Rivetra Privacy Policy
Policy version: 2026-07-12
Effective date: July 12, 2026
This Privacy Policy explains how L&B Superior Services, LLC, doing business as Rivetra ("Rivetra," "we," "us," or "our"), collects, uses, discloses, retains, and protects personal data in the Rivetra mobile app, web application, public website, client document portals, support channels, and related services.
1. Our Role
Rivetra acts as a controller or business for account registration, subscriptions, product security, support, website interactions, and our own business operations.
For client, property-owner, employee, subcontractor, vendor, and job data that a contractor company places in its workspace, the contractor company generally decides why and how the data is used. Rivetra generally processes that data as a service provider or processor on the company's instructions. Privacy requests about contractor-controlled records may therefore require coordination with the contractor company.
2. Data We Collect
Depending on the features used, we may process the following categories.
Account and identity data
- Name, email, phone number, user ID, employee ID, job title, company ID, role,
- Authentication records, password hashes, passkey credentials, multifactor
permissions, profile details, acceptance records, and account status.
status, session records, recovery activity, and security events. Rivetra does not store plaintext passwords or biometric templates used by the device.
Company and professional data
- Business and legal name, address, contact information, service area, trade,
license and CCB information, license expiration, tax or accounting settings, logo, website, certifications, insurance or bond references, and team roster.
Client, property, and project data
- Client and property-owner contact information, service and billing addresses,
jobsite ZIP, county and jurisdiction, project descriptions, notes, measurements, line items, estimates, invoices, contracts, change orders, schedules, approvals, signatures, messages, questions, photos, attachments, warranty records, and project history.
Workforce and location data
- Crew assignments, time entries, timesheets, checklists, employee or
subcontractor records, vehicle records, mileage, and jobsite or foreground location when a company enables a location-dependent feature and the device grants permission.
Financial and commercial data
- Prices, costs, margins, discounts, taxes, deposits, milestones, payment
- Rivetra does not receive or store full card numbers or online-banking
status, transaction references, expenses, receipts, vendor bills, bank-feed transaction data, accounting classifications, journal entries, reconciliations, subscription products, entitlement status, and refund or cancellation status.
credentials entered directly into Stripe, Plaid, Google Play, or a bank.
Integration data
- Provider account identifiers, selected pages, sites, properties, business
profiles, connection status, OAuth scopes, access and refresh tokens stored in protected form, provider metadata, webhooks, synced transactions, analytics, posts, leads, and content authorized by the company.
AI and generated-content data
- Prompts, project context, files or images submitted for analysis, generated
estimates, audit results, permit research, content drafts, assistant actions, model and policy versions, confidence information, approval records, and feedback or safety reports.
Device, diagnostics, and usage data
- IP address, device and browser type, operating system, app version, push
token, language, time zone, crash reports, request logs, feature events, security telemetry, and approximate network location. Rivetra does not use an advertising ID for targeted advertising.
Communications
- Support requests, legal and privacy requests, survey responses, product
feedback, and messages you choose to send through Rivetra or an external app.
3. Sources of Data
We receive data from users and company administrators; contractor clients and signers; devices and browsers; connected providers; payment and subscription processors; public licensing, permit, or business sources; company-authorized imports; and automatically generated security and service logs.
4. How We Use Data
We use data to:
- create and secure accounts and company workspaces;
- provide estimates, invoices, documents, signatures, payments, accounting,
- connect and synchronize services the company authorizes;
- provide AI-assisted features requested by users;
- verify subscriptions and manage company entitlements;
- send service, security, document, payment, and support communications;
- detect abuse, prevent fraud, troubleshoot errors, and maintain reliability;
- comply with law, enforce agreements, resolve disputes, and protect rights;
- understand feature performance and improve the Service using minimized or
- maintain required financial, signature, security, and compliance records.
scheduling, project, crew, growth, and reporting features;
aggregated data where practical; and
We do not use contractor client lists, job photos, private project details, bank transactions, or signed documents to advertise unrelated products to those individuals.
5. AI Processing
When a user invokes an AI feature, Rivetra may send the minimum reasonably necessary prompt, project context, image, receipt, or document data to the configured AI provider. We seek to exclude passwords, usable OAuth tokens, full payment credentials, and unrelated sensitive data.
AI providers process data under their service terms and Rivetra's provider configuration. Rivetra does not represent that an AI output is correct or that provider processing is legally appropriate for every category of information. Users should not submit unnecessary health, biometric, government-ID, child, or other highly sensitive data to AI features.
6. How We Disclose Data
We may disclose data to:
- cloud hosting, storage, authentication, monitoring, communications, and
- Google Play and RevenueCat for subscription purchase and entitlement status;
- Stripe, Plaid, banks, and payment providers for user-authorized financial
- AI providers for user-requested generation or analysis;
- Meta, Wix, Webflow, Google services, and other integrations the
- messaging or email apps when a user chooses to share content;
- the contractor company, its admins, authorized team members, clients, and
- professional advisers, auditors, insurers, and transaction counterparties
- courts, regulators, law enforcement, or other parties when reasonably
security providers;
features;
company connects;
document recipients according to roles and user actions;
subject to appropriate confidentiality duties; and
necessary to comply with law or protect users, Rivetra, or the public.
We may disclose data in a financing, merger, acquisition, reorganization, or sale, subject to this Policy and legally required notice.
7. Sale, Targeted Advertising, and Opt-Out Signals
Rivetra does not sell personal data for money. Rivetra does not currently share personal data for cross-context behavioral advertising or process personal data for targeted advertising profiles.
Rivetra applies the broad U.S. state-law meanings of "sale," "sharing," and "targeted advertising" when evaluating a new processing activity and will not begin such processing until the required notice, opt-out control, contracts, and data-protection assessment are operational. Rivetra recognizes Global Privacy Control and other legally recognized universal opt-out signals. Because Rivetra does not currently sell data or use it for targeted advertising, receiving such a signal does not change the operation of core contractor services.
Rivetra does not sell precise geolocation data. Rivetra does not knowingly sell personal data of individuals under 16 or use it for targeted advertising or covered profiling.
8. Processing Authority
Rivetra processes data to perform a contract, follow user or company instructions, comply with law, protect legitimate interests such as security and service operation, and obtain consent for processing that requires it. Consent may be withdrawn for future processing, but withdrawal does not invalidate processing already completed or records Rivetra must retain.
9. Retention
Retention depends on the record, company instructions, legal obligations, security needs, and provider requirements.
- Account and workspace data: while the account is active and for a reasonable
- Draft projects and ordinary attachments: until deleted by an authorized user,
- Invoices, payments, expenses, ledgers, tax support, and reconciliations: for
- Signature envelopes, contract versions, notices, consent, and delivery logs:
- ACH authorizations and payment audit records: for provider, network, dispute,
- OAuth tokens: until disconnection, expiration, revocation, or account closure,
- Security and diagnostic logs: generally for a shorter operational period,
- Backups: rotate on a limited schedule and are deleted or overwritten in the
wind-down period after verified closure.
closed under workspace policy, or removed under a verified request.
the period reasonably needed for tax, accounting, audit, dispute, and legal obligations, commonly at least seven years after the relevant tax year or transaction where appropriate.
for the contract limitation and retention period reasonably applicable to the transaction.
fraud, and legal retention periods.
subject to provider requirements. Historical logs do not retain usable tokens.
unless needed to investigate abuse, fraud, or an incident.
ordinary course; restoration may temporarily restore a record until deletion controls run again.
Rivetra may anonymize records instead of deleting them when the remaining data cannot reasonably identify an individual. Data subject to a legal hold is retained until the hold ends.
10. Security
Rivetra uses administrative, technical, and organizational safeguards designed for the nature of the data, including encrypted network transport, managed cloud security, role and company access controls, protected credentials, secret management, authentication safeguards, logging, backups, and incident response.
No system is perfectly secure. Users are responsible for device security, credential protection, accurate roles, provider-account security, and promptly removing users who no longer need access.
11. Privacy Rights
Rivetra provides the following privacy request process to U.S. residents, including Oregon and California residents, even when a particular statutory threshold or exemption would not independently compel every request type. An individual may request:
- confirmation and access;
- correction of inaccurate personal data;
- deletion;
- a portable copy;
- a list of specific third parties that received personal data;
- restriction or opt-out of sale, targeted advertising, or qualifying
- withdrawal of consent; and
- appeal of a denied request.
profiling;
Submit requests through the in-app privacy controls, the public deletion and rights page, or privacy@rivetra.app. Rivetra may verify identity, residency, account ownership, and authority. Authorized agents must provide evidence of authority. We will not discriminate for exercising a privacy right.
Rivetra uses the Oregon Consumer Privacy Act response framework: verified requests are answered without undue delay and within 45 days, with one additional 45-day extension when reasonably necessary and timely explained. A denial identifies the reason and appeal method. Appeals are decided within 45 days; a denied appeal includes instructions for contacting the Oregon Attorney General.
For California residents, Rivetra administers the CCPA/CPRA rights to know and access, correct, delete, receive portable information, opt out of sale or sharing, limit qualifying use or disclosure of sensitive personal information, use an authorized agent, and receive equal service and pricing without unlawful retaliation. Rivetra does not sell or share personal information and therefore does not currently require a "Do Not Sell or Share" transaction to preserve that status. Requests to know, correct, or delete are verified to the degree appropriate to the sensitivity and risk of the request.
This voluntary request process does not override statutory exemptions or permit Rivetra to disclose or delete another company's records without authority. Employment records, business-contact data, contractor-controlled customer data, deidentified data, privileged material, fraud evidence, security records, and legally retained transaction records are handled under the governing exemption, controller instruction, or retention rule. Rivetra may retain a limited suppression record so deleted data is not reintroduced.
12. Company-Controlled and Workforce Data
Company administrators determine access to workspace data. Employees, subcontractors, contractor clients, and property owners should first contact the contractor company for company-controlled records. Rivetra may assist the company or respond directly when required by law.
Companies are responsible for notices and consent required for employee monitoring, time tracking, location, messaging, background information, and workforce records. Rivetra does not determine whether a worker is an employee or independent contractor.
13. Children
Rivetra is a business service for adults and is not directed to children under
- Users must be at least 18. Do not create accounts for children or submit
children's personal data unless legally authorized and necessary for a legitimate project purpose. Contact us if you believe a child provided account data without appropriate consent.
14. International Processing
Rivetra is operated from the United States. Providers may process data in the United States and other countries. Laws in those locations may differ from the laws where a user lives. Rivetra will use legally required transfer mechanisms when applicable.
15. Changes
We may update this Policy for product, provider, security, or legal changes. We will update the version and effective date and provide additional notice or seek consent when required. Prior versions will be retained for acceptance and audit purposes.
16. Contact
L&B Superior Services, LLC, doing business as Rivetra
Attention: Rivetra Privacy
5441 S Macadam Avenue, Suite R, Portland, Oregon
Privacy rights: privacy@rivetra.app
Security and vulnerability reports: security@rivetra.app
General support: support@rivetra.app