1. Information we collect

We collect the following categories of information:

  • Account information. Information you provide when you create or manage an account, such as your name, email address, mobile phone number, and any required invite code.
  • Authentication data. Credentials and security data used to verify your identity, including password material handled by our managed identity provider and one-time passcodes sent for two-factor authentication.
  • Connected exchange credentials. The exchange API keys and signing keys you choose to connect, which we protect with the safeguards described in our Terms of Service and in Section 5 below.
  • Trading and usage data. Orders, fills, positions, portfolio and reporting data, and information about how you interact with the Service.
  • Device and log data. IP address, browser and device identifiers, and technical logs generated when you access the Service.

2. How we use information

We use the information we collect to:

  • provide, operate, maintain and improve the Service;
  • authenticate you and secure your account, including sending one-time passcodes and security-verification messages by SMS;
  • route and execute orders to connected third-party exchanges on your instruction;
  • provide portfolio analytics, reporting and customer support;
  • detect, investigate and prevent fraud, abuse, and security incidents, and enforce our Terms; and
  • comply with applicable laws, regulations and lawful requests.

3. SMS and mobile information

If you provide your mobile number, we use it to deliver one-time passcodes and account-security verification messages by SMS. These messages are transactional; we do not send marketing or promotional text messages.

We do not share your mobile information or SMS opt-in data with third parties or affiliates for marketing or promotional purposes. No mobile information is sold. SMS consent is collected at the point of authentication and is not transferred to, or shared with, any other party for their own use.

4. How we share information

We do not sell your personal information, and we do not share your data with third parties for marketing purposes. We share information only in the following limited circumstances:

  • Service providers (subprocessors). With reputable vendors that perform services on our behalf — including cloud hosting, database and authentication, payments, secrets management, and analytics — under contracts that require them to protect your information and use it only to provide those services.
  • Connected exchanges. To route and execute the orders you submit, using the credentials you connect, as described in our Terms of Service.
  • Legal and safety. When required by law, regulation or legal process, or to protect the rights, property or safety of River, our users, or others.
  • Business transfers. In connection with a merger, acquisition, financing or sale of assets, subject to this Policy.

All of the above categories exclude text messaging originator opt-in data and consent; this information will not be shared with any third parties, excluding aggregators and providers of the text message services used to deliver the messages.

5. Security

We maintain an information-security program with administrative, technical and physical safeguards designed to protect your data, and we are pursuing a SOC 2 Type II examination of those controls. Traffic is encrypted in transit using TLS, data is encrypted at rest, connected exchange credentials are protected with an additional layer of end-to-end encryption, passwords are stored only as salted hashes by our managed identity provider, and access follows least-privilege principles. No method of transmission or storage is completely secure, and you are responsible for safeguarding your password, API keys and connected credentials. Full details are in Section 9 of our Terms of Service.

6. Data retention

We retain personal information for as long as your account is active and as needed to provide the Service, and thereafter as required to comply with our legal and regulatory obligations, resolve disputes, and enforce our agreements. When information is no longer needed, we delete or de-identify it.

7. Your rights and choices

Depending on where you live, you may have rights to access, correct, delete, or obtain a copy of your personal information, and to opt out of certain processing. California residents have rights under the CCPA/CPRA, including the right to know, delete, and correct personal information and to not be discriminated against for exercising those rights; we do not sell or share personal information as those terms are defined under California law. To exercise any of these rights, contact us at the address below. You can stop receiving SMS messages at any time by replying STOP, though doing so may prevent you from completing identity verification.

8. Cookies and similar technologies

We use cookies and similar technologies to keep you signed in, remember your preferences, secure the Service, and understand usage. You can control cookies through your browser settings; disabling some cookies may affect how the Service functions.

9. Children's privacy

The Service is intended only for individuals who are at least 18 years old. We do not knowingly collect personal information from anyone under 18. If you believe a minor has provided us information, contact us and we will take appropriate steps to delete it.

10. Changes to this Policy

We may update this Privacy Policy from time to time. When we do, we will update the "Last updated" date above, and, if the changes are material, provide reasonable notice — for example, by email to the address associated with your account and/or an in-app notice. Your continued use of the Service after changes take effect constitutes acceptance of the updated Policy.

11. Contact

If you have questions about this Privacy Policy or our data practices, contact contact@rivermarkets.com.

Centos Group Inc.