Legal

Cookie Policy

Last updated: August 8, 2026

This Cookie Policy explains how RivoCRM ("RivoCRM," "we," "us," or "our") uses cookies, local storage, and similar technologies when you visit the RivoCRM website or use the RivoCRM application and related services (collectively, the "Service").

RivoCRM is currently operated in Canada as an unincorporated business under the name RivoCRM.

This Cookie Policy should be read together with our Privacy Policy.

1. What Are Cookies and Similar Technologies?

Cookies are small pieces of information that a website may store in your browser or on your device.

We may also use similar browser technologies, including:

  • local storage;
  • session storage;
  • authentication tokens;
  • security tokens; and
  • other browser-based storage mechanisms.

These technologies can be used to keep you signed in, remember preferences, maintain security, record privacy choices, understand Service performance, and provide other functionality.

For simplicity, this Policy may refer to cookies and similar technologies collectively as "cookies" unless a distinction is important.

2. Categories of Technologies We Use

RivoCRM may use the following categories of cookies and similar technologies.

Strictly Necessary Technologies

These technologies are required to operate, secure, or provide core functionality of the Service.

They may be used for purposes such as:

  • authenticating users;
  • maintaining login sessions;
  • protecting accounts;
  • preventing cross-site request forgery and similar attacks;
  • maintaining security state;
  • preventing automated abuse;
  • maintaining an active organization or workspace context;
  • processing privacy or cookie preferences; and
  • enabling other functionality necessary for the Service to work.

Because these technologies are necessary to provide the Service or a feature you request, they may operate even if you decline optional analytics.

Examples may include authentication/session information created by RivoCRM's authentication system and security information required to protect login, signup, or contact forms.

Preference and Functionality Technologies

RivoCRM may use browser storage to remember choices that improve your experience.

Examples may include:

  • light or dark theme preference;
  • sidebar state or width;
  • interface preferences;
  • previously selected workspace or organization context; and
  • other application preferences.

These technologies generally remember choices you make rather than being used for advertising.

Consent Storage

When RivoCRM displays privacy or cookie controls, we may store your selection in your browser so that we can remember it on future visits.

For example, the Service may use a local-storage value such as cookie_consent to record whether optional analytics have been accepted or declined.

This preference may remain on your device until it expires, is replaced, or you clear your browser's site data.

3. Analytics and Performance

RivoCRM may use Vercel Web Analytics, Vercel Speed Insights, and Google Analytics 4 to understand website usage and application performance.

These services may provide information such as:

  • page views;
  • routes visited;
  • referral information;
  • browser or device characteristics;
  • general geographic information;
  • website and application performance; and
  • Core Web Vitals and related performance measurements.

Vercel Web Analytics is designed as privacy-focused first-party analytics and does not rely on traditional tracking cookies to identify visitors across different websites.

Google Analytics 4 is a third-party analytics service operated by Google. When enabled, it may set or read cookies and similar technologies and may receive usage information about your visits. Google's processing of that information is governed by Google's own privacy and terms documentation.

Even where an analytics technology does not use traditional cookies, RivoCRM may choose to activate optional analytics only after you provide consent through our privacy controls.

If our consent controls are configured this way and you decline optional analytics, we will not intentionally load those optional analytics tools for that browser session or future visits while your preference remains stored.

RivoCRM does not currently use third-party advertising cookies for behavioural advertising.

4. Authentication and Sessions

RivoCRM uses authentication and session technologies to keep users securely signed in and associate requests with the correct account and organization.

Depending on our authentication implementation, this may involve secure cookies, tokens, or other browser storage.

Authentication technologies may:

  • identify an authenticated session;
  • protect login state;
  • maintain security information;
  • expire after a defined period;
  • be renewed while an account remains active; or
  • be deleted when you sign out.

Blocking authentication technologies may prevent you from signing in or using the RivoCRM application.

For security reasons, this Policy does not publish sensitive implementation details about authentication tokens or security mechanisms.

5. Cloudflare Turnstile and Bot Protection

RivoCRM may use Cloudflare Turnstile to help protect signup, login, contact, or other forms against automated abuse and malicious activity.

Turnstile may process technical signals about a visitor's browser or device to determine whether a request appears to come from a legitimate user rather than an automated system.

Turnstile generates a short-lived verification token that must be validated by RivoCRM's server before a protected action is accepted.

Depending on how Turnstile and Cloudflare security features are configured, Cloudflare may use cookies or similar technologies necessary to provide security and bot-protection functionality.

These technologies are treated as security-related rather than advertising technologies.

If RivoCRM enables a Turnstile configuration that requires additional privacy disclosures, we will update our privacy documentation accordingly.

6. Payments and Stripe

If you purchase a RivoCRM subscription or use billing functionality, you may interact with Stripe.

Stripe may use cookies and similar technologies as necessary to:

  • process payments;
  • prevent fraud;
  • authenticate payment activity;
  • provide checkout or billing functionality; and
  • maintain the security of its services.

Cookies or technologies used directly by Stripe are governed by Stripe's applicable privacy and cookie practices.

RivoCRM does not control all cookies or similar technologies that may be used on third-party payment pages.

7. Google Authentication and Integrations

If RivoCRM offers Sign in with Google or another Google integration and you choose to use it, your browser may communicate directly with Google.

Google may use cookies or similar technologies necessary to:

  • authenticate your Google account;
  • obtain your authorization;
  • maintain the security of the authentication process; and
  • provide the integration you request.

Google's own technologies are subject to Google's applicable privacy practices.

You do not need to use Google authentication unless the Service specifically requires it for a feature you choose.

8. Error Monitoring and Operational Diagnostics

RivoCRM may use error-monitoring, logging, and diagnostic tools to identify software errors, security issues, failed requests, and performance problems.

Depending on the provider and configuration, these tools may receive technical information such as:

  • browser and device information;
  • application route;
  • error messages;
  • timestamps;
  • request information; and
  • diagnostic context.

Operational monitoring that is reasonably necessary to secure, troubleshoot, and maintain the Service may operate independently of optional marketing or analytics consent.

We configure operational tools with the goal of limiting collection to information reasonably necessary for reliability and security.

We will update this Policy if we introduce monitoring technologies that materially change how cookies or similar technologies are used.

9. Third-Party Technologies

Depending on the features you use and our current production configuration, third parties that may receive browser or device information include:

ProviderPurpose
VercelApplication hosting and delivery; optional Web Analytics and Speed Insights
GoogleOptional Google Analytics 4; authentication or integrations when selected
StripePayments, subscriptions, checkout, billing, and fraud prevention
CloudflareTurnstile bot protection and related security functionality when enabled

Other providers may be added as RivoCRM develops.

The inclusion of a provider in this Policy does not necessarily mean that the provider places a cookie on every visit. Whether a provider receives information depends on the feature, page, configuration, and your choices.

Third-party services maintain their own privacy and data-handling practices.

10. Cookie and Analytics Choices

RivoCRM Privacy Controls

Where RivoCRM presents a cookie or privacy banner, you may be given the choice to accept or decline optional analytics.

Your choice may be stored in local storage or another browser-based mechanism so that we can remember it.

Strictly necessary security, authentication, session, and core functionality technologies may continue to operate even if you decline optional analytics.

Changing Your Choice

Where available, you may change your analytics preference using RivoCRM's cookie or privacy controls.

You may also clear the stored preference through your browser's site-data settings. If you clear the preference, RivoCRM may ask you to make a selection again on a future visit.

11. Browser Controls

Most browsers allow you to control cookies and site storage.

Depending on your browser, you may be able to:

  • view stored cookies and site data;
  • delete cookies;
  • clear local storage;
  • block cookies;
  • block third-party cookies; or
  • configure different settings for individual websites.

Blocking all cookies or browser storage may prevent important RivoCRM functionality from working correctly, including authentication, preferences, and security features.

Refer to the privacy or site-data settings provided by your browser for current instructions.

12. Retention

Different cookies and browser-storage technologies remain for different periods depending on their purpose and configuration.

Session and Authentication Data

Authentication and session information may expire when you sign out, when the browser session ends, or after the authentication session reaches its configured expiration period.

Some authentication sessions may persist across browser restarts where persistent login functionality is enabled.

Preferences

Interface preferences, theme settings, and cookie-consent selections stored in local storage may remain until:

  • you clear the site's browser data;
  • RivoCRM replaces or removes the stored value; or
  • the application is changed to use a different storage mechanism.

Security Information

Security and bot-protection tokens may be short-lived or retained for a period determined by the security provider and applicable configuration.

Analytics

Analytics and performance information is retained according to RivoCRM's configuration and the applicable service provider's retention practices.

We may change retention configurations as our infrastructure evolves.

13. Do Not Track and Global Privacy Signals

Browsers and devices may provide "Do Not Track" or other privacy preference signals.

Because there is not a single universally applicable technical or legal standard for every such signal, RivoCRM may not respond to every browser signal in the same way.

Where applicable law requires recognition of a legally valid opt-out preference signal for a particular type of processing, we will take reasonable steps to comply.

RivoCRM does not currently use third-party behavioural advertising cookies or sell personal information for advertising purposes.

14. Changes to This Cookie Policy

We may update this Cookie Policy as our Service, infrastructure, analytics, security tools, integrations, or legal obligations change.

When we update the Policy, we will revise the "Last updated" date at the top of this page.

If a change materially affects how optional cookies or similar technologies are used, we may provide additional notice or request a new consent choice where appropriate or required.

15. Contact Us

For questions about this Cookie Policy or RivoCRM's privacy practices, contact:

RivoCRM Privacy Officer

RivoCRM
Canada
Email: info@rivocrm.app
Mailing address: Address available on request

Additional information about how RivoCRM handles personal information is available in our Privacy Policy.