Home › Privacy policy
What we collect, why we collect it, and what we will never touch. Last updated 31 July 2026.
Eulav builds Revvy, an autonomous conversion rate optimisation practitioner for ecommerce stores. This policy explains how we handle information across our website and product.
When you create an account or contact us we collect your name, email address, company name and billing details. Billing is handled by our payment processor; we do not store full card numbers on our systems.
When you connect a store, Revvy reads information needed to find conversion problems: page structure and content, template and theme configuration, technical performance such as load times and JavaScript errors, aggregated traffic and conversion patterns, and product and collection page layouts.
Revvy does not access customer payment information, customer passwords or account credentials, personally identifiable customer data, or your order or financial records.
We use analytics to understand how visitors use eulav.io, including pages viewed, approximate location derived from IP address, browser and device type, and referring source. Cookie preferences are managed through the consent banner on your first visit.
We do not use your store data to train models that serve other customers without your explicit consent.
We share information only with service providers who help us operate: hosting and infrastructure, payment processing, analytics, and customer communication. Each is bound by contract to protect your data and use it only for the service they provide to us.
We may disclose information if legally required, or as part of a merger or acquisition, in which case you will be notified before your data becomes subject to a different policy.
We operate in line with GDPR for European users, CCPA for California residents, and PIPEDA for Canadian users, and we maintain SOC 2 aligned security controls.
To exercise any of these, email gtm@eulav.io. We respond within 30 days.
We keep account data for as long as your account is active. After closure we delete or anonymise personal data within 90 days, except where we are legally required to retain records such as invoices.
Data is encrypted in transit and at rest. Access is restricted to staff who need it, and we review our controls regularly. No system is perfectly secure, and if a breach affects your data we will notify you and the relevant regulator within the required timeframe.
Your information may be processed outside your country. Where data leaves the European Economic Area we rely on Standard Contractual Clauses or another approved safeguard.
Our services are for businesses and are not directed at anyone under 16. We do not knowingly collect data from children.
If we make material changes we will update the date at the top of this page and, where the change is significant, notify account holders by email.
Start using the AI that finds what's costing you sales and ships the fix.