Rever Finance Inc.
Rever Finance Inc. ("Rever," "we," "us") provides agentic AI finance operations for mid-market companies, currently offered to businesses in the United States, principally in software and manufacturing. Our platform connects to your ERP, banks, and business applications, on a read-only basis by default. AI agents reconcile transactions, prepare the financial close, and identify recoverable amounts, with postings and outbound actions held for approval by your authorized users as configured in the Service.
This Privacy Policy explains how we collect, use, and protect personal information when you visit rever.ai, join our waitlist, request a demonstration or security pack, take part in a proof-of-value engagement, contact our support or sales teams, or use the Rever platform (together, the "Service").
1. The two roles we play
Because Rever is a business-to-business service, we handle personal information in two distinct capacities.
(a) Rever as a controller (business). For information about our website visitors, prospects, and the individual users of our customers - names, work emails, role assignments, login and in-product activity - Rever decides how and why the data is used. This Policy governs that data.
(b) Rever as a processor (service provider). The financial records our agents work on - general ledger entries, bank feeds, invoices, purchase orders, vendor and customer master data ("Customer Content") - belong to our customer. Customer Content may incidentally contain personal information, for example a vendor contact's name on an invoice or an employee name on an expense line. We process Customer Content on our customer's documented instructions under our Data Processing Agreement, not under this Policy.
If you are an employee, vendor, or customer of a Rever customer and have questions about your data, please contact that company directly. See Section 8 for how we route such requests.
2. Information we collect
Account and user data. Name, work email address, job title, company name, role assignments (for example preparer, approver, auditor), authentication data, and SSO or SCIM attributes where the customer enables them.
Prospect and marketing data. Information you submit through our waitlist, contact forms, demonstration requests, or security-pack requests, including company size and finance-stack details you choose to share.
Demonstration, proof-of-value, and call information. If you attend a product demonstration, a proof-of-value engagement, or a support or sales call, we collect the information you share during it, including notes we take. Where we record or transcribe a session, we will notify participants and obtain consent as required by applicable law.
Usage, device, and log data. Log data, IP address, device and browser type, device identifiers, approximate location inferred from IP address, cookie and similar identifiers (see Section 10), pages viewed, and in-product activity such as approvals given, findings reviewed, and questions asked of the Eve assistant. In-product activity forms part of the audit trail that is a core feature of the Service.
Support and communications. Emails, support tickets, and call notes.
Children. The Service is intended for business use only and is not directed to children. We do not knowingly collect personal information from children. If you believe a child has provided us with personal information, please contact support@rever.ai and we will take steps to delete it.
Notice at collection
The table below summarises the categories of personal information we collect as a controller, why we collect them, who we disclose them to, and how long we keep them. We do not sell personal information and we do not share it for cross-context behavioral advertising.
| Category | Purpose | Disclosed to | Retention |
|---|---|---|---|
| Identifiers - name, work email, job title, company | Account provisioning, authentication, service communications | Hosting, email, support, and billing sub-processors | For the subscription term, and a limited period afterwards to handle wind-down, billing queries, and reinstatement |
| Commercial information - plan, usage volumes, credits, invoices | Usage-based billing, credit administration, value reporting | Billing sub-processor; your organisation's administrators | For the period required for tax, accounting, and audit purposes under applicable law |
| Internet and network activity - IP, device, pages viewed, in-product actions | Security, fraud prevention, product analytics, audit trail | Hosting, security, and analytics sub-processors | Security and system logs for a limited period set by our retention schedule; audit-trail records as described in Section 6 |
| Professional information - role, finance-stack details, company size | Qualifying and configuring the Service; marketing where permitted | CRM and marketing sub-processors | While the commercial relationship or your marketing consent remains active, and for a limited period afterwards |
| Audio and visual - call notes, and recordings where consented | Support, training, service improvement | Support and conferencing sub-processors | For a limited period set by our retention schedule |
| Sensitive personal information | We do not collect sensitive personal information as a controller, and we ask customers not to connect sources containing it | Not applicable | Not applicable |
We may retain any category for longer where retention is required by law, or where the information is needed to establish, exercise, or defend legal claims. See Section 6.
3. How we use information
We use personal information to:
- Provide and operate the Service - including connecting to the sources our customer authorizes, generating findings, and maintaining the approval and audit trail.
- Verify and secure accounts - confirming account and licence details, investigating suspicious activity, preventing fraud and abuse, enforcing our terms and policies, and maintaining the security of the Service, our systems, and our applications.
- Administer billing and report value - calculating usage-based charges and credits, and preparing the value reporting our customers rely on, being amounts identified and recovered, and hours saved.
- Provide the free plan - including its history scope and the zero-day scan preview.
- Handle contacts and support requests - responding to web-form submissions, support tickets, calls, and emails, and fulfilling your requests.
- Develop and improve the Service - analysing how the Service is used, including in aggregated or de-identified form, to improve functionality and to offer content and features likely to be relevant to you.
- Communicate with you - including security notices, service announcements, and administrative messages, and, with your consent where required, marketing. You can opt out of marketing at any time; service and administrative messages continue while you hold an account.
- Comply with law - including responding to lawful requests and meeting our regulatory obligations.
AI and model training. We do not use Customer Content to train models made available to other customers. Agent outputs in your workspace are generated from your records, and findings are presented with links to the underlying records.
No automated decisions with legal effect. We do not use personal information for profiling that produces legal or similarly significant effects. Financial postings are decided by your organization's authorized human approvers; our agents prepare and recommend.
4. How we share information
We do not sell personal information, and we do not share it for cross-context behavioral advertising. We disclose information only as follows.
- Sub-processors and service providers listed at rever.ai/legal/sub-processors, each bound by contract to protections at least as strong as those in this Policy, and permitted to use the information only to provide services to us.
- Payment processing. We use a third-party payment processor to handle card payments. That provider is not permitted to store, retain, or use billing information except to process payments on our behalf. We do not store complete payment card numbers.
- Your organization. Administrators and auditors at the customer that provisioned your account can see your in-product activity. This is by design, because the audit trail must be capable of replay.
- Professional advisers, including lawyers, accountants, auditors, bankers, and insurers, where we are legally obliged to share information or have a legitimate interest in doing so.
- Corporate transactions. In connection with a sale, merger, financing, transfer, or other disposition of all or part of our business, subject to this Policy.
- Legal and protective disclosures. Where required or permitted by law or legal process; where necessary to protect or defend our rights or property, or to enforce our agreements; or in urgent circumstances to protect personal safety or the public.
Government and law-enforcement demands. Where we receive a binding demand for information held in a customer's workspace, we will, where lawful and reasonably practicable, seek to redirect the requester to the relevant customer, notify the affected customer or individual, disclose only information responsive to the demand, and may challenge demands that appear overbroad or legally defective.
5. Security
Data is encrypted using AES-256 at rest and TLS 1.2 or higher in transit. Source connections are read-only by default; write credentials are held outside agent runtimes; and postings and outbound actions require approval by an authorized person. Access to production systems is role-based, logged, and granted on a least-privilege basis.
We operate an information security programme built around the SOC 2 Trust Services Criteria and the ISO/IEC 27001:2022 control framework, with a SOC 2 Type II examination conducted annually and ISO/IEC 27001:2022 certification. Our current attestation and certification status, together with available reports and certificates, is published at rever.ai/trust and provided under non-disclosure agreement on request. Our Security Measures document sets out the technical and organizational controls in full.
No system is completely secure, and we cannot guarantee the security of information transmitted to us.
6. Retention
We retain each category of personal information for the period described in the notice-at-collection table in Section 2, determined by how long the information is needed for the purpose it was collected for.
We may retain information beyond those periods where it is required by law, where it is needed to establish, exercise, or defend legal claims, or where a customer has contracted for extended retention of audit-trail records. Information retained on that basis remains subject to this Policy and, for Customer Content, to the Data Processing Agreement, until deletion.
Account and audit-trail data is retained while your organization's subscription is active. On our free plan, connected history is limited to 90 days. Customer Content is retained and deleted in accordance with the customer's instructions and our Data Processing Agreement; on termination, customers may export their data for a defined period, after which we delete or de-identify it within the period stated in that agreement. Residual copies may persist in backups for a limited period before being overwritten.
7. Where we and our service providers operate
Customer Content and account data are hosted in the United States by default, with region-pinned tenancy and, for enterprise customers, private cloud or self-hosted deployment options.
Rever's personnel, affiliates, and service providers may access information from locations outside the United States, including India, for engineering, support, and administrative purposes. Such access is subject to contractual commitments, access controls, logging, and the security measures described in Section 5, and, for Customer Content, to the terms of our Data Processing Agreement. Where the law of a country from which information is accessed does not provide the same protections as the law of your own, we continue to apply the safeguards described in this Policy.
Our current list of processing locations and sub-processors is published at rever.ai/legal/sub-processors.
8. Your privacy rights
Depending on your state of residence, you may have the right to access, correct, delete, or obtain a portable copy of your personal information, to limit the use of sensitive personal information, and to opt out of sale, sharing, or targeted advertising. We do not sell or share personal information or engage in targeted advertising. These rights are available under the comprehensive privacy laws of a growing number of states, including California, Colorado, Connecticut, Delaware, Florida, Indiana, Iowa, Kentucky, Maryland, Minnesota, Montana, Nebraska, New Hampshire, New Jersey, Oregon, Rhode Island, Tennessee, Texas, Utah, and Virginia, as and when each such law takes effect, and may be available in other states.
How to exercise a right. Email support@rever.ai. We will verify your identity using information already in our possession, and will not ask for more information than is necessary to do so.
Authorized representatives. You may use an authorized representative to submit a request on your behalf. We may ask for written authorization signed by you, and may ask you to verify your identity with us directly. (This is distinct from Rever's AI agents, which are software components of the Service.)
Response times. We will respond within the period required by applicable law, generally 45 days from receipt, extendable once where reasonably necessary. We will tell you if we need an extension, and will contact you if we need more information to act on your request.
Appeals. If we decline your request, we will explain why and how to appeal. We will respond to an appeal in writing within the period required by applicable law, and, where the appeal is unsuccessful, will tell you how to contact your state Attorney General.
No discrimination. We will not discriminate against you for exercising your rights.
If your information was provided to us by one of our customers. Where information is held in a customer's workspace as Customer Content, that customer is responsible for it and we act on their instructions. We do not control our customers' privacy practices, which may differ from those described here. If you wish to exercise rights in relation to that information, please contact the customer directly. If you prefer to contact us, tell us the name of the Rever customer concerned and we will notify them of your request and assist them in responding within a reasonable time. If you are an employee of a Rever customer, your organization's system administrator can usually correct or update your information directly.
9. Visitors and users outside the United States
The Service is designed and offered for the United States market, and this Policy is written to United States privacy law. If you access the Service from outside the United States, your information will be processed in the United States and in the other locations described in Section 7.
If you are located in a jurisdiction whose law affords you additional privacy rights, please contact legal@rever.ai. We will consider and respond to your request as applicable law requires.
10. Cookies and similar technologies
We use strictly necessary cookies for authentication and security, and limited analytics cookies to understand how our website is used. You can control cookies through your browser settings and, where offered, through our cookie banner. Blocking strictly necessary cookies may prevent you from logging in.
Because we do not sell personal information or share it for cross-context behavioral advertising, there is no such activity to opt out of. Where applicable law requires us to recognise opt-out preference signals such as Global Privacy Control, we do so.
11. Links to other websites
Our website may contain links to websites operated by others. We do not control those websites and are not responsible for their content or their privacy practices, and this Policy does not apply to them. Please review the privacy policy of any website you visit through a link from ours.
12. Not professional advice
The Service, and the findings, reconciliations, prepared entries, and value reporting it produces, are tools for your finance team. Except as separately agreed with us in writing, they are not accounting, audit, tax, or legal advice. Your organization remains responsible for its books of record, its financial statements, its internal control over financial reporting, and its statutory filings. Postings and outbound actions require approval by a person with authority in your organization.
13. Changes to this Policy
We may update this Policy from time to time. We will post the updated version here with a revised "Last updated" date and, for material changes, notify account administrators. Continued use of the Service after the effective date of a change constitutes acceptance of it.
14. Contact us
Rever Finance Inc.
Attn: Privacy