Privacy & Data Protection

Privacy Policy

Effective Date: January 1, 2025 • Last Updated: March 2025

Rivoner (“we”, “us”, or “our”) takes your privacy seriously. This Privacy Policy describes how we collect, use, disclose, and protect personal and commercial information when you access our website, merchant portal, and payment services.

1. Information We Collect

Merchant Account Information: When you create an account, we collect your business email address, hashed password, company or business name, contact details, and designated cryptocurrency payout wallet addresses.

Transaction Information: When transactions are processed through our payment gateway, we process transaction parameters including order amounts, fiat currency, customer email, order reference identifiers, and delivery status metadata. Card payment data is transmitted securely to certified PCI-DSS compliant processing endpoints; Rivoner does not store unencrypted primary account numbers (PAN) or CVV codes.

Technical & Log Data: We automatically collect standard server logs, IP addresses, browser user agent strings, and request timestamps to monitor system performance, enforce rate limits, and detect security threats.

2. How We Use Information

We use the collected information solely to:

  • Deliver payment processing, transaction verification, and automatic cryptocurrency payouts
  • Authenticate account access and manage merchant dashboard sessions
  • Send essential transactional notifications (payout confirmations, security alerts, and system notices)
  • Prevent fraud, abuse, card testing, and malicious activities
  • Comply with applicable legal obligations and financial industry standards

3. Data Sharing & Third Parties

We do not sell, rent, or trade your personal data. We disclose information only to:

  • Payment Acquirers & Processors: Necessary banking and card network partners to authorize card charges and conduct 3-D Secure authentication.
  • Blockchain Networks: Public transaction broadcasts necessary to deliver settled cryptocurrency to your designated wallet address. (Note: blockchain transactions are public by design).
  • Legal & Regulatory Authorities: When required by court order, valid subpoena, or applicable international law.

4. Security & Data Retention

We implement industry-standard encryption protocols (TLS 1.3), hashed credentials (bcrypt/Argon2), strict role-based access controls, and regular vulnerability audits. We retain merchant account and transaction records for the duration of the merchant relationship and as necessary to fulfill legal and accounting requirements.

5. Cookies & Tracking

We use strictly necessary session cookies required for authentication and security. We do not use third-party behavioral advertising or tracking trackers.

6. Your Rights & Inquiries

Depending on your jurisdiction, you may have rights to access, correct, or request deletion of your personal account data. To make an inquiry or exercise your privacy rights, please contact us through the Merchant Dashboard or via our support channels.