Skip to content
Rival

Privacy

Privacy policy

Rival is a service for professionals. This policy explains, in plain words, which data we process, why, who can access it and how to exercise your rights.

Last updated

This policy is written in French. The English version is a translation: if the two differ, the French version prevails.

In short

  • We collect your email, your account language, your workspace name and what you tell us about your brand: site, description, competitors, catalog, Shopify and Instagram connections.
  • We collect public data about the brands you follow: pages, catalogs, ads and public posts. Nothing private, and our crawler honors robots.txt.
  • OpenAI processes page extracts, catalog data, your brand context and your messages to the assistant. This data is not used to train its models.
  • We never sell data and show no advertising. Google Analytics audience measurement only runs with your consent.
  • You can ask for access, correction, deletion or a copy of your data at support@rival.watch.

1. Who is responsible for your data

The data controller is Riad Mahi, sole proprietor (French “entrepreneur individuel”) trading as Rival, registered in the French national business register under SIREN 918 773 755 (SIRET 918 773 755 00023, VAT FR26918773755), with its registered office at 74 allée des Ifs, 73220 Aiton, France (“Rival”, “we”).

For any question about your data, write to support@rival.watch. We answer within one month.

2. Who this policy applies to

It applies to three groups of people:

  • Visitors of the public site, including those who run an instant analysis, join the waitlist or ask for their full store comparison by email.
  • Users who create an account and work in a workspace, as owner or member.
  • Third parties whose public data appears in followed brands: competing brands, Facebook pages, Instagram business accounts, advertisers. These people have no Rival account; section 5 is about them.

3. Your account data

To create an account we only need your email address. You sign in with a one-time code or a link sent by email; Rival stores no password.

We then keep:

  • Your email address and the date the account was created.
  • The language of your account, French or English.
  • Your workspaces: their name, their address, your role (owner or member) and the members you invite.
  • Your plan and the state of your subscription, kept up to date by Stripe.
  • Your API keys for the MCP connection: Rival keeps only a fingerprint, never the key itself.

4. Your brand data

Everything you give Rival so it can read your market stays in your workspace and is visible to its members only:

  • Your brand: your site address, its description, its country, its logo and the public pages we read to understand it.
  • The competitors you add or accept among our suggestions.
  • Your catalog, read from your store: products, variants, prices, availability.
  • Your Shopify connection, if you enable it: the store domain, an encrypted access token and the permissions granted (reading products, inventory and orders, and creating discount codes when you ask for it). Orders are limited to the last 60 days and contain no customer name, address or email: only the number, date, amounts, discount codes and line items.
  • Your Instagram connection, if you enable it: the business account id and username, an encrypted access token and your posts with their statistics.
  • Your conversations with the assistant: your messages, its answers and, if you dictate a message, the audio recording for the time of its transcription.
  • Your decisions: the ones you reveal, plan, launch or dismiss, and the automation rules you configure.
  • Your feedback sent from the app: the message, its category, the page it was sent from, your plan, the Rival version and your browser, so we can reproduce a problem.

5. Public data about followed brands

To bring you decisions, Rival observes the brands you follow from public sources only:

  • Their public pages (home, pricing, products, collections): the text, the raw HTML and a screenshot, kept in a private storage space.
  • Their public catalogs, read from the store feeds (Shopify JSON, JSON-LD structured data).
  • Their public ads, read from the Meta Ad Library and, when the source is enabled, from TikTok’s: text, visuals, dates and publishing platforms.
  • Their public Instagram posts, read through Meta’s Graph API for business accounts: caption, visual, date and public counters.
  • Their news, read from their public RSS or Atom feeds.
  • The site you submit to the instant analysis on our public site, read the same way.

Our crawler identifies itself as RivalBot, reads each site’s robots.txt and honors its rules. It never enters a private area and never bypasses a protection.

This data can contain personal data of third parties: the name of an advertiser, of an executive quoted in a news item or of a person who appears in a post. We process it on the basis of our legitimate interest, and that of our users, in understanding a market from information these brands made public themselves. We never cross it with other sources and never use it for prospecting or profiling.

If your business or your name appears in Rival and you object, write to support@rival.watch: we stop collecting and delete the data concerned. Disallowing RivalBot in your robots.txt also stops any capture of your site.

6. Usage data and technical data

Rival measures how its product is used, in its own database and without any provider:

  • Product events: account created, workspace created and opened, competitor tracked, decision revealed or acted on, Shopify or Instagram connected, MCP key created, feedback sent, screen viewed. Each event carries your id, your workspace and the date, never the content of what you do.
  • They are kept for 13 months, then deleted automatically.
  • You can object at any time in Settings › Preferences, with the “Record my product usage” switch. Rival then stops recording your events.

This internal measurement only helps us understand what is useful in Rival. It falls under the consent exemption the CNIL allows for audience measurement strictly necessary to the service: it follows nobody across sites and sends nothing to third parties.

For security and incident diagnosis we also keep technical logs: application errors, with your id, your workspace id and the id of the job concerned, never your email; and, for the instant analysis and the waitlist, a hashed fingerprint of your IP address that protects us against abuse.

7. Processing by artificial intelligence

Rival relies on OpenAI models, called through its API. For each analysis we send OpenAI only what the model needs:

  • Page extracts and catalog data of followed brands, along with their public ads and posts.
  • Your brand context: name, description, site, country, catalog and competitors.
  • Your messages to the assistant, the conversation history and, for transcription, your dictated messages.
  • Your decisions and results, when Rival summarizes them for you.

We never send your email address or those of your members, your access tokens, or the detail of your store orders: only aggregates (volumes, amounts) enter the analyses.

Under the OpenAI API terms, data sent through the API is not used to train or improve its models. OpenAI keeps abuse-monitoring logs for up to 30 days, then deletes them.

AI-produced decisions are proposals with their evidence. The figures shown come from extractions or deterministic calculations, never from the model’s free text. You remain the only decision-maker: nothing is applied to your store without your validation or a rule you configured.

8. Why we process this data

Each processing relies on one of the legal bases of the GDPR:

  • Performance of the contract: creating your account, signing you in, reading your brand and your competitors, producing decisions, managing your subscription, answering your feedback.
  • Our legitimate interest: collecting public data about followed brands, measuring product usage, protecting the service against abuse, diagnosing errors.
  • Your consent: Google Analytics audience measurement on the public site, and the connection of your Shopify and Instagram accounts, which you can withdraw at any time.
  • Our legal obligations: keeping billing records and answering requests from authorities.
  • Our legitimate interest in reaching professionals: when you ask for your full store comparison, we record your work email, the domain analysed, your language, the version of the notice shown under the field and a fingerprint of your IP address. We use them to send you the report, then, now and then, advice about your market, and to limit abuse. You can object at any time with the unsubscribe link in every email; nothing is pre-ticked.

9. Who receives the data

Rival never sells, rents or shares data for advertising. Only the providers below access data, on our behalf and on our instructions:

  • Supabase: database, authentication and file storage. Supabase, Inc. (United States); data is hosted in the European Union, in Ireland (AWS region eu-west-1). Transfers covered by standard contractual clauses.
  • OpenAI: artificial intelligence models. OpenAI (United States), under its data processing addendum and standard contractual clauses.
  • Stripe: payment and invoicing. Stripe, Inc. (United States), certified under the Data Privacy Framework, and its European entities. Your card numbers never pass through Rival.
  • Resend: sending our replies to your feedback and the store comparisons requested on the site, from the rival.watch domain. Plus Five Five, Inc. (United States), standard contractual clauses.
  • Sentry: error monitoring. Functional Software, Inc. (United States), certified under the Data Privacy Framework. No email address in the reports.
  • Google: Google Analytics audience measurement through Firebase, only with your consent. Google Ireland Limited and Google LLC (United States), certified under the Data Privacy Framework.
  • Firecrawl: rendering of public pages that require a browser. SideGuide Technologies, Inc. (United States), standard contractual clauses. Firecrawl only receives the address of the page to read.
  • Meta: Ad Library and Instagram Graph API. Meta Platforms Ireland Ltd and Meta Platforms, Inc. (United States), certified under the Data Privacy Framework. Meta receives the page and account names searched and, if you connect Instagram, your authorization.
  • Shopify: connection of your store. Shopify International Ltd (Ireland), which covers its own transfers with standard contractual clauses.
  • Cloudflare Turnstile: bot protection on the instant analysis. Cloudflare, Inc. (United States), certified under the Data Privacy Framework.
  • Application host: Vercel Inc., 440 N Barranca Ave #4133, Covina, CA 91723, United States. Vercel Inc. is certified under the Data Privacy Framework.

We update this list before adding a provider. Brave web search, planned in the code, is not enabled; it will be added here if it is.

10. Transfers outside the European Union

Several providers are established in the United States. When they are certified under the EU-U.S. Data Privacy Framework, the transfer relies on the European Commission’s adequacy decision. Otherwise it relies on the European Commission’s standard contractual clauses, completed where needed by technical measures such as encryption.

You can obtain a copy of these safeguards by writing to support@rival.watch.

11. Cookies

Rival uses very few cookies, and none for advertising.

  • Necessary cookies, which need no consent: the Supabase session cookies (sb-…) that keep you signed in, the locale cookie that remembers your language, the last_workspace cookie that reopens your last workspace, and the rival_analytics_consent cookie that remembers your choice about audience measurement. Your light or dark theme is kept in your browser’s local storage.
  • Cloudflare Turnstile may set a technical cookie on the instant analysis page while it checks that you are not a bot.
  • Google Analytics, only if you accept it: the _ga and _ga_… cookies identify your browser for 13 months.

Once you accept, Rival sends Google the pages you view (with workspace names, identifiers and anything after “?” removed from the address), three steps (starting a sign-up, completing it and opening checkout for a plan, with the plan and billing period), technical details (browser, device, screen size, language, approximate location that Google derives from your IP address) and a random identifier. Never your email, your name, your workspace or anything you type into Rival. Advertising features and Google signals are turned off.

Google keeps these measurements for 14 months. Your choice, accepted or refused, is kept for 6 months; after that Rival asks again. Refusing changes nothing in how Rival works.

To change your mind, open Cookie preferences at the bottom of any public page, from Settings › Preferences in the app, or with the button below. If you withdraw your consent, Rival stops measuring right away and deletes the Google Analytics cookies from this site.

12. How long we keep data

  • Your account and your workspaces: as long as your account exists. You delete a workspace yourself from Settings › Workspace, and your account from Settings › Preferences: the workspace, its followed competitors, its decisions, its connections and its brand logo are erased right away. We keep only the audit log and the billing records, for the periods below.
  • Shopify and Instagram access tokens: until you disconnect the account or uninstall the app; they are then erased.
  • Captures of followed brands: as long as the brand is followed in a workspace. Social posts of an account no workspace follows any more are purged automatically.
  • Product events: 13 months.
  • Instant analyses and brand readings at sign-up: 7 days.
  • Emails left to receive a store comparison: 3 years from the request or from your last contact with us, as recommended by the CNIL for prospects. If you unsubscribe, we keep your address for the same period only so we never write to you again.
  • Your feedback and our replies: as long as your account exists.
  • Billing records and the usage ledger: 10 years, the legal retention period for accounting documents.
  • Error reports: 90 days at Sentry.
  • Google Analytics measurements: 14 months; your choice, 6 months.

13. How we protect data

  • Workspace isolation: every database query runs under your identity, and row level security rules block any access to another workspace’s data.
  • Encryption: Shopify and Instagram tokens are encrypted (AES-256-GCM) with a key separate from the database; API keys are stored as a fingerprint only; every exchange goes through TLS.
  • Private files: captures, HTML and logos live in private storage spaces, reachable only through signed links valid for a few minutes, after your rights are checked.
  • Restraint: Rival stores no password and no card number, caps AI spending per workspace and logs every call.

14. Your rights

Under the GDPR you can access your data, have it corrected or deleted, receive a copy in a structured, commonly used format, restrict its processing, object to processing based on our legitimate interest and withdraw a consent at any time.

To exercise them, write to support@rival.watch from your account address, or ask your workspace owner. We answer within one month.

You can also file a complaint with the CNIL, the French data protection authority.

15. A service for professionals

Rival is for businesses and professionals. It is not intended for people under 18, and we do not knowingly collect data about them. If you believe a minor created an account, write to us: we delete it.

16. Changes to this policy

We update this policy when Rival changes: new provider, new source, new feature. The date at the top of the page shows the latest version. For a significant change, we notify you by email or in the app before it applies.

Back to top