Rivetra Data Rights, Deletion and Retention Policy

Policy version: 2026-07-12

Effective date: July 12, 2026

This Policy explains how to request access, correction, export, selected-data deletion, user-account deletion, company-workspace deletion, integration disconnection, or an appeal.

1. Available Requests

Subject to identity, authority, legal applicability, and retention obligations, an eligible requestor may ask Rivetra to:

Rivetra does not currently sell personal data or use personal data for targeted advertising. Universal opt-out signals are recognized where legally required.

2. How to Submit a Request

Use one of these methods:

Include the account email, company name or ID if applicable, the request type, and enough detail to locate the affected records. Do not email passwords, full payment credentials, government ID numbers, or unnecessary sensitive data.

3. Identity and Authority Verification

Rivetra must protect company, employee, client, financial, and signed-document records from unauthorized deletion or export. We may verify account access, email, request history, company role, device or session evidence, and additional information reasonably necessary to authenticate the request.

A company owner or admin may request company-level actions. A user may request actions concerning their own account. Employees, subcontractors, contractor clients, property owners, and vendors may need to direct company-controlled requests to the contractor company. An authorized agent must provide evidence of authority, and Rivetra may verify directly with the individual.

Rivetra will not request more verification data than reasonably necessary. Opt-out requests will not be subjected to authentication when law prohibits it, although limited information may be needed to apply the preference.

4. User Account Deletion

Deleting a user account removes or anonymizes the user's profile, credentials, sessions, device registrations, optional personalization, and other associated personal data that Rivetra does not need to retain. Company-owned business records created by that user may remain, with the creator replaced by a deleted or anonymized reference where appropriate.

If the user is the only company administrator, Rivetra may require transfer of authority, company closure, or additional verification before deletion.

5. Selected Data Deletion

Authorized users may delete or request deletion of selected data without closing the account, including eligible photos, drafts, messages, integration connections, OAuth tokens, AI conversations, or other records. Deletion may be limited when the record is part of a signed document, financial ledger, payment history, security investigation, or another retained business record.

6. Company Workspace Deletion

Only a verified company owner or authorized administrator may request deletion of an entire workspace. Rivetra may notify other admins, place the workspace in a review or export period, and require resolution of active subscriptions, legal holds, payment disputes, or ownership conflicts.

Workspace deletion removes or anonymizes eligible clients, jobs, drafts, photos, documents, team profiles, messages, integration data, and configuration. Records subject to a retention exception are restricted from ordinary product use and retained only for the applicable purpose.

7. Integration Disconnection

Disconnecting Plaid, Stripe, Meta, Wix, Webflow, Google, or another available provider causes Rivetra to revoke or delete usable access and refresh tokens where supported. Synced records may remain when they are part of accounting, payment, publishing, security, or audit history. The provider may retain data under its own terms and legal obligations.

Disconnecting an integration at Rivetra does not necessarily close the third-party account or remove Rivetra from the provider's own app-management page. Users may need to revoke access with the provider as well.

8. Retention Exceptions

Rivetra may deny, limit, delay, anonymize, or restrict deletion when reasonably necessary to:

Where practical, retained records are minimized, access-restricted, and anonymized. Rivetra will explain a material limitation unless prohibited by law or doing so would compromise security.

9. Timing

Rivetra applies the Oregon Consumer Privacy Act response framework to verified U.S. privacy requests: it responds without undue delay and within 45 days. Rivetra may extend the response once by an additional 45 days when reasonably necessary and will give notice and an explanation within the initial period.

Time needed to obtain information required to authenticate identity or company authority may affect processing where permitted by law. Google Play account deletion requests will remain available through both an in-app path and a public web resource.

10. Appeals

If Rivetra denies or limits a privacy-right request, the response will explain the reason and provide appeal instructions where required. Submit an appeal through the same request channel with the subject "Rivetra privacy appeal." Rivetra will decide the appeal within 45 days and, if denied, provide information for contacting the Oregon Attorney General. California requests also receive the verification, authorized-agent, non-discrimination, and access/correction/deletion/portability treatment stated in the Privacy Policy.

11. Subscription Cancellation

Deleting data, closing an account, or uninstalling Rivetra does not cancel a Google Play subscription. Cancel recurring billing separately at:

https://play.google.com/store/account/subscriptions

12. Completion

After completion, Rivetra will identify the categories deleted, anonymized, disconnected, or retained, subject to security and legal limitations. A minimal record of the request, verification, decision, and completion may be retained to demonstrate compliance.

13. Contact

L&B Superior Services, LLC, doing business as Rivetra

Attention: Rivetra Privacy

5441 S Macadam Avenue, Suite R, Portland, Oregon

Email: privacy@rivetra.app