This Privacy Policy explains how ISCT LLC ("RUV Labs," "we," "us") collects, uses, shares, and protects personal information when you use RUV Labs at ruvlabs.com and related services (the "Service").
For the purposes of the EU and UK General Data Protection Regulation ("GDPR"), ISCT LLC is the controller of personal information processed through the Service, except where stated otherwise.
1. Summary
- We collect what we need to run a trusted professional network: your account and profile, verification results, the content you post, your messages, and payment status.
- Identity documents and face scans for KYC are processed by our verification provider (Didit), not stored by us. We receive the result.
- Documents you upload for badges are deleted as soon as we review them, and in any case within 14 days.
- We do not sell your personal information and do not share it for cross-context behavioral advertising.
- Analytics cookies (Google Analytics 4) are used only with your consent where consent is required.
2. Information we collect
2.1 Information you give us
| Category | Examples |
|---|---|
| Account | Name, email address, and profile photo from your Google sign-in |
| Profile | Display name, handle, headline, bio, country, time zone, languages, roles, skills, work history, education, portfolio items, what you are looking for |
| Verification | Legal name, year of birth, ID-issuing country and verification outcome received from Didit; a one-way fingerprint of your ID number and of your name and date of birth, used only to keep one account per person; documents you upload for badges (temporarily); LinkedIn profile URL if you use LinkedIn import; work or school email if you use email verification |
| Content | Posts, Deal Room listings, Insights, saved items, reports you submit |
| Messages | Direct-message requests and conversations |
| Payments | Plan, purchase history, and billing country. Card details are handled by Stripe; we do not receive full card numbers. |
| Communications | Messages you send to support, appeals, or other addresses |
| Expert Review | Materials you submit for review and the resulting report; for reviewers, payout status from Stripe Connect |
2.2 Information collected automatically
| Category | Examples |
|---|---|
| Device and log data | IP address (stored in hashed form in our logs), browser type, device type, pages viewed, referring URL, timestamps |
| Usage data | Features used, posting and messaging activity counts, Deal Room views, profile views |
| Cookies and similar technologies | See our Cookie Policy |
| Security signals | Bot-detection results (Cloudflare Turnstile), rate-limit events, fraud signals |
2.3 Information from third parties
- Google: basic profile data when you sign in.
- Didit: verification outcome, document-issuing country, legal name, year of birth, and fraud signals.
- Stripe: payment status, billing country, and, for Expert Reviewers, payout account status.
- LinkedIn (only if you choose LinkedIn import): information visible on your public LinkedIn profile that our staff views to confirm your badges.
3. Biometric information
Identity verification uses a selfie and a photo of your government ID to confirm that you are the person on the ID. This biometric processing is performed by Didit on our behalf. We do not receive or store face geometry or biometric templates. Before you start verification, we ask for your explicit consent. Didit retains verification data according to its own retention schedule and our instructions, and in any case no longer than necessary for verification, fraud prevention, and legal obligations. See our Verification & KYC Policy for details.
4. How we use information and our legal bases
| Purpose | Legal basis (GDPR) |
|---|---|
| Create and operate your account; show your profile and content | Performance of a contract |
| Verify identity and award badges | Contract; legitimate interests in a trusted network; explicit consent for biometric processing |
| Enforce posting limits, block duplicate content and contact details, prevent spam, fraud and abuse | Legitimate interests (platform integrity and safety); legal obligations |
| Enable direct messages, connections, and Deal Room introductions | Contract |
| Process payments, subscriptions, refunds, and reviewer payouts | Contract; legal obligations (tax and accounting) |
| Send service emails (security, billing, verification, account notices) | Contract; legitimate interests |
| Send product updates and newsletters | Consent or legitimate interests, with an easy opt-out |
| Analytics with Google Analytics 4 | Consent where required; otherwise legitimate interests |
| Improve and secure the Service; debug errors | Legitimate interests |
| Handle reports, enforcement, and appeals | Legitimate interests; legal obligations |
| Comply with law and respond to lawful requests | Legal obligations |
We use automated systems to detect duplicate posts, contact details, spam, and policy violations. These systems block content before it is posted or flag it for human review. Penalties such as posting suspensions are applied based on rule-based thresholds and can be appealed for human review.
5. What other members and the public can see
- Public: your profile (display name, handle, photo, headline, country, roles, skills, badges, work history, portfolio) and your posts are visible to anyone, including visitors who are not signed in, and may appear in search engines. Profiles of members who have not completed verification are excluded from search-engine indexing.
- Signed-in members only: Deal Room listings.
- Only the participants: direct messages.
- Pro members can see a list of members who viewed their profile, unless the viewer uses Pro incognito mode.
- Your legal name and verification documents are never shown publicly.
6. How we share information
We share personal information only as described here:
| Recipient | Purpose |
|---|---|
| Cloudflare | Hosting, database, file storage, security, bot detection, email routing |
| Didit | Identity verification |
| Stripe | Payments, tax calculation, subscription management, Expert Reviewer payouts |
| Sign-in; Google Analytics 4 (with consent where required) | |
| Resend | Sending transactional emails |
| Sentry | Error monitoring |
| Expert Reviewers | If you buy an Expert Review, the reviewer assigned to you receives your submitted materials |
| Legal and safety | When required by law, to respond to lawful requests, or to protect rights, safety, and the integrity of the Service |
| Business transfers | In connection with a merger, acquisition, or sale of assets, subject to this Policy |
Our service providers process information on our instructions and under contractual confidentiality and data protection obligations.
We do not sell personal information and do not share it for cross-context behavioral advertising. We honor Global Privacy Control (GPC) signals.
7. International transfers
We are based in the United States, and our providers may process information in the United States and other countries. When we transfer personal information from the EU, EEA, UK, or Switzerland, we rely on appropriate safeguards such as the European Commission's Standard Contractual Clauses (and the UK Addendum) or a provider's certification under the EU-U.S. Data Privacy Framework, where applicable.
8. Retention
| Data | Retention |
|---|---|
| Badge documents you upload | Deleted when reviewed; maximum 14 days |
| Verification outcome | While your account exists, plus 1 year |
| ID fingerprints (one account per person) | Until you delete your account |
| Profile and posts | Until you delete them or your account |
| A sign-up you never finished (signed in with Google but did not complete your profile) | Deleted after 7 days, or right away if you choose "Cancel sign-up" |
| Direct messages | Until you delete your account; copies remain visible to the other participant labeled as from a deleted user |
| Payment records | 7 years (tax and accounting) |
| Deal Room view records | 7 days |
| Profile view records | 1 year |
| Server logs | 30 days |
| Enforcement and audit records | 2 years |
9. Your rights
Depending on where you live, you may have the right to access, correct, delete, or receive a copy of your personal information; to object to or restrict certain processing; to withdraw consent at any time; and to not be discriminated against for exercising your rights.
- Self-service: download your data and delete your account in Settings.
- Requests: email privacy@ruvlabs.com. We may need to verify your identity. We respond within 30 days.
- California residents: you have the right to know, delete, correct, and opt out of sale or sharing (we do neither). You may use an authorized agent.
- EU/UK residents: you may lodge a complaint with your local data protection authority.
Account deletion becomes final 30 days after you request it, so you can change your mind. Some records are kept longer where the law requires (for example, payment records).
10. Security
We use encryption in transit (TLS), encryption at rest provided by our infrastructure, access controls with multi-factor protection for administrators, audit logging, minimization of sensitive data, and short-lived access links for verification documents. No system is perfectly secure; please report vulnerabilities to security@ruvlabs.com.
11. Children
The Service is not intended for anyone under 18, and we do not knowingly collect information from minors. If you believe a minor has an account, contact privacy@ruvlabs.com.
12. EU representative
We will publish the details of our representative in the European Union here once appointed. Until then, contact privacy@ruvlabs.com.
13. Changes
We may update this Policy. If changes are material, we will notify you before they take effect. The effective date above shows when this Policy was last updated.
14. Contact
ISCT LLC (operator of RUV Labs) Privacy requests: privacy@ruvlabs.com