1. Scope
This Privacy Policy explains how Rivora Finance collects, uses, discloses and protects information when people visit our website, request a demo, authenticate to the application, use a business workspace, receive a secure quote or invoice link, or otherwise interact with Rivora.
2. Information we collect
Depending on how Rivora is used, we may process account information (such as name, email, provider account identifier and role), organization information, customer and lead contact details, job and task information, quote and invoice data, signatures and signature timestamps, documents, activity records, support requests, device/browser information, and information submitted through website forms. We do not ask users to provide their Google or Microsoft password to Rivora.
3. Customer-controlled data
Business customers decide what customer, lead, job and billing data they enter into their workspace. For this information, the business customer is generally responsible for determining the purpose and lawful basis for collection, while Rivora processes the data to provide the service. Our Data Processing Addendum provides additional terms for business customers.
4. How we use information
We use information to provide and secure the service; authenticate users; maintain organization and role permissions; generate quotes, invoices and reports; support electronic signatures; respond to demo and support requests; diagnose errors; prevent abuse; maintain audit and activity records; improve the product; comply with law; and communicate operational notices.
5. Service providers
Rivora relies on service providers to operate the platform. Current infrastructure may include Netlify for web hosting and deployment, Supabase for authentication and database services, and Google or Microsoft identity services when a customer uses those sign-in options. These providers process information according to their own terms and privacy practices and the services we configure with them.
6. Data sharing
We do not sell personal information to advertisers. We may disclose information to service providers that help us operate Rivora, when directed by an authorized organization user, to protect rights or security, in connection with a business transaction, or when required by law.
7. Retention
We retain information for as long as reasonably necessary to provide the service, maintain business and security records, resolve disputes and meet legal obligations. Organization owners should export records they need before closing an account. Backup copies may persist for a limited period after deletion.
8. Security
We use reasonable administrative and technical measures designed to protect information, including identity-provider authentication, organization-level permissions and database access controls. No security measure can guarantee absolute protection. If we learn of a security incident affecting protected information, we will respond in accordance with applicable law and our incident-response procedures.
9. Choices and requests
Authorized users can update certain account and organization data in Rivora. Requests to access, correct or delete personal information may be directed to the business that collected the information or to Rivora at andrew@rivasit.net. We may need to verify identity and authority before completing a request.
10. Children and prohibited data
Rivora is a business service and is not directed to children under 13. Rivora should not be used to intentionally collect children’s data in ways subject to COPPA. Unless a separate written agreement expressly permits it, Rivora must not be used to store PHI or other specially regulated data described in our Acceptable Use Policy.
11. Changes to this policy
We may update this Privacy Policy as the product, service providers or legal requirements change. The effective date above identifies the current version.