Privacy Policy
How ChannelRivet handles information across this website, merchant connections, WooCommerce integrations, and Meta services.
ChannelRivet is designed so the merchant's WordPress site remains the primary operating environment. The hosted ChannelRivet Meta Connect service is used to complete OAuth authorization without distributing the Meta App Secret to merchant sites.
1. Scope
This Privacy Policy explains how ChannelRivet collects, uses, stores, and discloses information when you visit channelrivet.com, create an account or purchase a product, use a ChannelRivet connector, or authorize ChannelRivet to access supported third-party commerce or advertising services such as Meta.
A merchant that installs ChannelRivet on a WooCommerce site remains responsible for its own store privacy notice and for determining the lawful basis and consent settings that apply to its customers and visitors.
2. Information we may process
Website and account information
When you use this website, contact us, create an account, obtain a license, or make a purchase, we may process information such as your name, email address, company or store name, website address, account identifiers, order and license information, support correspondence, and technical information needed to operate and secure the service. Payment card details are handled by the payment provider used at checkout; ChannelRivet does not need your full card number to operate the connector.
Merchant connection information
When a merchant connects a supported channel, ChannelRivet may process identifiers for the merchant's store and authorized business assets. For the Meta connector this can include a Business Portfolio ID, catalog ID, Pixel or Dataset ID, authorization state, and other identifiers returned by Meta that are necessary to establish and maintain the connection.
OAuth authorization information
The ChannelRivet Meta Connect broker on channelrivet.com receives the authorization response from Meta so it can securely complete OAuth. The broker stores OAuth state temporarily for approximately 15 minutes. After authorization, it creates a one-time encrypted handoff containing the merchant access token for up to approximately 5 minutes; the handoff is deleted when exchanged or when it expires. The merchant plugin then stores the resulting Meta access token encrypted in that merchant's own WordPress database.
ChannelRivet does not ask merchants to disclose their Meta password, and the Meta App Secret is not distributed inside the WooCommerce plugin.
WooCommerce catalog and event information
Depending on the connector features a merchant enables, the plugin can process WooCommerce product and catalog information and send it to the selected channel. When Meta Pixel or Conversions API tracking is enabled, event data sent to Meta can include event type, product identifiers, order value and currency, browser attribution identifiers, IP address, user agent, and hashed matching identifiers such as email address, phone number, name, city, state, postal code, country, or logged-in user identifier where available and permitted by the merchant's configuration.
Operational queue, synchronization, diagnostic, and event-ledger information is stored primarily in the merchant's WordPress database. Temporary server-event payloads can be encrypted at rest while awaiting delivery and are removed according to the connector's delivery and retention rules.
Technical and security information
We may process server logs, request timestamps, IP addresses, browser or user-agent information, error information, security events, and similar technical data to operate, protect, troubleshoot, and improve ChannelRivet.
3. How we use information
We use information to provide and secure ChannelRivet; authenticate and maintain merchant connections; synchronize commerce-channel data; deliver enabled tracking events; provide licenses, downloads, updates, support, diagnostics, and account functions; prevent abuse; investigate failures; comply with legal obligations; and improve product reliability.
4. Meta and other third-party services
When you connect Meta, information is transmitted to and received from Meta according to the permissions you authorize and the ChannelRivet features you enable. Meta processes information under its own terms and privacy policy. Merchants should review their Meta Business settings and ensure that only the assets and permissions needed for their use of ChannelRivet are authorized.
Removing ChannelRivet from Meta or disconnecting the connector stops future authorized API activity, but it does not automatically delete information that Meta independently retains under its own policies.
5. Cookies and local technologies
This website and the ChannelRivet plugin may use cookies, browser storage, WordPress/WooCommerce session technologies, and channel attribution identifiers that are necessary for authentication, account functions, commerce, security, preferences, and enabled integration features. Marketing or measurement technologies should be governed by the merchant's configured consent requirements where applicable.
6. Sharing and disclosure
We disclose information only as needed to operate ChannelRivet, including to services a merchant deliberately connects, infrastructure and service providers that help us host, secure, communicate, sell, license, or support the product, and authorities or other parties when required by law or necessary to protect rights, security, and the integrity of the service. We do not sell Meta access tokens or merchant customer data.
7. Retention
We retain information only as long as reasonably necessary for the purpose for which it was collected, to provide the service, maintain security and audit records, resolve disputes, enforce agreements, or satisfy legal obligations. OAuth broker state and one-time token handoffs are intentionally short-lived as described above. A merchant controls the retention of most ChannelRivet operational records stored inside its own WordPress installation.
8. Security
ChannelRivet uses technical and organizational safeguards appropriate to the information it handles. Sensitive connector credentials are encrypted at rest where the product stores them, HTTPS is required for the hosted OAuth flow, and support exports are designed to omit access tokens and other secrets. No internet service can guarantee absolute security.
9. Your choices and data rights
You may disconnect ChannelRivet from a supported service, remove ChannelRivet's authorization from that service, manage or delete your ChannelRivet account where available, and request access, correction, or deletion of information that ChannelRivet controls, subject to applicable legal exceptions.
For detailed deletion instructions, visit ChannelRivet Data Deletion.
10. Children's privacy
ChannelRivet is a business and ecommerce integration product and is not directed to children. We do not knowingly seek to collect children's personal information through the ChannelRivet merchant-connection service.
11. Changes to this policy
We may update this Privacy Policy as ChannelRivet, supported channels, or legal requirements change. The date at the top of this page identifies the latest revision.
12. Contact
Privacy questions and requests can be sent to [email protected]. Do not send passwords, Meta App Secrets, access tokens, payment card numbers, or other credentials by email.
Who we are
Suggested text: Our website address is: https://channelrivet.com.
Comments
Suggested text: When visitors leave comments on the site we collect the data shown in the comments form, and also the visitor’s IP address and browser user agent string to help spam detection.
An anonymized string created from your email address (also called a hash) may be provided to the Gravatar service to see if you are using it. The Gravatar service privacy policy is available here: https://automattic.com/privacy/. After approval of your comment, your profile picture is visible to the public in the context of your comment.
Media
Suggested text: If you upload images to the website, you should avoid uploading images with embedded location data (EXIF GPS) included. Visitors to the website can download and extract any location data from images on the website.
Cookies
Suggested text: If you leave a comment on our site you may opt-in to saving your name, email address and website in cookies. These are for your convenience so that you do not have to fill in your details again when you leave another comment. These cookies will last for one year.
If you visit our login page, we will set a temporary cookie to determine if your browser accepts cookies. This cookie contains no personal data and is discarded when you close your browser.
When you log in, we will also set up several cookies to save your login information and your screen display choices. Login cookies last for two days, and screen options cookies last for a year. If you select "Remember Me", your login will persist for two weeks. If you log out of your account, the login cookies will be removed.
If you edit or publish an article, an additional cookie will be saved in your browser. This cookie includes no personal data and simply indicates the post ID of the article you just edited. It expires after 1 day.
Embedded content from other websites
Suggested text: Articles on this site may include embedded content (e.g. videos, images, articles, etc.). Embedded content from other websites behaves in the exact same way as if the visitor has visited the other website.
These websites may collect data about you, use cookies, embed additional third-party tracking, and monitor your interaction with that embedded content, including tracking your interaction with the embedded content if you have an account and are logged in to that website.
Who we share your data with
Suggested text: If you request a password reset, your IP address will be included in the reset email.
How long we retain your data
Suggested text: If you leave a comment, the comment and its metadata are retained indefinitely. This is so we can recognize and approve any follow-up comments automatically instead of holding them in a moderation queue.
For users that register on our website (if any), we also store the personal information they provide in their user profile. All users can see, edit, or delete their personal information at any time (except they cannot change their username). Website administrators can also see and edit that information.
What rights you have over your data
Suggested text: If you have an account on this site, or have left comments, you can request to receive an exported file of the personal data we hold about you, including any data you have provided to us. You can also request that we erase any personal data we hold about you. This does not include any data we are obliged to keep for administrative, legal, or security purposes.
Where your data is sent
Suggested text: Visitor comments may be checked through an automated spam detection service.