Legal

Privacy Policy

Last updated: April 21, 2026  ·  Effective: April 21, 2026

SaaSRival (“we,” “our,” or “us”) operates the SaaSRival platform, a competitive intelligence service for the SaaS industry. This Privacy Policy explains what data we collect, why we collect it, how we use it, and your rights regarding your personal information.

By accessing or using SaaSRival you agree to the practices described here. If you do not agree, please discontinue use and contact us at privacy@saasrival.com to request deletion of any data we hold about you.


1. Data We Collect

1.1 Account Information

When you create an account, we collect:

  • Name and email address (required for login and billing)
  • Password hash (never stored in plaintext; managed by Supabase Auth)
  • Authentication session metadata required to keep you signed in
  • Profile photo URL if uploaded directly in the future

1.2 Usage Analytics

We collect anonymous and pseudonymous usage data to improve the product:

  • Pages visited, features used, and session duration
  • Search queries made within the platform (e.g., brand names, category filters)
  • Button clicks, filter selections, and export actions
  • Browser type, operating system, screen resolution, and approximate geographic region (country-level)
  • Referral source (e.g., how you found SaaSRival)

Analytics are collected via PostHog (self-hosted or PostHog Cloud). We do not use Google Analytics. Session recordings are disabled by default.

1.3 Payment Information

All payment processing is handled by Stripe. We never store credit card numbers, CVVs, or full billing addresses on our own servers. We receive from Stripe:

  • Subscription plan (Free, Starter, Pro, or Enterprise)
  • Billing email address
  • Last 4 digits of your payment card (for display in account settings)
  • Payment status (active, past_due, cancelled)
  • Invoice history

1.4 Support Communications

If you contact us by email, we retain the content of that communication and your contact details to resolve your issue. We do not use third-party helpdesk software at this stage.

1.5 Data We Do NOT Collect

  • We do not collect Social Security numbers, national ID numbers, or government-issued identifiers
  • We do not collect health or financial data beyond subscription billing
  • We do not build advertising profiles or sell your data to third parties
  • We do not track you across third-party websites

2. Data Sources for the SaaSRival Intelligence Database

SaaSRival aggregates publicly available information about SaaS companies — not about our users. This section explains where that data comes from.

SourceData TypeCollection Method
Meta Ads LibraryAd creatives, spend estimates, impressions, demographicsOfficial Meta Ads Library API (v21.0) and official embed iframes — no scraping of Facebook.com itself
Public SaaS websitesPricing pages, technology stack signals, job postingsAutomated crawling of publicly accessible pages only; robots.txt is respected
Clearbit Logo APICompany logosAPI lookup by domain name
GitHub public APIOpen-source activity signalsGitHub REST API (rate-limited, no authentication bypass)
Groq / LLM providersRevenue estimates, category classificationInternal inference only; brand data sent to LLM API for enrichment

This database pertains to businesses, not individuals. No personal data of private individuals is intentionally collected in the intelligence database. If you are a private individual and believe your personal data appears in our platform, contact privacy@saasrival.com for removal.


3. How We Use Your Data

PurposeLegal Basis (GDPR)Data Used
Provide the serviceContract performanceAccount info, subscription status
Process billingContract performanceEmail, Stripe payment tokens
Send transactional emailsContract performanceEmail address (invoices, password reset, plan changes)
Improve the productLegitimate interestAnonymous usage analytics, feature adoption metrics
Prevent fraud and abuseLegitimate interestIP address, usage patterns, account info
Marketing emailsConsent (opt-in only)Email address — only if you explicitly opt in
Legal complianceLegal obligationAny data required by law (e.g., tax records)

We do not use your data for automated decision-making that produces legal or similarly significant effects on you.


4. Cookie Policy

We use a minimal set of cookies. We do not use advertising cookies or cross-site tracking cookies.

CookieTypePurposeRetention
__sessionStrictly necessarySupabase authentication session tokenSession / 7 days (remember me)
ph_*AnalyticsPostHog anonymous usage analytics1 year
sr_prefsFunctionalYour UI preferences (sidebar state, theme)1 year

We do not use cookie consent banners for strictly necessary cookies. For analytics cookies (ph_*), we rely on our legitimate interest in improving the product. EU/EEA users who wish to opt out of analytics cookies may do so by emailing privacy@saasrival.com or by blocking cookies in their browser settings.


5. Third-Party Services (Sub-processors)

The following third parties process personal data on our behalf. Each is a Data Processor under GDPR where applicable.

ServicePurposeData SharedLocation
SupabaseDatabase & backend infrastructureAccount data, usage recordsUS (AWS us-east-1)
Supabase AuthAuthentication and user managementEmail, name, OAuth tokensUS (SOC 2 Type II certified)
StripePayment processingEmail, billing infoUS / Ireland (PCI DSS Level 1)
PostHogProduct analyticsAnonymous usage eventsUS / EU (configurable)
Google Cloud StorageAd creative media storageNo personal data — brand media onlyUS

For transfers to the United States, we rely on Standard Contractual Clauses (SCCs) or service providers that participate in an equivalent adequacy framework. Supabase and Stripe each maintain DPA (Data Processing Agreement) programs — contact us if you require a signed DPA.


6. Data Retention

Data TypeRetention PeriodReason
Account informationDuration of account + 30 days after deletion requestService provision; reasonable deletion window
Payment / billing records7 years from invoice dateLegal obligation (tax / accounting law)
Usage analytics (identified)12 months, then anonymisedProduct improvement
Usage analytics (anonymous)Indefinite (no personal data)Aggregate product metrics
Support communications2 years from last interactionService quality and dispute resolution
Backup copiesUp to 90 days beyond deletion dateBackup rotation cycle; purged in next cycle

7. Your Rights — GDPR (EU / EEA Users)

If you are located in the EU, EEA, or UK, you have the following rights under the General Data Protection Regulation (GDPR) or UK GDPR:

  • Right of Access (Art. 15): Request a copy of all personal data we hold about you.
  • Right to Rectification (Art. 16): Ask us to correct inaccurate or incomplete personal data.
  • Right to Erasure / “Right to Be Forgotten” (Art. 17): Request deletion of your personal data where we have no legitimate grounds to retain it.
  • Right to Restriction of Processing (Art. 18): Ask us to pause processing your data while a dispute is resolved.
  • Right to Data Portability (Art. 20): Receive your data in a structured, machine-readable format (JSON or CSV).
  • Right to Object (Art. 21): Object to processing based on legitimate interest, including for analytics.
  • Right to Withdraw Consent: Where processing is based on consent (e.g., marketing emails), withdraw at any time without affecting prior lawful processing.

To exercise any of these rights, email privacy@saasrival.com with the subject line “GDPR Request” and your registered email address. We will respond within 30 days. If you are dissatisfied with our response, you have the right to lodge a complaint with your local supervisory authority (e.g., the ICO in the UK, or your national DPA in the EU).

We do not currently have a formal EU establishment or EU representative. We will appoint one if our EU user base grows to a scale that requires it under GDPR Art. 27.


8. Your Rights — CCPA (California Residents)

If you are a California resident, the California Consumer Privacy Act (CCPA) as amended by the CPRA gives you the following rights:

  • Right to Know: Request disclosure of what personal information we collect, use, disclose, and sell.
  • Right to Delete: Request deletion of personal information we collected from you, subject to exceptions.
  • Right to Correct: Request correction of inaccurate personal information.
  • Right to Opt Out of Sale / Sharing: We do not sell or share your personal information for cross-context behavioural advertising. No opt-out is required as we do not engage in this practice.
  • Right to Limit Use of Sensitive Personal Information: We do not collect sensitive personal information as defined by the CPRA.
  • Right to Non-Discrimination: We will not discriminate against you for exercising your CCPA rights.

To submit a CCPA request, email privacy@saasrival.com with the subject line “CCPA Request”. We will verify your identity before processing the request. We will respond within 45 days, with a possible extension of 45 additional days where required.

Categories of personal information collected: Identifiers (name, email, IP address), commercial information (subscription history), and internet or other network activity (usage analytics). We do not sell any of these categories.


9. Data Security

We implement industry-standard technical and organisational measures to protect your personal data:

  • All data transmitted between your browser and our servers is encrypted via TLS 1.2 or higher (HTTPS only)
  • Database access is restricted by Supabase Row Level Security (RLS) policies — users can only access their own data
  • API keys and secrets are stored in environment variables and never committed to source code
  • Supabase Auth manages password hashing and authentication — we never handle raw passwords
  • Payment card data is handled entirely by Stripe; we are PCI DSS compliant by delegation
  • Access to production databases is restricted to a minimal team with audit logging enabled

No system is 100% secure. In the event of a data breach affecting your personal data, we will notify you as required by applicable law (within 72 hours for GDPR, without undue delay for CCPA).


10. Children’s Privacy

SaaSRival is a B2B platform intended for business professionals. We do not knowingly collect personal data from individuals under the age of 16. If you become aware that a child under 16 has provided us with personal data, please contact us immediately at privacy@saasrival.com.


11. Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of material changes by:

  • Posting the updated policy on this page with a new “Last Updated” date
  • Sending an email to your registered address for significant changes
  • Displaying an in-app notification banner for 14 days following the change

Your continued use of SaaSRival after the effective date of a revised policy constitutes your acceptance of the changes.


12. Contact & Data Requests

Data Controller: SaaSRival

Privacy Contact: privacy@saasrival.com

Response SLA: 30 days (GDPR) / 45 days (CCPA)

For legal notices: legal@saasrival.com

For general product support, please use the in-app chat or email support@saasrival.com.


© 2026 SaaSRival. All rights reserved.  · Terms of Service · Privacy Policy