Rivetra Privacy Policy

Policy version: 2026-07-12

Effective date: July 12, 2026

This Privacy Policy explains how L&B Superior Services, LLC, doing business as Rivetra ("Rivetra," "we," "us," or "our"), collects, uses, discloses, retains, and protects personal data in the Rivetra mobile app, web application, public website, client document portals, support channels, and related services.

1. Our Role

Rivetra acts as a controller or business for account registration, subscriptions, product security, support, website interactions, and our own business operations.

For client, property-owner, employee, subcontractor, vendor, and job data that a contractor company places in its workspace, the contractor company generally decides why and how the data is used. Rivetra generally processes that data as a service provider or processor on the company's instructions. Privacy requests about contractor-controlled records may therefore require coordination with the contractor company.

2. Data We Collect

Depending on the features used, we may process the following categories.

Account and identity data

Company and professional data

Client, property, and project data

Workforce and location data

Financial and commercial data

Integration data

AI and generated-content data

Device, diagnostics, and usage data

Communications

3. Sources of Data

We receive data from users and company administrators; contractor clients and signers; devices and browsers; connected providers; payment and subscription processors; public licensing, permit, or business sources; company-authorized imports; and automatically generated security and service logs.

4. How We Use Data

We use data to:

We do not use contractor client lists, job photos, private project details, bank transactions, or signed documents to advertise unrelated products to those individuals.

5. AI Processing

When a user invokes an AI feature, Rivetra may send the minimum reasonably necessary prompt, project context, image, receipt, or document data to the configured AI provider. We seek to exclude passwords, usable OAuth tokens, full payment credentials, and unrelated sensitive data.

AI providers process data under their service terms and Rivetra's provider configuration. Rivetra does not represent that an AI output is correct or that provider processing is legally appropriate for every category of information. Users should not submit unnecessary health, biometric, government-ID, child, or other highly sensitive data to AI features.

6. How We Disclose Data

We may disclose data to:

We may disclose data in a financing, merger, acquisition, reorganization, or sale, subject to this Policy and legally required notice.

7. Sale, Targeted Advertising, and Opt-Out Signals

Rivetra does not sell personal data for money. Rivetra does not currently share personal data for cross-context behavioral advertising or process personal data for targeted advertising profiles.

Rivetra applies the broad U.S. state-law meanings of "sale," "sharing," and "targeted advertising" when evaluating a new processing activity and will not begin such processing until the required notice, opt-out control, contracts, and data-protection assessment are operational. Rivetra recognizes Global Privacy Control and other legally recognized universal opt-out signals. Because Rivetra does not currently sell data or use it for targeted advertising, receiving such a signal does not change the operation of core contractor services.

Rivetra does not sell precise geolocation data. Rivetra does not knowingly sell personal data of individuals under 16 or use it for targeted advertising or covered profiling.

8. Processing Authority

Rivetra processes data to perform a contract, follow user or company instructions, comply with law, protect legitimate interests such as security and service operation, and obtain consent for processing that requires it. Consent may be withdrawn for future processing, but withdrawal does not invalidate processing already completed or records Rivetra must retain.

9. Retention

Retention depends on the record, company instructions, legal obligations, security needs, and provider requirements.

Rivetra may anonymize records instead of deleting them when the remaining data cannot reasonably identify an individual. Data subject to a legal hold is retained until the hold ends.

10. Security

Rivetra uses administrative, technical, and organizational safeguards designed for the nature of the data, including encrypted network transport, managed cloud security, role and company access controls, protected credentials, secret management, authentication safeguards, logging, backups, and incident response.

No system is perfectly secure. Users are responsible for device security, credential protection, accurate roles, provider-account security, and promptly removing users who no longer need access.

11. Privacy Rights

Rivetra provides the following privacy request process to U.S. residents, including Oregon and California residents, even when a particular statutory threshold or exemption would not independently compel every request type. An individual may request:

Submit requests through the in-app privacy controls, the public deletion and rights page, or privacy@rivetra.app. Rivetra may verify identity, residency, account ownership, and authority. Authorized agents must provide evidence of authority. We will not discriminate for exercising a privacy right.

Rivetra uses the Oregon Consumer Privacy Act response framework: verified requests are answered without undue delay and within 45 days, with one additional 45-day extension when reasonably necessary and timely explained. A denial identifies the reason and appeal method. Appeals are decided within 45 days; a denied appeal includes instructions for contacting the Oregon Attorney General.

For California residents, Rivetra administers the CCPA/CPRA rights to know and access, correct, delete, receive portable information, opt out of sale or sharing, limit qualifying use or disclosure of sensitive personal information, use an authorized agent, and receive equal service and pricing without unlawful retaliation. Rivetra does not sell or share personal information and therefore does not currently require a "Do Not Sell or Share" transaction to preserve that status. Requests to know, correct, or delete are verified to the degree appropriate to the sensitivity and risk of the request.

This voluntary request process does not override statutory exemptions or permit Rivetra to disclose or delete another company's records without authority. Employment records, business-contact data, contractor-controlled customer data, deidentified data, privileged material, fraud evidence, security records, and legally retained transaction records are handled under the governing exemption, controller instruction, or retention rule. Rivetra may retain a limited suppression record so deleted data is not reintroduced.

12. Company-Controlled and Workforce Data

Company administrators determine access to workspace data. Employees, subcontractors, contractor clients, and property owners should first contact the contractor company for company-controlled records. Rivetra may assist the company or respond directly when required by law.

Companies are responsible for notices and consent required for employee monitoring, time tracking, location, messaging, background information, and workforce records. Rivetra does not determine whether a worker is an employee or independent contractor.

13. Children

Rivetra is a business service for adults and is not directed to children under

  1. Users must be at least 18. Do not create accounts for children or submit
  2. children's personal data unless legally authorized and necessary for a legitimate project purpose. Contact us if you believe a child provided account data without appropriate consent.

14. International Processing

Rivetra is operated from the United States. Providers may process data in the United States and other countries. Laws in those locations may differ from the laws where a user lives. Rivetra will use legally required transfer mechanisms when applicable.

15. Changes

We may update this Policy for product, provider, security, or legal changes. We will update the version and effective date and provide additional notice or seek consent when required. Prior versions will be retained for acceptance and audit purposes.

16. Contact

L&B Superior Services, LLC, doing business as Rivetra

Attention: Rivetra Privacy

5441 S Macadam Avenue, Suite R, Portland, Oregon

Privacy rights: privacy@rivetra.app

Security and vulnerability reports: security@rivetra.app

General support: support@rivetra.app