Privacy Policy
Last updated: August 8, 2026
This Privacy Policy describes how RivoCRM ("RivoCRM," "we," "us," or "our") collects, uses, discloses, stores, and otherwise processes personal information when you visit our website or use the RivoCRM application and related services (collectively, the "Service").
RivoCRM is currently operated in Canada as an unincorporated business under the name RivoCRM.
This Privacy Policy applies to information for which RivoCRM determines the purposes of processing, as well as information that RivoCRM processes on behalf of customers in providing the Service.
1. Scope
This Privacy Policy applies to:
- visitors to the RivoCRM website;
- individuals who create or use RivoCRM accounts;
- administrators and members of customer workspaces;
- communications with RivoCRM, including support requests; and
- personal information processed through the Service on behalf of customers, including information about real estate contacts, leads, clients, properties, transactions, and related records.
This Privacy Policy does not apply to third-party websites, applications, or services that you access through links or integrations from the Service. Those third parties maintain their own privacy practices and policies.
2. Our Role and Customer Data
Account and Service Data
For information required to create and administer your RivoCRM account, provide subscriptions, secure the Service, provide customer support, and operate our website, RivoCRM generally determines how and why that information is processed.
Customer CRM Data
Customers may upload, create, import, or otherwise process information through RivoCRM about their contacts, leads, buyers, sellers, clients, colleagues, properties, transactions, tasks, communications, and other business activities ("Customer Data").
For Customer Data, the customer generally determines the purposes for which the information is collected and used. RivoCRM processes Customer Data on the customer's behalf as a service provider or processor in order to provide the Service.
Customers are responsible for ensuring that they have all rights, permissions, notices, consents, or other lawful authority required to collect, upload, use, communicate, and instruct RivoCRM to process Customer Data.
If your personal information is stored in RivoCRM by one of our customers and you wish to exercise privacy rights relating to that information, you should normally contact that customer directly. We will assist our customer with applicable privacy requests where appropriate.
3. Information We Collect
Information You Provide
Depending on how you use RivoCRM, we may collect:
Account information
- name;
- email address;
- username and profile information;
- password credentials, which are stored using password hashing rather than as plain-text passwords;
- profile or avatar image; and
- account preferences.
Organization and workspace information
- organization or workspace name;
- organization logo;
- workspace memberships;
- user roles and permissions;
- invitations, including an invitee's email address and assigned role; and
- seat and usage information.
Billing and subscription information
- subscription plan;
- billing status;
- Stripe customer, subscription, invoice, and related identifiers; and
- seat and plan usage.
Payment card information is processed by Stripe. RivoCRM does not intend to store full payment card details in its application database.
CRM and Customer Data
Depending on the features used by a customer, Customer Data may include:
- contact and lead names;
- email addresses;
- telephone numbers;
- mailing or property addresses;
- contact stages and statuses;
- tags;
- notes;
- custom fields;
- property information;
- transaction information;
- prices;
- MLS or listing identifiers;
- important dates;
- linked contacts and parties;
- tasks and reminders;
- activities;
- comments;
- workflow or Autoplan configurations;
- email or SMS content;
- recipient information; and
- files, images, or other content uploaded to the Service.
The precise information stored in RivoCRM is determined in part by the customer using the Service.
Support and communications
When you contact us, we may collect your name, email address, message, attachments, and other information you choose to provide.
AI feature information
If AI features are enabled and you choose to use them, we may process chat messages, prompts, titles, instructions, and relevant contextual information needed to provide the requested AI functionality.
Information From Third Parties
We may receive information from third parties used to provide the Service, including:
- Google, if you use Google authentication or an enabled Google integration;
- Stripe, including subscription, invoice, payment status, and billing event information;
- workspace administrators who invite you to a RivoCRM organization; and
- other integrations that you or your organization choose to connect to RivoCRM.
The information received depends on the integration and the permissions you authorize.
Information Collected Automatically
When you use the Service, we may automatically collect:
- IP address;
- browser and device information;
- user agent;
- pages or application areas viewed;
- access dates and times;
- authentication and session information;
- active organization or workspace context;
- application and server logs;
- security and fraud-prevention information;
- error and diagnostic information; and
- cookie and similar technology information.
When two-factor authentication is enabled, the Service may process information necessary to provide that security feature, including authentication secrets and recovery or backup codes.
4. Hosting and Infrastructure
RivoCRM uses third-party infrastructure providers to operate the Service.
Vercel
The RivoCRM website and application are hosted and delivered using Vercel infrastructure. In providing hosting, deployment, networking, logging, security, and related infrastructure services, Vercel may process technical information and Customer Data as necessary to provide those services.
Neon
RivoCRM uses Neon to provide its hosted PostgreSQL database infrastructure. Information stored in the RivoCRM application database, including account information and Customer Data, may therefore be stored and processed using Neon infrastructure.
Neon itself uses cloud infrastructure providers and may process data in the region configured for the applicable RivoCRM database. RivoCRM may change infrastructure configurations or regions as the Service evolves.
RivoCRM remains responsible for selecting and configuring its service providers appropriately, while those providers maintain responsibility for their respective infrastructure and services under their agreements with RivoCRM.
Additional infrastructure and subprocessors may be used for specific features as described in this Privacy Policy.
5. How We Use Information
We may use personal information to:
- create and administer RivoCRM accounts;
- provide, maintain, and operate the Service;
- authenticate users and manage sessions;
- operate multi-tenant organizations and workspaces;
- apply roles, permissions, and access controls;
- provide CRM, contact, property, transaction, task, workflow, and communication functionality;
- process subscriptions, trials, invoices, and seat limits;
- send account verification, password reset, invitation, security, billing, and other transactional communications;
- send email or SMS communications at a customer's instruction when the customer uses applicable RivoCRM features;
- provide and store uploaded files;
- provide optional AI-enabled functionality;
- respond to support requests;
- troubleshoot errors and improve reliability;
- monitor and protect the Service against abuse, fraud, unauthorized access, and security threats;
- comply with applicable law;
- establish, exercise, or defend legal rights;
- enforce our Terms of Service and other agreements; and
- understand and improve Service performance and usage, including through analytics where required consent has been obtained.
We will not use Customer Data for materially unrelated purposes except with appropriate authorization or where permitted or required by law.
6. AI Features
RivoCRM may offer optional features that use artificial intelligence.
When you use an AI-enabled feature, information necessary to respond to your request may be transmitted to the applicable AI service provider. This may include the prompt or message you submit and relevant context selected by the feature.
Because CRM records may contain personal information about clients and other individuals, users should not submit information to an AI feature unless they are authorized to process that information for the intended purpose.
RivoCRM does not use Customer Data to train RivoCRM's own general-purpose foundation models.
Third-party AI providers process information according to RivoCRM's arrangements with those providers and their applicable service terms. The specific providers used may change as RivoCRM's AI functionality evolves.
AI-generated information may be inaccurate or incomplete. Customers remain responsible for reviewing outputs before relying on them or using them in communications, transactions, or business decisions.
7. Service Providers and Subprocessors
We use service providers to help operate RivoCRM. Depending on the features enabled, these may include providers for:
- application hosting and delivery, including Vercel;
- database hosting, including Neon;
- payment processing, including Stripe;
- transactional and application email;
- SMS and telecommunications;
- file and object storage;
- authentication and identity services;
- AI functionality;
- bot and abuse prevention;
- application monitoring and error diagnostics; and
- analytics.
These providers may process information only to the extent necessary to provide their services to RivoCRM, subject to applicable contractual arrangements and law.
We may maintain or publish additional information about subprocessors as the Service develops.
8. How We Disclose Information
We may disclose personal information:
To service providers. We disclose information to infrastructure and technology providers where necessary to operate the Service.
Within your organization. Information may be visible to workspace owners, administrators, team members, assistants, or other authorized users according to the roles, permissions, and features configured for the organization.
For support and security. Authorized RivoCRM personnel may access account or Customer Data where reasonably necessary to investigate support requests, security incidents, abuse, or technical problems. Where product functionality permits support impersonation or similar administrative access, such access will be limited to authorized operational purposes.
For legal purposes. We may disclose information where reasonably necessary to comply with law, regulation, court orders, lawful government requests, or to protect the rights, security, and safety of RivoCRM, our customers, users, or others.
Business transactions. Information may be transferred in connection with a merger, financing, acquisition, reorganization, sale of assets, or similar transaction, subject to applicable legal requirements.
We do not sell personal information for money.
9. International Processing and Transfers
RivoCRM operates from Canada, but our infrastructure and service providers may operate in Canada, the United States, and other countries.
As a result, personal information may be stored or processed outside your province, territory, or country of residence. Information processed in another jurisdiction may be subject to the laws of that jurisdiction and may be accessible to courts, law-enforcement agencies, or government authorities in accordance with applicable law.
We use contractual, technical, and organizational measures appropriate to the nature of the information and our use of service providers.
10. Cookies and Similar Technologies
RivoCRM may use cookies and similar technologies that are necessary to:
- authenticate users;
- maintain sessions;
- remember preferences;
- provide security features;
- prevent abuse; and
- operate core functionality.
Where analytics or other non-essential cookies are used and consent is required, RivoCRM will provide appropriate choices.
Additional information is provided in our Cookie Policy.
11. Analytics
RivoCRM may use privacy-conscious website or application analytics to understand Service performance and usage.
Where required, non-essential analytics will only be enabled after appropriate consent. Users may be able to withdraw analytics consent through the cookie or privacy controls provided by the Service.
12. Communications
RivoCRM may send transactional communications necessary to operate your account, including:
- email verification;
- password reset messages;
- workspace invitations;
- security notifications;
- billing and subscription messages;
- service notices; and
- important product or policy notices.
Where RivoCRM sends its own marketing communications, we will provide unsubscribe functionality where required by applicable law.
Customer-Sent Communications
RivoCRM may provide functionality allowing customers to send email or SMS messages to contacts.
Customers are responsible for ensuring that they have all necessary consent or other lawful authority to send those communications and for complying with applicable communications and anti-spam laws, including Canada's Anti-Spam Legislation (CASL), where applicable.
Customers are also responsible for honoring applicable unsubscribe, opt-out, and consent requirements.
13. Data Retention
We retain account information and Customer Data for as long as reasonably necessary to:
- provide the Service;
- maintain an active customer relationship;
- satisfy the purposes described in this Privacy Policy;
- comply with legal, accounting, tax, or regulatory requirements;
- resolve disputes;
- prevent fraud or abuse; and
- enforce our agreements.
Customers may delete certain records through the Service where that functionality is available.
When an account or organization is deleted, we will delete or de-identify associated personal information within a reasonable period, except where continued retention is necessary or permitted for legal, security, fraud-prevention, backup, billing, or other legitimate purposes.
Deleted information may remain temporarily in backups, logs, or disaster-recovery systems until those systems are overwritten or the applicable retention period expires.
We intend to document more specific retention periods as our infrastructure and operational procedures mature.
14. Security
We use reasonable administrative, technical, and organizational safeguards designed to protect information against unauthorized access, loss, misuse, alteration, or disclosure.
Depending on the system and feature, safeguards may include:
- encrypted network connections;
- password hashing;
- authentication and session controls;
- optional two-factor authentication;
- role-based permissions;
- tenant and organization access controls;
- infrastructure access restrictions;
- logging and monitoring;
- managed cloud infrastructure; and
- backup and recovery procedures.
No internet-based service or storage system can guarantee absolute security.
Users are responsible for maintaining the confidentiality of their credentials, enabling available security features where appropriate, and configuring workspace roles and permissions carefully.
15. Security Incidents and Data Breaches
If we become aware of a breach of security safeguards involving personal information, we will investigate and respond in accordance with applicable law.
Where required by applicable privacy law, we will notify affected individuals and applicable regulators and maintain records of security breaches as required.
Customers should promptly contact RivoCRM if they believe their account, credentials, or Customer Data may have been compromised.
16. Your Privacy Rights
Depending on your location and applicable law, you may have rights relating to your personal information, which may include the right to:
- request access to personal information;
- request correction of inaccurate information;
- request deletion in certain circumstances;
- request information about how personal information is used or disclosed;
- withdraw consent where processing is based on consent, subject to legal or contractual restrictions; and
- make a complaint about our privacy practices.
Canada
RivoCRM is based in Canada and handles personal information in accordance with applicable Canadian privacy requirements, including the principles of the Personal Information Protection and Electronic Documents Act (PIPEDA) where applicable.
Individuals may request access to or correction of personal information held by RivoCRM, subject to applicable exceptions and legal limitations.
Requests Concerning Customer CRM Data
If your information appears in a RivoCRM customer's CRM records, that customer generally controls the information.
You should first direct your request to the business or organization that collected your information. RivoCRM will provide reasonable assistance to our customer in responding to valid privacy requests where required.
Account Privacy Requests
For personal information associated directly with your RivoCRM account or your interactions with RivoCRM, contact our Privacy Officer using the information below.
We will not discriminate against individuals for exercising privacy rights provided by applicable law.
17. Children
RivoCRM is a business productivity service and is not directed to children.
The Service is not intended for individuals under 16 years of age, or a higher minimum age where required by applicable law. We do not knowingly solicit personal information from children for the purpose of creating RivoCRM accounts.
If we learn that personal information has been collected from a child in circumstances where it should not have been collected, we will take appropriate steps to address it.
18. Customer Data Ownership
As between RivoCRM and the customer, customers retain their rights in the Customer Data they submit to the Service.
Customers grant RivoCRM the rights necessary to host, copy, transmit, process, display, back up, and otherwise handle Customer Data solely as necessary to provide, secure, maintain, and support the Service, comply with the customer's lawful instructions, and as otherwise permitted by the customer's agreement with RivoCRM and applicable law.
RivoCRM does not acquire ownership of a customer's CRM contact database merely because the information is stored using the Service.
19. Privacy Accountability
RivoCRM has designated a Privacy Officer responsible for overseeing privacy inquiries and our privacy practices.
Our privacy program may include policies and procedures relating to:
- access to personal information;
- service-provider management;
- security safeguards;
- retention and deletion;
- incident response;
- privacy requests; and
- employee or contractor access to information.
We review and update these practices as the Service develops.
20. Changes to This Privacy Policy
We may update this Privacy Policy as RivoCRM, our infrastructure, our features, or applicable legal requirements change.
When we update the Policy, we will revise the "Last updated" date at the top of this page.
If changes are material, we may provide additional notice through the Service, website, or email where appropriate.
Your continued use of the Service after an updated Privacy Policy becomes effective is subject to applicable law and our Terms of Service.
21. Contact Us
For questions, privacy requests, or complaints relating to this Privacy Policy or RivoCRM's handling of personal information, contact:
RivoCRM Privacy Officer
RivoCRM
Canada
Email: info@rivocrm.app
Mailing address: Address available on request