← Back to Rivet

Privacy Policy

Last updated: 20 May 2026

This Privacy Policy explains how Rivet (provided by Jason Coughlan, an individual based in An Muileann gCearr, Ireland) collects, uses, stores, and protects personal information.

This policy applies to:

1. Who is responsible for your data

For shop owner data

Jason Coughlan is the Data Controller for personal information about shop owners who subscribe to Rivet.

For end customer data

When a shop uses Rivet to store information about their own customers (the people getting devices repaired), the shop is the Data Controller and Rivet is the Data Processor. The shop instructs us how to handle their customers’ data; we act on those instructions.

2. What data we collect

2.1 From shop owners (our direct customers)

When you sign up to Rivet, we collect:

2.2 From end customers (your customers)

When shops use Rivet, they enter the following about their customers:

This data is entered by the shop, not by us. The shop is responsible for obtaining consent from their customers to store this information.

2.3 SMS notification data

When Rivet sends SMS to end customers:

3. Why we collect this data

We collect and process data for the following purposes:

4. Legal basis for processing (GDPR)

We rely on the following legal bases under GDPR:

For end customer data, the shop owneris responsible for establishing the legal basis for processing (typically the shop’s own contract or legitimate interest with their customer).

5. Where your data is stored

Your primary data remains in the EU. Some service providers (e.g. Vercel, ClickSend) may be based outside the EU but operate under standard contractual clauses or equivalent data transfer mechanisms required by GDPR.

6. How long we keep your data

You can request earlier deletion at any time.

7. Who we share data with

We share data only with the following third parties:

Each of these has its own privacy policy and signed data processing agreements with us (or operates under EU standard contractual clauses).

We do not:

8. Your rights under GDPR

If you’re in the EU/EEA (which includes Ireland), you have the following rights:

To exercise any of these rights, email us at jasoncoughlan@cjcreativemedia.net. We will respond within 30 days.

For end customers

If you are a customer of a shop that uses Rivet, your primary data rights are with that shop (the Data Controller). However, you can also contact us directly if needed.

9. Security

We protect your data with:

No system is completely secure. In the event of a data breach affecting your information, we will notify you and the Irish Data Protection Commission within 72 hours of becoming aware, as required by GDPR.

10. Cookies

Rivet uses minimal cookies, only those essential for:

We do not use third-party tracking cookies, advertising cookies, or analytics cookies that would require explicit consent. If we add analytics in the future, we will update this policy and seek consent where required.

11. Children’s data

Rivet is a business tool for repair shops and is not directed at or intended for children under 16. We do not knowingly collect data from children. If you believe we have inadvertently collected such data, please contact us.

12. Changes to this Privacy Policy

We may update this Privacy Policy occasionally. Material changes will be communicated to active shop owners by email at least 30 days in advance.

13. Contact us

For any privacy questions or to exercise your rights:

You can also contact the Irish Data Protection Commission directly:


This policy was written specifically for Rivet’s actual data practices. Last reviewed and updated on 20 May 2026.