How RivalProof handles information
Privacy Policy
Effective and last updated:
This Privacy Policy explains how RivalProof collects, uses, discloses, and retains personal information through its website, business communications, competitor research service, and customer accounts. It also explains the choices available to you.
1. Scope and responsible business
This Policy applies to RivalProof's website and services. It does not govern third-party websites, including competitor pages and services linked from a report.
RivalProof is responsible for the personal information described in this Policy. RivalProof is a United States business service intended for business representatives who are at least 18 years old.
2. Information we collect
Depending on how you interact with RivalProof, we may collect:
- Contact and account information: name, work email, job role, organization, authentication identifiers, account role, and communication preferences.
- Customer setup information: brand name, website, competitor names and domains, business priorities, approved source URLs, time zone, report recipients, and instructions.
- Service content: comments, feedback, support messages, report questions, approved findings, reports, and review decisions.
- Billing information: billing contact, transaction status, plan, Stripe customer and subscription identifiers, invoices, and payment history. Stripe receives and processes full payment card details. RivalProof does not store complete card numbers.
- Technical and security information: IP address, browser and device information, request timestamps, authentication events, audit records, error details, and essential cookie or session identifiers.
- Public research information: approved public URLs, page titles, ad-library entries, public creator-program materials, official online-store information, visible text, short proof excerpts, dates, technical records that show whether a page changed, saved copies of cleaned page text, and selected screenshots or page files. Public sources may incidentally contain a person's name or professional role, but RivalProof does not intentionally collect sensitive personal information from monitored sources.
- Business prospect information: business name, website, industry, professional name and role, publicly listed or provider-supplied business contact information, the source of that information, outreach history, and do-not-contact status.
Please do not provide Social Security numbers, government identification, personal health information, account passwords, private competitor data, or other sensitive personal information.
3. Where information comes from
We collect information directly from customers and prospects, from use of the website and service, from payment and authentication providers, from publicly accessible business websites and libraries, from official platform access, and from business research or contact-data providers. Customers may also provide authorized business-content exports and information about authorized team members and report recipients. Customers must not provide private messages, audience-level personal data, or sensitive personal information in an export.
4. How we use information
We use information to:
- review submitted competitors, evidence sources, and requests;
- create accounts and control authorized workspace access;
- check approved public pages, identify changes, save proof, and prepare reports;
- use automated analysis and human review to classify and explain observed changes;
- deliver reports, alerts, account notices, and support;
- process payments and manage subscriptions;
- enforce plan limits, prevent duplicate processing, and measure service costs;
- secure the service, investigate abuse, debug failures, and maintain audit records;
- send relevant one-to-one business outreach and record opt-out requests;
- comply with law and resolve disputes; and
- improve research accuracy, report usefulness, and service reliability.
RivalProof does not use Customer reports or confidential instructions to train a public artificial intelligence model. RivalProof does not make decisions that produce legal or similarly significant effects about individuals.
5. How we disclose information
We may disclose information to:
- Service providers: hosting, database, storage, authentication, payment, email, artificial intelligence, web research, scheduling, security, and business research providers that process information to perform services for RivalProof. Current core providers include Netlify, Supabase, Stripe, Resend, OpenAI, and GitHub.
- Customer-authorized users: owners, team members, report recipients, and agency representatives with authorized access to the relevant workspace or report.
- Legal and safety recipients: courts, regulators, law enforcement, or other parties when reasonably necessary to comply with law, protect rights or safety, investigate fraud, or enforce agreements.
- Transaction participants: advisers and counterparties involved in a financing, reorganization, merger, acquisition, or sale, subject to appropriate confidentiality and use restrictions.
- Other recipients you direct: parties you ask us to contact or with whom you authorize us to share a report.
RivalProof does not sell personal information for money. RivalProof does not share personal information for cross-context behavioral advertising and does not use third-party advertising trackers.
6. Artificial intelligence
When a supported public page changes, RivalProof may send the relevant before-and-after text, source context, and Customer priorities to an artificial intelligence provider to produce structured analysis. RivalProof limits the submitted material to what is reasonably needed for that task and applies human review where required by the service. Customers should not include personal or sensitive information in research instructions.
7. Cookies and tracking signals
RivalProof uses essential cookies or similar storage needed for sign in, security, session continuity, and core site functions. RivalProof does not currently use advertising cookies or third-party behavioral analytics.
Some browsers offer a “Do Not Track” signal. Because there is no uniform standard for that signal and RivalProof does not use cross-site behavioral advertising, the service does not currently respond differently to it. Where applicable law requires recognition of a browser-based opt-out preference for sale or targeted advertising, RivalProof will honor that signal. RivalProof does not currently engage in either activity.
8. Retention
RivalProof keeps information only as long as reasonably needed for the purposes described in this Policy, including service delivery, security, billing, dispute resolution, and legal obligations.
- Raw page assets and screenshots are normally retained for up to 30 days.
- Saved page text, page comparisons, and related proof not included in a report are normally kept for up to 12 months.
- Evidence included in a report, reports, account records, customer instructions, and audit records are retained while the account is active and afterward only as reasonably needed for the stated purposes.
- Billing and transaction records may be retained as required for tax, accounting, fraud prevention, and dispute obligations.
- Prospect records are retained while outreach remains relevant. Do-not-contact information may be retained longer so that RivalProof can honor the request.
When information is deleted from active systems, limited copies may remain in encrypted or access-controlled backups until those backups expire or are safely overwritten.
9. Security
RivalProof uses administrative and technical safeguards designed for the nature of the information it handles. These include access controls, tenant separation, encrypted network transport, server-side secrets, signed billing webhooks, audit records, and restricted provider access. No online system can guarantee absolute security.
If you believe information associated with RivalProof has been compromised, contact RivalProof promptly through the contact method below.
10. Your choices and privacy requests
Depending on your location and relationship with RivalProof, you may have the right to request access to, correction of, deletion of, or a portable copy of personal information. You may also object to or restrict certain uses and appeal a denied request where applicable.
To make a request, use the contact method below and describe the request. RivalProof may ask for information needed to verify identity and authority. An authorized agent may submit a request when permitted by law, but RivalProof may require proof of authorization. RivalProof will not discriminate against a person for exercising an applicable privacy right.
You may opt out of sales outreach at any time by replying to the message or contacting RivalProof. Transactional messages needed to provide a purchased service may continue while the service remains active.
11. United States processing
RivalProof and its core providers operate in the United States. Information may be processed and stored in the United States, where privacy laws may differ from those in another country. The service is currently offered to United States businesses.
12. Children
RivalProof is not directed to children and is not offered to anyone under 18. RivalProof does not knowingly collect personal information from children under 13. If you believe a child has provided personal information, contact RivalProof so the information can be reviewed and deleted where appropriate.
13. Changes to this Policy
RivalProof may update this Policy as the service, providers, or legal requirements change. The effective date at the top will be updated. RivalProof will provide reasonable additional notice before a material change applies to active customers.
14. Contact
Privacy questions and requests may be submitted through the contact page or by email to hello@rivalproof.com.