Version 2.0 (supersedes the version last updated January 20, 2021)
Raiven, Inc. ("Raiven," "we," "us") provides procurement technology and services to businesses. This policy explains what personal information we handle, why, who we share it with, how long we keep it, and your choices.
What this covers
This policy applies to raiven.com and our other websites, the Raiven Platform, the Raiven Mobile app, Raiven Assist, and our sales, marketing, and support activities.
Two things have their own notices:
If you bought a product from an online store we operate under another company's brand, see the Store Privacy Notice posted on that store. Raiven is the seller of record there and handles your information under that notice.
If your information is in the Platform because your employer put it there, see Section 3. Your employer controls that information.
Collection of Information
In short
We do not sell personal information and never share it for advertising.
We run no advertising trackers — no ad pixels, ad networks, or retargeting.
We use no session recording, screen replay, or keystroke logging.
We collect no sensitive personal information — no government IDs, precise location, biometrics, health data, or contents of private communications.
Our services are for business use and are not directed to anyone under 18.
We publicly commit not to re-identify anything we de-identify (Section 6).
Our two roles
Where we are the controller. When you visit our sites, submit a form, request a demo, appear in our prospect or customer records, register or administer a Platform account, contact support, or attend an event, we decide the purposes. This policy governs that information.
Where we are a processor. When a business customer uses the Platform, that customer decides what information about its own personnel goes in and how it's used — names, work email and phone, job titles, branch assignments, approval authority, and the quotes and orders those people create. For that information:
Our customer is the controller; we are a processor and service provider.
We use it only to provide the services under our agreement with that customer. We do not use it for our own marketing, do not sell it, and do not share it for advertising.
To access, correct, or delete it, contact your employer. If you contact us, we will refer you or act on their instruction, and tell you which.
Our customer agreement and Data Processing Addendum govern, and control over this policy for that information.
What we collect, from where, and why
Categories. Name, business email and phone, mailing address, employer, job title, industry, and account number · username, hashed credentials, role and permissions · subscription and order details, billing contact, transaction records, quotes and purchase orders, supplier and category activity · billing and payment information — we do not store full card numbers; card data is handled by a PCI DSS–compliant processor · support tickets, emails, call notes, and Raiven Assist correspondence · IP address, browser, operating system, device model, pages viewed, session duration, and, in the app, device identifiers and push tokens.
Where it comes from. Directly from you · automatically through cookies (Section 5) · from our business customers and referral partners · from suppliers, carriers, payment processors, and tax and fraud services in connection with transactions · and:
From third-party business-data providers, enrichment vendors, and publicly available sources. We license business contact information — typically name, employer, job title, business email, and business phone — about people at companies that fit our customer profile, so we can contact them about Raiven. You may hear from us without having given us your information yourself. Every such message tells you how to stop, and we honor that. To ask what we hold or to be removed entirely, write to [email protected].
Why we use it. To provide, secure, and support the Platform, app, and Raiven Assist · administer accounts and authenticate users · process subscriptions, invoices, payments, and taxes · transmit quotes and purchase orders to suppliers at a user's request · provide reporting and supplier performance information to customers · generate automated comparisons and recommendations (Section 6) · communicate about service, security, billing, and support · market our services to businesses and measure whether that works · detect and prevent fraud and security incidents · comply with law and enforce our agreements · and develop and improve our products, subject to Section 6.
Cookies and analytics
We use strictly necessary cookies for sign-in, session integrity, and security · Google Analytics for aggregate usage measurement, with Google Signals disabled and no audience export to any advertising platform · HubSpot, which sets a cookie letting us recognize a returning visitor and associate website activity with a business contact record — disclosed here because it can identify you, not merely count you · and functional embeds for scheduling, video, and bot protection, which receive your IP address in order to work.
We do not use advertising or retargeting pixels of any kind, ad networks or ad servers, session recording or keystroke logging, or cross-site tracking for advertising.
You can block or delete cookies in your browser; strictly necessary cookies are required for the service to function. Because we do not sell your information, share it for behavioral advertising, or engage in targeted advertising, there is no advertising opt-out to offer. If that changes we will update this policy in advance, provide an opt-out, and honor Global Privacy Control signals.
Automated processing and de-identified data
The Platform uses automated processing and machine learning to compare supplier quotes, classify products and categories, reconcile documents, and generate recommendations, including Best Value™ decisioning. These outputs concern products, suppliers, and business purchasing — they are not decisions about individuals. We do not use automated processing to make decisions about people that produce legal or similarly significant effects. Output is advisory and our customers are responsible for reviewing it.
We do not use customer data in identifiable form to train models for other customers or for general-purpose model development, and we do not build individual profiles for advertising.
De-identified and aggregated data. We use de-identified and aggregated transaction, purchasing, and usage data for analytics, benchmarking, supplier negotiations, performance reporting, program optimization, and the development, training, and improvement of our products, models, and services. We publicly commit that we will: use measures reasonably designed to prevent re-identification; not attempt to re-identify, and not permit any third party to do so; contractually require recipients to keep the data de-identified; and not link it back to an identifiable person. The only exception is a controlled internal test to confirm our de-identification methods work.
Who we share with
Service providers and processors — cloud hosting, payment processing, CRM, email, support ticketing, analytics, tax, and security. Each is contractually limited to working on our instructions and prohibited from selling the information or using it for its own purposes. Current list available on request.
Suppliers and carriers — the information needed to fulfill a quote, order, or delivery. They act independently under their own privacy practices.
Our business customers — where you are an authorized user, your employer receives account and activity information.
Professional advisors and insurers, under confidentiality · legal and safety — to comply with law, subpoenas, and lawful requests, defend claims, investigate fraud, and protect safety · corporate transactions — a financing, merger, or asset sale, where any acquirer is bound by this policy or gives notice before materially changing it.
We do not sell personal information, do not share it for cross-context behavioral or targeted advertising, and do not disclose it for anyone else's direct marketing.
We also disclose de-identified and aggregated information, subject to Section 6.
How long we keep it
Website analytics
14 months
Marketing and prospect records
While the relationship continues, and no more than 36 months after last meaningful engagement
Platform account records
The subscription term; Customer Data available for export 30 days after termination, then deleted in the ordinary course
Transaction, invoicing, and tax records
7 years
Support and Raiven Assist correspondence
3 years from resolution
Security and access logs
12 months, longer for an active investigation
Do-not-contact records
Indefinitely, so we don't contact you again
Where law requires longer, or we need information for an active claim or investigation, we keep it for that period and then delete it.
Security
We maintain safeguards appropriate to the information we hold, including encryption in transit and at rest, segregated database infrastructure, network and application firewalls, intrusion detection, least-privilege access controls, hashed credentials, logging and monitoring, vulnerability management, and personnel training and confidentiality obligations.
If we confirm unauthorized access to personal information we hold, we will notify affected individuals and, where applicable, our business customers and regulators, without undue delay and within the time applicable law requires. For information held on behalf of a business customer, we notify that customer within 72 hours of confirmation and support their own obligations.
No system is perfectly secure. If you believe your interaction with us is no longer secure, contact us immediately.
Your choices and rights
We offer these to everyone this policy covers, wherever you live, whether or not a law requires it of us. Residents of states with privacy laws have them as a matter of law.
You may ask us to know and access what we hold and give you a copy · correct anything inaccurate · delete your information · port it in a machine-readable format · opt out of marketing, and of any sale, sharing, targeted advertising, or profiling, none of which we do · limit use of sensitive information, which we don't collect.
How. Email [email protected], call (888) 272-0090, or write to the address below.
Process. We verify identity using information we already hold and won't ask for more than we need. An authorized agent may act for you with written permission. We respond within 45 days, and will tell you inside that window if we need up to 45 more.
Limits. We may decline in whole or part where the law permits — for example where we must keep tax or accounting records, where deletion would impair security or fraud prevention, or where a business customer controls the information under Section 3. We'll tell you why.
Appeals. If we deny a request, appeal within 60 days by emailing [email protected] with "Privacy Appeal" in the subject. Someone not involved in the original decision reviews it and we respond in writing within 45 days. If we deny the appeal, we'll tell you how to contact your state attorney general.
No retaliation. We will never deny service, change pricing, reduce quality, or retaliate because you exercised these rights.
Age. Our services are for business use and are not directed to anyone under 18. We do not knowingly collect information from anyone under 18. If you believe we have, write to [email protected] and we will delete it.
California. We have not sold or shared personal information, as those terms are defined under California law, in the preceding 12 months, and we do not disclose it for third parties' direct marketing.
Changes
For material changes we give at least 30 days' advance notice by email, in-platform notice, or prominent website notice, and the change takes effect at the end of that period. If a material change would expand how we use information already collected in a way you wouldn't reasonably expect, we'll get your consent first. Changes required by law or to address a security risk may take effect immediately. We always update the effective date and version above, and keep prior versions available on request.
Raiven, Inc., Attn: Privacy, 100 Spectrum Center Drive, Suite 870, Irvine, California 92618
Raiven operates in the United States and our services are directed to United States businesses. Information is processed and stored in the United States. If you need this policy in an alternative format, contact us and we'll provide one.
Find out how you can turn procurement into a performance advantage