Privacy Policy

Effective date: April 11, 2025 · Last updated: April 11, 2025

Rizzl ("we", "our", "us") operates the rizzl.io website and Rizzl platform. This page informs you of our policies regarding the collection, use, and disclosure of personal data when you use our Service and the choices you have associated with that data.

1. Information We Collect

1.1 Account Data

When you register, we collect your name, email address, and authentication credentials. If you use SSO (Google, Okta, Azure AD, or SAML), we receive your identity token from the provider.

1.2 Workspace Data

We store your studio name, team members, client records, and workspace configuration. This includes plan selection, notification preferences, and integration settings.

1.3 Content You Upload

Assets (AEP, MOGRT, MP4, MOV, images, etc.), portal content, comments, and task data are stored in your workspace. Files are stored in Cloudflare R2 (or your own storage if using BYOS).

1.4 Usage Data

We automatically collect: pages visited, features used, browser type, device type, IP address, and timestamps. We use this to improve the product and diagnose issues.

1.5 Payment Data

Payment processing is handled by Stripe. We do not store your full credit card number. Stripe's privacy policy governs payment data handling.

2. How We Use Your Information

We do not sell, rent, or trade your personal information to third parties for marketing purposes.

3. Data Storage & Security

Your data is stored on:

All data is transmitted over TLS 1.3. Database backups are encrypted and retained for 30 days. We use role-based access control internally — only authorized personnel can access production data for support purposes.

4. Data Sharing

We share data only with the following service providers who are necessary to operate Rizzl:

We do not share data with advertising networks, data brokers, or any other third parties.

5. Client Portal Data

When your clients access review portals, we collect their IP address, browser user agent, and any comments or approvals they submit. This data belongs to your workspace and is visible only to workspace members with appropriate permissions.

IP Vault restrictions, when enabled, add an additional security layer by limiting portal access to specific IP ranges.

6. Data Retention

7. Your Rights

Under GDPR, CCPA, and other applicable privacy laws, you have the right to:

To exercise any of these rights, email support@rizzl.io. We respond within 30 days.

8. Cookies & Local Storage

Rizzl uses localStorage to maintain your session (authentication token, workspace ID, user preferences). We do not use third-party tracking cookies, advertising pixels, or analytics scripts.

9. Children's Privacy

Rizzlis not intended for use by children under 16. We do not knowingly collect personal data from children. If you believe a child has provided us with personal data, contact us and we will delete it.

10. International Transfers

If you access Rizzl from outside the United States, your data may be transferred to and processed in the US or EU, where our servers are located. We ensure appropriate safeguards are in place for international transfers in compliance with GDPR Standard Contractual Clauses.

11. Changes to This Policy

We may update this policy periodically. Material changes will be communicated via email to account holders and/or via an in-app notification at least 30 days before taking effect. Continued use of Rizzl after changes constitutes acceptance.

12. Contact

For privacy-related questions or requests:

Email: support@rizzl.io
Data Protection Officer: Rizzl Privacy Team
Response time: Within 30 days of receipt