How we handle your data.
Depending on your plan and the accounts you connect, RaveHQ may hold your business profile, website, inquiries, booking or customer records, and authorized channel access. This page explains how we handle payments, connected accounts, customer data and permissions, and which providers we use.
We never see or store your card number.
All payments are processed by Stripe, a PCI-compliant payment processor. Your card details are entered directly into Stripe's secure checkout and never touch RaveHQ's servers. RaveHQ stores only what's needed to manage your subscription — plan, billing status, and a Stripe customer reference — never full card numbers.
Managed cloud infrastructure, encrypted in transit.
RaveHQ runs on managed cloud infrastructure (Cloudflare for the site and edge network, Railway for application hosting). We don't run our own servers or data centers — we rely on these providers' operational security, uptime, and patching practices.
The public website, audit tool, and account connections use HTTPS/TLS in transit.
Used to run your account. Never sold.
Your connected-account access and business data are used only to deliver the plan you chose: maintaining the 51-check evidence register, building your dashboard and action queue, and operating only the authorized discovery, inquiry, booking, recovery, reputation, referral, reactivation, or customer-acquisition work included in that plan. We do not sell your personal data or your business's data to advertisers, data brokers, or any third party.
This aligns with our full Privacy Policy, which covers what we collect, how long we retain it, and your rights to access, export, or delete it.
When you connect customer or lead data, we follow your documented instructions.
If you enable inquiry response, booking follow-up, recovery, review requests, referrals, reactivation, or another connected workflow, RaveHQ may process contact details, messages, consent and suppression state, booking or appointment records, and verified outcomes. Your business determines the lawful purpose and source of that data; RaveHQ acts as your processor or service provider, subject to applicable law. These standard terms govern how we handle it:
- —Purpose limitation. We process customer and lead data only to run and secure the workflows you enable, and keep records of the actions taken.
- —On your instructions. We process this data only on your documented instructions, as set through your account configuration and these terms. We don't decide new purposes for it.
- —No selling, no secondary use. We never sell your customers' data, never use it to train models for other customers, and never repurpose it for advertising or brokerage.
- —Retention and deletion. Retention periods by record type are published in the Privacy Policy’s retention table; both pages use the same terms.
- —Appropriate security. We apply the technical and organizational measures described on this page — encrypted transport and connected-account tokens, tenant-scoped access, signed callbacks where supported, session protections, and audit records — to protect the data we process for you.
- —Subprocessors. We use the core subprocessors listed below to run the service and update the register when that core processing chain changes. Customer-directed providers you connect remain governed by your account with that provider as well as RaveHQ's configured authority.
Need a formal, signed Data Processing Agreement for your compliance file? We'll sign a full DPA on request — email [email protected] and we'll send one over.
Who we rely on to run the service.
The table below lists the providers that process data on RaveHQ's behalf, what each one is used for, and the data region involved. Providers you connect yourself, such as Google or Meta, are explained separately below the table. We update this list when the core processing chain changes and communicate material changes to affected customers under our terms.
| Subprocessor | Purpose | Data region |
|---|---|---|
| Anthropic | Account-specific AI analysis, classification, drafting, and action preparation, under Anthropic's business/API terms. Only the data needed for the enabled feature is sent, and RaveHQ does not designate customer content for model training. | Processing: global; storage: United States by default |
| Resend | Transactional, lifecycle, reply-capture, review-request, and other policy-authorized email delivery. Processes recipient addresses, message content, and delivery events. | United States |
| Railway | Application hosting and database — where your account data and the service itself run. | United States (US East, Virginia) |
| Backblaze | Encrypted offsite copies of the service databases, kept for disaster recovery. | United States (US East) |
| Stripe | Payment processing and subscription billing. Handles card data directly — RaveHQ never sees or stores card numbers. | United States / global |
| Cloudflare | CDN, DNS, TLS, and edge security for the website and app. Processes connection metadata to route and protect traffic. | Global edge network |
| Apify | Optional public-web and business-profile data collection when that audit source is enabled. Processes the business name, public listing URL and publicly available review data needed for the requested audit. | Provider-controlled international processing |
| Public business identity and profile evidence, and customer-directed Google Business Profile or Google Ads connections when enabled. Data exchanged depends on the selected Google service and granted scopes. | Global provider network | |
| DataForSEO | Optional public search, local-business, and AI-search evidence when that source is enabled. Processes the business, location, domain, or query needed for the requested measurement. | Provider-controlled |
Customer-directed services such as Meta, Twilio, a CMS, CRM, or booking platform process data only when you connect and enable them; their own terms and your provider account also apply. Data-region labels above summarize the ordinary provider path and are not a residency guarantee; the Railway and Backblaze regions were checked against our live configuration in October 2026. If residency is a requirement, contact us at [email protected] before onboarding so we can confirm the available configuration.
The safeguards, in plain terms.
We don't hold SOC 2 or ISO 27001 certification. These safeguards describe how the product works, last reviewed in October 2026.
- —Encrypted access tokens. The access tokens that connect your accounts (such as Google Business Profile) are encrypted at rest per tenant using Fernet symmetric encryption — they are never stored in plaintext.
- —Tenant-scoped access. Your account data — records, dashboards, exports, billing controls, and connected credentials — is restricted to authorized users of your business account. Administrative access is restricted separately.
- —Encrypted transport, hardened edge. Every connection runs over HTTPS/TLS (TLS 1.2 minimum) with HSTS enforced, DNSSEC enabled, and forced HTTPS at the edge. There is no unencrypted path in or out.
- —Verified inbound and outbound events. Supported integrations verify incoming provider messages (signature-checked callbacks) and use idempotency keys so a retried action is not repeated. Provider or public confirmations are recorded separately from leads, bookings, and completed outcomes.
- —Consent, quiet hours, suppression, and unsubscribe. Before sending, RaveHQ checks the configured purpose, channel permission, allowed sending times, and opt-out list — settings your business sets for its account. Marketing messages include the required unsubscribe path; an opt-out is honored and suppressed from future marketing sends.
- —No review-gating. RaveHQ does not select review-invite recipients or filter the review invite based on predicted sentiment. Every review request we send carries the same public Google review link, for every recipient.
- —No faked data or authority. We do not fabricate reviews, ratings, leads, bookings, outcomes, revenue, or provider confirmations. AI-drafted content remains inside the account's approval policy; eligible narrow automations may run only from business-approved templates and rules.
Found a security issue? Tell us directly.
If you believe you've found a security vulnerability or have any concern about how your data is handled, email us directly:
Please put “Security” in the subject and include as much detail as possible so we can investigate.
Find your first visible growth gap in 20 seconds.
Start with public evidence. No sign-up or card. See what is measured now — and what requires connected data.
Start Free Audit →