RivalMove

Privacy Policy

Effective 15 September 2026. Short version: we keep what we need to run your account, we monitor only public pages, we never sell data, and you can leave with your data at any time.

1. Who is responsible

The data controller for rivalmove.com and the RivalMove application is Gianmarco Gavazzi (sole proprietorship, Italy). Contact for any privacy request: info@rivalmove.com.

2. What we collect and why

DataPurposeLegal basis
Account: name, email, password hash or Google id, profile picture (Google)Create and secure your account, sign you in, send service emailsContract
Workspace content: competitors and sources you add, reports, notes, shared cardsProvide the ServiceContract
Billing: plan, subscription status, Stripe customer id, invoices (held by Stripe)Charge for paid plans, accounting and tax obligationsContract · legal obligation
Usage analytics: pages viewed, features used, session duration, device and browser type, approximate location from IPUnderstand and improve the product, fix bugsLegitimate interest (you can object — see section 7)
Marketing consent flag and timestampSend product updates and offers only if you opted inConsent (withdraw any time in Settings)
Referral code and who referred youCredit referrals from shared cardsLegitimate interest
Technical logs: IP address, request metadata, error tracesSecurity, abuse prevention, rate limiting, debuggingLegitimate interest
AI usage records: tokens and cost per call, linked to your workspaceCost control and fair useLegitimate interest

We do not collect special categories of data, and we do not sell personal data.

3. Data about companies we monitor

The Service processes content from public web pages of the companies you track (changelogs, release notes, blogs). That content may incidentally include names of employees or authors published by those companies. We process it only to derive product intelligence, we link every item back to its public source, and we remove items on request from the person concerned (write to info@rivalmove.com).

4. Who we share data with (processors)

We use the following providers under data-processing agreements. Where data leaves the EU/EEA it is protected by the EU–US Data Privacy Framework or Standard Contractual Clauses.

  • Railway (hosting, PostgreSQL database)EU region. Runs the application and stores all account and workspace data.
  • OpenAI (language models)USA · EU Data Privacy Framework / SCCs. Receives the text of public competitor pages to classify and summarise them. It does not receive your name, email or billing data. API data is not used to train models.
  • Stripe (payments)EU / USA · SCCs. Processes payments and stores billing details; we only keep a customer id and subscription status.
  • Resend (transactional email)EU / USA · SCCs. Delivers account and, with consent, marketing emails.
  • PostHog (product analytics)EU cloud (Frankfurt). Measures how the product is used: page views, feature events, session length. Linked to your account id and email so we can support you.
  • Google (sign-in with Google, favicon service)EU / USA · DPF. Authenticates you if you choose Google sign-in; provides company favicons shown in the catalog.
  • GitHub (public releases API)USA · DPF. Fetches public release notes of monitored repositories. No personal data of yours is sent.

We may also disclose data when required by law or to protect our rights, and to a successor in case of a merger or sale of the business (you would be notified).

5. Cookies and local storage

We use only what is needed to run the Service:

  • Session cookie (authjs.session-token) — keeps you signed in. Strictly necessary.
  • Analytics (PostHog, first-party) — a pseudonymous id and session data in cookies/local storage to measure product usage. Used under legitimate interest; you can object (section 7) or block it with your browser.
  • Preferences (local storage) — e.g. whether you have seen the product tour.

We do not use advertising cookies or third-party tracking pixels.

6. How long we keep data

Account and workspace data: for as long as your account exists, then deleted within 30 days of closure. Billing records: 10 years as required by Italian tax law (held by Stripe and in our accounting). Technical logs: up to 90 days. Analytics: 12 months, then aggregated. Public shared cards: until you delete them or your account is closed.

7. Your rights

Under the GDPR you can ask us to access, correct, delete or export your data, to restrict or object to processing based on legitimate interest (including analytics), and to withdraw consent at any time without affecting past processing. Marketing consent can be withdrawn in Settings.

Write to info@rivalmove.com; we answer within 30 days. You can also lodge a complaint with your supervisory authority — in Italy, the Garante per la protezione dei dati personali.

8. Security

Data is encrypted in transit (TLS) and at rest at our hosting provider. Passwords are stored as salted hashes. Access to production systems is limited to the operator and protected by strong authentication. Our crawler only reads public pages and never stores credentials for third-party sites.

9. Children

The Service is for business use and not directed at children under 16. We do not knowingly collect their data.

10. Changes

We may update this policy; the effective date at the top changes when we do. For material changes we notify you by email or in the app.

See also the Terms of Service.