Skip to main content

Privacy Policy

Last updated September 4, 2026

Information we collect

When you place an order or contact us, we collect the details needed to serve you, such as your name, email, phone number, shipping address, order note, purchased items, and correspondence. We may also retain limited technical information such as IP address and browser request data for fraud prevention, security, and troubleshooting.

How we use information

We use customer information to process payment, fulfill and support orders, provide receipts, prevent abuse, maintain business records, and improve the store. Marketing email is sent only when you separately opt in, and every campaign includes an unsubscribe link.

Product Alerts

If you ask for a back-in-stock or price-drop alert, we use the email address and product preference you provide only to confirm and operate that alert. This is separate from marketing consent. Brevo processes the confirmation and one-time alert emails on our behalf. You can cancel an alert from its private manage link. Unconfirmed and active requests expire automatically; an active request is kept for no more than 90 days. Personal data attached to a completed, cancelled, expired, or otherwise terminal alert is removed after a 30-day support window. We retain minimal provider-message correlation for up to 180 days to resolve delayed delivery events, and suppression markers for up to three years to avoid sending to addresses that bounced permanently, complained, or opted out.

Analytics and measurement

Vercel Web Analytics and Speed Insights provide aggregate traffic and performance measurements. Google Analytics loads in the background after the page becomes idle, with analytics storage enabled and all advertising purposes denied. It may use first-party Google Analytics cookies to distinguish sessions and returning visitors. It receives privacy-filtered page and commerce events. Commerce events may include product identifiers and names, prices, quantities, coupon codes, and a transaction reference, but the event contract excludes your name, email, phone number, shipping address, order note, payment identifiers, and card details. Search terms that resemble personal, order, URL, or secret data are not sent. Learn more about how Google processes information.

First-party visitor measurement

When enabled, our own lightweight measurement uses a random browser identifier reused within the same store-calendar day and per-tab session storage. We retain a day-specific protected digest rather than that browser identifier, together with the initial session IP address observed by our server, session times, the observed traffic source, approximate city, state and country inferred from the request IP, an estimate of visible-tab time, and whether checkout began. IP addresses are available only to authorized administrators in these session reports for traffic review and troubleshooting; a shared network or VPN address does not identify an individual visitor. These analytics records do not contain form entries, precise location, customer names, email addresses or product browsing histories, and are not linked to orders or payment records. We do not send IP addresses to a separate geolocation service for this feature. Detailed session summaries, including their IP addresses, are scheduled for deletion after 30 days. This measurement honors Do Not Track and Global Privacy Control signals and does not affect the ability to browse, use the cart or check out.

Email delivery and engagement

Our email provider may report delivery, bounce, complaint, unsubscribe, open, and link-click activity so we can operate campaigns and suppress unsafe future sends. RiveraHotDeals stores the validated delivery and engagement status needed for those purposes rather than retaining raw webhook payloads.

Service providers

We share only the information required by providers that operate the store, including PayPal for payment, Cloudflare for security and bot protection, Vercel for hosting and site measurement, Google Analytics for traffic and commerce-funnel measurement, database providers, email delivery services such as Resend or Brevo, Cloudinary for images, and optional address-assistance providers. Those providers process information under their own terms and privacy obligations.

Retention and security

We retain order and transaction records as reasonably needed for customer support, accounting, fraud prevention, and legal obligations. Administrative access is restricted, sensitive connections use encryption in transit, and payment credentials are handled by PayPal rather than stored by RiveraHotDeals.

Your choices

You can unsubscribe from marketing at any time, and you can cancel a Product Alert independently from its private manage link. Browser privacy controls and content blockers can block third-party analytics requests without affecting your cart or checkout. To request access, correction, or deletion of information where applicable, use our contact page. Some transaction records and email-safety suppression markers may need to be retained for legal, security, or operational reasons.

Policy changes

We may update this policy when the store or its providers change. The latest version and update date will remain available on this page.