Privacy

Privacy Policy

RAVES is committed to protecting your personal data. This policy explains what data we collect, how we use it, who we share it with, and your rights.

Last updated: June 30, 2026

RAVES.AI, Inc. acts as a data controller for data collected on our website and marketing activities. For data processed within the platform on behalf of our customers, RAVES acts as a data processor.

1. Data We Collect

Account & contact data — name, email address, job title, company, and phone number when you register, book a demo, or contact us.

Platform usage data — pages visited, features used, session duration, and error logs, used to operate and improve the Services.

Workforce data (customer-controlled) — employee and contractor profiles, timesheets, payroll figures, contracts, and documents entered by customers and their workers. Customers are the data controllers for this data; RAVES processes it on their behalf.

Device & technical data — IP address, browser type, operating system, and referring URL, collected automatically when you access our website or platform.


2. How We Use Your Data

  • Providing, operating, and improving the RAVES platform and Services.
  • Sending transactional communications — account confirmations, invoices, security alerts.
  • Sending marketing communications where you have given consent or we have a legitimate interest (you can unsubscribe at any time).
  • Analytics and product development using aggregated, anonymised data.
  • Complying with legal obligations and responding to lawful requests from authorities.
  • Fraud prevention, security monitoring, and platform integrity.

3. Sharing Your Data

We do not sell your personal data. We may share data with:

  • Service providers — cloud hosting, payment processing, email delivery, and analytics tools — who process data on our behalf under data processing agreements.
  • Professional advisors — lawyers, accountants, and auditors under confidentiality obligations.
  • Authorities — where required by law, court order, or to protect the rights and safety of RAVES or others.
  • Business transfers — in the event of a merger, acquisition, or asset sale, where data may be transferred to the successor entity.

4. International Transfers

RAVES is headquartered in the United States. If you are located outside the US, your data may be transferred to and processed in the US or other countries where our service providers operate.

For transfers from the European Economic Area (EEA) or UK, we rely on appropriate safeguards including Standard Contractual Clauses (SCCs) approved by the relevant supervisory authority.


5. Data Security

We implement industry-standard security measures to protect your data:

  • Encryption in transit (TLS 1.2+) and at rest (AES-256).
  • Role-based access controls limiting data access to authorised personnel.
  • Regular penetration testing and vulnerability assessments.
  • SOC 1 & SOC 2 Type II and ISO 9001:2015 certifications.
  • Incident response procedures with notification timelines compliant with GDPR and applicable law.

No method of transmission or storage is 100% secure. If you believe your account has been compromised, contact us immediately at security@raves.ai.


6. Data Retention

We retain personal data for as long as necessary to fulfil the purposes described in this policy, or as required by applicable law:

  • Account data — retained for the duration of the customer relationship plus 7 years.
  • Platform workforce data — retained per the customer's data retention configuration; deleted within 90 days of account closure on request.
  • Marketing data — retained until you unsubscribe or withdraw consent.
  • Server logs — typically 90 days.

7. Your Rights

Depending on your location, you may have the following rights regarding your personal data:

  • Access — request a copy of the personal data we hold about you.
  • Rectification — ask us to correct inaccurate or incomplete data.
  • Erasure — request deletion of your data where no overriding legal basis applies.
  • Restriction — ask us to limit how we process your data in certain circumstances.
  • Portability — receive your data in a structured, machine-readable format.
  • Objection — object to processing based on legitimate interests or for direct marketing.
  • Withdraw consent — where processing is based on consent, withdraw it at any time without affecting prior processing.

To exercise any of these rights, contact us at privacy@raves.ai. We will respond within 30 days (or 72 hours for breach notifications as required by GDPR).

You also have the right to lodge a complaint with your local data protection authority. For EEA residents, find your authority at edpb.europa.eu.


8. California Privacy Rights (CCPA)

If you are a California resident, you have additional rights under the California Consumer Privacy Act (CCPA):

  • Right to know — what personal information we collect, use, disclose, and sell.
  • Right to delete — request deletion of personal information we have collected.
  • Right to opt-out — we do not sell personal information.
  • Right to non-discrimination — we will not discriminate against you for exercising your rights.

To submit a CCPA request, contact privacy@raves.ai or use our Contact page.


9. Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of material changes via email or a prominent notice on our platform at least 14 days before the changes take effect. The "Last updated" date at the top of this page reflects the most recent revision.

Questions about this policy?
Our team is happy to help clarify anything.
Contact Us