Privacy policy
Last updated: July 12, 2026
rivalDrop provides one-time white-label competitor teardown reports to marketing agencies. This policy explains what information we collect, why we collect it, and how we protect it. rivalDrop is a service of Groundlayer LLC.
1. Information we collect
Information you provide through the intake form:
- Agency name
- Agency website URL
- Work email address
- Optional agency logo URL (public PNG or SVG)
- Client store name and public store URL
- Up to three competitor store URLs
- Optional focus area (pricing, SEO, product gaps, etc.)
Information collected through Stripe Checkout:
- Stripe Checkout Session ID
- Order status (paid, processing, delivered)
- Amount paid and currency
- Email address used at checkout
Stripe processes payment details (card information) directly. We do not collect, store, or have access to card numbers. Stripe's privacy policy applies to payment data: stripe.com/privacy.
Information collected automatically:
- Website usage analytics through Plausible Analytics, a cookie-free, privacy-focused analytics service. See Plausible's data policy.
- Basic server connection metadata (IP address, timestamp, request path) logged temporarily for operational security and error diagnosis. These logs are retained for no more than 14 days.
- Cloudflare routes HTTPS traffic to our infrastructure and may process request and connection metadata as part of providing that service, under its own privacy policy. See Cloudflare's privacy policy.
2. How we use your information
- To prepare and deliver your competitor teardown report.
- To match your payment to your intake submission via Stripe Checkout Session lookup.
- To send order status, delivery, and exception notifications by email (via Resend).
- To improve the report format and service quality.
- To resolve disputes, process refunds, and comply with legal obligations.
We do not sell, rent, or share your personal information for third-party marketing.
3. Automated processing and human review
After intake is submitted and payment is verified, the report is generated through automated analysis of public storefront data. This processing runs on local infrastructure. Authorized Groundlayer LLC operators may review intake details and generated reports when handling exceptions, factual corrections, security incidents, refunds, or quality checks. No client or competitor data is used to train AI models or for any purpose beyond your order.
Automated exception alerts sent to our internal operations channel contain order references and error classes only; they do not contain customer data.
4. Third-party services
We use the following services to run the business:
- Stripe: payment processing for direct Stripe payment link orders. Stripe's privacy policy
- Resend: transactional email delivery (order confirmations, delivery, exceptions, refund notices). Resend's privacy policy
- Cloudflare: DNS and HTTPS routing. Cloudflare routes HTTPS traffic to our infrastructure and may process request and connection metadata under its own privacy policy. Cloudflare's privacy policy
- Plausible Analytics: cookie-free, privacy-focused website analytics. Plausible's data policy
5. Data retention
We retain intake data (agency name, work email, client store information, and competitor URLs), the evidence bundles collected for your order, and delivered report files for 12 months from delivery, unless you request earlier deletion or an active dispute requires preservation. You may request deletion at any time by emailing hello@rivaldrop.com.
Operational server logs are retained for no more than 14 days. Payment, tax, and accounting records are retained only as long as legally required, and are limited to what those obligations actually require.
6. Your rights
You can ask us to access, correct, export, or delete personal information we hold about you. Email hello@rivaldrop.com. We respond to such requests within 30 days.
7. Security
We use HTTPS for all page loads, encrypted connections between our services (Stripe API, Resend API, Cloudflare tunnel), and least-necessary access principles. The pipeline server binds only to localhost (127.0.0.1) and is not directly exposed to the internet. The cloudflared tunnel provides the only public ingress point and can be revoked independently.
Do not send store admin passwords, private customer data, or non-public credentials. rivalDrop only needs public URLs.
8. Children's privacy
This service is for businesses and is not directed at individuals under 18.
9. Changes to this policy
We may update this policy as the service changes. The date above reflects the latest revision. If we make material changes, we notify registered users by email.
10. Contact
Questions about this policy? Email hello@rivaldrop.com.