How RigCue uses your information.
This notice covers the RigCue shop-preview builder, private shop manager, hosted request page, and request-status links used during the private founding pilot.
Effective date: August 23, 2026
What is collected
RigCue collects the shop display name, website, shop type, selected equipment families, preview color, fulfillment choice, contact name, work email, quote-request email, pricing acknowledgement, and the consent shown in the builder. For the external pilot, RigCue compares the shop website and full work address with a server-held private-pilot invitation and records whether the invited work inbox and alert inbox have been verified. One-time access records may include a hashed recipient address, claim purpose, expiry, send status, and email-provider message identifier. A customer request may also include the requester's name, email or phone, contact preference, project answers, requested date, postal code, fulfillment choice, and optional notes. Private shop evaluations store the structured job scenario—project choices, requested date, postal code, fulfillment, and optional job notes—but omit customer contact details. They also include two usefulness ratings and may require a short explanation when information is missing or a category should change. A shop may record a Yes, Maybe, or No future-paid-pilot decision and one structured reason after completing the evaluation scorecard.
How it is used
The information is used to create and operate the shop-specific pilot, save equipment requests in the participating shop's RigCue inbox, show a limited request status, and let the shop contact the requester about that request. Customer-contact consent is recorded separately from the request-boundary acknowledgement used in private evaluations. Evaluation and decision data is used to determine whether the self-serve pilot is useful enough to continue developing. Request consent is not marketing consent.
Who can see it
Pilot configuration and request details are stored in the site's protected database. Full requests are available only through the shop's current private management session after a one-time claim to the exact invited work address has been verified. A participating shop receives only requests submitted to that shop. The RigCue operator may access stored pilot data only when needed for support, security, abuse response, or pilot evaluation. RigCue does not sell submitted contact information.
What appears in a hosted preview
A preview or customer-request link is shareable and is not a shop login. It may show the shop name, shop type, selected equipment families, and fulfillment choice. The private shop-management link is different: it must not be forwarded because a person who completes its one-time verification can manage that shop's pilot workspace on that device. Recovery links are also one-time, expire after 30 minutes, and replace older manager sessions only after the link is successfully verified.
Customer requests and status links
The standalone hosted preview remains a sandbox unless the visitor chooses a handoff action. On an activated shop request page, RigCue stores a request only after a successful submission and then creates a high-entropy private status link. That link shows the request reference, project summary, category candidate, and manually updated shop status; it does not show the requester's contact details or notes.
Limited pilot activity data
RigCue records a small number of first-party pilot events to understand whether the self-serve path works: whether a browser tab viewed or started the preview builder, opened an active customer link, started a request, reached a shortlist, copied a customer link from the private manager, or viewed the unlocked future-paid-pilot checkpoint. A random identifier is created for each public browser tab; authenticated manager events instead use the current private management session. Both are transformed into a one-way keyed value on the server before storage. Shop-scoped event rows are associated with an internal shop-workspace ID, so the RigCue operator can evaluate them alongside that named shop's setup. These event rows do not contain customer or manager names, emails, phone numbers, postal codes, job answers, notes, request contents, shop or status tokens, full referrers or query strings, device details, or browser fingerprints. RigCue also derives milestones already created by normal use, such as manager claim, test verification, activation, evaluation completion, non-test submission count, and request-status progression. There are no advertising trackers or cross-site profiles. A separate, short-lived hashed network identifier is used only for abuse prevention, not pilot analytics.
Email delivery
The private owner test remains inbox-only until RigCue's verified sender is configured. External pilot workspaces are not opened in that state. When email delivery is connected, RigCue sends a one-time verification link to the shop's exact approved work address, sends recovery links only to that verified address, and sends a clearly labeled TEST alert containing a six-digit confirmation code to the request-alert inbox before activation. The code is stored only as a one-way hash and must be entered in the private manager to prove control of that inbox. Active shops receive new-request alerts, while the complete request remains in the private RigCue inbox. Alert emails omit requester contact details, exact postal codes, notes, and job answers. RigCue does not send customer confirmations or status-change emails during this pilot. Work-inbox verification proves control of the invited address; it is not a legal determination of business ownership.
What not to submit
Do not enter payment-card or bank information, government identifiers, driver's-license information, insurance documents, medical details, exact street addresses, or other sensitive information. The pilot does not accept uploads, payments, credit applications, or live location.
Service infrastructure
The pilot is hosted through OpenAI Sites and uses Cloudflare Worker and D1 database infrastructure. When verified delivery is connected, RigCue uses Resend to deliver manager verification, recovery, and shop alert emails and stores the limited delivery metadata described above. Resend receives the destination address and the minimal email content needed to deliver those messages.
Consent and expiration
Each setup stores the time and version of the preview consent and price acknowledgement. The hosted pilot expires after 14 days and does not renew or charge automatically. Raw first-party pilot-event rows are marked with a 30-day expiration, are excluded from reporting after that point, and are physically removed in bounded cleanup when new activity is recorded or an owner or shop manager opens the evidence view. A scheduled deletion job is not active in this private pilot. Pilot configuration and submitted requests, evaluations, and decisions remain in the protected database during the pilot evaluation period. The current cleanup target for those product records is deletion or de-identification within 90 days after the pilot ends; automated deletion of those product records is not yet active.
Questions, correction, or deletion
RigCue is currently a private, invitation-only working pilot. To ask a privacy question or request correction or deletion, reply to the email through which pilot access was provided. A manager who has lost access can use the self-service manager recovery page with the workspace ID and verified work email. A dedicated RigCue privacy address and finalized retention automation will be added before public launch.