Effective Date: May 1, 2026 · Rimplo, Inc.
This Privacy Policy describes how Rimplo, Inc. ("Rimplo," "we," "us," or "our") collects, uses, and shares information about you when you use our website, products, and services (collectively, the "Services").
We are committed to protecting your privacy and handling your data in an open and transparent manner. This policy is designed to be concise and easy to understand, and describes how we collect, use, and protect your information. We implement privacy-protective practices and provide you with control over your data, including the ability to request complete erasure of your information upon request.
For a B2B SaaS company like Rimplo, it is important to distinguish between the data we control and the data we process on behalf of our customers.
or "Business" under CCPA
Website & Account Data
Website visitors, prospective customers, and direct users of our platform (e.g., billing contacts, account administrators).
We determine the purposes and means of processing this data. This entire policy primarily applies to this data.
or "Service Provider" under CCPA
Customer Data
Our customers' end-users, leads, and accounts (e.g., data from Salesforce, Stripe, Intercom).
We process this data strictly on behalf of and under the instructions of our customers, who are the Data Controllers.
If you are a customer of a Rimplo customer, please refer to that customer's privacy policy for information on how they handle your data.
We collect information to provide and improve our Services, to communicate with you, and for marketing purposes.
This includes information you voluntarily provide when you sign up for an account, request a demo, or contact us.
Name, email address, phone number, company name, job title, and password.
To create and manage your account, provide access to the Services, and communicate with you.
Performance of a contract with you.
Billing address, payment method details (handled by a third-party payment processor — we do not store full credit card numbers).
To process payments and manage subscriptions.
Performance of a contract with you.
Records of correspondence when you contact our support or sales teams.
To respond to your inquiries and improve our customer service.
Legitimate interest (improving service quality).
Email addresses of invitees, invitation tokens, invitation timestamps, inviter identity.
To enable account administrators to invite team members and manage access to the Services.
Performance of a contract with you.
Files you upload to the platform, including file names and upload timestamps.
To provide file storage and sharing functionality within the Services.
Performance of a contract with you.
Messages you send to our AI assistant, conversation history, and selected AI model preferences.
To provide AI-powered analytics, insights, and conversational assistance within the Services.
Performance of a contract with you.
When you interact with our website or Services, we automatically collect certain information.
IP address, browser type, operating system, pages viewed, time spent on pages, and referring URLs.
To monitor and analyze the performance and usage of our Services, and to ensure security.
Legitimate interest (maintaining and improving the Services).
Session storage for authentication tokens and user preferences. We do not use tracking pixels, third-party analytics services (such as Google Analytics), or cross-site tracking technologies.
To remember your preferences and maintain your authenticated session.
Necessary for the service to function.
JWT access tokens (15-minute expiration), refresh tokens stored in HTTP-only cookies (7-day expiration), with SameSite cookie policy.
To securely authenticate your sessions and maintain login state across the Services.
Performance of a contract with you.
Rimplo's core service involves processing data that our customers feed into the platform via integrations (e.g., Salesforce, HubSpot, Stripe, Google Ads, Notion).
This data is highly variable but typically includes customer relationship management
(CRM) data, product usage metrics, support ticket history, billing information, and
communication logs.
We currently support data connections with Salesforce, HubSpot, Stripe, Google Ads
and Notion. Each integration uses OAuth 2.0 authentication (with PKCE where applicable)
to securely access your data without storing your login credentials.
We process this data solely to provide the AI-powered revenue intelligence services to
our customers, such as churn prediction, upsell opportunity identification
and deal acceleration.
Google Ads data accessed through our integration is used solely to provide advertising
analytics and revenue intelligence within the Rimplo platform. This data is not shared with
third parties, used for advertising purposes, or used to train AI models.
When you connect an integration (such as Google Ads, HubSpot, Salesforce, or Stripe), Rimplo receives an OAuth refresh token that allows us to access your data on your behalf. We apply the following technical and organisational measures to protect these credentials:
AI Model Training Clause: Rimplo does not use, sell, or share Customer Data to train, retrain, or improve our general AI models or any third-party AI models. All processing is done to provide the contracted service to the specific customer.
Rimplo uses artificial intelligence to provide revenue intelligence features such as churn prediction, upsell opportunities, and conversational data analysis. Here's how your data interacts with AI systems:
When you interact with our AI assistant, your messages, conversation history, and
any referenced file contents are processed by large language models to generate
responses.
Customer data from connected integrations may be analyzed by AI to generate insights,
predictions, and recommendations.
If you upload files (CSV, JSON, etc.) and reference them in AI conversations, the file
contents are sent to AI providers for analysis.
We use OpenRouter as an intermediary service to route AI requests to various large language model providers. Depending on your model selection, your data may be processed by:
(Claude models)
(GPT models)
(Gemini models)
These providers process your data according to their respective privacy policies and data processing agreements. We do not control how these providers handle data once transmitted.
We do not use your data to train, fine-tune, or improve any AI models (ours or third-party).
We do not sell or share your AI conversation data for advertising purposes.
We do not store AI conversation history on our servers beyond what is necessary for the current session (conversation history is maintained client-side).
We do not sell your personal data (as Data Controller) to third parties. We only share your information in the following circumstances:
We use third-party vendors to perform services on our behalf, such as hosting, payment processing, and analytics. These providers are contractually obligated to protect your data and use it only for the purposes we instruct.
Cloud hosting, file storage (S3), and serverless computing — United States
Primary user account and data storage — United States
Data warehouse for analytics and connector configurations — United States/Europe
Data orchestration and ETL processing for third-party integrations
AI request routing to multiple LLM providers (Anthropic, OpenAI, Google)
We may disclose your information if required to do so by law or in the good faith belief that such action is necessary to comply with a legal obligation, protect and defend the rights or property of Rimplo, or protect the personal safety of users of the Services or the public.
In connection with any merger, sale of company assets, financing, or acquisition of all or a portion of our business by another company.
Rimplo is a global company. Your data may be stored and processed in any country where we have facilities or where we engage service providers, primarily in the United States and Europe.
Our primary infrastructure is hosted on Amazon Web Services (AWS) in the United States, with analytics data stored on ClickHouse Cloud. If you are accessing our Services from outside the United States, please be aware that your data will be transferred to and processed in the United States, where data protection laws may differ from those in your jurisdiction.
Depending on your location, you may have the following rights regarding your personal data. To exercise any of these rights, please contact us using the details in Section 10.
The right to request copies of the personal data we hold about you.
GDPR, CCPA/CPRA
The right to request that we correct any information you believe is inaccurate or incomplete.
GDPR, CCPA/CPRA
The right to request that we erase your personal data, under certain conditions.
GDPR, CCPA/CPRA
The right to object to our processing of your personal data (e.g., for direct marketing) or to opt-out of the sale or sharing of your personal information. Note: Rimplo does not sell your personal data.
GDPR, CCPA/CPRA
The right to request that we transfer the data we have collected to another organization, or directly to you, under certain conditions.
GDPR
The right not to be discriminated against for exercising any of your privacy rights.
CCPA/CPRA
Data Erasure on Demand: You have the right to request complete deletion of all your personal data from our systems. Upon receiving a verified erasure request, we will permanently delete your account data, uploaded files, AI conversation references, and any other personal information we hold about you. To request data erasure, please contact us at privacy@rimplo.com with the subject line "Data Erasure Request." We will process your request and confirm deletion within 30 days.
We retain your personal data only for as long as necessary to fulfill the purposes for which it was collected, including to satisfy legal, accounting, or reporting requirements.
Retention periods for specific data types:
Retained for the duration of your account plus 3 years after account closure for legal compliance.
Access tokens expire after 15 minutes; refresh tokens expire after 7 days.
Retained while the integration is active; deleted upon disconnection.
Pending invitations expire after 48 hours; accepted invitation records retained with account data.
Retained until deleted by the user or account closure.
Retained for 12 months for security and analytics purposes.
OAuth session data (PKCE) automatically expires after 10 minutes.
Our Services are not directed to individuals under the age of 16. We do not knowingly collect personal data from children under 16. If we become aware that a child under 16 has provided us with personal data, we will take steps to delete such information.
We will notify you of any changes by posting the new Privacy Policy on this page and updating the "Effective Date" at the top. We encourage you to review this Privacy Policy periodically for any changes.
We may update this Privacy Policy from time to time. We will notify you of any changes by posting the new Privacy Policy on this page and updating the "Effective Date" at the top.
We encourage you to review this Privacy Policy periodically for any changes