Skip to main content

Cookie Policy

Reviyo uses no advertising cookies, no analytics cookies, and no third-party trackers. This page lists every single thing we store in your browser, and explains why that means you do not get a consent banner.

Last updated: 30 September 2026 · Version 2026-09-30.1

1. The short version

We store nothing in your browser except what is strictly necessary to run the page you asked for.

No Google Analytics. No Meta Pixel. No advertising tags. No cross-site tracking. No profiling. No selling. Nothing we could show you a “reject all” button for, because there is nothing optional to reject.

2. If you are a customer scanning a QR code

The review page at /r/… sets no cookies at all, and stores nothing of its own on your device.

The random session identifier that ties the steps of your visit together is held in the page’s memory only, for as long as the tab is open. Close the tab and it is gone from your device. It is never written to a cookie, to local storage, or to session storage, and it cannot be read by any other site.

The one exception, for completeness: if you happen to be signed in to a Reviyo business account in the same browser — for example a shop owner previewing their own page — then the sign-in item described in clause 3 is already present on your device. It is not set by the review page, it plays no part in the review flow, and your review session is not linked to it.

3. If you have a Reviyo account

Signing in stores your session so you are not asked for your password on every page, and two tools on the QR code page remember what you typed into them, on your own device. Here is everything that involves:

Browser storage used by Reviyo
NameTypePurposeLifetime
sb-yagchgwgbttxfihlyddm-auth-tokenLocal storage (first-party, set by us)Holds your signed-in session and refresh token so you stay signed in. Without it, the dashboard cannot work.Until you sign out, or the session expires.
reviyo:whatsapp-message:…Local storage (first-party, set by us)Remembers the WhatsApp review-request message you wrote, so it is ready next time on this device.Until you clear site data.
reviyo:qr-codes:…Local storage (first-party, set by us)Remembers the names of the extra QR codes you made (for example “Table 4”), so you can download them again.Until you remove the code, or clear site data.

That is the complete list. The first item is set by Supabase, our authentication provider; the other two are set by Reviyo and hold only text you typed. All three stay on our own origin: no other website can read them, they contain no advertising identifier, and they are not used to track you anywhere.

You can clear them at any time by clearing site data in your browser settings. That signs you out and resets the saved message and code names on this device; QR codes you have already printed keep working.

4. The one third-party script, and when it loads

Reviyo loads exactly one third-party script: checkout.razorpay.com, the Razorpay payment checkout.

It is deliberately constrained:

  • It is not on the landing page, the pricing page, the review page, or any policy page.
  • It loads only on the Billing page, only after you are signed in, and only at the moment you click a button to start a payment.
  • If you never start a payment, it never loads and Razorpay sets nothing in your browser.
  • Once it loads, Razorpay sets its own cookies to run the checkout and to detect payment fraud. Those are strictly necessary to take a payment you asked to make.

Razorpay’s own privacy policy governs what it stores at that point: razorpay.com/privacy.

There are no other embeds anywhere on Reviyo — no YouTube, no Google Fonts fetched from Google’s servers, no Maps iframe, no social widgets, no chat widget, no A/B testing tool, no session-replay tool, no heatmaps.

5. Our analytics and visit counts do not use cookies

The dashboard shows a business how many people opened its review page, started a review, generated a draft, and opened Google. That is real, and it is worth being precise about how it works:

  • The counts are recorded server-side, in our own database, against the in-memory session identifier described in clause 2.
  • No cookie, pixel, beacon, or third-party analytics service is involved.
  • We do not record your IP address, user agent, device fingerprint, advertising ID, or location with these counts.
  • The data cannot identify you, cannot follow you to another website, and is never shared with an advertiser.

We also count visits to our own public pages (the home page, pricing, guides, and policies) so we know which pages people read. Each visit adds one to a daily total for that page, stored with the date and, on the page you arrived at, the name of the website that linked you (for example, google.com). Nothing else is sent: no cookie, no identifier, and nothing stored in your browser, and the same limits in the list above apply. Customer review pages and the signed-in app are never counted.

This is why neither kind of count changes the answer in clause 6: there is no tracking technology in your browser to consent to.

6. Why you do not see a cookie consent banner

You were probably expecting one. Here is the honest reasoning, so you can check it yourself.

Under Indian law

India has no cookie-specific rule. The DPDPA, 2023 is a general consent law about processing personal data — it has no equivalent of the EU’s ePrivacy Directive and does not require a banner for storing information on a device. Our obligation under the DPDPA is to give you a clear, itemised notice and to obtain consent for the personal data we actually process. We do that at the point of collection: on the review page before you write anything, and at signup. It is set out in full in our Privacy Policy.

Under EU/UK law, if it applies to us

Article 5(3) of the ePrivacy Directive requires prior consent for storing or reading information on a user’s device, except where it is strictly necessary to provide a service the user explicitly requested. Every item in clause 3 and clause 4 falls squarely inside that exemption — keeping you signed in when you asked to sign in, remembering what you typed into a dashboard tool so that tool works, and running a checkout when you clicked “pay”. We have no non-essential storage at all.

The conclusion

A consent banner exists to let you refuse optional tracking. We have no optional tracking, so a banner would offer you a choice that does not exist. Showing one anyway — with a “reject” button that changes nothing — would be theatre, and arguably a dark pattern of the kind the Central Consumer Protection Authority’s 2023 guidelines discourage.

If we ever add analytics, advertising, or any other non-essential tracking, we will add a real consent banner with a genuine reject option before we turn it on, and we will update this page first.

7. Controlling browser storage yourself

You can block or delete cookies and local storage in any browser’s settings, and you can use private browsing. Blocking storage for this site will sign you out and prevent you from signing in again, because the sign-in session has nowhere to live. It will not affect the review page, which stores nothing.

Reviyo does not respond to the Do Not Track header, because there is nothing for us to stop doing.

8. Questions

If any of the above turns out not to match what you observe in your browser’s developer tools, we want to know. Email support@reviyo.in and we will fix either the behaviour or this page.