Legal
Privacy Policy
Last updated 4 September 2026 · Aventura Virtual Solutions Inc. (Canada), operating CloseRev
CloseRev matches sales records against advertising and call records, so we handle personal data — both yours and your customers'. This sets out exactly what we hold, why, how long, and how to get rid of it.
1. Two different roles
We handle two kinds of personal data, and our responsibilities differ for each.
- Your account data — your name, work email, company name, phone number and billing details. Here we are the controller: we decide what to collect and why.
- Data you upload — the customer records inside your files. Here we are a processor: you remain the controller, we act on your instructions, and we never use that data for our own purposes. Terms are in our DPA.
2. What we collect
In the last 12 months we have collected the following categories, using the classification required by California law.
| Category | Examples we collect | Source | Purpose |
|---|---|---|---|
| Identifiers | Name, work email, company name, phone number, account and workspace identifiers, IP address | You, at signup | Provide the service, authenticate you, support |
| Commercial information | Plan, subscription status, billing history | You and our payment processor | Billing, plan limits, accounting |
| Internet or network activity | Server logs, actions in your workspace (uploads, matches, overrides, exports, deletions) | Automatically | Security, debugging, your own audit trail |
| Professional information | Company name, role or industry if you tell us | You | Support and product relevance |
| Customer records you upload | Your customers' names, phone numbers, email addresses, transaction amounts and dates, marketing channel | You, by upload | Matching and reporting, on your instructions only |
We do not collect biometric data, precise geolocation, or sensitive personal information as defined by California law, and you must not upload special-category data — see the Acceptable Use Policy. Card details go directly to our payment processor and never reach our servers.
3. Why we process it, and on what legal basis
- To provide the service — performance of our contract with you.
- To secure accounts and prevent abuse — our legitimate interests.
- To bill you and keep records — contract, and legal obligation for tax.
- To send service messages (verification, password reset, receipts, security and billing notices) — contract. These are not marketing and cannot be opted out of while you hold an account.
- To send marketing — only with your consent, which you may withdraw at any time.
4. Selling and sharing
We never sell personal information, and we never use data you upload for our own marketing or to train machine-learning models. That applies without exception to your customers' records.
One thing does need naming plainly. If you accept advertising cookies on our public marketing site, the advertising vendors listed in our Cookie Policy receive information about your visit — and California law counts that as “sharing” for cross-context behavioural advertising, even though no money changes hands. It happens only if you turn that category on, only on our marketing pages, and never on signed-in pages, so it never touches your workspace or the customer records you upload.
We honour Global Privacy Control. If your browser sends that signal we treat it as an instruction to opt out of sharing: advertising stays off, and it cannot be overridden by clicking accept. You can also change your mind at any time from Your privacy choices.
5. Marketing communications
We send marketing only to people who have opted in. Consent is optional, is never a condition of using CloseRev, and is recorded with the date and the wording you agreed to. Every marketing message identifies us and carries a one-click unsubscribe, and we act on unsubscribes promptly. You can also withdraw consent from your account settings or by emailing us.
6. Who we share it with
Only the vendors needed to run the service, each bound by contract to protect it. The current list, and what each one can see, is on our Subprocessors page. We may also disclose personal data where legally required, to protect our rights or someone's safety, or to a successor in a merger or sale of assets — in which case this policy continues to apply until you are notified otherwise.
7. How long we keep it
| Data | Retention |
|---|---|
| Uploaded files and match results | Until you delete them, or your workspace retention window elapses (24 months by default, configurable) |
| Account data | While your account is open, then deleted within 30 days of closure |
| Invoices and tax records | As long as tax law requires, typically 6–7 years |
| Server and security logs | Up to 90 days |
| Marketing consent records | While consent stands, plus 3 years as proof it was given |
Deleting an import removes its records, its match results and the original uploaded file from storage.
8. Security
Data is encrypted in transit and at rest. Each workspace is isolated and every query is scoped to it. Passwords are hashed with PBKDF2-HMAC-SHA256 at 600,000 iterations, each with its own random salt. Email links are single-use, expiring, and stored only as hashes. Access by our staff is least-privilege. Our Security page describes this in more detail — including what we have not done yet.
9. International transfers
We are established in Canada, which the European Commission recognises as providing adequate protection for commercial organisations subject to PIPEDA. Where personal data is transferred from the EEA or UK to a vendor outside an adequate jurisdiction, we rely on the Standard Contractual Clauses (with the UK Addendum where applicable) together with supplementary measures including encryption. You may request a copy of the relevant safeguards.
10. Your rights
Depending on where you live — under the GDPR and UK GDPR, California's CCPA as amended by the CPRA, PIPEDA in Canada, and comparable laws elsewhere — you may have the right to:
- know what we hold and obtain a copy;
- correct inaccurate data;
- delete data;
- restrict or object to processing, including direct marketing;
- portability of data you provided;
- withdraw consent at any time, without affecting processing already carried out;
- not be discriminated against for exercising these rights — we do not offer a lesser service or different price to anyone who does.
Most of these you can exercise yourself in the product: export your data, delete an import, or close your account. For anything else, email privacy@closerev.com. We respond within 30 days (45 where California law allows an extension, with notice). We may need to verify your identity before acting. An authorised agent may submit a request on your behalf with written proof.
If you are dissatisfied you may complain to your local data protection authority, or in Canada to the Office of the Privacy Commissioner.
11. If you are someone else's customer
If your details reached us because a business uploaded them, that business is the controller and decides what happens to your data. Please contact them. If you contact us instead we will route your request to them and support them in answering it.
12. Automated decision-making
CloseRev matches records algorithmically, but it does not make decisions producing legal or similarly significant effects about individuals. Match results are advisory, are shown with their confidence, and can be overridden by a human.
13. Cookies
We use strictly necessary cookies, cookie-free analytics, and Google Analytics only where you have agreed to it. Details are in our Cookie Policy.
14. Children
CloseRev is a business tool, is not directed at anyone under 16, and we do not knowingly collect their data.
15. Changes
If we make a material change we will email account owners before it takes effect. The date at the top always reflects the current version.
16. Contact
Aventura Virtual Solutions Inc., Canada — privacy@closerev.com.