Privacy Policy
Effective date: August 14, 2026
This Privacy Policy describes how [Company Name] (“we,” “us,” or “our”) collects, uses, and shares information when you use the RiversideIQ platform (“Service”). By using the Service, you consent to the practices described here.
1. Information We Collect
a. Account information
When you create an account, we collect your first and last name, email address, and a hashed password. We never store your password in plain text.
b. Billing information
Payment is processed by Stripe. We do not receive or store your full credit card number. Stripe provides us with a token, the last four digits of your card, card brand, and billing status. Please refer to Stripe’s Privacy Policy for details on how they handle payment data.
c. Usage data
We automatically collect information about how you interact with the Service, including pages visited, searches performed, filters applied, CSV exports downloaded, and timestamps. This data is used to improve the Service and enforce usage quotas.
d. Device and log data
When you access the Service, our servers automatically log your IP address, browser type, operating system, referring URL, and access times. This information is used for security monitoring and debugging.
e. Cookies
We use cookies and similar technologies for the following purposes:
- Essential cookies: Required to keep you signed in and to maintain your session. These cannot be disabled while using the Service.
- Analytics cookies: Help us understand how the Service is used so we can improve it. You may decline these via the cookie banner.
You can manage cookie preferences at any time through your browser settings. Disabling essential cookies may prevent you from using certain features.
2. How We Use Your Information
We use the information we collect to:
- Provide, maintain, and improve the Service.
- Process payments and manage your subscription.
- Send you the weekly breach digest and service-related emails.
- Enforce our Terms of Service and usage quotas.
- Detect and prevent fraud, abuse, and security incidents.
- Respond to your requests and support inquiries.
3. How We Share Your Information
We do not sell your personal information. We share information only in the following circumstances:
Service providers
We use the following third-party services to operate the platform. Each processes data on our behalf and is bound by their own privacy policies:
- Supabase — database hosting and authentication
- Stripe — payment processing and subscription management
- Resend — transactional and digest email delivery
- Vercel — application hosting and CDN
Legal requirements
We may disclose your information if required by law, regulation, legal process, or governmental request, or when we believe disclosure is necessary to protect our rights, your safety, or the safety of others.
Business transfers
If [Company Name] is involved in a merger, acquisition, or sale of assets, your information may be transferred as part of that transaction. We will notify you of any such change.
4. Data Retention
We retain your account information for as long as your account is active. If you cancel your subscription and request account deletion, we will delete your personal data within 30 days, except where retention is required by law (e.g., billing records for tax purposes). Aggregated, anonymized usage data may be retained indefinitely.
5. Data Security
We implement industry-standard security measures to protect your information, including encryption in transit (TLS), hashed passwords, and access controls. However, no method of transmission or storage is 100% secure, and we cannot guarantee absolute security.
6. Your Rights
All users
You may at any time:
- Access and update your account information.
- Cancel your subscription through the billing portal.
- Request deletion of your account and personal data by emailing jcrook72@gmail.com.
- Opt out of non-essential cookies via the cookie banner.
California residents (CCPA)
If you are a California resident, you have the right to:
- Know what personal information we collect and how it is used.
- Delete your personal information, subject to certain exceptions.
- Opt out of sale — we do not sell personal information, so this right is satisfied by default.
- Non-discrimination — we will not discriminate against you for exercising your privacy rights.
To exercise these rights, email jcrook72@gmail.com with the subject line “CCPA Request.” We will verify your identity and respond within 45 days.
7. Children’s Privacy
The Service is not directed to individuals under 18. We do not knowingly collect personal information from children. If we learn that we have collected information from a child under 18, we will delete it promptly.
8. International Users
The Service is hosted in the United States and is intended for US-based users. If you access the Service from outside the United States, your information will be transferred to and processed in the United States. By using the Service, you consent to this transfer.
9. CAN-SPAM Compliance
Our weekly digest emails and service announcements comply with the CAN-SPAM Act. Each email includes our physical mailing address and a way to unsubscribe. You can opt out of digest emails by managing your subscription through the billing portal or by contacting us. We honor opt-out requests within 10 business days.
10. Changes to This Policy
We may update this Privacy Policy from time to time. If we make material changes, we will notify you by email or by posting a notice on the Service at least 30 days before the changes take effect. Your continued use of the Service after the effective date constitutes acceptance of the revised policy.
11. Contact Us
If you have questions about this Privacy Policy, contact us at:
[Company Name]
Email: jcrook72@gmail.com