as the Terms describe, including the application fee, monthly renewals and commission (contract).
  • To keep the Service and accounts secure, prevent fraud and abuse, and enforce the Terms and house rules (our legitimate interests).
  • To answer payment disputes and chargebacks with the records listed in Section 5.4 of the Terms (our legitimate interests in defending charges you authorized).
  • To send service emails: application status, receipts, confirmations, security alerts and changes to the Terms (contract and legitimate interests).
  • To comply with the law, for example tax and accounting records (legal obligation).

We do not use your data for advertising, we do not sell it, and we do not share it for cross-context behavioral advertising. We do not make decisions about you based solely on automated processing that have legal or similarly significant effects. Applications are reviewed by a person.

4. Who we share it with

We share personal data only with service providers that process it for us, and only as needed:

  • Stripe: payment processing, saved cards, subscriptions and dispute handling.
  • Resend: sending our emails.
  • Railway: hosting the website and its database.
  • Cloudflare: DNS, content delivery, security filtering and forwarding mail sent to our support address.
  • Google (Workspace): the inbox where support email is read and answered.
  • Our bot server and network-proxy providers: running the bot and carrying its traffic to the marketplace.
  • Discord and Telegram: delivering notifications, only if you link them.

We also share data in these cases:

  • With the marketplace you connect (currently Skinport), when the bot signs in and buys as you. Skinport sees that activity as coming from your account, under Skinport's own privacy policy.
  • With Steam, when we look up the public Steam profile you give us.
  • With card networks and banks, through Stripe, when a payment you made is disputed.
  • With authorities, when the law requires it or to protect rights, safety and property.
  • With a buyer or successor if our business is merged, acquired or sold, under the same protections.

5. Where your data is stored

Our servers and providers are located in [e.g. the United States and Germany], so your data may be processed outside your country. Where the law requires it (for example for data from the EU, EEA or UK), transfers rely on safeguards such as the European Commission's Standard Contractual Clauses offered by our providers.

6. How long we keep it

  • Account and trading data: while your account exists. When your account is deleted, your account, sign-in sessions, Hit List and purchase history are deleted from our database with it.
  • Skinport connection: disconnecting Skinport in Account clears the signed-in session the bot holds for you. Your stored Skinport sign-in details and encrypted card security code are removed from the bot servers when you ask us to delete them or your account.
  • Payment records and the record of your agreement: for at least 24 months after your last payment (so disputes can be answered), and longer where tax or accounting law requires.
  • Sign-in sessions: until you sign out or the session expires.
  • Waitlist entries and applications that do not become accounts: until you ask us to delete them, or until we no longer need them.
  • Support email: as long as needed to handle your request and any follow-up.

7. How we protect it

Connections to the Service are encrypted (HTTPS). Passwords are stored only as one-way hashes. Your card security code and the personal details captured from your Skinport account are encrypted at rest. Staff access to the admin console requires an administrator account with an additional verification step. No system is perfectly secure. If a breach affects your data, we will tell you and the authorities where the law requires.

8. Your rights

Depending on where you live, you may have the right to: access the data we hold about you and get a copy; correct it; have it deleted; restrict or object to some uses; receive it in a portable format; and withdraw consent where we rely on it. To use any of these, email [email protected]from your account's email address. We answer within 30 days. We may need to keep some records after a deletion request where the law requires or allows it (for example, payment records and the record of your agreement while a dispute is possible).

EU, EEA and UK residents can also complain to their local data protection authority. California residents have the right to know, delete and correct personal information, and not to be discriminated against for using these rights. We do not sell or share personal information as those terms are defined in California law.

Deleting your data ends your seat. It does not cancel billing on its own: cancel your membership in Account first (Terms, Section 3.6).

9. Children

The Service is only for people aged 18 or over (Terms, Section 1.3). We do not knowingly collect data from anyone younger. If you believe a minor has given us data, email us and we will delete it.

10. Changes to this policy

We will update this page when our data practices change and change the date at the top. For material changes we will also email members before the change takes effect.

11. Contact

[LEGAL ENTITY NAME], [ADDRESS]. Email: [email protected].

Terms of Service · Back to Revenant