Bridge by Rizolvr — Privacy Policy

Version 2.0 — Effective September 9, 2026 · A product of Rizolvr LLC (Wyoming)

Supersedes Version 1.0, effective May 6, 2026.

1. Information We Collect

  • Account Information: Name, email address, and shop name provided during signup.
  • Lightspeed POS Data: Data synced via OAuth 2.0 — customers, items, sales, work orders, reference data (categories, manufacturers, vendors, tags, employees). On Standard and Premium, Bridge reads this data and does not change it. On Pro, where you have separately authorized it, Bridge can also make the changes you direct.
  • Billing Information: Card details are collected and stored by Stripe. Rizolvr LLC never sees or stores your card.
  • Tool Usage: Per-request logs containing tenant ID, tool name, response row count, and latency. We do not log the natural-language questions you ask your AI assistant — those never reach Rizolvr.
  • Change Records: Where you have enabled write access, we record each change made through Bridge — the seat that initiated it, the tool used, the time, and the state of the affected record before and after the change. Because the affected record may itself contain personal data, such as a customer's contact details, these change records may contain personal data.

2. How We Use Your Information

  • To operate and maintain the Service.
  • To improve the Service using operational metadata — the per-request logs described in Section 1 (tenant ID, tool name, row count, latency). We do not examine the contents of your point-of-sale data to improve the Service.
  • To answer the queries your AI assistant sends to Bridge on your behalf, and — where you have enabled write access — to carry out the changes it directs.
  • To send service-related emails (onboarding, billing, security alerts, kill-switch notifications).
  • To detect and block abuse — e.g., a runaway AI agent exhausting the rate limit or attempting to access tenants other than yours.
  • To maintain the change records described in Section 1 and make them available to you.

3. Data Storage & Isolation

Your synced POS data is stored in a dedicated database of its own, hosted with Amazon Web Services in the United States. The credential that reaches that database is scoped to it alone, so no query — however malformed — can reach another customer's data. Where you have enabled write access, changes are made through the Lightspeed API using your authorization, not by altering your Bridge database directly, and the affected records are then re-synced.

Per-customer secrets (database credentials and Lightspeed tokens) are held in an encrypted secrets store, accessible only to the specific services that need them. All data in transit uses TLS 1.2+.

4. Data Bridge Writes on Your Behalf

Where you have enabled write access, Bridge writes two kinds of data outside our own systems.

Into your Lightspeed account. Bridge makes the changes you direct, and additionally records a short dated note in the affected record's internal note field, identifying the change as having been made through Bridge. This note is visible to anyone with access to that record in your point-of-sale system.

Nothing to anyone else. Bridge does not write your data to any third-party system other than your own Lightspeed account and the AI assistant you have authorized to receive it.

5. Data Sharing

We do not sell personal or identifiable customer data to third parties. Limited disclosure occurs only:

  • To service providers processing data on our behalf under confidentiality agreements: Stripe (payment processing), Amazon Web Services (hosting and the delivery of our transactional email), Cloudflare (bot protection on account signup, password reset, and our enterprise contact form), and Google (website analytics — see Section 9).
  • For legal compliance when required by law or valid legal process.
  • To AI assistants you authorize. When you connect an AI client (e.g., Claude Desktop) to Bridge, the AI receives the data it requests via tool calls. Your contract with that AI provider governs how that data is used and stored on their side.

6. AI Assistant Boundaries

Bridge passes data to your AI client. Once the data leaves Bridge and arrives at your AI client, the AI provider's privacy policy and data-retention practices apply. We encourage you to review the privacy policies of any AI assistant you connect:

  • Anthropic (Claude): claude.ai/privacy
  • OpenAI (ChatGPT): openai.com/privacy
  • Google (Gemini): support.google.com/gemini

7. Data Retention & Deletion

Your data is retained while your subscription is active. On cancellation, we retain it for sixty (60) days as a grace period during which you can reactivate or request a one-time export. After 60 days your tenant database is permanently dropped and your stored credentials are deleted. To expedite deletion before the grace period ends, contact bridge@rizolvr.com.

8. Your Rights

  • Access the personal data we hold about you.
  • Request correction of inaccurate data.
  • Request deletion of your account and associated data.
  • Disconnect your Lightspeed account at any time (revokes Bridge's OAuth grant).
  • Request a one-time export of your synced data (CSV per entity).
  • Request immediate revocation of your MCP token in case of suspected compromise.
  • Request a copy of the change records associated with your account.

9. Analytics, Cookies & Local Storage

We look at how you use Bridge. We don't look at what's inside your shop.

Your point-of-sale data. We do not analyse, profile, aggregate, or mine the data Bridge syncs from your Lightspeed account — your customers, your sales, your inventory, your work orders. It is synced for one purpose: to answer the questions you ask and to carry out the changes you direct. We do not combine it with other customers' data, we do not use it to train models, and we do not sell it. Your customers' information is yours. It is not ours to study.

Our website and portal. We use standard web analytics on rizolvr.com and portal.rizolvr.com to understand how people find us and how our customers use the product — pages viewed, referring source, approximate location derived from IP address, and general device and browser characteristics. We use Google Analytics 4 for this. Today our analytics are configured to send the address of the page visited and nothing that follows it, so the details of what you were looking at do not leave your browser.

These never mix. Web analytics describe visits to our pages. They are not joined to the data Bridge syncs from your point-of-sale system.

Our sites also use essential cookies and local storage for session authentication.

10. Changes to Privacy Policy

We may update this Policy from time to time. When we make a material change, we will email the account holder at the address on the account, with a link to the updated Policy, and we will update the version number and effective date shown at the top of this page.

11. Contact

Questions about privacy: bridge@rizolvr.com