Privacy Policy
Last updated: 20 May 2026
This Privacy Policy explains how Rivet (provided by Jason Coughlan, an individual based in An Muileann gCearr, Ireland) collects, uses, stores, and protects personal information.
This policy applies to:
- Shop owners — the businesses that subscribe to Rivet to manage their repair operations
- End customers — the people whose repair details are stored in Rivet by shop owners
1. Who is responsible for your data
For shop owner data
Jason Coughlan is the Data Controller for personal information about shop owners who subscribe to Rivet.
For end customer data
When a shop uses Rivet to store information about their own customers (the people getting devices repaired), the shop is the Data Controller and Rivet is the Data Processor. The shop instructs us how to handle their customers’ data; we act on those instructions.
2. What data we collect
2.1 From shop owners (our direct customers)
When you sign up to Rivet, we collect:
- Email address (for login and communications)
- Shop name
- Shop phone number
- Subscription and billing information (handled by our payment provider, Stripe)
- Account activity logs (status changes, edits, login times)
2.2 From end customers (your customers)
When shops use Rivet, they enter the following about their customers:
- Customer name
- Customer phone number
- Customer email (optional)
- Device details (make, model, IMEI/serial number, passcode if provided)
- Repair details (problem reported, diagnosis, pricing, notes)
- Repair history
This data is entered by the shop, not by us. The shop is responsible for obtaining consent from their customers to store this information.
2.3 SMS notification data
When Rivet sends SMS to end customers:
- The phone number is sent to our SMS provider (ClickSend)
- The message content includes shop name, customer first name, device details, and tracking link
- ClickSend retains records of sent messages per their own privacy policy
3. Why we collect this data
We collect and process data for the following purposes:
- To provide the service: Operating the Rivet platform requires storing shop and repair data
- To send SMS notifications: As instructed by the shop, on a per-status-change basis
- To process payments: Stripe handles billing on our behalf
- To improve the service: Aggregated, anonymised usage patterns may inform product decisions
- To communicate with shop owners: Service updates, billing, support
- Legal compliance: Where required by Irish or EU law
4. Legal basis for processing (GDPR)
We rely on the following legal bases under GDPR:
- Contract performance: Most data processing is necessary to deliver the service you signed up for
- Legitimate interest: Service improvements, security monitoring
- Legal obligation: Tax records, fraud investigations
- Consent: Where required, for example for non-essential marketing communications
For end customer data, the shop owneris responsible for establishing the legal basis for processing (typically the shop’s own contract or legitimate interest with their customer).
5. Where your data is stored
- All Rivet data is stored on Supabase servers in Dublin, Ireland (eu-west-1)
- Payment information is processed by Stripe (Ireland and EU)
- SMS data is processed by ClickSend (Australia, with EU-region processing for European customers)
- Application hosting is provided by Vercel (data may be cached at edge locations globally for performance, but persistent data remains in EU)
Your primary data remains in the EU. Some service providers (e.g. Vercel, ClickSend) may be based outside the EU but operate under standard contractual clauses or equivalent data transfer mechanisms required by GDPR.
6. How long we keep your data
- Active accounts: As long as your subscription is active
- After account closure: Data is retained for up to 30 days, then permanently deleted (subject to backup retention cycles of up to 90 days)
- Billing records: Retained for 7 years for tax compliance purposes
- SMS records (at ClickSend): Retained per their policy, typically 4 months
You can request earlier deletion at any time.
7. Who we share data with
We share data only with the following third parties:
- Supabase — database hosting (Dublin, Ireland)
- Vercel — application hosting
- ClickSend — SMS sending
- Stripe — payment processing
- Legal authorities — only when legally required
Each of these has its own privacy policy and signed data processing agreements with us (or operates under EU standard contractual clauses).
We do not:
- Sell your data
- Share your data with marketers or advertisers
- Use your data to train AI models
- Access your data routinely for any purpose other than support
8. Your rights under GDPR
If you’re in the EU/EEA (which includes Ireland), you have the following rights:
- Right of access: Request a copy of the personal data we hold about you
- Right to rectification: Correct inaccurate data
- Right to erasure: Request deletion of your data (“right to be forgotten”)
- Right to restriction: Limit how we process your data
- Right to data portability: Receive your data in a portable format
- Right to object: Object to certain types of processing
- Right to lodge a complaint: With the Irish Data Protection Commission (https://www.dataprotection.ie)
To exercise any of these rights, email us at jasoncoughlan@cjcreativemedia.net. We will respond within 30 days.
For end customers
If you are a customer of a shop that uses Rivet, your primary data rights are with that shop (the Data Controller). However, you can also contact us directly if needed.
9. Security
We protect your data with:
- HTTPS encryption for all data in transit
- Row-Level Security policies in our database (Supabase)
- Magic-link authentication (no passwords to leak)
- Limited access — only Jason Coughlan has administrative access to production systems
- Regular updates to dependencies and infrastructure
No system is completely secure. In the event of a data breach affecting your information, we will notify you and the Irish Data Protection Commission within 72 hours of becoming aware, as required by GDPR.
10. Cookies
Rivet uses minimal cookies, only those essential for:
- Authentication (keeping you logged in)
- Basic functionality
We do not use third-party tracking cookies, advertising cookies, or analytics cookies that would require explicit consent. If we add analytics in the future, we will update this policy and seek consent where required.
11. Children’s data
Rivet is a business tool for repair shops and is not directed at or intended for children under 16. We do not knowingly collect data from children. If you believe we have inadvertently collected such data, please contact us.
12. Changes to this Privacy Policy
We may update this Privacy Policy occasionally. Material changes will be communicated to active shop owners by email at least 30 days in advance.
13. Contact us
For any privacy questions or to exercise your rights:
- Email: jasoncoughlan@cjcreativemedia.net
- Address: An Muileann gCearr, Co. Westmeath, Ireland
You can also contact the Irish Data Protection Commission directly:
- Website: https://www.dataprotection.ie
- Phone: +353 (0)761 104 800
This policy was written specifically for Rivet’s actual data practices. Last reviewed and updated on 20 May 2026.