RaveHQ
How It Works Pricing Industries Radar Insights About Log in Start Free Audit →
Home How It Works Pricing Industries Radar Insights About Start Free Audit →

Privacy Policy

Last updated: October 2026

Who we are

RaveHQ is operated by Avon Services FZ-LLC, Compass Building, Al Hulaila Industrial Zone-FZ, Ras Al Khaimah, UAE, operating as ravehq.co. This policy explains how we handle personal data when you use our website and services. Questions about this policy: [email protected].

What we collect

  • Account and billing data — your name, business name, email address, locations, plan, billing status, and Stripe customer or subscription references. Payment-card details are entered directly with Stripe and are not stored by RaveHQ.
  • Audit data — publicly available information about your business (public Google reviews, public listing/profile completeness, public website technical signals) fetched by our engine to generate your free audit. Your RaveScore is computed from the public Google review evidence only; the listing and website signals are reported alongside it, never inside it. No login or connection to your business is required for this.
  • Connected-business data — only when you authorize a supported connection: business-profile, website or CMS, social, advertising, messaging, booking, CRM, and related provider data needed for the plan and workflows you enable. Connection credentials and tokens are stored separately from ordinary account content and scoped to the business account that authorized them.
  • Customer-journey data — contact details, inquiries, message history, consent and suppression status, booking or appointment records, referral or reactivation state, and outcome evidence that you provide or make available through a connected system. The exact fields depend on the workflow you enable.
  • Usage and security data — pages or features used, dashboard actions, login and session events, provider receipts, error records, device or connection metadata, and audit logs needed to operate, secure, and troubleshoot the service.
  • Communication data — support emails, form submissions, replies, instructions, and other messages you send to RaveHQ.

Public scans and connected accounts

The free scan reads public business evidence and does not authenticate to your business accounts. Paid features may ask you to connect supported services through the provider’s authorization flow or by supplying credentials for a customer-owned account. A connection does not give RaveHQ unlimited authority: the plan, provider permissions, customer-set policy, approval rules, budgets, quiet hours, suppression rules, and stop-loss limits still control what may run.

You can revoke a provider connection from that provider, from an available account control, or by contacting [email protected]. RaveHQ then stops new work that depends on the connection and removes or invalidates the stored credential as the provider and retention rules permit. Disconnecting does not rewrite completed-action receipts, billing records, suppression records, or other evidence that must remain to prevent duplicate work, honor an opt-out, or document what already happened.

How we use it

  • To create and secure your account, manage your subscription, and provide customer support.
  • To produce the public scan, RaveScore, 51-check evidence register, dashboard, action queue, reports, and service emails included in your plan.
  • To operate only the connected discovery, website, inquiry, qualification, booking, recovery, reputation, referral, reactivation, and customer-acquisition workflows that you authorize.
  • To keep attempted actions, provider confirmations, leads, bookings, completed outcomes, attribution, opt-outs, and modeled opportunities separate and auditable.
  • To prevent fraud, unauthorized access, duplicate actions, unwanted communications, and other misuse; and to diagnose reliability or security issues.

Some features use an external AI provider to analyze evidence, classify or draft content, and prepare account-specific actions. We send only the data needed for the requested feature under the provider’s business/API terms. RaveHQ does not sell this data, does not use one customer’s private data to train models for another customer, and does not designate customer content for model training.

Your customer and lead data

Your business decides why customer or lead data is collected, which sources are lawful to connect, which communications are permitted, and which workflows RaveHQ may operate. For that data, RaveHQ acts as a processor or service provider on your documented instructions, subject to applicable law. You are responsible for the notices, permissions, consent, and other legal basis required for the sources and channels you enable.

RaveHQ does not repurpose a connected customer list as an unrelated cold-outreach list. Consent, purpose, channel permissions, quiet hours, suppression, and opt-out state remain part of the operating record. We retain the minimum opt-out record needed to prevent future messages covered by that opt-out, even after other message content is deleted. This does not limit a permitted service or transactional message, such as a reply to a request that person made.

Data sharing

We share data only as needed with the subprocessors that host, secure, bill, deliver messages for, or provide intelligence to the service; with providers you direct RaveHQ to connect (for example Google, Meta, Twilio, a CMS, CRM, or booking service); with professional advisers under confidentiality; or when disclosure is legally required. The current core subprocessor register is on our Security & Trust page. We do not sell data to advertisers or data brokers.

Cookies

We set only the cookies the service needs, each named here:

  • aios_session keeps you signed in to the app; it ends when you sign out or your session expires.
  • aios_csrf protects app forms against cross-site requests; it expires after 72 hours.
  • aios_google_signin_state and aios_gbp_oauth_state link a Google sign-in or a Google Business Profile connection back to your browser; each is set only during that step and expires after 10 minutes.
  • aios_founder_session is used only for RaveHQ staff sign-in; it expires after 90 days.
  • rhq_lpv counts unique visits on campaign pages that a RaveHQ customer publishes (under /lp/); it is first-party and expires after 30 days.

On ravehq.co we store your cookie choice (accepted or declined) in your browser, and we do not set analytics cookies; if that changes, this page will name the provider, purpose, and lifetime of each one. You can change your choice at any time with the Cookie settings button at the bottom of every page, or disable cookies in your browser; signing in requires the essential app cookies above.

Retention

Different records have different retention periods, set out below. Deletion requests are handled by people, not by an automatic process. Separately, some records follow automatic schedules, shown in the table: email-less free scans, backups, sessions and operations logs.

Record What it covers How long we keep it
Account and business data Your account, business profile, connected-tool data, reports, review data we collected for your business While your account exists. After cancellation we keep it so you can reactivate. We delete or de-identify it when you make a verified deletion request.
Free review scan / free audit Business name, website, email if you gave one Radar scans without an email are deleted automatically after 90 days. Other free-scan records are kept until you ask us to delete them.
Opt-out and suppression records The email address or number that asked not to be contacted Kept in minimal form for as long as needed to keep honoring the opt-out, including after a deletion request.
Outreach and messaging records Messages we sent or received, delivery receipts Kept as a record of what was sent. On a verified deletion request we delete or de-identify the personal details.
Newsletter Your subscription, frequency choice and consent record Until you unsubscribe. We keep the unsubscribe and consent record as proof of your choice.
Billing Stripe customer and subscription references, invoices As long as needed for tax and accounting. Card details are held by Stripe, not RaveHQ.
Backups Encrypted copies of our databases Local encrypted backups rotate after 8 days. Prior versions in our offsite encrypted backup expire after 30 days. Deleted data can persist in backups until then.
Security and operations records Sign-in sessions, rate-limit and security events, routine operations logs Sessions and security tokens expire automatically. Routine operations logs are kept for 7 days.

You can request an account-specific retention explanation or deletion by emailing [email protected]. We will delete or de-identify eligible data after verifying the request; suppression records may be retained so we keep honoring opt-outs, and records needed to prove completed actions, secure the service, or meet legal obligations may be retained for those limited purposes.

Your rights

Depending on your location, you may have rights to access, correct, export, or delete your personal data. If you have an account, email [email protected] from your account address. If you do not have an account, email [email protected] and identify the data or business involved; we may need to verify your identity, or refer the request to the business that holds the relationship with you. We will respond within 30 days.

Security

We use TLS encryption in transit, encrypted connected-account tokens, tenant-scoped access controls, signed provider callbacks where supported, session and login protections, and audit records. No system is 100% secure — if you believe your data has been compromised, contact us immediately. Our current security posture, data-processing terms, and subprocessor list are on our Security & Trust page.

Changes

We post the updated policy on this page with its effective date, and keep a dated revision history below. For material changes, we email account holders and subscribers at least 14 days before they take effect, unless the law requires a change sooner.

Contact

[email protected]

Revision history

  • October 2026 — current version. Names the operating entity, lists every cookie, adds the retention table and a request route for people without an account. These describe existing practices and do not change how we use personal data, so they take effect when published.
  • 2 August 2026 — previous version.
RaveHQ
How It Works Pricing Compare Industries Insights Methodology About Free Scan Get Started Contact Security Privacy Terms [email protected]
RaveHQ badge
© 2026 RaveHQ. All rights reserved.
Built on Claude by Anthropic.