Privacy Policy

We respect your privacy and are committed to protecting your personal data. This policy explains what information we collect, how we use it, and your rights.


Effective date

20 September 2026

Last updated

20 September 2026

01

Introduction

Revenue House (“Revenue House”, “we”, “us”) provides fractional revenue operations consultancy services. This Privacy Policy explains how we collect, use, disclose and safeguard personal data when you visit revenue.house or engage with our services.

Please read this policy carefully. By using this website you acknowledge that you have read and understood the practices described here.

02

Data controller

Revenue House is the data controller responsible for the personal data described in this policy.

Revenue House
hello@revenue.house

03

Personal data we collect

3.1 Information you provide directly

Health Check bookings. When you book a Revenue Engine Health Check we collect your first name, surname and email address. You may also optionally tell us what you would like to discuss, your company name and website, and how you came to find us. Bookings are processed through Google Calendar appointment scheduling and the consultation takes place via Google Meet.

Contact enquiries. When you submit the contact form we collect your first name, last name, work email address, company name and the nature of your enquiry, together with any message you choose to add. Submissions are delivered to our Google Workspace inbox and are also stored in the website’s own database, hosted by Hostinger, by the form software used on this site.

Enquiries and booking details are also recorded in our customer relationship management system, where we keep a history of our contact with you.

Newsletter subscriptions. When you subscribe to Insights we collect your email address. The subscription list is hosted and administered by Substack.

Client engagements. In the course of a professional engagement we may receive additional business information, including commercial data, systems documentation and the contact details of your personnel. Such data is governed by the engagement agreement between us and by our duty of professional confidentiality.

3.2 Call recordings

Health Check consultations and client working sessions are recorded with your agreement.

Recording enables the conversation to be given full attention rather than divided between listening and note-taking. Our work product derives directly from these sessions: the Health Check scorecard, the findings and prioritised recommendations of an Audit, and the process documentation produced during a Rebuild are each built from what is discussed. An accurate record is therefore a functional requirement of the engagement rather than an administrative convenience.

Consent is requested at the outset of each session, before recording commences, and Google Meet displays a notice to all participants for the duration of any recording. Where you prefer not to be recorded, the session proceeds on the basis of written notes; we may subsequently need to confirm particular details with you.

Recordings are stored in our Google Workspace environment. Access is limited to those working on your engagement — the principal consultant and any associate or subcontractor engaged on the project, each bound by a written confidentiality undertaking. Where members of your own team are involved in the work, recordings and material derived from them may also be shared with the colleagues you nominate. They are never sold, published, disclosed to any other third party, or used for marketing or for training artificial intelligence models.

3.3 Information collected automatically

Server logs. Our hosting provider and Cloudflare record standard technical information for each request, including IP address, browser type, referring page and timestamp. These records are used for security, abuse prevention and service availability.

Analytics. Subject to your consent, Google Analytics collects information about your visit, including pages viewed, session duration, approximate geographic region and device type. See section 5.

04

Purposes and legal bases for processing

Purpose

Data used

Legal basis (GDPR)

Arranging and preparing for a Health Check

Booking details

Performance of a contract, or steps taken at your request prior to entering into one — Art. 6(1)(b)

Recording consultations to produce an accurate written output

Call recording

Consent — Art. 6(1)(a)

Responding to enquiries

Contact form data

Legitimate interests — Art. 6(1)(f)

Managing enquiries, contacts and client relationships

Name, email, company, enquiry and engagement history

Legitimate interests — Art. 6(1)(f)

Sending the Insights newsletter

Email address

Consent — Art. 6(1)(a)

Measuring website usage

Analytics data

Consent — Art. 6(1)(a)

Maintaining site security and availability

Server logs

Legitimate interests — Art. 6(1)(f)

Delivering contracted services

Engagement data

Performance of a contract — Art. 6(1)(b)

Meeting tax, accounting and professional record obligations

Engagement and billing records

Legal obligation — Art. 6(1)(c)

Where we rely on legitimate interests, we have assessed that our interest in operating and securing the website and in responding to enquiries does not override your rights and freedoms.

05

Cookies and analytics

5.1 Consent

Google Analytics is not loaded and no analytics cookies are placed on your device until you give your consent through the banner presented on your first visit. If you decline, no analytics data is collected and nothing is transmitted to Google.

The same applies to HubSpot’s tracking cookies: they are not loaded until you consent.

You may withdraw or change your consent at any time using the Cookie settings link in the website footer. Withdrawal takes effect immediately and previously placed cookies are cleared.

5.2 Cookies used

Cookie

Provider

Purpose

Duration

_ga, _ga_[ID]

Google Analytics

Distinguishes returning visitors from new ones; supports aggregate usage reporting

Up to 24 months

hubspotutk, __hstc

HubSpot

Associates your website activity with your contact record once you identify yourself

Up to 6 months

__hssc, __hssrc

HubSpot

Tracks the current session and whether the browser was restarted

30 minutes / session

__cf_bm and related

Cloudflare

Distinguishes legitimate visitors from automated traffic; essential to site security

Up to 30 minutes

Functional cookies

WordPress and associated plugins

Page delivery, form handling and spam prevention

Session or short-lived

Cloudflare’s security cookies and the site’s functional cookies are strictly necessary for the operation of the website and are not subject to consent.

5.3 How analytics data is used

Analytics data is used to understand how this website is used and to inform what we publish and offer. It is not used for advertising, and it is not sold or disclosed to third parties for their own purposes.

Where you have given us your details — by booking a consultation or submitting the contact form — we may associate your activity on this website with your record in our customer relationship management system, so that we can see how you came to us and respond in context. This happens only where you have consented to analytics and tracking cookies, and you can withdraw that consent at any time from the Cookie settings link in the footer.

Google Analytics data retention is set at 14 months, after which records are deleted automatically.

06

Disclosure of personal data

We do not sell, rent or trade personal data. We do not disclose personal data to third parties for their own marketing purposes.

Personal data is shared with the following service providers, each acting as a processor or independent controller in connection with the services they supply:

Provider

Services supplied

Google LLC

Email, calendar, appointment scheduling, video conferencing and recording, document storage, analytics

HubSpot, Inc.

Customer relationship management — contact records, enquiry history and engagement pipeline

Substack Inc.

Newsletter distribution and subscriber management

Hostinger International Ltd

Website and database hosting

Cloudflare, Inc.

DNS, content delivery, security

Each provider maintains its own privacy policy governing its handling of data. Where we change the provider in any of these categories, this policy is updated to reflect it.

We may engage associates or subcontractors to work on an engagement. Where they have access to personal data or client materials, they do so only to the extent necessary for that engagement and under written confidentiality obligations no less protective than those in this policy.

We may additionally disclose personal data where required by applicable law, by order of a competent court or regulatory authority, or where necessary to establish, exercise or defend legal claims.

07

International transfers

Our service providers process personal data in jurisdictions including the United States and the European Union. Where personal data originating in the European Economic Area or the United Kingdom is transferred outside those territories, transfers are made on the basis of the European Commission’s Standard Contractual Clauses, the UK International Data Transfer Addendum, or another lawful transfer mechanism relied upon by the provider concerned.

08

Retention

We keep personal data for as long as it serves the purpose it was collected for, and for as long afterwards as we are required to keep records. In practice:

–

Where you become a client, the records of our work together — correspondence, notes and recordings — are kept for the duration of the engagement and for the period afterwards required by tax, accounting and professional record-keeping rules, typically seven years.

–

Where no engagement follows, your enquiry, booking details and contact record are kept while there is a realistic prospect of working together, and deleted once there is not — in practice, around two years from our last contact with you.

–

Newsletter subscriptions are kept until you unsubscribe.

–

Website analytics are deleted automatically after 14 months.

–

Server logs are held for the short periods set by our hosting and security providers, typically 30 days or less.

You may ask us to delete your data at any time. See section 10.

09

Security

We maintain technical and organisational measures appropriate to the nature of the data we hold. These include encrypted transmission (HTTPS), multi-factor authentication on all accounts holding client data, access restricted to personnel and contractors working on the relevant engagement, and the use of established providers with recognised security certifications.

Client materials and call recordings are held in our Google Workspace environment, with access controlled through named accounts. Where work is carried out on a device — including a personally owned device used for business purposes — that device is subject to our security requirements: full-disk encryption, a passcode or biometric lock, automatic screen locking, and the ability to be locked or erased remotely if lost or stolen.

No method of transmission or storage is entirely secure, and we cannot guarantee absolute security.

10

Your rights

Subject to applicable law, you have the right to:

–

Access — obtain confirmation of whether we process your personal data, and a copy of it

–

Rectification — have inaccurate or incomplete data corrected

–

Erasure — request deletion of your data where there is no continuing lawful basis for retaining it

–

Restriction — request that processing be limited in defined circumstances

–

Portability — receive data you provided to us in a structured, machine-readable format

–

Objection — object to processing carried out on the basis of legitimate interests

–

Withdrawal of consent — withdraw consent at any time, including consent to a call recording, without affecting the lawfulness of processing carried out beforehand

To exercise any of these rights, contact us at hello@revenue.house. We will respond within one month of receipt. Where a request is complex we may extend this period by a further two months and will notify you accordingly. No fee is charged.

11

Complaints

If you are dissatisfied with how we have handled your personal data, we ask that you contact us first so that we may address the matter.

If you are located in the European Economic Area or the United Kingdom, you also have the right to lodge a complaint with your national supervisory authority.

12

Children

This website and our services are directed at businesses and are not intended for individuals under the age of 18. We do not knowingly collect personal data from children.

13

Changes to this policy

We may update this policy from time to time to reflect changes in our practices or in applicable law. The effective date at the top of this page indicates when it was last revised. Where a change materially affects how we handle your personal data, we will provide notice through the website and, where appropriate, to newsletter subscribers.

Questions?

We’re here to help.

If you have any questions about this Privacy Policy, please get in touch.

Contact us
Scroll to Top