How we handle your data.
Depending on your plan and the accounts you connect, you may trust RaveHQ with your business profile, website, inquiries, booking or customer records, and authorized channel access. Here is exactly how payments, data, isolation, and authority are handled — no vague claims, no certifications we do not have.
We never see or store your card number.
All payments are processed by Stripe, a PCI-compliant payment processor used by millions of businesses worldwide. Your card details are entered directly into Stripe's secure checkout and never touch RaveHQ's servers. RaveHQ stores only what's needed to manage your subscription — plan, billing status, and a Stripe customer reference — never full card numbers.
Managed cloud infrastructure, encrypted in transit.
RaveHQ runs on managed cloud infrastructure (Cloudflare for the site and edge network, Railway for application hosting). We don't run our own servers or data centers — we rely on these providers' operational security, uptime, and patching practices.
Every connection to RaveHQ — the website, the audit tool, and account access — is encrypted in transit over HTTPS/TLS. There is no unencrypted path to or from our servers.
Used to run your account. Never sold.
Your connected-account access and business data are used only to deliver the plan you chose: maintaining the 51-check evidence register, building your dashboard and action queue, and operating only the authorized discovery, inquiry, booking, recovery, reputation, referral, reactivation, or customer-acquisition work included in that plan. We do not sell your personal data or your business's data to advertisers, data brokers, or any third party.
This aligns with our full Privacy Policy, which covers what we collect, how long we retain it, and your rights to access, export, or delete it.
When you connect customer or lead data, we follow your documented instructions.
If you enable inquiry response, booking follow-up, recovery, review requests, referrals, reactivation, or another connected workflow, RaveHQ may process contact details, messages, consent and suppression state, booking or appointment records, and verified outcomes. Your business determines the lawful purpose and source of that data; RaveHQ acts as your processor or service provider, subject to applicable law. These standard terms govern how we handle it:
- —Purpose limitation. We process customer and lead data only to deliver, secure, and evidence the connected workflows included in your plan and enabled by your account policy.
- —On your instructions. We process this data only on your documented instructions, as set through your account configuration and these terms. We don't decide new purposes for it.
- —No selling, no secondary use. We never sell your customers' data, never use it to train models for other customers, and never repurpose it for advertising or brokerage.
- —Retention and deletion. We delete or de-identify eligible data after a verified request or account termination, subject to the limited retention needed for billing, security, legal obligations, completed-action evidence, and permanent suppression of an opted-out address or number.
- —Appropriate security. We apply the technical and organizational measures described on this page — encrypted transport and connected-account tokens, tenant-scoped access, signed callbacks where supported, session protections, and audit records — to protect the data we process for you.
- —Subprocessors. We use the core subprocessors listed below to run the service and update the register when that core processing chain changes. Customer-directed providers you connect remain governed by your account with that provider as well as RaveHQ's configured authority.
Need a formal, signed Data Processing Agreement for your compliance file? We'll sign a full DPA on request — email [email protected] and we'll send one over.
Who we rely on to run the service.
These are the core third-party providers that may process data on RaveHQ's behalf. The exact path depends on the feature used. We update this list when the core processing chain changes and communicate material changes to affected customers under our terms.
| Subprocessor | Purpose | Data region |
|---|---|---|
| Anthropic | Account-specific AI analysis, classification, drafting, and action preparation. Only the data needed for the enabled feature is submitted under Anthropic's business/API terms; RaveHQ does not designate customer content for model training. | Processing: global; storage: United States by default |
| Resend | Transactional, lifecycle, reply-capture, review-request, and other policy-authorized email delivery. Processes recipient addresses, message content, and delivery events. | United States |
| Railway | Application hosting and database — where your account data and the service itself run. | Deployment-selected Railway region |
| Stripe | Payment processing and subscription billing. Handles card data directly — RaveHQ never sees or stores card numbers. | United States / global |
| Cloudflare | CDN, DNS, TLS, and edge security for the website and app. Processes connection metadata to route and protect traffic. | Global edge network |
| Apify | Optional public-web and business-profile data collection when that audit source is enabled. Processes the business name, public listing URL and publicly available review data needed for the requested audit. | Provider-controlled international processing |
| Public business identity and profile evidence, and customer-directed Google Business Profile or Google Ads connections when enabled. Data exchanged depends on the selected Google service and granted scopes. | Global provider network | |
| DataForSEO | Optional public search, local-business, and AI-search evidence when that source is enabled. Processes the business, location, domain, or query needed for the requested measurement. | Provider-controlled |
Customer-directed services such as Meta, Twilio, a CMS, CRM, or booking platform process data only when you connect and enable them; their own terms and your provider account also apply. Data-region labels above summarize the ordinary provider path and are not a residency guarantee. If residency is a requirement, contact us at [email protected] before onboarding so we can confirm the available configuration.
The safeguards, in plain terms.
Everything below is already how the product works — not a roadmap. We don't hold SOC 2 or ISO 27001 certification and we don't claim to; here is what we actually do.
- —Encrypted access tokens. The access tokens that connect your accounts (such as Google Business Profile) are encrypted at rest per tenant using Fernet symmetric encryption — they are never stored in plaintext.
- —Tenant-scoped access. Customer routes, records, dashboards, exports, billing controls, and connected credentials are resolved through the authenticated tenant. Founder administration is a separate protected surface.
- —Encrypted transport, hardened edge. Every connection runs over HTTPS/TLS (TLS 1.2 minimum) with HSTS enforced, DNSSEC enabled, and forced HTTPS at the edge. There is no unencrypted path in or out.
- —Verified inbound and outbound events. Supported provider callbacks are signature-checked, retryable actions use idempotency keys, and provider or public verification is stored separately from leads, bookings, and completed outcomes.
- —Consent, quiet hours, suppression, and unsubscribe. Customer communications run only from configured sources and channels inside the saved purpose, consent, quiet-hour, suppression, and opt-out policy. Marketing messages include the required unsubscribe path; an opt-out is honored and suppressed from future marketing sends.
- —No review-gating. RaveHQ never suppresses or filters the public Google review invite based on predicted sentiment. Every review request we send carries the same public Google review link, for every recipient, in line with FTC and Google policy.
- —No faked data or authority. We do not fabricate reviews, ratings, leads, bookings, outcomes, revenue, or provider confirmations. AI-drafted content remains inside the account's approval policy; eligible narrow automations may run only from business-approved templates and rules.
Found a security issue? Tell us directly.
If you believe you've found a security vulnerability or have any concern about how your data is handled, email us directly:
We respond to security reports within one business day. Please include as much detail as possible so we can investigate quickly.
Find your first visible growth gap in 20 seconds.
Start with public evidence. No sign-up or card. See what is measured now — and what requires connected data.
Start Free Audit →