Rivetra Data Rights, Deletion and Retention Policy
Policy version: 2026-07-12
Effective date: July 12, 2026
This Policy explains how to request access, correction, export, selected-data deletion, user-account deletion, company-workspace deletion, integration disconnection, or an appeal.
1. Available Requests
Subject to identity, authority, legal applicability, and retention obligations, an eligible requestor may ask Rivetra to:
- confirm whether Rivetra processes personal data;
- provide access or a portable copy;
- correct inaccurate account or profile data;
- identify specific third-party recipients where required by law;
- delete selected personal data or connected-account data;
- delete a user account and associated personal data;
- close and delete an entire company workspace;
- opt out of sale, targeted advertising, or qualifying profiling;
- withdraw consent for future optional processing; or
- appeal a denial.
Rivetra does not currently sell personal data or use personal data for targeted advertising. Universal opt-out signals are recognized where legally required.
2. How to Submit a Request
Use one of these methods:
- in-app Settings > Privacy and Data;
- public request page:
https://rivetra.app/data-deletion/; or - email: privacy@rivetra.app with the subject "Rivetra privacy request."
Include the account email, company name or ID if applicable, the request type, and enough detail to locate the affected records. Do not email passwords, full payment credentials, government ID numbers, or unnecessary sensitive data.
3. Identity and Authority Verification
Rivetra must protect company, employee, client, financial, and signed-document records from unauthorized deletion or export. We may verify account access, email, request history, company role, device or session evidence, and additional information reasonably necessary to authenticate the request.
A company owner or admin may request company-level actions. A user may request actions concerning their own account. Employees, subcontractors, contractor clients, property owners, and vendors may need to direct company-controlled requests to the contractor company. An authorized agent must provide evidence of authority, and Rivetra may verify directly with the individual.
Rivetra will not request more verification data than reasonably necessary. Opt-out requests will not be subjected to authentication when law prohibits it, although limited information may be needed to apply the preference.
4. User Account Deletion
Deleting a user account removes or anonymizes the user's profile, credentials, sessions, device registrations, optional personalization, and other associated personal data that Rivetra does not need to retain. Company-owned business records created by that user may remain, with the creator replaced by a deleted or anonymized reference where appropriate.
If the user is the only company administrator, Rivetra may require transfer of authority, company closure, or additional verification before deletion.
5. Selected Data Deletion
Authorized users may delete or request deletion of selected data without closing the account, including eligible photos, drafts, messages, integration connections, OAuth tokens, AI conversations, or other records. Deletion may be limited when the record is part of a signed document, financial ledger, payment history, security investigation, or another retained business record.
6. Company Workspace Deletion
Only a verified company owner or authorized administrator may request deletion of an entire workspace. Rivetra may notify other admins, place the workspace in a review or export period, and require resolution of active subscriptions, legal holds, payment disputes, or ownership conflicts.
Workspace deletion removes or anonymizes eligible clients, jobs, drafts, photos, documents, team profiles, messages, integration data, and configuration. Records subject to a retention exception are restricted from ordinary product use and retained only for the applicable purpose.
7. Integration Disconnection
Disconnecting Plaid, Stripe, Meta, Wix, Webflow, Google, or another available provider causes Rivetra to revoke or delete usable access and refresh tokens where supported. Synced records may remain when they are part of accounting, payment, publishing, security, or audit history. The provider may retain data under its own terms and legal obligations.
Disconnecting an integration at Rivetra does not necessarily close the third-party account or remove Rivetra from the provider's own app-management page. Users may need to revoke access with the provider as well.
8. Retention Exceptions
Rivetra may deny, limit, delay, anonymize, or restrict deletion when reasonably necessary to:
- comply with tax, accounting, employment, licensing, payment-network,
- preserve invoices, ledgers, payments, ACH authorizations, signed envelopes,
- complete a transaction requested by the user;
- establish, exercise, or defend legal claims;
- resolve fraud, chargebacks, refunds, abuse, or security incidents;
- protect another person's rights or company-owned records;
- honor a legal hold or government request;
- maintain backups until ordinary secure rotation; or
- retain a minimal suppression record so deleted data is not reintroduced.
signature, contract, lien, insurance, or other legal obligations;
notice evidence, and transaction-level audit trails;
Where practical, retained records are minimized, access-restricted, and anonymized. Rivetra will explain a material limitation unless prohibited by law or doing so would compromise security.
9. Timing
Rivetra applies the Oregon Consumer Privacy Act response framework to verified U.S. privacy requests: it responds without undue delay and within 45 days. Rivetra may extend the response once by an additional 45 days when reasonably necessary and will give notice and an explanation within the initial period.
Time needed to obtain information required to authenticate identity or company authority may affect processing where permitted by law. Google Play account deletion requests will remain available through both an in-app path and a public web resource.
10. Appeals
If Rivetra denies or limits a privacy-right request, the response will explain the reason and provide appeal instructions where required. Submit an appeal through the same request channel with the subject "Rivetra privacy appeal." Rivetra will decide the appeal within 45 days and, if denied, provide information for contacting the Oregon Attorney General. California requests also receive the verification, authorized-agent, non-discrimination, and access/correction/deletion/portability treatment stated in the Privacy Policy.
11. Subscription Cancellation
Deleting data, closing an account, or uninstalling Rivetra does not cancel a Google Play subscription. Cancel recurring billing separately at:
https://play.google.com/store/account/subscriptions
12. Completion
After completion, Rivetra will identify the categories deleted, anonymized, disconnected, or retained, subject to security and legal limitations. A minimal record of the request, verification, decision, and completion may be retained to demonstrate compliance.
13. Contact
L&B Superior Services, LLC, doing business as Rivetra
Attention: Rivetra Privacy
5441 S Macadam Avenue, Suite R, Portland, Oregon
Email: privacy@rivetra.app