RIVOCEO / POLICIES & TRUST
Privacy policy
How information moves through RivoCEO—from browsing and building an audience to customer support and the professional records in our dataset.
Draft preparedWebsite information and professional records are different data flows.
A business email can still be personal information.
Buying or previewing a record does not establish consent.
On this page 9 sections
Who this notice is for
This notice addresses people who visit RivoCEO, use an account, select an audience, place an order, or ask for help. It also addresses people whose professional details appear in the executive-contact dataset, even if they have never visited this website.
RivoCEO is the business name used throughout this notice. Our correspondence address is 4827 Westheimer Road, Suite 615, Houston, TX 77057, USA. We do not publish an email address; privacy correspondence can be addressed to RivoCEO, Privacy Requests, at this postal address.
Information used to operate the service
When you use available account, order, or support features, the service can process your name, email, company, billing information, selected filters, order references, and messages. Provide only what the interaction needs; a support message is not a safe place for passwords, card numbers, or unrelated customer files.
The website and its infrastructure process requests and technical details needed to serve pages and protect access. These can include IP addresses, browser information, authentication identifiers, and diagnostic logs. Browser-held account, cart, and support-session information is explained in the cookies and storage notice.
Information in the audience dataset
The audience tools work with recorded names, job titles, business email addresses, company phone numbers, company names, locations, industry labels, and company-size or revenue bands. Field availability varies. The chief-executive classification includes some broader management roles; it is not a statement that every person has the exact title CEO.
Professional records are maintained separately from customer registration and enquiry information. Inclusion in the dataset does not show that a person opened an account, purchased a product, or agreed to receive marketing. The source categories and collection methods for the underlying dataset still require operator confirmation; this draft does not claim that every record was publicly sourced or collected with consent.
What the information is used for
Audience information supports filtering, matching counts, contact previews, and preparation of requested business-contact files. Names and company context may appear in previews; masking an email address or telephone number does not make the entire record anonymous.
Customer and transaction information supports account access, audience selections, order handling, verification work, delivery, support, and investigation of disputed records. Security and diagnostic information helps identify misuse and troubleshoot failures.
The lawful basis for each processing activity must match the actual operation and the law that applies. A customer contract does not, by itself, provide a basis for processing every person listed in a dataset. Any reliance on legitimate interests, consent, or a legal obligation requires its own assessment; this notice is not a substitute for that work.
Recipients and paid access to records
RivoCEO offers professional contact information to business customers for payment. Providing identifiable records in this way may qualify as a sale of personal information under applicable law, even when the arrangement is described as a license or the email is a work address.
Customers receive data for their own permitted business uses and remain responsible for their subsequent processing. Restrictions on resale do not eliminate the need to honor applicable privacy rights.
Google Cloud and Firebase are used in the current data and content infrastructure. Operational suppliers can also be involved in hosting, authentication, verification, payment processing, or support when those features are enabled. The final notice must identify the actual recipient categories and deployed providers, rather than treating every library in the codebase as a service that receives data.
Information may also need to be disclosed to satisfy a valid legal requirement, investigate fraud, or protect legal rights. Any disclosure should be limited to what the situation requires.
Payment information
Use only the payment options actually offered during checkout. The provider handling that payment has its own privacy information. Order records can contain the payment reference, status, amount, and billing details needed to reconcile the purchase.
Do not send payment credentials through contact or privacy-request channels. This draft does not make an unverified claim that payment details are never stored or that a particular provider is currently active.
Retention and international processing
Different records serve different purposes. Account data supports the account; order records support fulfillment, accounting, and disputes; support messages document the enquiry. The final retention schedule must specify the relevant periods or concrete criteria, including deletion from backups and operational systems.
A deletion request may leave limited records that must be retained for a legal obligation or to ensure that a suppressed contact is not reintroduced. Any exception should be explained in the response, not used as an indefinite reason to keep everything.
Hosting and supplier arrangements can involve processing outside a person’s country. Storage locations, applicable transfer mechanisms, and the way to request information about safeguards must be confirmed before publication. Use of a cloud service alone is not proof that every transfer requirement is met.
Your choices and requests
Rights depend on applicable law and can include access, correction, deletion, portability, restriction, objection, withdrawal of consent, and opting out of sale or certain forms of sharing. See Your data rights for the information that helps identify a record. A purchase or account should not be required to exercise a privacy right.
Where applicable, a request may be made through an authorized representative. Verification should be proportionate to the request; a request to obtain private account information is different from an opt-out of sale.
You may raise a concern with the relevant privacy authority. Where a law provides an appeal process or protection against discrimination for exercising a right, that protection is not removed by this notice. Browser privacy signals and any required opt-out mechanisms must be tested before their operation is represented as supported.
Security, children, and changes
Protect your sign-in details and any private support or download links. No online service can promise that every security incident will be prevented. Specific certifications, encryption guarantees, or audit claims should appear here only after they are verified.
RivoCEO is designed for adult business use, not as a service for children. Information believed to have been included improperly should be raised through the verified privacy channel once available.
A revised notice should describe the practices in effect at that time. Material changes may require additional notice or other steps; silently changing a webpage does not authorize a new use of existing information.
Read the related policies before choosing an audience or placing an order.