HomePrivacy Policy

Privacy Policy

How Rivers DX collects, uses, and shares information — for visitors to this website, prospective and active clients, and end-users of the campaigns we operate on our clients' behalf.

Last updated: September 10, 2026

1. Who we are

This Privacy Policy is issued by Rivers DX (“Rivers DX,” “we,” “us,” or “our”), a digital growth agency headquartered in Columbia, SC. It covers information we collect through riversdx.com (the “Site”), through direct communications with prospective and active clients, and through the marketing platforms we operate on behalf of our clients.

If you have questions about this policy or wish to exercise any of the rights described below, contact us at hello@riversdx.com or by mail at the address at the bottom of this page.

2. Scope — three groups this policy addresses

Our data-collection practices differ meaningfully depending on your relationship with us. This policy addresses three groups. Please read the section that fits your relationship:

  • Site visitors.Anyone browsing riversdx.com. See Sections 3–4.
  • Clients & prospective clients. Business owners and staff who contact us, meet with us, or engage us. See Section 5.
  • End-users of client campaigns. Consumers and business contacts who interact with websites, ads, forms, call-tracking numbers, or other properties that Rivers DX operates on behalf of a client. See Section 6. In that context, we act as a service provider (CCPA) or processor(GDPR/UK GDPR) on our client’s behalf, and our client’s own privacy policy governs the primary relationship.

3. Information we collect from site visitors

Information you provide through the contact form

When you submit our contact form, we collect the information you enter: first name, last name, business name (optional), email address, phone number, business website (optional), and the free-form message you send us. A hidden anti-spam field and a Cloudflare Turnstile challenge are also submitted so we can distinguish real inquiries from automated abuse.

Information collected automatically

When you visit the Site, we and our sub-processors automatically collect:

  • Device and browser data — IP address, user-agent string, approximate location derived from IP, referring URL, pages viewed, timestamps, and interaction events.
  • Cookies and similar technologies — first- and third-party cookies, local storage, and pixels set by Google Tag Manager, Google Analytics 4, and (on some pages) Meta and Google Ads conversion tags. See Section 10.
  • Security and integrity signals — Cloudflare edge logs (including IP, request path, and headers) retained briefly for DDoS protection, rate-limiting, and Turnstile bot-detection scoring.

4. How we use site-visitor information

  • To respond to your inquiry and follow up on it.
  • To route qualified inquiries into our CRM (GoHighLevel) so we can schedule a call, send a proposal, or continue the conversation by email.
  • To measure marketing performance (aggregate page views, conversion rates, traffic sources) and improve the Site.
  • To detect and prevent spam, fraud, credential stuffing, and other abuse.
  • To comply with legal obligations and enforce our Terms of Service.

We do not sell or rent personal information, and we do not use contact-form submissions for cold outbound marketing to third parties.

5. Client & prospective-client information

During the sales process and throughout an engagement, we collect and maintain business-contact information (names, titles, work email addresses, phone numbers), engagement notes, meeting recordings and transcripts (with your knowledge), invoicing details, and copies of contracts and statements of work.

When you engage Rivers DX, you typically grant us delegated access to marketing platforms operated in your business’s name. Depending on the scope of work, this may include:

  • Advertising platforms — Google Ads (via our Manager / MCC account link), Meta Ads (via a Business Manager partner relationship), Microsoft Ads, LinkedIn Ads.
  • Analytics platforms — Google Analytics 4, Google Search Console, Google Business Profile, Google Tag Manager.
  • SEO tooling — Ahrefs, Semrush (site audits, rank tracking, backlink data associated with your domain).
  • Lead-tracking and call-tracking — CallRail (call recordings, transcripts, form submissions, source attribution), CRM systems such as GoHighLevel, HubSpot, ServiceTitan, Jobber, Housecall Pro, or ServicePal, and email/marketing-automation tools such as Mailchimp or Klaviyo.
  • Operational systems — dispatch, work-order, and point-of-sale systems (e.g., Vonigo, ServicePal) when reporting on cost per sold job requires outcome data.

Access is used solely to perform the services described in your agreement. Credentials are stored in a password manager or a platform-native secrets store, never in plain-text config files, and are limited to the personnel who need them.

6. End-users of client campaigns (processor role)

When Rivers DX operates a client’s website, landing pages, ads, or lead-capture systems, we may receive personal information about people who interact with those properties. This can include:

  • Phone calls, voicemails, and call transcripts captured by CallRail on dynamic tracking numbers assigned to marketing sources;
  • Form submissions and lead-form responses (including name, contact details, and any information the user chose to include);
  • Web-session data (IP, device, referring source, pages viewed, events) collected via Google Analytics 4, Meta Pixel, and Google Ads conversion tags;
  • Google Business Profile performance signals (calls, direction requests, website clicks by query and surface) — aggregated per location;
  • Search-performance signals (queries, pages, clicks, impressions, positions) from Google Search Console;
  • Outcome events (booked, inspected, quoted, sold, revenue) received from the client’s CRM or dispatch system so we can compute cost per sold job.

In this context Rivers DX acts as a service provider under the California Consumer Privacy Act / California Privacy Rights Act, and (where applicable) as a processor under the EU / UK General Data Protection Regulation. Our client is the business (the controller) responsible for the primary customer relationship and the primary privacy notice. If you are a consumer who interacted with a business Rivers DX serves and want to exercise a privacy right, please contact that business first; if you cannot reach them, contact us at hello@riversdx.com and we will route your request to them.

7. Sub-processors we rely on

We use the following categories of sub-processors to store, process, and transmit information. The list is not exhaustive and may change; each sub-processor is bound by contractual data-protection commitments consistent with applicable law.

  • Hosting, edge, and security: Cloudflare (edge network, Workers, Turnstile), Fly.io, Vercel, Amazon Web Services, Google Cloud Platform.
  • Analytics and tag management: Google (Analytics 4, Tag Manager, Search Console, Business Profile, Ads), Meta Platforms (Pixel, Conversions API).
  • Advertising: Google Ads, Meta Ads, and other paid-media platforms we run for clients.
  • SEO and market intelligence: Ahrefs, Semrush.
  • Lead capture, call tracking, and CRM: CallRail, GoHighLevel, HubSpot, Klaviyo, Mailchimp, ServiceTitan, Jobber, Housecall Pro, ServicePal, Vonigo.
  • Business operations and knowledge: Microsoft 365 / SharePoint, Google Workspace, ClickUp, Slack, Neon Postgres, Metabase, BigQuery.
  • AI and reporting: Anthropic (Claude) for narrative report generation from de-identified structured KPI data.

We do not authorize sub-processors to use client or end-user data for their own advertising or model-training purposes beyond what is required to provide the contracted service.

8. How we share information

We share information in the following limited circumstances:

  • With your consent or at your direction — for example, when you ask us to introduce you to another vendor.
  • With sub-processors as described in Section 7.
  • Between clients and Rivers DX — reports, dashboards, and recommendations produced from client-owned data are shared with the client that owns that data. Cross-client data is used only in aggregate and de-identified benchmarks.
  • For legal reasons — to comply with law, respond to lawful requests, enforce agreements, or protect rights, property, and safety.
  • In a business transaction — if Rivers DX is involved in a merger, acquisition, financing, or sale of assets, information may be transferred as part of that transaction subject to reasonable confidentiality protections.

9. Data retention

We retain information only as long as we need it for the purposes described in this policy or as required by law. General guidance:

  • Contact-form inquiries — retained in our CRM indefinitely unless you ask us to delete them, so that we can trace the origin of an ongoing relationship. You can request deletion at any time.
  • Cloudflare edge and security logs— short retention windows (typically days to weeks) governed by Cloudflare’s defaults.
  • Analytics data — retained per the retention period configured on the underlying property (GA4 defaults to 14 months for event-scoped data).
  • Client and end-user data processed on behalf of a client — retained per the client’s instructions and the underlying platform’s retention settings; deleted or returned at the end of the engagement per contract.
  • Books, records, and contracts — retained for the periods required by tax, accounting, and other applicable laws.

10. Cookies and similar technologies

We use cookies and comparable technologies (local storage, pixels, and scripts) for three purposes: to make the Site work (essential), to measure how the Site is used (analytics), and to attribute conversions from paid campaigns (advertising). You can control cookies through your browser settings; blocking analytics or advertising cookies will not stop you from using the Site.

We do not currently display a cookie-consent banner because the Site does not target visitors in jurisdictions that require prior opt-in for the cookies we use. If our audience changes, we will update this policy and the Site accordingly.

11. Your rights

Depending on where you live, you may have rights to access, correct, delete, port, or restrict the processing of information we hold about you, and to object to certain uses. These include rights under the California Consumer Privacy Act / California Privacy Rights Act (CCPA/CPRA), the EU and UK General Data Protection Regulation (GDPR/UK GDPR), and comparable laws in Virginia, Colorado, Connecticut, Utah, and other US states.

To exercise any of these rights, email hello@riversdx.com with the subject line “Privacy Request.” We may need to verify your identity before acting on your request. If you are a consumer whose data we process on behalf of one of our clients, we will forward your request to that client, who is the controller of that information.

You have the right not to be discriminated against for exercising these rights. If we cannot resolve your concern, you may have the right to lodge a complaint with your local data-protection authority.

12. Security

We use industry-standard administrative, technical, and physical safeguards to protect information, including encryption in transit, role-based access, credential management via a password manager, multi-factor authentication on privileged accounts, and least-privilege access to client platforms. No system is perfectly secure; we cannot guarantee absolute security, but we work continuously to reduce risk.

13. International data transfers

Rivers DX is based in the United States, and the sub-processors we rely on operate globally. If you access the Site or provide information from outside the United States, you understand that your information will be transferred to and processed in the United States and other jurisdictions that may not offer the same level of data-protection law as your home country. Where applicable, we rely on Standard Contractual Clauses or other lawful transfer mechanisms.

14. Children

The Site is not directed to children under 13, and we do not knowingly collect personal information from children under 13. If you believe a child has provided us with personal information, contact us and we will delete it.

15. Changes to this policy

We may update this policy from time to time. When we do, we will change the “Last updated” date at the top of the page. Material changes will be highlighted on the Site or communicated to active clients directly.

16. Contact us

For any privacy-related question or request:

Rivers DX
7418 Coachmaker Road
Columbia, SC 29209
US
Email: hello@riversdx.com
Phone: +1-803-704-4346