Privacy Policy
Last updated: 2 August 2026
Who we are
RaveHQ operates ravehq.co — an autonomous local growth platform spanning digital-foundation improvement, connected customer acquisition, conversion, reputation, referrals, and reactivation. Questions about this policy: [email protected].
What we collect
- Account and billing data — your name, business name, email address, locations, plan, billing status, and Stripe customer or subscription references. Payment-card details are entered directly with Stripe and are not stored by RaveHQ.
- Audit data — publicly available information about your business (public Google reviews, public listing/profile completeness, public website technical signals) fetched by our engine to generate your free audit. Your RaveScore is computed from the public Google review evidence only; the listing and website signals are reported alongside it, never inside it. No login or connection to your business is required for this.
- Connected-business data — only when you authorize a supported connection: business-profile, website or CMS, social, advertising, messaging, booking, CRM, and related provider data needed for the plan and workflows you enable. Connection credentials and tokens are stored separately from ordinary account content and scoped to the tenant that authorized them.
- Customer-journey data — contact details, inquiries, message history, consent and suppression status, booking or appointment records, referral or reactivation state, and outcome evidence that you provide or make available through a connected system. The exact fields depend on the workflow you enable.
- Usage and security data — pages or features used, dashboard actions, login and session events, provider receipts, error records, device or connection metadata, and audit logs needed to operate, secure, and troubleshoot the service.
- Communication data — support emails, form submissions, replies, instructions, and other messages you send to RaveHQ.
Public scans and connected accounts
The free scan reads public business evidence and does not authenticate to your business accounts. Paid features may ask you to connect supported services through the provider’s authorization flow or by supplying credentials for a customer-owned account. A connection does not give RaveHQ unlimited authority: the plan, provider permissions, customer-set policy, approval rules, budgets, quiet hours, suppression rules, and stop-loss limits still control what may run.
You can revoke a provider connection from that provider, from an available account control, or by contacting [email protected]. RaveHQ then stops new work that depends on the connection and removes or invalidates the stored credential as the provider and retention rules permit. Disconnecting does not rewrite completed-action receipts, billing records, suppression records, or other evidence that must remain to prevent duplicate work, honor an opt-out, or document what already happened.
How we use it
- To create and secure your account, manage your subscription, and provide customer support.
- To produce the public scan, RaveScore, 51-check evidence register, dashboard, action queue, reports, and service emails included in your plan.
- To operate only the connected discovery, website, inquiry, qualification, booking, recovery, reputation, referral, reactivation, and customer-acquisition workflows that you authorize.
- To keep attempted actions, provider confirmations, leads, bookings, completed outcomes, attribution, opt-outs, and modeled opportunities separate and auditable.
- To prevent fraud, unauthorized access, duplicate actions, unwanted communications, and other misuse; and to diagnose reliability or security issues.
Some features use an external AI provider to analyze evidence, classify or draft content, and prepare account-specific actions. We send only the data needed for the requested feature under the provider’s business/API terms. RaveHQ does not sell this data, use one customer’s private data to train another customer’s experience, or intentionally submit customer content for third-party model training.
Your customer and lead data
Your business decides why customer or lead data is collected, which sources are lawful to connect, which communications are permitted, and which workflows RaveHQ may operate. For that data, RaveHQ acts as a processor or service provider on your documented instructions, subject to applicable law. You are responsible for the notices, permissions, consent, and other legal basis required for the sources and channels you enable.
RaveHQ does not repurpose a connected customer list as an unrelated cold-outreach list. Consent, purpose, channel permissions, quiet hours, suppression, and opt-out state remain part of the operating record. Unsubscribe and suppression records may be retained after other message content is deleted so the system does not contact that person again.
Data sharing
We share data only as needed with the subprocessors that host, secure, bill, deliver messages for, or provide intelligence to the service; with providers you direct RaveHQ to connect (for example Google, Meta, Twilio, a CMS, CRM, or booking service); with professional advisers under confidentiality; or when disclosure is legally required. The current core subprocessor register is on our Security & Trust page. We do not sell data to advertisers or data brokers.
Cookies
We use essential cookies to keep you logged in and remember your preferences. We use analytics cookies to understand how the site is used. You can disable non-essential cookies in your browser settings; the core service will continue to function.
Retention
We retain data only for the period needed to provide the service, preserve account history and evidence, honor suppression or opt-out choices, maintain security, resolve disputes, and meet billing or legal obligations. Different records therefore have different retention periods. You can request an account-specific retention explanation or deletion by emailing [email protected]. We will delete or de-identify eligible data after verifying the request; records needed to prevent unwanted contact, prove completed actions, secure the service, or meet legal obligations may be retained for those limited purposes.
Your rights
Depending on your location, you may have rights to access, correct, export, or delete your personal data. To exercise any of these rights, email [email protected] from the address associated with your account. We will respond within 30 days.
Security
We use TLS encryption in transit, encrypted connected-account tokens, tenant-scoped access controls, signed provider callbacks where supported, session and login protections, and audit records. No system is 100% secure — if you believe your data has been compromised, contact us immediately. Our current security posture, data-processing terms, and subprocessor list are on our Security & Trust page.
Changes
We may update this policy. Material changes will be communicated by email to active subscribers at least 14 days before they take effect. The “last updated” date at the top of this page reflects the most recent revision.