Privacy Policy
Introduction
Riskgrove operates a transaction fraud scoring platform used by digital payment companies -- including consumer fintech apps, BNPL providers, digital marketplaces, and online lenders -- to evaluate payment risk in real time. This Privacy Policy describes how Riskgrove, Inc. ("the Company," "we," "us," or "our") collects, uses, and protects information in connection with our website riskgrove.com and our related sales and marketing operations.
This policy covers information collected through riskgrove.com, through demo requests and marketing communications, and through direct correspondence with prospective and current customers. It does not cover the transaction data that our platform customers submit for fraud scoring -- that data is governed by the data processing agreements between the Company and each customer, and is handled under strict contractual confidentiality.
The Company is based at 375 Hudson Street, 4th Floor, New York, NY 10013 and can be reached at [email protected].
1. Information We Collect
1.1 Information You Provide
We collect information you submit directly, including:
- Contact details (name, business email, phone) when you fill out a demo request form, contact us, or subscribe to updates;
- Company information you choose to share (employer, role, platform type, approximate transaction volume);
- The content of any messages you send us, including questions about our API or integration process.
We use this information to respond to inquiries, schedule product demonstrations, send requested technical documentation, and follow up on potential customer relationships. We do not use contact form submissions to build marketing lists without your consent.
1.2 Information Collected Automatically
When you visit riskgrove.com, we automatically collect limited technical information:
- IP address and approximate location (city/region level);
- Browser type, operating system, device class;
- Pages visited, referring URLs, time on page;
- Cookie and similar identifiers (see Section 5).
This information is used for site operation, security monitoring, and aggregate usage analytics. We do not build individual behavioral profiles from website analytics for advertising purposes.
1.3 What We Do Not Collect Through This Site
riskgrove.com is a marketing and documentation site. We do not process payment card data, financial account information, or sensitive personal information through this site. The fraud scoring platform itself operates under separate contractual and data-handling arrangements with each customer -- visitor data on riskgrove.com is not processed through our fraud scoring models.
1.4 We Do Not Knowingly Collect Children's Data
riskgrove.com is not directed to children under 13. We do not knowingly collect personal information from children. If you believe a child has provided us information, contact [email protected] and we will delete it.
2. How We Use Information
We use the information we collect to:
- Respond to demo requests and sales inquiries from risk teams, payment operations leads, and technical decision-makers at digital payment platforms;
- Send technical documentation, integration guides, and product updates to contacts who have requested them;
- Operate, maintain, and improve riskgrove.com;
- Detect and prevent spam, abuse, or unauthorized access to our site or platform;
- Comply with legal obligations applicable to our business under US federal and New York law.
We do not sell personal information for monetary value. We do not use personal information collected through this site to train fraud detection models without explicit written agreement with the data subject.
3. Sharing of Information
We share personal information only with:
- Service providers acting on our behalf (hosting, email delivery, CRM, analytics) under contractual confidentiality terms that restrict their use of the data;
- Legal authorities, when required by applicable law or to protect rights, safety, or property;
- A successor entity in the event of a merger, acquisition, or asset sale, subject to this Policy.
We do not sell personal information to third parties. We do not share contact information with data brokers.
4. Industry Regulatory Context
Riskgrove serves customers in regulated financial services sectors. Our platform customers who operate as financial institutions, money services businesses, or payment processors may be subject to federal and state regulations including the Bank Secrecy Act, the Gramm-Leach-Bliley Act (GLBA), and applicable state money transmission licensing requirements. Those obligations run to our customers, not to riskgrove.com visitors. If you are a prospective customer with compliance questions about data handling under GLBA or similar frameworks, please contact [email protected].
5. Cookies and Tracking
We use cookies and similar technologies to operate the site, remember preferences, and measure usage. For details and choices, see our Cookie Notice.
6. Data Retention
We retain personal information only as long as needed for the purposes described, to comply with legal or accounting obligations, and to resolve disputes. Contact form submissions and demo request data are retained for up to 24 months after the last interaction. Inactive marketing-list contacts are purged after 24 months. Server access logs are retained 90 days, then aggregated.
7. Security
We use administrative, technical, and physical safeguards designed to protect personal information, including TLS encryption in transit, restricted-access databases, and least-privilege access controls. No system is perfectly secure; we cannot guarantee absolute security.
8. Your General Rights
Depending on your jurisdiction, you may have rights including access, correction, deletion, and the ability to limit certain processing. To make a request, email [email protected]. We will respond within the timeframe required by applicable law.
9. New York Residents
New York does not currently have a comprehensive consumer privacy statute. As a matter of policy, we extend the following baseline rights to all U.S. residents regardless of state of residence.
9.1 Baseline Rights
- Right to Know: request the categories of personal information we have collected about you.
- Right to Delete: request deletion of personal information you have provided.
- Right to Correct: request correction of inaccurate personal information.
- Right to Opt Out of Marketing: unsubscribe from marketing emails or opt out via the link in each marketing message.
9.2 How to Exercise
Email [email protected] with a description of your request and enough detail for us to verify your identity. We respond within 45 days.
9.3 Sector-Specific Rights
If you are protected by federal sector laws (e.g., GLBA, FCRA), those laws may give you additional rights with respect to data covered by them.
10. California Visitors
If you are a California resident, you may also exercise the rights granted under the California Consumer Privacy Act ("CCPA") and California Privacy Rights Act ("CPRA"), including the right to know, the right to delete, the right to correct, and the right to opt out of sale or sharing. We do not sell personal information and do not "share" personal information for cross-context behavioral advertising.
To submit a CCPA / CPRA request, email [email protected] with the subject line "California Privacy Request."
11. Changes to This Policy
We may update this Policy from time to time. Material changes will be reflected by a new "Last updated" date and, where appropriate, a notice on the Service.
12. Contact
Questions, requests, or complaints can be sent to:
Riskgrove, Inc.375 Hudson Street, 4th Floor, New York, NY 10013
Email: [email protected]
Phone: +1 (212) 608-0193