FixRiver.com and the FixRiver CRM mobile application are owned and operated by FixRiver, a company incorporated under the name FIXRIVER LLC, with a tax identification number (EIN) 352840404 and registered office at 7901 4TH ST N, STE 300, ST PETERSBURG, FL, USA, 33702.
This Privacy Policy explains what personal data we collect, why we process it, who we share it with, how long we keep it and how you can have it deleted. It covers:
- the website fixriver.com and every page on it;
- the FixRiver CRM mobile application for iOS and Android (the “App”); and
- the channels we use to talk to you: email and WhatsApp.
Please read it before using the website or the App. We take care of your personal data and undertake to guarantee its confidentiality and security.
Last updated: August 6, 2026.
1. The two roles we play
As data controller. We decide the purposes and means of processing for: the account data of the people who use the App, the data of people who contact us or request a quote, and the pseudonymous browsing data of the website. For all of that, FIXRIVER LLC is the controller and this policy applies in full.
As data processor. The business content that an organization stores in FixRiver CRM — customer records, conversations, notes, files and tasks — belongs to that organization. We run the technology; the data is theirs. In that case we act only on their documented instructions, under a written data processing agreement, and they are the controller.
If you are a customer of a business that uses FixRiver CRM and you want to know what that business holds about you, contact that business. If you are not sure who it is, write to us and we will point you to the right place without disclosing anything about you.
2. Cookies: we do not use them
Neither fixriver.com nor the FixRiver CRM App uses cookies. We do not set cookies of our own, we do not embed third-party advertising, marketing or tracking cookies, and there is no consent banner on this site because there is nothing to consent to.
What we use instead:
- On the website. Our own analytics store a random identifier and the campaign parameters of the link you arrived from in your browser’s local storage. Local storage is not a cookie: it is never attached to network requests, it is not readable by other websites, and it cannot be used to follow you around the internet. Clearing site data for fixriver.com removes it, and from that point on you are a new anonymous visitor to us. Section 7 of our Data Deletion page explains the exact steps.
- In the App. A session token is stored in the operating system’s secure storage on your device so you do not have to sign in on every launch. Signing out or uninstalling the App removes it. The App contains no advertising SDK, no third-party analytics SDK and no cross-app tracking of any kind, and it does not use the advertising identifiers of iOS or Android (IDFA / AAID).
One caveat, for completeness: our hosting provider and Cloudflare, which sits in front of the site as a security and delivery layer, keep short-lived server logs that include IP addresses, and Cloudflare may place a strictly necessary security cookie on your browser if it needs to challenge traffic it considers abusive. That is a security measure operated by Cloudflare, it does not identify you to us, and we never use it for analytics, profiling or advertising.
3. What we collect
3.1 When you visit fixriver.com. Automatically, and without asking you for anything: which pages and sections you viewed, the site or search term that referred you, the campaign parameters and advertising click identifiers of the link you arrived from, your browser’s user agent, your screen size, and a random session identifier stored in your own browser. This is first-party and pseudonymous: on its own it does not name you. Your IP address is processed by our host and by Cloudflare in order to deliver the page and block abuse; we do not store it alongside the analytics events.
3.2 When you contact us or request a quote. Your name, email address, phone number and whatever you choose to tell us: the platform you use today, your billing range, your message. If you write to us on WhatsApp, we also hold your phone number, your WhatsApp profile name and the history of that conversation.
3.3 When you use the FixRiver CRM App.
- Account data. Your name, work email address, phone number if you provide one, your role and the organization you belong to. Accounts in FixRiver CRM are created by invitation, by us or by your organization’s administrator; you cannot register from the App.
- Authentication data. The session token described in section 2, and the technical records of your sign-ins. Passwords are stored only as a one-way hash; we never see them in readable form.
- Device data. Device model, operating system version, App version and language, and — only if you turn notifications on — the push token issued by Apple or Google for your device.
- Usage and diagnostic data. Which screens you open and what errors or crashes occur, so we can fix them. This is tied to your account, not sold, not shared with advertisers and not used to build a profile of you.
- Business content. The customer records, conversations, notes, files and tasks your organization manages in the CRM. We process this as a processor: see section 1.
3.4 If you bought something on the website. Your name, billing email, country and the record of the transaction. Card details are handled entirely by Stripe; we never see or store them.
4. What the App does not collect
The FixRiver CRM App does not access, collect or transmit:
- your location, at any level of precision, in the foreground or in the background;
- the contacts stored on your phone, your calendar, your call log or your SMS messages;
- your camera, your microphone or your photo library;
- health, fitness or biometric data;
- the list of other apps installed on your device;
- advertising identifiers, and it does not track you across apps or websites owned by other companies. We do not use the App Tracking Transparency framework because we do nothing that requires it.
The only device permission the App requests is push notifications, and it is optional. If you decline it, every feature of the App keeps working; you simply will not receive alerts. No feature, and no part of your paid service, is conditional on granting it.
5. Why we process your data, and on what legal basis
- To provide the service — authenticate you, show you your organization’s data, keep the App working. Legal basis: performance of a contract.
- To send you operational notifications — a new message, an assigned task, a change that affects your work. Legal basis: performance of a contract, and your consent at the operating-system level for push.
- To give you support when you write to us. Legal basis: performance of a contract and our legitimate interest in answering you.
- To keep the service secure — detect abuse, fraud and unauthorized access. Legal basis: legitimate interest and legal obligation.
- To fix errors and improve the product using diagnostic and usage data. Legal basis: legitimate interest.
- To understand how the website is used and measure our campaigns, with pseudonymous first-party data and no cross-site tracking. Legal basis: legitimate interest.
- To bill you and meet our tax and accounting obligations. Legal basis: legal obligation.
Information collected automatically is used only to identify potential cases of abuse and to establish statistical information regarding usage. We do not use it to make automated decisions that produce legal or similarly significant effects about anyone.
6. Push notifications
Notifications are opt-in. Your device asks you the first time, and you can change your mind at any moment in the operating system settings for FixRiver CRM, without opening the App. We use them only for operational messages about your own work — never for advertising or for messages from third parties. Turning them off does not restrict any other functionality.
To deliver a notification we send it, together with the push token of your device, to Apple’s Push Notification service (on iOS) or to Google’s Firebase Cloud Messaging (on Android). There is no other way to deliver a push notification on those platforms. We keep the content of notifications minimal.
7. Who we share data with
We share personal data only with the providers listed below, only to the extent needed for the purpose stated next to each one, and under written agreements. We require every third party with whom we share user data — including analytics tools, infrastructure providers, third-party SDKs and any parent, subsidiary or related entity that has access to it — to provide the same or equal protection of user data as stated in this policy. None of them is allowed to use the data for their own purposes.
We do not sell your personal data, and we do not share it for cross-context behavioral advertising.
- Apple Inc. — delivery of push notifications to iOS devices. Receives the push token and the notification payload.
- Google LLC (Firebase Cloud Messaging) — delivery of push notifications to Android devices. Receives the push token and the notification payload. We do not use Google Analytics for Firebase or Google’s advertising products in the App.
- Meta Platforms (WhatsApp Business Platform) — when your organization manages WhatsApp conversations from the CRM, phone numbers, WhatsApp profile names and message content necessarily pass through Meta as the operator of that channel, under Meta’s own terms and privacy policy.
- Artificial intelligence providers (currently OpenAI and Anthropic) — only for the features described in section 8, and only when those features are enabled and used.
- Our hosting provider and Cloudflare — serving the website and the App’s API, and protecting them from attack. They keep short-lived logs that include IP addresses.
- Stripe — payments made on the website. Stripe acts as an independent controller for the payment data it holds; card details never reach us.
- Our own automation infrastructure, running on servers we control, which processes analytics events and contact requests. This is not a third party: it is us.
- Professional advisers, and public authorities where we are required to disclose by law.
When a purchase is completed on the website we may send a one-way hashed identifier — such as an email address, or the advertising click identifier the visitor arrived with — to Meta and LinkedIn, so the sale is attributed to the campaign it came from. This applies to the website only; the App does not do this. You can opt out of advertising measurement from your own account settings on each of those platforms, and deleting your data with us also stops it.
8. Artificial intelligence features
Some FixRiver CRM features use artificial intelligence models operated by third parties — currently OpenAI and Anthropic — to summarize a conversation, suggest a reply or classify an incoming message. We want to be explicit about this, because it means content leaves our systems.
- What is sent: only the text needed for the specific task you asked for, at the moment you ask for it — typically the conversation or record on screen.
- What is never sent: credentials, payment data, or bulk exports of your database.
- What the provider may do with it: process it to return the result, and nothing else. Our agreements with these providers prohibit them from using the content to train their models. They retain it only for the short abuse-monitoring window their business terms allow, and then delete it.
- Your control: these features are off unless your organization enables them, and the App asks for your explicit permission before sending content to an AI provider for the first time. You may decline and keep using the App in full. An administrator can turn them off for the whole organization at any time, and you can withdraw your permission from the App’s settings.
AI output can be wrong. It is always a draft for a person to read, edit and approve — never an automated decision about a customer, and never a substitute for professional judgment.
9. International transfers
FIXRIVER LLC is established in the United States, and some of our providers process data in the United States and in the European Economic Area. If you are in the EEA, the UK or Switzerland, that means your information may be transferred outside your country. Where it is, the transfer is covered by the European Commission’s Standard Contractual Clauses or another valid transfer mechanism, together with the technical measures described in section 11.
10. How long we keep it
- Account data of App users: while the account is active, and up to 30 days after your organization’s contract with us ends.
- Business content in the CRM: for as long as your organization instructs us to. On termination it is returned or deleted within 30 days.
- Support and contact conversations, including WhatsApp: 24 months from the last message.
- Website analytics events: 24 months.
- Diagnostic and crash data: 12 months.
- Server and security logs: the short automatic cycle of our host and of Cloudflare, measured in days.
- Invoices and payment records: for the period required by applicable tax and accounting law, and used for nothing else.
11. Information security
We secure the information you provide on servers in a controlled, protected environment. Traffic between your device and our systems travels over TLS; data is encrypted at rest; access is limited to the people who need it for their work, under least-privilege rules and with multi-factor authentication for administrative access. We keep reasonable administrative, technical and physical safeguards against unauthorized access, use, modification and disclosure of personal data in our control and custody, and we review them periodically.
No transmission over the Internet or a wireless network can be guaranteed to be perfectly secure. If a breach affects your personal data and is likely to result in a risk to your rights, we will notify you and the competent authority without undue delay and, where required, within 72 hours.
12. Your rights
Wherever you are, you can ask us to give you a copy of your data, correct it, delete it, or stop using it in a particular way. If you are in the European Economic Area or the United Kingdom, those rights are:
- The right to be informed.
- The right of access.
- The right to rectification.
- The right to erasure.
- The right to restrict processing.
- The right to data portability.
- The right to object.
- Rights in relation to automated decision-making and profiling.
Where we rely on your consent — for push notifications, or for the AI features in section 8 — you can withdraw it at any time, from your device settings or from the App’s settings respectively, without giving a reason and without losing access to the rest of the service.
If you are a California resident, you have the equivalent rights under the CCPA and CPRA, including the right to know, to delete, to correct, to opt out of sale or sharing (we do neither), and the right not to be discriminated against for exercising them.
To exercise any of these rights, write to contacto@fixriver.com. Requests are free, we answer within 30 days, and we will not ask you for documents we do not need. If you are not satisfied with how we handled your request, you may complain to your national data protection authority.
13. Deleting your account and your data
You can have your account and the personal data associated with it deleted, in either of these ways:
- From inside the App: open Settings → Account → Delete account and follow the steps. If your account was created for you by your organization, you can also ask its administrator to remove it.
- From the web, without reinstalling the App: go to fixriver.com/data-deletion/, or email contacto@fixriver.com with the subject Data deletion.
When you delete your account we delete the personal data associated with it: your profile, your credentials, your device and push tokens, your diagnostic records and your support history with us. We acknowledge the request within 72 hours and complete it within 30 days. A small number of items must be kept — invoices required by tax law, anything needed to defend a legal claim, aggregated figures that no longer identify anyone, and a minimal record that you asked and that we complied. Our Data Deletion page explains all of this in detail, including what happens to business content that belongs to your organization rather than to you.
14. Children
FixRiver CRM is a business tool, and neither the App nor this website is directed to children. You must be at least 18 years old to hold an account. We do not knowingly collect personal data from anyone under 18, we do not include content or advertising aimed at minors, and if we learn that we hold data belonging to one we delete it. If you believe a minor has given us personal data, write to contacto@fixriver.com and we will remove it.
15. Links to other websites
Our website and the App may contain links to services that are not owned or controlled by us. We are not responsible for those services or their privacy practices. We encourage you to read the privacy statement of each one you visit.
16. Legal disclosure
We will disclose information we collect, use or receive if required or permitted by law, such as to comply with a subpoena or similar legal process, and when we believe in good faith that disclosure is necessary to protect our rights, protect your safety or the safety of others, investigate fraud, or respond to a government request.
17. Changes to this policy
If we change how we handle personal data we will update this page and change the date at the top. When a change is material — a new category of data, a new provider, a new purpose — we will tell you in the App or by email before it takes effect, and where the law requires it we will ask for your consent again.
18. Contact
For anything to do with this policy, your personal data or your rights, write to contacto@fixriver.com. That address is monitored and is our privacy contact point for both the website and the App.
FIXRIVER LLC · EIN 352840404 · 7901 4TH ST N, STE 300, ST PETERSBURG, FL, USA, 33702.