This Privacy Policy explains how ReceiverX LLC, a Texas limited liability company ("ReceiverX," "we," "us," or "our"), collects, uses, shares, and protects personal information in connection with the ReceiverX website, mobile applications, APIs, and related services (the "Service").
This policy is a Notice at Collection for purposes of the California Consumer Privacy Act (CCPA/CPRA) and an Article 13/14 notice for purposes of the EU/UK General Data Protection Regulation (GDPR). A summary table of categories collected, purposes, sources, recipients, and retention is included at the end of this policy.
Quick links: Your Rights and Choices · Do Not Sell or Share My Personal Information · Sub-processors · Contact
1. Who is the Controller / Processor
- For personal data you submit when you sign up directly (not through an organization), ReceiverX is the controller.
- For personal data of members and content of an organization that uses ReceiverX (a "Tenant"), the Tenant is the controller and ReceiverX is the processor acting on the Tenant's documented instructions under our DPA. Tenant administrators set retention, sharing, visibility, and access policies. Direct data-subject rights requests to your Tenant administrator first; we will assist them in responding.
- For personal data you provide about third-party recipients (for example, a recipient email when you send an inspection report), you are the controller and ReceiverX is the processor for the delivery.
- For account, billing, security, fraud-prevention, audit-log, and aggregated technical data we process to operate the Service, ReceiverX is an independent controller, including for the access logs we maintain when a recipient opens a magic-link report.
2. Information We Collect
2.1 Information You Provide
- Account information: name, email address, password (stored as a bcrypt one-way hash), profile image, username, organization name, role.
- Authentication and security data: sign-in events; multi-factor authentication (TOTP) secrets, encrypted at rest using AES-256-GCM; backup codes (hashed); password-reset tokens; IP address, browser, and device information for login attempts.
- Customer Content: inspection reports, images and PDFs you upload, captions, locations, notes, address-book entries (including recipient names and email addresses), and any other content you submit.
- Recipient information: when you direct us to deliver a report, the recipient's email address and any associated label or note. You are responsible for having a lawful basis to share this information with us.
- Payment information: for paid plans purchased through our website, our merchant of record, Paddle, collects your payment details directly under its own privacy policy. We receive limited information such as the last four digits of the card, brand, expiration, billing country, and transaction status. We do not store full card numbers.
- Communications: messages you send us (for example, support requests).
2.2 Information Collected Automatically
- Usage data: pages and screens viewed, features used, requests made, timestamps, and similar event metadata.
- Device and connection data: IP address, device identifier, operating system, browser, app version, language, time zone.
- Cookies and similar technologies: see Section 7.
- Diagnostics: crash logs, error reports, performance metrics.
- Mobile permissions: with your permission, the mobile app may access your camera (to capture commodity images) and storage (to save offline packs). You can revoke these permissions in your device settings.
2.3 Recipient Access Logs (Magic-Link Report Delivery)
When you send a report to a recipient via magic link, we capture: the time the link was sent and viewed, view count, the recipient IP address and user-agent string, and any failed verification attempts. Recipients are notified that they are accessing a confidential report through a logged channel before the report renders.
These logs are used in two distinct roles:
- As Processor (on behalf of the sender / Tenant) — to populate the audit trail that the sender and the Tenant administrator can review for delivery confirmation, downstream sharing decisions, and dispute resolution.
- As Independent Controller (for our own purposes) — to detect and prevent abuse, brute-force or scraping of magic links, fraud, and security incidents, and to improve the security of the Service.
We do not use recipient access logs for advertising or to build profiles of recipients. See Section 4 for the Article 14 notice to recipients.
2.4 Information from Third Parties
- Single sign-on: if you sign in with Google, we receive your name, email, profile picture, and a provider identifier.
- Payment processing (Paddle): transaction status and tokens from Paddle, our merchant of record for website purchases.
- Service providers: delivery and bounce information from our email provider; rate-limit and security signals from our infrastructure providers.
2.5 Sensitive Personal Information
In limited cases, our Service may process the following CPRA "Sensitive Personal Information": account credentials (password hash, TOTP secret), and precise geolocation if you choose to attach it to a report. We use sensitive PI only for the purposes for which it was provided (authentication, security, and report content) and do not use it to infer characteristics about you. You may request to limit our use of sensitive PI as described in Section 9.
Users under 16 may not register for or use the Service. We do not knowingly permit registration by anyone under 16, and we do not knowingly collect personal information from children under 13 without verifiable parental consent under COPPA. See Section 13.
3. How We Use Information — Purposes and Legal Bases
| Purpose | Examples | GDPR legal basis |
|---|---|---|
| Provide and operate the Service | Authentication, content storage, AI scanning, report delivery | Contract (Art. 6(1)(b)) |
| Secure the Service | Fraud detection, MFA, rate limiting, abuse logs | Legitimate interests (Art. 6(1)(f)) and legal obligation |
| Process payments and manage subscriptions | Billing, taxes, refunds | Contract; legal obligation |
| Customer support | Responding to inquiries | Contract; legitimate interests |
| Diagnose problems and improve the Service | Crash logs, performance analytics, de-identified telemetry | Legitimate interests |
| Send transactional emails | Verification, password reset, security alerts, report delivery | Contract; legal obligation |
| Comply with legal obligations | Tax, accounting, lawful requests | Legal obligation |
| Recipient access logs | Audit of magic-link views, abuse prevention | Legitimate interests (recipient); contract (sender) |
We do not use Customer Content to train, fine-tune, or evaluate AI models. See Section 5.
You may withdraw consent at any time where processing is based on consent.
4. Notice to Report Recipients (GDPR Article 14)
If you received a report through ReceiverX, this is your notice under GDPR Article 14 (and analogous notice requirements under U.S. state law).
Who is responsible for your data.
- The report sender (an individual user or the user's organization, the "Tenant") is the controller of the personal data they provided to us about you (your email address) and the report content shared with you. Contact the sender directly for sender-specific questions.
- ReceiverX LLC acts as the processor for delivering the report on the sender's behalf, and as an independent controller for the access logs we maintain to secure the Service.
Our contact details. ReceiverX LLC, info@receiver-x.com (privacy: privacy@receiver-x.com); mailing address ReceiverX LLC, c/o Texan Registered Agent LLC, 5900 Balcones Drive, Suite 100, Austin, TX 78731, USA. Once appointed, our EU/UK Article 27 representative will be listed in Section 16.
Categories of personal data we process about you.
- Identifiers: email address (provided by the sender) and any name or label the sender associated with you.
- Report content the sender chose to share with you (which may include images, captions, locations, and grading information).
- Access logs when you open the link: timestamp, IP address, user-agent, view count, and failed verification attempts.
Source. The report sender provided your email address. Access-log data is collected automatically when you open the link.
Purposes and legal bases (GDPR Art. 6).
- Deliver the report at the sender's request — performance of a contract with the sender; necessity for the legitimate interest of the sender in communicating with you (Art. 6(1)(b)/(f)).
- Maintain delivery and view audit trail — legitimate interests of the sender and Tenant in operating an auditable inspection workflow (Art. 6(1)(f)).
- Detect and prevent abuse, fraud, and security incidents — our legitimate interests as Service operator (Art. 6(1)(f)) and compliance with security-related legal obligations.
Recipients of your data. Our Sub-processors listed in Section 6 (in particular, our hosting, database, file-storage, and email-delivery providers). We do not share your information with advertisers and do not sell or "share" it for cross-context behavioral advertising.
International transfers. Your data is processed in the United States. Where Section 11 applies, we rely on the Standard Contractual Clauses, the UK Addendum, and equivalent safeguards.
Retention. We retain access logs for up to 24 months. Report content is retained for as long as the sender retains the report or as the Tenant's retention policy directs (see Section 10).
Your rights. You have the rights described in Section 9, including access, correction, deletion, restriction, objection, and (in the EEA/UK/Switzerland) the right to lodge a complaint with a supervisory authority.
How to exercise rights. Email info@receiver-x.com or contact the sender directly. We will route requests to the appropriate controller.
Choice not to view. You are not obligated to open the link. Links expire automatically; not opening the link will not result in adverse consequences from us.
No automated decisions with legal effects. We do not use your data to make solely automated decisions producing legal or similarly significant effects on you.
5. AI Features and Customer Content
When you use AI-assisted scanning, images you upload are sent to our AI processing pipeline, which may include AWS Bedrock and other providers identified on our sub-processor list, acting solely as our processors.
- We do not use Customer Content to train, fine-tune, or evaluate foundation models or models used by other customers, and we contractually require our AI sub-processors to refrain from doing the same.
- We do not perform human review (RLHF, annotation, evaluation) of Customer Content except (a) as you specifically request for support, (b) to investigate a documented security or abuse incident, or (c) as required by law.
- We select AI processing providers whose contractual terms commit them not to retain prompt or output data beyond what is needed to return a response, other than minimal abuse-monitoring metadata where the provider's terms and applicable law require it. Specific retention windows depend on the provider; for AWS Bedrock, prompt and output data are not stored or used by the model provider beyond returning the response (per AWS Bedrock service terms in effect at the time of Processing). We will update this Policy if we engage an AI provider whose retention practices materially differ.
- We may use de-identified, aggregated technical telemetry (latency, error rates, classification confidence) to operate and improve the Service.
- AI Output is stored with the corresponding inspection report under your account.
- See the AI section of our Terms of Service for limitations on AI Output and your obligation to apply human review.
6. Sub-Processors
We use the following categories of sub-processors. The current itemized sub-processor list, including entity names, services, and processing locations, is published at /legal/sub-processors and is also available on request to info@receiver-x.com.
Sub-processors (process Customer Content on our behalf):
| Purpose | Provider (current) | Location |
|---|---|---|
| Application hosting and edge delivery | Vercel Inc. | United States |
| Database (PostgreSQL) | Neon Inc. | United States |
| File storage | Vercel Blob (Vercel Inc.) and/or Cloudflare R2 (Cloudflare, Inc.) | United States |
| Transactional email | Resend | United States |
| Rate limiting and caching | Upstash Inc. | United States |
| Single sign-on (optional) | Google LLC | United States |
| AI image analysis | Amazon Web Services (AWS Bedrock) | United States |
| Video content delivery (training videos) | BunnyWay d.o.o. (bunny.net) | EU (Slovenia); global edge |
Platform providers (independent controllers — not DPA sub-processors for Tenant Customer Content):
| Purpose | Provider (current) | Location |
|---|---|---|
| Mobile app distribution; in-app purchase processing where used | Apple Inc.; Google LLC (Google Play) | United States |
| Merchant of record and payment processing for website purchases | Paddle (Paddle.com Inc. — U.S.; Paddle.com (Canada) Ltd. — Canada; Paddle.com Market Limited — all other countries) | United States; Canada; United Kingdom |
We require sub-processors to maintain appropriate technical and organizational measures and to process personal data only on our documented instructions.
Sub-processor change notice. We will give at least 30 days' prior notice of any new or replacement sub-processor by updating the list at /legal/sub-processors and, by default, emailing all Tenant administrative and legal contacts of record. Tenants may register additional notification addresses or distribution lists with legal@receiver-x.com. If a Tenant has a reasonable, documented objection on data-protection grounds, we will work in good faith to provide an alternative; if we cannot, the Tenant may terminate the affected portion of the Service for material cause and receive a refund of prepaid, unused fees. Emergency replacements (for example, a sub-processor breach or termination) may occur with shorter notice.
7. Cookies and Similar Technologies
We use cookies and similar technologies to:
- Keep you signed in.
- Remember your preferences (such as language and theme).
- Measure and improve performance.
- Detect and prevent fraud and abuse.
You can control cookies through your browser settings. Some features may not work without certain cookies. Where required by law, we will request your consent before placing non-essential cookies and will honor recognized opt-out signals such as Global Privacy Control (GPC) as a valid opt-out of "sale" and "sharing" under applicable U.S. state laws.
8. No Advertising
The Service does not display third-party advertising. We do not sell your personal information, and we do not share it for cross-context behavioral advertising.
9. Your Rights and Choices
Depending on where you live, you may have rights regarding your personal information, including the right to:
- Access the personal information we hold about you.
- Correct inaccurate information.
- Delete personal information.
- Port your information to another service.
- Restrict or object to certain processing, including profiling.
- Withdraw consent where processing is based on consent.
- Limit Use of Sensitive PI under California law.
- Opt out of "sale," "sharing," or targeted advertising under California, Colorado, Connecticut, Virginia, Utah, Texas, Oregon, and other US state laws.
- Opt out of solely automated decisions that produce legal or similarly significant effects.
- Lodge a complaint with your local data-protection authority (EEA/UK).
9.1 How to Exercise Rights
- Account holders: use the tools in Settings to update profile information, download a copy of your data, and delete your account; or email info@receiver-x.com.
- Tenant members: contact your Tenant administrator first; we will assist them.
- Recipients of reports: email info@receiver-x.com or contact the sender directly.
We will respond within the time required by applicable law (typically 30–45 days). We may need to verify your identity before fulfilling certain requests. You may use an authorized agent. We will not discriminate against you for exercising your rights.
9.2 Authorized Agents and Verification
Authorized agents must provide signed, written permission. We may require verification of the agent's identity and confirmation directly from the consumer.
9.3 Appeals
If we deny a request and you reside in a U.S. state that grants an appeal right (for example, Colorado, Virginia, Connecticut, Texas), you may appeal by replying to our denial email; we will respond within the statutory period.
9.4 Do Not Sell or Share My Personal Information
To opt out of "sale" or "sharing" of your personal information for cross-context behavioral advertising, including targeted advertising:
- Use the "Do Not Sell or Share My Personal Information" link in the website footer.
- Send a Global Privacy Control (GPC) signal from your browser; we honor GPC as a valid opt-out for the browser sending it.
- For mobile, follow the device-level controls in Section 8.
- Or email privacy@receiver-x.com.
Because users under 16 are not permitted to register for or use the Service, we do not knowingly sell or share the personal information of any user under 16. Children under 13 are subject to additional COPPA-specific protections.
10. Data Retention
We retain personal information only as long as necessary to provide the Service, comply with our legal obligations, resolve disputes, and enforce our agreements. Typical retention periods:
| Data | Retention |
|---|---|
| Account data | While account is active. After deletion, removed from active systems within 30 days, from backups within 90 days, except records we must retain for legal, tax, or fraud-prevention reasons (typically up to 7 years) |
| Customer Content (reports, images, PDFs) | While retained by you or per your Tenant's retention policy. Deleted content purged from active systems within 30 days and from backups within 90 days |
| Recipient access logs | Up to 24 months |
| Audit logs (admin actions) | Up to 24 months |
| Login / security logs | Up to 24 months |
| Email delivery logs | Up to 12 months |
| Payment records | As required by tax and accounting law (typically up to 7 years) |
When termination occurs, the export window in Section 12 of our Terms applies.
11. International Data Transfers
We are based in the United States, and our sub-processors are primarily located in the United States. If you access the Service from outside the United States, your personal information will be transferred to and processed in the United States and other countries that may have data-protection laws different from your country.
For transfers from the European Economic Area, the United Kingdom, or Switzerland, we rely on appropriate safeguards, including the European Commission's Standard Contractual Clauses (Module 2 for transfers from controllers to processors and Module 3 for processor-to-processor) together with the UK International Data Transfer Addendum, and, where applicable, the EU-US Data Privacy Framework. Copies of the SCCs we rely on are available on request.
12. Security and Breach Notification
We use industry-recognized technical and organizational measures appropriate to the risk, including:
- TLS encryption in transit.
- Encryption at rest for sensitive credentials (TOTP secrets via AES-256-GCM); bcrypt password hashing.
- Access controls, least-privilege permissions, and audit logging.
- Multi-factor authentication for users and administrators.
- Regular vulnerability scanning and security testing.
No method of transmission or storage is 100% secure. You are responsible for keeping your password and devices secure. Notify us immediately if you suspect unauthorized access.
Breach notification. As a processor, we will notify Tenants and direct controllers of a personal-data breach affecting their data without undue delay after becoming aware of it, and in any event within the time required by applicable law and our DPA. We will notify affected individuals where required by law and will cooperate with regulators on required notifications under the GDPR (Articles 33–34) and U.S. state breach-notification laws.
13. Children
The Service is intended for users age 16 or older. We do not knowingly permit registration or use by anyone under 16; if we learn that a user is under 16, we will deactivate the account and delete the data. In addition, we do not knowingly collect personal information from children under 13 without verifiable parental consent under the Children's Online Privacy Protection Act (COPPA, 16 C.F.R. Part 312). We do not knowingly sell or share the personal information of any user under 16 (and, for users under 13, only with verifiable parental consent and only as COPPA permits). If you believe we have collected information from a person under 16, contact us at privacy@receiver-x.com and we will delete it.
14. Mobile App Disclosures
Our mobile app may collect and use the following categories of data, also disclosed in our App Store and Google Play privacy labels:
- Identifiers: account ID, device ID.
- Contact info: email address.
- User content: photos and inspection report content you create.
- Usage data: product interactions and diagnostics.
- Diagnostics: crash logs and performance data.
We do not use the App Tracking Transparency framework to track you across other companies' apps and websites without your permission.
15. Changes to This Policy
We may update this Privacy Policy from time to time. For material changes, we will provide additional notice (for example, by email or in-product notice) and will not apply changes retroactively to data already collected without an appropriate legal basis. The "Last Updated" date above will be revised. Your continued use of the Service after the effective date constitutes acceptance.
16. Contact
For privacy questions, requests, or complaints:
ReceiverX LLC Website: https://receiver-x.com Email: info@receiver-x.com Privacy: privacy@receiver-x.com Mailing address: ReceiverX LLC, c/o Texan Registered Agent LLC, 5900 Balcones Drive, Suite 100, Austin, TX 78731, USA
EEA/UK Representative. Where required by GDPR Article 27 or UK GDPR Article 27, we will appoint a representative in the EEA and/or the UK before commencing in-scope processing. EEA and UK users may, in the meantime, contact us at privacy@receiver-x.com for any GDPR/UK GDPR matter and we will respond directly. Once an Article 27 representative is appointed, the representative's name and contact details will be published here.
Appendix A — CCPA/CPRA Categories Collected (Past 12 Months)
Scroll horizontally to see all columns →
| Category (Cal. Civ. Code §1798.140) | Collected? | Sources | Business / Commercial Purpose | Disclosed for Business Purpose to | Sold? | Shared? |
|---|---|---|---|---|---|---|
| A. Identifiers (name, email, IP, device ID, account ID) | Yes | You; automatic | Operate Service, security, support | Sub-processors in §6 | No monetary sale; however, see footnote* | No |
| B. Customer records (Cal. Civ. Code §1798.80) | Yes | You | Account management, billing | Sub-processors in §6 | No | No |
| C. Protected classifications | No | — | — | — | No | No |
| D. Commercial information (subscription, transaction history) | Yes | You; Paddle | Billing, support | Paddle, accountants | No | No |
| E. Biometric information | No | — | — | — | No | No |
| F. Internet/network activity (usage data, device/browser) | Yes | Automatic | Operate, secure, improve, analytics | Sub-processors in §6 | No monetary sale; however, see footnote* | No |
| G. Geolocation (precise) | Sometimes (if you attach) | You | Report content | Recipients you choose | No | No |
| H. Sensory data (photos uploaded for grading) | Yes | You | Generate AI Output, deliver reports | AI sub-processors, recipients | No | No |
| I. Professional/employment information | If you provide it | You | Account profile | None beyond §6 | No | No |
| J. Education information | No | — | — | — | No | No |
| K. Inferences | Limited (technical) | Automatic | Improve Service | Sub-processors in §6 | No | No |
| L. Sensitive PI (account credentials; precise geo if attached) | Yes | You | Authentication; report content | None beyond purpose | No | No |
*Sale/share footnote. ReceiverX does not sell personal information for monetary consideration and does not share personal information for cross-context behavioral advertising.