Privacy Policy
Last updated: April 20, 2026
Rivvak (“we,” “us”) builds and operates custom AI agent systems for marketing agencies. This page describes what data we collect when you visit rivvak.com or use our products, what we do with it, and the rights you have over it.
1. What we collect
- Contact details you give us: name, email, company, phone, anything you type into a form (quote, contact, demo request).
- Account data: if you log into the dashboard, we store your authentication identity (email + auth-provider subject) and the workspaces/agents you create.
- Usage telemetry: standard server logs (IP, user agent, timestamps, request paths, status codes) and anonymous performance metrics for pages you visit.
- Integration data: if you connect a third-party tool (Apollo, Instantly, Gmail, HubSpot, etc.) we store the minimum access credentials and the data your agents need to do their job. We do not copy your full CRM into our systems.
- Payment data: handled by our payment processor (Stripe). We never see your card number.
2. How we use it
- Run the product you signed up for.
- Respond to you when you reach out.
- Debug, monitor, and improve the service.
- Send operational and (if you opt in) marketing email.
- Meet legal, tax, and security obligations.
We do not sell your personal data. We do not use your account data or agent-integration data to train third-party models.
3. Who we share it with
Only with:
- Infrastructure providers that host and run the service (Vercel for hosting; Upstash for key/value storage; Cloudflare for networking).
- AI providersyou've opted into via the product (Anthropic, OpenAI, Puter.js, and local Ollama models running on our infrastructure). Content you send through an agent is forwarded to whichever provider is routed for that turn.
- Payment processor (Stripe) for billing.
- Email service provider for transactional + opt-in marketing email.
- Legal recipients when required by subpoena, court order, or applicable law.
4. Retention
- Contact submissions: 24 months from last activity.
- Account and agent data: for the life of your account, plus 30 days after cancellation.
- Server logs: 30 days rolling.
- Billing records: 7 years (tax).
5. Your rights
You can request access, correction, deletion, or export of your personal data. You can opt out of marketing email at any time via the link in any marketing message. If you're in the EEA, UK, or California, you have the full rights under GDPR, UK GDPR, or CCPA/CPRA respectively. We respond to verified requests within 30 days.
To exercise a right, email support@rivvak.com with the subject “Privacy Request”.
6. Cookies
We use a minimal set of strictly-necessary cookies for authentication and session management. We do not use third-party advertising or cross-site tracking cookies.
7. Security
Data is encrypted in transit (TLS 1.2+) and at rest. Access to production systems is role-based and logged. We run dependency scans and security reviews before releases. No system is perfect — if you believe you've found a vulnerability, email support@rivvak.com with “Security” in the subject and we'll respond within 72 hours.
8. Children
Rivvak is a B2B service and not intended for anyone under 16. We do not knowingly collect personal data from children.
9. International transfers
Rivvak is operated from Florida, USA. If you access the service from outside the US, your data will be transferred to and processed in the US and in whichever regions our infrastructure providers operate. We use contractual safeguards (Standard Contractual Clauses where applicable) to protect cross-border transfers.
10. Changes
We'll update this page when our practices change and revise the “Last updated” date above. Material changes to how we handle your data will also be communicated by email where you have an account.
11. Contact
Rivvak — Wellington, Florida, USA — support@rivvak.com
This policy is written in plain language, not legalese. Where local law imposes stricter obligations, those obligations apply.