Legal · Privacy notice

Who we collect information about, why, who sees it, how long we keep it, and the rights you have over it.

EffectiveOctober 2, 2026
Version1.2
Applies toOwners, directors, team members and contacts of a Rivet workspace, and visitors to this site
Summary
  • 01We collect what is needed to verify a company and the people behind it, to run its accounts, cards and payments, and to meet the law. We do not sell personal information. A Google Ads conversion tag on this site measures whether an ad led to a visit. The chat on this site is Intercom.
  • 02Verification, banking, card and payment partners receive the information they need to provide their product. They are named on the product screen and process it under their own privacy terms as well as ours.
  • 03Financial records are kept for at least five years after a workspace closes because the law requires it. Everything else is kept only as long as it is needed.
  • 04You can ask for a copy of your information and ask us to correct it. Where the law allows, you can also ask us to delete it or stop using it. Write to [email protected].

This is a summary. The sections below are the document.

01

Scope and who is responsible

This notice explains how Bilitech LLC (30 N Gould St Ste N, Sheridan, WY 82801, United States) (together "Rivet", "we") handle personal information in connection with Rivet: the website at rivet.global, the dashboard, mobile access and the API (the "Service"). Bilitech LLC is the controller for this processing.

It covers everyone whose information reaches us through a business workspace: the person who opens it, the company’s directors and beneficial owners, team members who are invited in, cardholders, and the payees and counterparties named in transactions. It also covers people who visit the site, contact us, or talk to sales.

The company that opens a workspace is itself a controller of the information it puts into the Service about its own staff and counterparties. It must have a lawful basis to share that information with us and must tell those people that we and our partners will process it. This notice is written so it can be given to them for that purpose.

02

What we collect

CategoryExamplesWhere it comes from
IdentityName, date of birth, nationality, residential address, government ID document and its number, a selfie or liveness check, role in the company, ownership percentage.You, or the administrator who adds you; the identity-verification provider.
CompanyLegal name, registration number, registered and operating addresses, incorporation documents, ownership structure, industry, expected activity, tax identifiers.The person opening the workspace; public registers.
Contact and accountWork email, phone number, login credentials (hashed), multi-factor settings, role and permissions, preferences such as colour scheme.You; your use of the Service.
Financial and transactionAccount details issued to the company, balances, payment instructions, payee names and account details, card numbers (tokenised), merchant, amount, currency, receipts and memos, blockchain addresses and transaction hashes.Your use of the Service; partner institutions; payment networks.
Verification and riskResults of sanctions, politically-exposed-person, adverse-media and fraud checks; risk scores; requests for information and your answers; case notes.Identity-verification and screening providers; partner institutions; our compliance team.
Device and usageIP address, approximate location derived from it, browser and device type, time zone, pages and actions in the dashboard, error logs.Your browser and device, automatically.
CommunicationsEmails, support messages, sales enquiries and the details in them, call notes.You.
BillingPlan, invoices, payment-method type and last four digits, billing address. Full card numbers are held by our payment processor, not by us.You; the payment processor.

We do not knowingly collect information about anyone under 18, and the Service is not offered to them.

03

Why we use it, and the legal basis

Where data-protection law such as the GDPR or UK GDPR applies, we rely on one of the bases in the right-hand column. Where it does not, we use information for the purposes listed.

PurposeBasis
Verifying the company and the people behind it; screening against sanctions and fraud lists; ongoing monitoring of transactions.Legal obligation (anti-money-laundering and sanctions law); legitimate interest in preventing fraud.
Opening and running the workspace: accounts, balances, cards, payouts, conversions, team roles and approvals.Performance of the contract with the company; the company’s legitimate interest in running its business.
Sharing what a partner institution needs to provide its product.Performance of the contract; legal obligation.
Billing the plan and issuing invoices.Performance of the contract; legal obligation (tax and accounting records).
Keeping the Service secure, detecting abuse, and investigating incidents.Legitimate interest in security; legal obligation.
Support, and responding to your questions and complaints.Performance of the contract; legitimate interest.
Improving the Service by analysing how it is used, in aggregate.Legitimate interest. Product analytics are first-party and aggregated.
Measuring whether a Google ad led to a visit or a sign-up.Legitimate interest in understanding advertising; consent where required by local law.
Telling administrators about changes to terms, fees, products, security and outages.Performance of the contract; legal obligation.
Marketing to business contacts who asked to hear from us, with an unsubscribe in every message.Consent, or legitimate interest for existing customers; you can object at any time.
Responding to lawful requests from courts, regulators and law enforcement.Legal obligation.

We make some decisions automatically, such as declining a transaction that matches a sanctions list or exceeds a risk threshold. A decision that significantly affects you is reviewed by a person on request. Write to [email protected].

04

Who we share it with

In short · Partners who provide a product, providers who run our infrastructure, Google for ad-conversion measurement, Intercom for the chat, and authorities where the law requires. Never data brokers.

RecipientWhat and why
Identity-verification and screening providersIdentity, company and document information, to verify the company and the people behind it and to screen against sanctions, PEP and fraud lists. They may retain records under their own legal obligations.
Partner institutions: banks, electronic-money institutions, card issuers and programme managers, payment processors, digital-asset service providersThe information each needs to open a named account, issue a card, execute a payment or conversion, or provide a digital-asset service in the company’s name, and to meet its own verification and reporting duties. Each is named on the product screen and processes information as its own controller under its own privacy terms.
Payment networks and correspondent banksPayee and payer details that travel with a payment so it can be delivered and traced.
Subscription-billing and payment processorBilling contact, plan and payment-method details, to collect plan fees and issue invoices.
Cloud hosting, email delivery, error monitoring and customer-support toolingInfrastructure providers acting on our instructions as processors, bound by contract to use the information only to provide their service to us.
Google (Ads conversion tag, gtag.js)Page URL, referrer, device and event signals so we can measure whether a Google ad led to a visit or a sign-up. Google may set its own cookies as part of that measurement.
IntercomThe chat on this site. Intercom receives the page you are on and the messages you send, and may set its own cookies.
Professional advisers, auditors and insurersWhere needed to run the business and meet our obligations.
Regulators, law enforcement, courts and tax authoritiesWhere the law requires or permits, including suspicious-activity reporting, which we may be prohibited from telling you about.
A buyer or successor of our businessIn a merger, acquisition or reorganisation, under the same protections as this notice.

Within a workspace, administrators can see the names, roles and activity of team members, the details of cards issued to them, and the transactions they make. That is a feature of a business account, not a disclosure by us.

05

International transfers

We operate from the United States and use providers and partner institutions in the United States, the European Economic Area, the United Kingdom and the countries where a product is delivered. Your information will therefore be transferred to, stored and processed in countries other than your own, including ones whose data-protection law differs from yours.

Where the GDPR or UK GDPR applies to a transfer, we rely on an adequacy decision where one exists, and otherwise on the European Commission’s standard contractual clauses or the UK International Data Transfer Addendum, with additional safeguards where needed. A copy of the relevant clauses is available on request.

06

How long we keep it

InformationRetained for
Verification records, transaction records, statements, audit logs and communications about themAt least five years after the workspace is closed or the relationship ends, or longer where a partner institution or a law requires it.
Invoices and billing recordsSeven years, for tax and accounting law.
Account, profile and preference informationFor the life of the workspace, then deleted or anonymised within 90 days except where it forms part of a record above.
Support and sales communicationsThree years from the last message, unless part of a complaint or dispute.
Device and usage logsTwelve months, then deleted or aggregated.
Information about an application that was declined or abandonedFive years, as anti-money-laundering law requires.

Backups roll off on their own schedule and may hold information for a short period after it is deleted from live systems.

07

How we protect it

Information is encrypted in transit and at rest. Access inside Rivet is limited to the people who need it for their role, is protected by multi-factor authentication, and is logged. Card numbers are tokenised by the card issuer and are never stored in full on our systems. Full payment-method details for billing are held by our payment processor. Identity documents are held by the verification provider and the partner institutions that require them, with access from our side limited to compliance staff.

No system is perfectly secure. If a breach affects your information in a way that is likely to put you at risk, we will tell the affected workspace’s administrators and, where required, you and the relevant authority, without undue delay.

08

Your rights

Depending on where you live, you may have the right to:

  • ·Ask for a copy of the personal information we hold about you, and for details of how we use it.
  • ·Ask us to correct information that is inaccurate or incomplete. Much of it you can correct yourself in the dashboard.
  • ·Ask us to delete information, or to restrict or stop a particular use of it. We will do so unless we have to keep it. Most verification and transaction records fall under a legal retention period and cannot be deleted before it ends.
  • ·Receive information you gave us in a portable format, or have it sent to another provider.
  • ·Object to processing based on legitimate interests, and to direct marketing at any time.
  • ·Withdraw consent where consent is the basis, without affecting processing done before you withdrew it.
  • ·Ask for a person to review an automated decision that significantly affects you.
  • ·Complain to a data-protection authority. For example, your national authority in the EEA, the Information Commissioner’s Office in the UK, or your state attorney general in the United States.

Write to [email protected]. We will need to confirm who you are before we act, and will respond within one month, or sooner where a shorter period applies. We do not charge for these requests unless they are clearly unfounded or excessive.

If you are a resident of California or another US state with a consumer-privacy law: we do not sell personal information or share it for cross-context behavioural advertising, and have not done so in the preceding 12 months. The categories we collect, the purposes and the recipients are set out above. You have the rights to know, to delete, to correct and to non-discrimination described in this section, and you may use an authorised agent to exercise them.

09

Cookies and similar technologies

In short · Necessary storage for the site to work, plus Google’s Ads conversion tag to measure whether ads led to a visit, and Intercom for the chat.

The site and dashboard store a small number of items in your browser: the session token that keeps you signed in, your colour-scheme choice, the fact that you have read the cookie notice, and short-lived state that a page needs while you are on it. Those are strictly necessary for the site to work as you have set it up.

We also load Google’s conversion tag (gtag.js, Google Ads account AW-18463661651) so we can tell whether a Google ad led to a visit or a sign-up. Google may set its own cookies as part of that. You can clear stored items at any time through your browser. You will be signed out and see the notice again.

The chat on this site is Intercom. Intercom receives the page you are on and the messages you type, and may set its own cookies.

10

People you add to a workspace

When an administrator invites a team member, names a beneficial owner, orders a card for someone or enters a payee, the company is giving us that person’s information. The company must have the right to do so and must tell the person. We use the information only to provide the Service to the company and to meet our legal obligations, and we treat it as described in this notice.

A team member can see and update their own profile in the dashboard. A beneficial owner or payee who wants to know what we hold about them can write to [email protected].

11

Changes to this notice

We will update this notice when our practices change. For a material change we will email the workspace’s administrators and show a notice in the dashboard before it takes effect. The version number and effective date at the top of this page always identify the current notice.

12

Contact

Privacy questions and requests: [email protected]. By post: Bilitech LLC, Attn: Privacy, 30 N Gould St Ste N, Sheridan, WY 82801, United States.

If you are in the EEA or the UK and would like the contact details of our representative there, ask at the same address.

Legal · Privacy notice · v1.2 · effective October 2, 2026 · Bilitech LLC
Global

USD, EUR, GBP and 24 more currencies in the account. Payouts go to 20+ countries on the local rail.

Any hour

You can convert currencies and settle on-chain at any hour, including when banks are closed.

Rivet is a financial technology platform, not a bank. Regulated partner institutions provide the accounts, payment services and cards, under their own terms and eligibility rules. Those institutions hold and move the funds. The money is not pooled on our balance sheet.

The names and logos of Amazon, Meta, Visa, Google Play, App Store, Swift, SEPA, Faster Payments, Circle, Tether and others are trademarks of their owners. We show them so you can tell which network a payment settles on. Rivet is not affiliated with, endorsed by, or sponsored by these companies. Digital assets are not deposits, are not legal tender, and may lose value. Products and services are not available in all jurisdictions.

© 2026 Bilitech LLC. All rights reserved.Bilitech LLC · 30 N Gould St Ste N, Sheridan, WY 82801