Privacy Policy
Last Updated: December 27, 2025
SLPWLK LLC ("we," "us," or "our"), operating as Rivet, is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our construction billing automation platform (the "Service").
1. Information We Collect
Information You Provide
- Account Information: Name, email address, phone number, company name when you create an account
- Business Information: Company address, trade type, contractor license number, and tax ID
- Financial Documents: AIA G702/G703 forms, invoices, lien waivers, and other construction documents you upload
- Project Data: Project names, contract amounts, schedules of values, change orders, and billing periods
- Payment Information: Billing address (payment card details are processed directly by Stripe and never stored on our servers)
Information Collected Automatically
- Usage Data: Pages visited, features used, actions taken within the Service
- Device Information: Browser type, operating system, IP address
- Cookies: Session cookies for authentication and analytics cookies (see Section 7)
2. How We Use Your Information
We use the information we collect to:
- Provide the Service, including processing documents and tracking project billing
- Sync data with connected accounting systems (QuickBooks Online, Xero)
- Generate lien waivers and compliance documents
- Send transactional emails (billing confirmations, document notifications)
- Provide customer support
- Improve and develop new features
- Prevent fraud and enforce our Terms of Service
3. Third-Party Service Providers
We share information with the following categories of service providers:
- Clerk - Authentication and user management
- Stripe - Payment processing (PCI DSS Level 1 certified)
- Neon - Database hosting
- Vercel - Application hosting
- AWS S3 - Document storage
- Sentry - Error monitoring
- Resend - Transactional email delivery
These providers process data on our behalf and are contractually obligated to protect your information.
4. Data Security
We implement security measures including:
- Encryption in transit using TLS 1.3
- Encryption at rest using AES-256 for sensitive data (OAuth tokens, credentials)
- Role-based access control
- Audit logging of data access
- Rate limiting to prevent abuse
While we strive to protect your information, no method of transmission over the Internet is 100% secure. We cannot guarantee absolute security.
5. Data Retention
We retain your data as follows:
- Account Data: Retained while your account is active and for 30 days after deletion request
- Project Data: Retained while your account is active; deleted upon account closure
- Uploaded Documents: Retained while your account is active; deleted upon account closure
- Audit Logs: Retained for 2 years for compliance purposes
- Billing Records: Retained for 7 years as required by tax law
6. Your Rights
Depending on your location, you may have the following rights:
- Access: Request a copy of the personal information we hold about you
- Correction: Request correction of inaccurate information
- Deletion: Request deletion of your personal information (subject to legal retention requirements)
- Data Portability: Request your data in a machine-readable format
- Objection: Object to processing of your personal information
To exercise these rights, contact us at privacy@slpwlk.io. We will respond within 30 days.
California Residents (CCPA)
California residents have additional rights under the CCPA. We do not sell personal information. You may request disclosure of the categories of personal information we collect and our business purposes for collecting it.
7. Cookies
We use the following types of cookies:
- Essential Cookies: Required for authentication and security (cannot be disabled)
- Analytics Cookies: Help us understand how users interact with the Service
You can control cookies through your browser settings. Disabling essential cookies will prevent you from using the Service.
8. International Data Transfers
Our servers are located in the United States. If you access the Service from outside the United States, your information will be transferred to and processed in the United States. By using the Service, you consent to this transfer.
9. Children's Privacy
The Service is not intended for individuals under 18 years of age. We do not knowingly collect personal information from children.
10. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of material changes by posting the new policy on this page and updating the "Last Updated" date. Your continued use of the Service after changes constitutes acceptance of the updated policy.
11. Contact Us
If you have questions about this Privacy Policy or wish to exercise your rights, please contact us at privacy@slpwlk.io.
For questions about data processing in connection with QuickBooks Online or Xero, please also refer to Intuit's Privacy Statement and Xero's Privacy Notice.