Revinate
GDPR evidence
We power 950 million+ guest profiles and $17.2 billion in direct revenue for over 12,500 hotels
Revinate and GDPR
Revinate states it holds a data processing agreement. CertReports captured this on 18 Sep 2026 from its trust centre (Vanta); it is a vendor statement, not an independent confirmation.
Evidence
- Kind
- listing
- Issued or listed
- 4 Jun 2018
- Expires or valid through
- 29 Aug 2027
- Scope
- Revinate collects Personal Data for the purposes of providing services and Revinate's solutions to its hospitality customers to support them in their marketing efforts. We receive and store any information provided by our customers to us through the Services. Some of our products allow our hospitality business customers (hotels and restaurants) to provide Personal Data to us from their guest management systems. This information may include first and last name, title, company name, e-mail address, telephone number, postal address, the hotels where guests stayed, the dates of their stay, transactional data such as the amount paid for a hotel room, and guest preferences you provided to our customer, such as preferred floor. All this data is processed to provide marketing and hotel reservation services. We may provide personal data to subprocessors in order to maintain business operations or improve performance of our product. We keep our list of subprocessors available to customers at: https://www.revinate.com/subprocessors/
| Source | Captured | Quote | Links |
|---|---|---|---|
Data Privacy Framework list Official registry · HTTP 200 | 17 Sep 2026 | Revinate: Active: EU-US Certification, SW-US Certification, UK Extension Certification | Live pagesha256 55e1bf2220 |
What GDPR means, and what it does not
"GDPR compliant" is a claim, not a certification. The verifiable facts are a public DPA, SCC usage, an EU representative, data residency options and a Data Privacy Framework listing.
Read the GDPR guide and browse all vendors with evidenceQuestions buyers ask
Is Revinate GDPR compliant?
There is no GDPR certification in general use. The verifiable facts are a public data processing agreement, standard contractual clauses, an EU representative and a Data Privacy Framework listing. See the legal artefacts and the DPF row on this page, each with its capture date.
How does CertReports verify this?
Every state carries a capture date, a source and a snapshot link. Registry rows come from the official registry data; vendor statements come from the vendor’s own page or trust centre; nothing is inferred. Vendors can dispute any row and corrections ship within two business days.
Change history
- 18 Sep 2026GDPR evidence addedA GDPR row entered the index with state Vendor-stated.
- 18 Sep 2026Subprocessor added: Amazon Web ServicesAmazon Web Services appeared on the subprocessor list.
- 18 Sep 2026Subprocessor added: ApifyApify appeared on the subprocessor list.
- 18 Sep 2026Subprocessor added: CrowdStrikeCrowdStrike appeared on the subprocessor list.
- 18 Sep 2026Subprocessor added: Google Cloud PlatformGoogle Cloud Platform appeared on the subprocessor list.
- 18 Sep 2026Subprocessor added: LeanDataLeanData appeared on the subprocessor list.
- 18 Sep 2026Subprocessor added: MarketoMarketo appeared on the subprocessor list.
Alternatives with GDPR evidence
Similar vendors (shared product tags) whose GDPR row is verified or vendor-stated, ranked by similarity.
No same-category vendor has GDPR evidence in the index yet.