Cookie Policy
Reviyo uses no advertising cookies, no analytics cookies, and no third-party trackers. This page lists every single thing we store in your browser, and explains why that means you do not get a consent banner.
Last updated: 30 September 2026 · Version 2026-09-30.1
1. The short version
We store nothing in your browser except what is strictly necessary to run the page you asked for.
No Google Analytics. No Meta Pixel. No advertising tags. No cross-site tracking. No profiling. No selling. Nothing we could show you a “reject all” button for, because there is nothing optional to reject.
2. If you are a customer scanning a QR code
The review page at /r/… sets no cookies at all, and stores nothing of its own on your device.
The random session identifier that ties the steps of your visit together is held in the page’s memory only, for as long as the tab is open. Close the tab and it is gone from your device. It is never written to a cookie, to local storage, or to session storage, and it cannot be read by any other site.
The one exception, for completeness: if you happen to be signed in to a Reviyo business account in the same browser — for example a shop owner previewing their own page — then the sign-in item described in clause 3 is already present on your device. It is not set by the review page, it plays no part in the review flow, and your review session is not linked to it.
3. If you have a Reviyo account
Signing in stores your session so you are not asked for your password on every page, and two tools on the QR code page remember what you typed into them, on your own device. Here is everything that involves:
| Name | Type | Purpose | Lifetime |
|---|---|---|---|
sb-yagchgwgbttxfihlyddm-auth-token | Local storage (first-party, set by us) | Holds your signed-in session and refresh token so you stay signed in. Without it, the dashboard cannot work. | Until you sign out, or the session expires. |
reviyo:whatsapp-message:… | Local storage (first-party, set by us) | Remembers the WhatsApp review-request message you wrote, so it is ready next time on this device. | Until you clear site data. |
reviyo:qr-codes:… | Local storage (first-party, set by us) | Remembers the names of the extra QR codes you made (for example “Table 4”), so you can download them again. | Until you remove the code, or clear site data. |
That is the complete list. The first item is set by Supabase, our authentication provider; the other two are set by Reviyo and hold only text you typed. All three stay on our own origin: no other website can read them, they contain no advertising identifier, and they are not used to track you anywhere.
You can clear them at any time by clearing site data in your browser settings. That signs you out and resets the saved message and code names on this device; QR codes you have already printed keep working.
4. The one third-party script, and when it loads
Reviyo loads exactly one third-party script: checkout.razorpay.com, the Razorpay payment checkout.
It is deliberately constrained:
- It is not on the landing page, the pricing page, the review page, or any policy page.
- It loads only on the Billing page, only after you are signed in, and only at the moment you click a button to start a payment.
- If you never start a payment, it never loads and Razorpay sets nothing in your browser.
- Once it loads, Razorpay sets its own cookies to run the checkout and to detect payment fraud. Those are strictly necessary to take a payment you asked to make.
Razorpay’s own privacy policy governs what it stores at that point: razorpay.com/privacy.
There are no other embeds anywhere on Reviyo — no YouTube, no Google Fonts fetched from Google’s servers, no Maps iframe, no social widgets, no chat widget, no A/B testing tool, no session-replay tool, no heatmaps.
5. Our analytics and visit counts do not use cookies
The dashboard shows a business how many people opened its review page, started a review, generated a draft, and opened Google. That is real, and it is worth being precise about how it works:
- The counts are recorded server-side, in our own database, against the in-memory session identifier described in clause 2.
- No cookie, pixel, beacon, or third-party analytics service is involved.
- We do not record your IP address, user agent, device fingerprint, advertising ID, or location with these counts.
- The data cannot identify you, cannot follow you to another website, and is never shared with an advertiser.
We also count visits to our own public pages (the home page, pricing, guides, and policies) so we know which pages people read. Each visit adds one to a daily total for that page, stored with the date and, on the page you arrived at, the name of the website that linked you (for example, google.com). Nothing else is sent: no cookie, no identifier, and nothing stored in your browser, and the same limits in the list above apply. Customer review pages and the signed-in app are never counted.
This is why neither kind of count changes the answer in clause 6: there is no tracking technology in your browser to consent to.
7. Controlling browser storage yourself
You can block or delete cookies and local storage in any browser’s settings, and you can use private browsing. Blocking storage for this site will sign you out and prevent you from signing in again, because the sign-in session has nowhere to live. It will not affect the review page, which stores nothing.
Reviyo does not respond to the Do Not Track header, because there is nothing for us to stop doing.
8. Questions
If any of the above turns out not to match what you observe in your browser’s developer tools, we want to know. Email support@reviyo.in and we will fix either the behaviour or this page.
