Privacy Policy
Effective 15 September 2026. Short version: we keep what we need to run your account, we monitor only public pages, we never sell data, and you can leave with your data at any time.
1. Who is responsible
The data controller for rivalmove.com and the RivalMove application is Gianmarco Gavazzi (sole proprietorship, Italy). Contact for any privacy request: info@rivalmove.com.
2. What we collect and why
| Data | Purpose | Legal basis |
|---|---|---|
| Account: name, email, password hash or Google id, profile picture (Google) | Create and secure your account, sign you in, send service emails | Contract |
| Workspace content: competitors and sources you add, reports, notes, shared cards | Provide the Service | Contract |
| Billing: plan, subscription status, Stripe customer id, invoices (held by Stripe) | Charge for paid plans, accounting and tax obligations | Contract · legal obligation |
| Usage analytics: pages viewed, features used, session duration, device and browser type, approximate location from IP | Understand and improve the product, fix bugs | Legitimate interest (you can object — see section 7) |
| Marketing consent flag and timestamp | Send product updates and offers only if you opted in | Consent (withdraw any time in Settings) |
| Referral code and who referred you | Credit referrals from shared cards | Legitimate interest |
| Technical logs: IP address, request metadata, error traces | Security, abuse prevention, rate limiting, debugging | Legitimate interest |
| AI usage records: tokens and cost per call, linked to your workspace | Cost control and fair use | Legitimate interest |
We do not collect special categories of data, and we do not sell personal data.
3. Data about companies we monitor
The Service processes content from public web pages of the companies you track (changelogs, release notes, blogs). That content may incidentally include names of employees or authors published by those companies. We process it only to derive product intelligence, we link every item back to its public source, and we remove items on request from the person concerned (write to info@rivalmove.com).
4. Who we share data with (processors)
We use the following providers under data-processing agreements. Where data leaves the EU/EEA it is protected by the EU–US Data Privacy Framework or Standard Contractual Clauses.
- Railway (hosting, PostgreSQL database) — EU region. Runs the application and stores all account and workspace data.
- OpenAI (language models) — USA · EU Data Privacy Framework / SCCs. Receives the text of public competitor pages to classify and summarise them. It does not receive your name, email or billing data. API data is not used to train models.
- Stripe (payments) — EU / USA · SCCs. Processes payments and stores billing details; we only keep a customer id and subscription status.
- Resend (transactional email) — EU / USA · SCCs. Delivers account and, with consent, marketing emails.
- PostHog (product analytics) — EU cloud (Frankfurt). Measures how the product is used: page views, feature events, session length. Linked to your account id and email so we can support you.
- Google (sign-in with Google, favicon service) — EU / USA · DPF. Authenticates you if you choose Google sign-in; provides company favicons shown in the catalog.
- GitHub (public releases API) — USA · DPF. Fetches public release notes of monitored repositories. No personal data of yours is sent.
We may also disclose data when required by law or to protect our rights, and to a successor in case of a merger or sale of the business (you would be notified).
5. Cookies and local storage
We use only what is needed to run the Service:
- Session cookie (
authjs.session-token) — keeps you signed in. Strictly necessary. - Analytics (PostHog, first-party) — a pseudonymous id and session data in cookies/local storage to measure product usage. Used under legitimate interest; you can object (section 7) or block it with your browser.
- Preferences (local storage) — e.g. whether you have seen the product tour.
We do not use advertising cookies or third-party tracking pixels.
6. How long we keep data
Account and workspace data: for as long as your account exists, then deleted within 30 days of closure. Billing records: 10 years as required by Italian tax law (held by Stripe and in our accounting). Technical logs: up to 90 days. Analytics: 12 months, then aggregated. Public shared cards: until you delete them or your account is closed.
7. Your rights
Under the GDPR you can ask us to access, correct, delete or export your data, to restrict or object to processing based on legitimate interest (including analytics), and to withdraw consent at any time without affecting past processing. Marketing consent can be withdrawn in Settings.
Write to info@rivalmove.com; we answer within 30 days. You can also lodge a complaint with your supervisory authority — in Italy, the Garante per la protezione dei dati personali.
8. Security
Data is encrypted in transit (TLS) and at rest at our hosting provider. Passwords are stored as salted hashes. Access to production systems is limited to the operator and protected by strong authentication. Our crawler only reads public pages and never stores credentials for third-party sites.
9. Children
The Service is for business use and not directed at children under 16. We do not knowingly collect their data.
10. Changes
We may update this policy; the effective date at the top changes when we do. For material changes we notify you by email or in the app.
See also the Terms of Service.