Privacy Policy
What this covers
How TheRiot Agency collects, uses and shares information when you visit theriot.agency, send us a form, or receive messages from us. It also covers our client portal and TRAi DataIQ, which we run at theriot.app, and the data you connect to them. Last updated 23 September 2026.
Who we are
TheRiot Agency operates this website. You can reach us at info@theriot.agency, on (617) 544-7468, or at 6586 Hypoluxo Road, Suite 141, Lake Worth, FL 33467. For anything about your personal data, write to info@theriot.agency and put "Privacy" in the subject line.
Information you give us
When you send a contact form or subscribe to our newsletter, we collect the name, email address, company and message you enter. We use it to answer you, to send you material you asked for, and to keep a record of the conversation. We store it in our own systems and in HubSpot, our customer relationship platform.
Information we collect automatically
When you visit, we and the services listed below collect your IP address, browser and device type, the pages you view, how you arrived, and how you move through the site. Some of this is set through cookies and similar technologies in your browser.
We record website sessions
We use our own tool, TRAi Signal, to record how visitors use this site. It captures page views, clicks, scrolling and mouse movement, and can replay a visit to show us where a page confused someone. We use it only to improve the site. It does not capture what you type into form fields, and we do not use it to identify you personally. It does not run if your browser sends a Global Privacy Control or Do Not Track signal.
Cookies and similar technologies
Some cookies are necessary — they keep the site working and remember choices such as light or dark mode. The rest are for analytics and advertising, and they are the ones you can turn off. We do not need your permission for the necessary ones. We ask for it for the others where the law requires it.
Who we share information with
We do not sell your personal information for money. We do share it with the services that run our measurement and advertising, which under some state laws counts as "sharing" for targeted advertising. Those services are: Google (Analytics and Ads), Meta (Facebook advertising), LinkedIn (advertising), HubSpot (customer relationship management and email), Apollo (identifies the company a visitor works for, not the person), and Cloudflare (hosting and tag delivery). Each one uses the data under its own privacy policy. We also share information with professional advisers, or where the law requires it.
How TRAi DataIQ uses Google user data
TRAi DataIQ is the reporting part of TheRiot Agency’s client portal. If you are a client and you connect a Google account to it, TRAi DataIQ asks Google for permission to READ three things, and nothing else: your Google Analytics 4 properties, your Google Ads accounts and your Search Console sites. It never writes to them, never changes a setting, and never creates or edits an advertisement.
What TRAi DataIQ does with that access
- What it reads. From Google Analytics: sessions, users, conversions, traffic sources and landing pages. From Google Ads: campaign, ad group, keyword, search term and conversion reports. From Search Console: clicks, impressions, average position and the queries people used. It reads only the properties and accounts you choose.
- Why it reads it. To show your own marketing numbers to you, and to the TheRiot Agency team that works on your account, on the boards and in the reports inside your client portal.
- How often. Once a day, automatically, and again when you press Refresh.
- Where it is kept. The permission Google gives us is stored encrypted in our own systems on Cloudflare, in the United States. The numbers we read are stored in our own database so a board opens quickly.
- Who can see it. You, the people you invite to your portal, and the TheRiot Agency staff assigned to your account. Nobody else. We do not sell this data, we do not share it with advertisers, and we do not use it to build advertising profiles or to train artificial intelligence models.
- How long we keep it. We keep your numbers while you are a client, so your year-on-year trends stay complete. When you disconnect Google, we delete the stored permission straight away and the reading stops. When you leave us, we delete the data we hold for you. We write down every deletion we make, and we will give you written confirmation of it if you ask. You can ask us to delete the data sooner at any time.
- How to stop it. Disconnect Google at any time from the Connections page in your portal, or remove TheRiot Agency from your Google account at myaccount.google.com/permissions. We delete the stored permission when you do, and the reading stops immediately.
TRAi DataIQ’s use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
To ask about this data, or to have it deleted, write to info@theriot.agency and put "Privacy" in the subject line.
The TRA Work browser extension
TRA Work is a Chrome browser extension for the contractors who work with TheRiot Agency. It shows a contractor the tasks assigned to them on TRA Work, and lets them log time, tick off checklist items and hand work back for review. It is not offered to the public, and it only works with a TRA Work account that we set up.
What the TRA Work extension does with your information
- What it collects. Your name and email address, which it shows so you can see which account you are signed in with. A session token that our server issues when you sign in. The hours, date and note you enter when you log time, and the checklist items you tick. If you start a timer, its start time is kept only in your own browser.
- What it does not collect. It does not read the pages you visit, and it cannot: it has no access to any website except our own server. It does not record your browsing history, your screen, your location, your files or your messages. It collects nothing for advertising.
- Where it goes. The extension talks to one server that we run on Cloudflare. That server passes each request to our Salesforce system as you, using your own sign-in, so you see only what your own account allows. Your Salesforce access token stays on that server and never reaches your browser.
- Who can see it. You, and the TheRiot Agency staff who manage your work. We do not sell it, we do not share it with advertisers, and we do not use it to train artificial intelligence models.
- How long we keep it. Your session ends when you sign out, or after a period without use. Time entries you save are business records, and we keep them under our normal retention practice.
- How to stop it. Sign out in the extension, or remove it from Chrome. We can also switch off your access at any time.
To ask about this data, or to have it deleted, write to info@theriot.agency and put "Privacy" in the subject line.
How we protect your information
We protect everything described on this page, including the data we read from your Google account, with the safeguards in our Information Security Policy. We will send you a copy on request. These are the measures that matter most.
- Encryption. Every connection to this site and to your client portal uses HTTPS, so what travels between your browser and us is encrypted. The data we hold is encrypted at rest by the platforms that store it, Cloudflare and Salesforce.
- Your Google permission is kept apart. The permission you grant is held in a separate credential store, not in the database that holds your numbers, and never in our source code. The working keys our system uses to read your accounts expire less than an hour after they are issued.
- Access control. Multi-factor authentication is on for every system that supports it. Each person gets the least access their job needs, and we take it away the day the job changes or the person leaves. Only the TheRiot Agency people assigned to your account can open your data.
- One client cannot reach another. Your portal proves who you are on our server, not in your browser. A request that names a record belonging to someone else is refused, not answered.
- Protected and patched devices. Every company device runs Microsoft Defender for Business with continuous vulnerability assessment. We fix critical faults within 7 days, high within 14, and the rest within 30.
- Deletion you can check. Disconnect Google and we delete the stored permission at once. Leave us and we delete the data we hold for you. We record each deletion, and we can give you written confirmation of it.
No system is perfectly secure. We keep a written incident response process: contain it, assess it, fix it, tell the people we must, write it down and learn from it. If a breach affects your personal data, we tell you and any authority the law names, within the time the law requires.
Advertising and how we use it
We use Google Ads, Meta and LinkedIn to advertise our services, and to show our advertising to people who have visited this site. If you send us a form, we record that as a conversion so we can tell which advertising works. That record tells the advertising platform an enquiry happened. It does not send them your message.
Your choices
You can turn off analytics and advertising cookies at any time through the privacy settings on this site. You can set a Global Privacy Control signal in your browser, and we honour it. You can turn off cookies entirely in your browser settings, though parts of the site may then work less well. To stop marketing email, use the unsubscribe link in any message we send.
If you are in the EU or the UK
We rely on your consent for analytics, advertising and session recording, and you can withdraw it at any time. We rely on our legitimate interest in running and securing the site for the necessary parts. Where you send us an enquiry, we process it to take steps you asked for before entering a contract. You have the right to access, correct, delete, restrict or port your data, to object to processing, and to complain to your data protection authority. Your data is processed in the United States. Our providers' standard data processing terms include the European Commission's standard contractual clauses, which is the basis we rely on for transfers out of the EU and the UK.
If you are in California or another US state with privacy rights
You have the right to know what we collect, to have it deleted, to correct it, and to opt out of its being shared for targeted advertising. Use the privacy settings on this site, or write to info@theriot.agency. We will not treat you differently for exercising these rights. We honour Global Privacy Control as an opt-out signal.
SMS and text messaging
No mobile information is shared with third parties or affiliates for marketing or promotional purposes. Text messaging originator opt-in data and consent are not shared with any third party. If you have opted in to messages from us, reply STOP to any message to stop them. See our SMS Consent page for the full terms.
How long we keep information
We keep enquiries and the correspondence that follows for as long as we have a relationship with you, and then for as long as our records and legal obligations require. We keep session recordings for 90 days, after which they are deleted automatically. Analytics and advertising data are kept for the period each provider sets, which their own policies describe.
Children
This site is for business audiences. We do not knowingly collect information from anyone under 16. If you believe a child has given us information, write to info@theriot.agency and we will delete it.
Changes to this policy
We update this page when what we do changes. The date at the top tells you when it last changed. If a change matters to you, we will say so more clearly than a new date.