Privacy

Privacy at Rivenset Software

This page explains the baseline privacy approach for the Rivenset website and DeclinePilot. It should be reviewed again before public launch if analytics, forms, payments, account systems, or additional third-party services are added.

This website

The initial Rivenset website package is a static site and does not include an advertising tracker, analytics script, account system, or contact form. If you email Rivenset, your email provider and Rivenset's receiving mail provider process the message as necessary to deliver and respond to it.

DeclinePilot for WooCommerce

DeclinePilot is designed as a local WooCommerce extension. In the current release design, Rivenset does not operate a DeclinePilot telemetry or product-analytics service, and the plugin performs no product-owned outbound analytics calls.

Information DeclinePilot reads

DeclinePilot reads WooCommerce order and operational information necessary for payment-recovery eligibility and merchant-facing diagnostics, such as order state, amount/currency, payment gateway, billing email when a recovery email must be sent, selected operational metadata, and bounded replacement-order context.

Information DeclinePilot is designed not to store in its custom analytics tables

  • Card PANs or CVC values
  • Payment tokens
  • API secret keys
  • Raw gateway payloads
  • Customer names or postal addresses
  • A separate clear-text customer-email copy for analytics
  • Full payment transaction identifiers

Local event and risk records

DeclinePilot maintains bounded local operational records for recovery accounting, gateway-health calculations, safety frequency caps, attribution, and the current recovery queue. These records include fields such as order ID, normalized event type, gateway ID, amount/currency, normalized source/category/code, timestamps, and a keyed pseudonymous subject hash where needed for cross-order safety limiting.

Order metadata

DeclinePilot stores operational markers on WooCommerce orders, including failure timing, recovery counts/timestamps, campaign markers, normalized failure category/code/source/confidence, tracked retry/recovery attribution markers, and paid/recovered markers.

Retention and erasure

Local event retention is merchant-configurable from 45 to 730 days, with a 180-day default. DeclinePilot integrates with WordPress personal-data tools for exporting matching event data and erasing its pseudonymous cross-order email linkage while retaining accounting rows without that linkage.

Support bundles

The downloadable support bundle is designed to exclude customer names, emails, addresses, order IDs, site URL, API credentials, payment tokens, full transaction IDs, raw gateway payloads, and custom recovery-email content.

Changes

This policy will be updated if Rivenset introduces website analytics, contact forms, licensing infrastructure, telemetry, hosted services, or other processing not described here.