RivalGauge
Data processing addendum
The terms covering personal data we handle on your behalf. It applies automatically to every account, so there is nothing to sign and nothing to request.
This addendum is already in force for your account. It forms part of the terms of service and applies from the moment you open an account. You do not need to ask for a countersigned copy. If your own compliance process requires a signed document, write to support@rivalgauge.com and we will sign this text unchanged.
Parties and scope
This addendum is between Safe Haven Ventures LLC, a Colorado limited liability company trading as RivalGauge (we, us, the processor), and the customer who holds the account (you, the controller). It covers personal data we process on your behalf in providing the service, and it prevails over the general terms wherever the two conflict on that subject.
Who is who
You are the controller. We are the processor. The widget sits on your website, the people who use it are giving their details to you, and you decide why you collect them and what you do next. We process them to deliver the report, record the lead, and make it available to you.
For your own account data, meaning your company name, your account email and your billing record, we are the controller and the privacy page describes that handling.
Having a lawful basis to contact the people who use your widget is your responsibility. It is your form, on your site, under your brand. We do not market to them, we do not sell their details, and we never use one customer's leads to serve another.
What is processed
| Item | Detail |
|---|---|
| Subject matter | Providing the website scanning and lead capture service |
| Duration | For as long as your account is open, plus the retention described below |
| Nature and purpose | Collecting a lead's details, generating and delivering a report, storing the lead record, and delivering it to the destinations you configure |
| Categories of data subject | Visitors to your website who submit your widget |
| Categories of personal data | Email address, the website domain submitted, the trade and city submitted, the origin the widget was embedded on, and the resulting report |
| Special category data | None. The service neither requests nor requires it, and it must not be submitted through the widget |
Our obligations
- We process personal data only on your documented instructions. Your use of the service, and the settings you choose in it, are those instructions.
- We do not sell personal data, and we do not use it to train models. The AI visibility check is sent the trade and city only; no lead identity and no scanned domain reach a model provider.
- Everyone with access is bound by confidentiality.
- We make available the information needed to show compliance with this addendum, and we will answer reasonable written audit questions. Where a physical audit is genuinely required by law, we will agree a scope that does not compromise other customers' data.
- If we believe an instruction breaks data protection law, we will tell you rather than quietly comply.
Security
The measures actually in place today, rather than a generic list:
- All traffic is served over HTTPS with HSTS. Data at rest lives in Cloudflare's managed database and object storage.
- Payment card details never reach us. They are entered on Stripe's own hosted page.
- Dashboard access is by a short-lived, single-use sign-in link sent to the account address, exchanging into a server-side session that can be revoked. Sign-in tokens are stored as hashes, never as values.
- Webhook deliveries are signed with HMAC-SHA256 so your receiver can verify the payload came from us unaltered, and delivery targets are checked to prevent requests to internal network addresses.
- Each account's data is isolated by tenant, and every request is resolved to exactly one account before any record is read.
- Shareable report pages are unguessable, marked no-index, and expire 90 days after the scan.
We do not claim a certification we do not hold. We are not SOC 2 or ISO 27001 audited, and this page will say so until that changes.
Subprocessors
You give general authorisation for us to engage subprocessors. The current list, what each is for and what each sees, is published at subprocessors. We impose data protection obligations on each one no less protective than these, and we remain responsible to you for their performance.
Changes are notified as described on that page, including your right to object and cancel with a refund of the unused remainder.
Data subject requests
If a person contacts us directly about data we hold for you, we will not respond substantively on your behalf. We will tell them to contact you and let you know it happened.
You can satisfy most requests yourself from the dashboard, which shows every lead your widget captured. Where you need our help to access, correct, export or delete a record, write to support@rivalgauge.com and we will assist within a reasonable period and at no charge.
Every report email carries a one click unsubscribe header and an opt out link. A person who opts out is added to a suppression list checked before any further send.
Incidents
If we become aware of a personal data breach affecting data we process for you, we will notify you without undue delay and in any case within 72 hours of becoming aware, with what we know: what happened, which categories and roughly how many records, the likely consequences, and what we are doing. Notice goes to your account email address, so keep it current.
International transfers
We are a United States company and the service is operated from the United States. Where you are subject to UK or EU data protection law and personal data is transferred out of that jurisdiction, the transfer is made under the applicable Standard Contractual Clauses, which are incorporated into this addendum by reference, with us as data importer and you as data exporter. The subprocessor list identifies where each party operates.
Return and deletion
Lead records are kept while your account is open, so your list is there when you come back for it. On request after closing your account we delete them. Shareable report pages expire on their own 90 days after the scan. Billing records are kept for as long as tax and accounting rules require, which is a legal obligation rather than a choice, and backups age out on their ordinary cycle.
Governing law
This addendum is governed by the laws of the State of Colorado, and the courts located in Denver County, Colorado have exclusive jurisdiction, matching the terms of service. Nothing in it limits rights that cannot be limited by the data protection law that applies to you.