Acceptable Use Policy
Last updated: August 8, 2026
This Acceptable Use Policy ("AUP") governs use of the RivoCRM website, application, and related services (collectively, the "Service").
RivoCRM is currently operated in Canada as an unincorporated business under the name RivoCRM ("RivoCRM," "we," "us," or "our").
This AUP forms part of the RivoCRM Terms of Service. Capitalized terms not defined in this AUP have the meanings given to them in the Terms of Service.
By accessing or using the Service, you agree to comply with this AUP.
1. Purpose
RivoCRM is designed to help real estate professionals and related businesses manage contacts, leads, properties, transactions, tasks, workflows, communications, and other business activities.
This AUP is intended to protect:
- RivoCRM customers and users;
- clients, leads, contacts, and other individuals whose information may be processed through the Service;
- the security, integrity, and availability of RivoCRM;
- our infrastructure and service providers;
- email and telecommunications networks; and
- RivoCRM's ability to provide a reliable and lawful Service.
You are responsible for ensuring that your use of RivoCRM complies with all laws, professional obligations, brokerage policies, and other requirements applicable to you.
2. General Requirement
You may use RivoCRM only for lawful and legitimate business purposes consistent with the functionality of the Service.
You may not use the Service, and may not permit or assist another person to use the Service, in a manner prohibited by this AUP.
3. Illegal, Fraudulent, or Harmful Activity
You must not use the Service to:
- engage in, facilitate, promote, or assist unlawful activity;
- commit or facilitate fraud, deception, identity theft, or financial crime;
- impersonate another person or organization without authorization;
- knowingly provide materially false or misleading information;
- violate applicable privacy, data-protection, consumer-protection, anti-spam, telecommunications, export-control, or professional regulations;
- threaten, harass, abuse, stalk, or unlawfully discriminate against another person;
- exploit, endanger, or unlawfully collect information about minors;
- distribute unlawful or malicious content;
- infringe another person's intellectual-property, privacy, publicity, confidentiality, contractual, or other legal rights; or
- use RivoCRM in connection with activity that creates a material risk of harm to RivoCRM, our users, our providers, or third parties.
4. Email, SMS, Autoplans, and Messaging
If you use RivoCRM to send or automate email, SMS, or other communications, you must do so responsibly and lawfully.
You must not:
- send spam or unsolicited bulk communications;
- send commercial electronic messages without the consent or other lawful authority required by applicable law;
- send messages to recipients who have validly opted out where continued messaging is prohibited;
- intentionally disguise or falsify sender identity or contact information;
- use misleading subject lines or deceptive message content;
- use RivoCRM to conduct unlawful robocalling, automated texting, or telemarketing;
- repeatedly contact recipients in a manner that is abusive or harassing;
- use purchased, scraped, harvested, or unlawfully obtained contact lists where you do not have the rights or lawful basis necessary to contact those individuals;
- circumvent sending limits, suppression lists, unsubscribe systems, carrier restrictions, or provider anti-abuse controls; or
- use Autoplans or other automation features to avoid legal obligations that would apply if the communication were sent manually.
You are responsible for compliance with laws applicable to your communications, which may include Canada's Anti-Spam Legislation ("CASL"), the U.S. CAN-SPAM Act, the Telephone Consumer Protection Act ("TCPA"), and similar laws in other jurisdictions.
Where required, you are responsible for:
- obtaining and documenting consent;
- accurately identifying the sender;
- including required contact information;
- providing a valid unsubscribe or opt-out mechanism;
- processing opt-out requests within legally required periods; and
- maintaining any records necessary to demonstrate compliance.
RivoCRM may impose sending limits, restrict communication functionality, block messages, or suspend sending privileges where reasonably necessary to prevent abuse, protect recipients, preserve deliverability, comply with provider requirements, or comply with law.
5. Contact and Lead Data
You may store and process contact or lead information through RivoCRM only where you have the right or lawful authority to do so.
You must not:
- import unlawfully obtained personal information;
- scrape websites, directories, social networks, MLS systems, or other sources in violation of applicable law or contractual restrictions;
- upload purchased or third-party lead databases where your possession or intended use of the information is unlawful;
- use contact information for a materially different unlawful purpose from the purpose for which it was obtained;
- knowingly maintain information obtained through identity theft, fraud, unauthorized account access, or other unlawful activity; or
- instruct RivoCRM to process information in a manner that violates applicable privacy or data-protection law.
RivoCRM does not independently verify the legal basis for every contact or record you upload. Responsibility for the lawful collection and use of Customer Data remains with you as described in the Terms of Service.
6. Real Estate and Professional Use
RivoCRM provides software and does not replace your professional responsibilities.
If you are a real estate professional, brokerage, team, assistant, administrator, or other regulated professional, you must use the Service consistently with the obligations applicable to you.
You must not use RivoCRM to:
- knowingly violate brokerage policies that apply to your use of client information;
- knowingly violate applicable real estate regulatory requirements;
- improperly disclose confidential client information;
- intentionally circumvent required brokerage supervision or approvals;
- falsify transaction, client, property, or compliance records;
- misrepresent your identity, brokerage affiliation, professional role, registration, licensing, or authorization;
- access records belonging to another agent, team, organization, or CRM book without authorization; or
- use information obtained through RivoCRM for an unauthorized purpose.
You are responsible for determining whether particular documents or categories of sensitive information are appropriate to store in RivoCRM.
Unless RivoCRM expressly provides a feature intended for a particular regulated document or recordkeeping requirement, you should not assume that storing information in RivoCRM by itself satisfies your brokerage, regulatory, legal, or professional recordkeeping obligations.
7. Privacy and Confidential Information
You must respect the privacy and confidentiality of individuals whose information you process through RivoCRM.
You must not:
- access personal information without authorization;
- disclose Customer Data to persons who are not authorized to receive it;
- intentionally expose another person's credentials, authentication secrets, financial account credentials, or other highly sensitive secrets;
- upload confidential information that you have no right to possess or process;
- use Customer Data for unlawful surveillance, harassment, discrimination, or profiling; or
- attempt to use RivoCRM to discover information belonging to another customer or organization.
You are responsible for assigning appropriate roles and permissions to your organization's users and removing access when it is no longer required.
8. Account and Access Abuse
You must not:
- access another person's account without authorization;
- share credentials to circumvent seat, user, or subscription limits;
- create accounts using false identities for abusive or fraudulent purposes;
- sell, rent, transfer, or provide unauthorized access to RivoCRM accounts;
- use another person's session, authentication token, API credential, or security credential without authorization;
- attempt to take over another user's account;
- abuse password-reset, invitation, verification, or authentication systems; or
- use administrative, support, impersonation, or organization-management features to obtain access to information you are not authorized to view.
If you discover that you can access information you believe you should not be able to access, stop accessing that information and report the issue to RivoCRM.
9. Security and Service Integrity
You must not interfere with or compromise the security, integrity, availability, or performance of the Service.
Without our prior written authorization, you must not:
- probe, scan, or test the vulnerability of RivoCRM or its infrastructure;
- conduct penetration testing against the Service;
- bypass or attempt to bypass authentication or authorization controls;
- circumvent rate limits, quotas, usage controls, security measures, or access restrictions;
- exploit or attempt to exploit vulnerabilities;
- introduce malware, ransomware, spyware, viruses, worms, malicious scripts, or harmful code;
- intentionally cause excessive traffic or resource consumption;
- conduct denial-of-service or distributed denial-of-service activity;
- interfere with another customer's use of the Service;
- attempt to obtain database, server, infrastructure, or administrative credentials;
- intercept communications or traffic without authorization; or
- attempt to access RivoCRM infrastructure outside the interfaces and functionality made available to you.
Good-faith security researchers should obtain written authorization from RivoCRM before performing active security testing.
10. Scraping, Automated Access, and Bots
You must not use automated systems to access or interact with RivoCRM in a manner that is unauthorized or harmful.
Unless expressly permitted by RivoCRM, you must not:
- scrape non-public Service content;
- spider or crawl authenticated areas of the Service;
- systematically extract data belonging to other customers;
- use bots to create accounts;
- generate artificial traffic, usage, clicks, or activity;
- automate requests in a manner designed to bypass Service limits;
- use unauthorized scripts or tools to interact with private APIs; or
- use automated systems in a manner that materially degrades Service performance.
You may use export, API, integration, automation, and similar functionality that RivoCRM expressly provides to you, subject to the limits and permissions associated with those features.
You may export your own Customer Data using functionality made available by RivoCRM.
11. Files, Content, and Malicious Material
Content uploaded, stored, generated, or transmitted through RivoCRM must comply with this AUP.
You must not knowingly upload, store, or distribute:
- malware or malicious executable code;
- files intended to compromise a system or account;
- content you are legally prohibited from possessing or distributing;
- content that infringes intellectual-property rights;
- unlawfully obtained personal or confidential information;
- credentials or secrets belonging to third parties that you are not authorized to process; or
- content designed primarily to facilitate fraud, abuse, or attacks against another person or system.
RivoCRM does not routinely pre-screen all Customer Data.
However, we may investigate, restrict, quarantine, disable access to, or remove content where we reasonably believe doing so is necessary to protect the Service, comply with law, respond to a valid legal request, or enforce this AUP.
12. AI Features
If RivoCRM provides AI-enabled functionality, you must use those features lawfully and responsibly.
You must not knowingly use RivoCRM AI features to:
- facilitate fraud or impersonation;
- generate unlawful spam or deceptive outreach;
- evade legal or professional obligations;
- obtain unauthorized access to information;
- submit personal or confidential information that you do not have authority to process;
- create malicious code intended to compromise systems; or
- make automated decisions about individuals where doing so would violate applicable law.
AI outputs may be inaccurate or incomplete. You remain responsible for reviewing AI-generated content before using it in professional work, client communications, transactions, or business decisions.
13. Intellectual Property and Competitive Misuse
You must respect RivoCRM's intellectual property and the rights of our licensors.
Except to the extent expressly permitted by applicable law or authorized by RivoCRM, you must not:
- copy non-public RivoCRM software or source code;
- reverse engineer, decompile, or attempt to derive non-public source code;
- remove proprietary notices;
- reproduce substantial portions of the Service for unauthorized commercial purposes;
- use unauthorized extraction techniques to reproduce RivoCRM's non-public interfaces, workflows, or proprietary materials; or
- access the Service primarily for the purpose of copying non-public functionality to create a substantially competing product.
Nothing in this section prevents lawful interoperability, security research expressly authorized by RivoCRM, or activities that cannot legally be restricted.
14. Excessive or Abusive Resource Use
You must not use the Service in a way that unreasonably consumes resources or materially affects other users.
Examples may include:
- unusually high automated request volumes;
- deliberate attempts to bypass plan limits;
- excessive storage of data unrelated to legitimate use of RivoCRM;
- repeated generation of communications that cause provider complaints or blocklisting;
- abusive API or automation activity; or
- workloads that threaten Service stability.
We may apply reasonable technical limits, throttling, quotas, or temporary restrictions to protect Service reliability.
Where practical, we will attempt to contact you before imposing a material restriction for ordinary excessive usage.
15. Third-Party Services
Your use of integrations or third-party services through RivoCRM must also comply with any applicable terms, policies, and restrictions imposed by those providers.
You must not use RivoCRM to circumvent a third-party provider's security controls, usage restrictions, messaging policies, or legal requirements.
Violations that threaten RivoCRM's relationship with an infrastructure, payment, email, telecommunications, AI, authentication, or other provider may result in restriction or suspension of the affected feature or account.
16. Enforcement
We may investigate suspected violations of this AUP.
Depending on the nature, severity, frequency, and risk of the conduct, we may:
- contact you for additional information;
- issue a warning;
- require corrective action;
- limit usage;
- throttle activity;
- block particular content or communications;
- disable an integration or feature;
- temporarily suspend an account or organization;
- remove content where legally permitted and reasonably necessary; or
- terminate access in accordance with the Terms of Service.
Where reasonably practicable, we will consider the circumstances and attempt to use a proportionate response.
We may take immediate action without advance notice where we reasonably believe it is necessary to:
- prevent imminent harm;
- stop fraud or abuse;
- protect Customer Data;
- respond to a security incident;
- preserve Service availability;
- comply with law or a valid legal request; or
- protect RivoCRM, our customers, our providers, or third parties from material risk.
17. Cooperation and Investigation
You agree to reasonably cooperate with investigations into suspected abuse, security incidents, unauthorized access, or violations associated with your account.
We may preserve relevant account information, logs, or Customer Data where reasonably necessary to investigate an incident, comply with law, enforce our agreements, or protect legal rights.
Where required by law, we may report suspected unlawful activity to appropriate authorities or respond to lawful requests for information.
18. Reporting Abuse and Security Issues
If you believe RivoCRM is being used in violation of this AUP, contact:
Email: info@rivocrm.app
Please provide enough information for us to understand and investigate the issue.
If you discover a potential security vulnerability, do not exploit it, access Customer Data beyond what is necessary to identify the issue, or publicly disclose it before giving RivoCRM a reasonable opportunity to investigate.
Security reports may also be sent to:
Email: info@rivocrm.app
19. Changes to This AUP
We may update this AUP as the Service, our features, applicable laws, or abuse and security risks evolve.
When we update this AUP, we will revise the "Last updated" date at the top of this page.
For material changes, we may provide additional notice through the Service, website, or email where appropriate.
Continued use of the Service after an updated AUP becomes effective constitutes acceptance to the extent permitted by applicable law.
20. Contact Us
Questions about this AUP may be sent to:
RivoCRM
RivoCRM
Canada
Email: info@rivocrm.app
Mailing address: Address available on request
Privacy-related questions should be directed to the RivoCRM Privacy Officer as described in our Privacy Policy.