Legal
Privacy Policy
Last updated:
This policy explains how Headwaters collects, uses, retains, and shares personal data in connection with our warm-network reactivation service for independent consultants and fractional advisors. It is written in plain English; the formal version is at the bottom of this page.
1. Who we are
The service is operated under the brand Headwatersand delivered on shared infrastructure hosted on Polsia (Render-backed) with a Neon Postgres data store. References to “we”, “us”, or “our” in this policy mean the operator of Headwaters.
2. Scope of this policy
This policy covers data we process when you sign up for Headwaters, when you import your network and connect third-party accounts, while drafts and analytics are generated on your behalf, and when billing is processed. It does not cover the third-party services we link to (LinkedIn, Stripe); each of those has its own privacy policy that applies to data you give them directly.
3. What data we collect
We collect a deliberately small set of data, only what the service needs:
- Account data: email address, display name, and sign-in identifier stored on the authentication
Userrecord. - Authentication data: hashed password (bcrypt) and session cookies managed by better-auth — we never store your password in clear text.
- LinkedIn OAuth tokens:
accessToken,refreshToken,idToken, and grantedscopestored on the linkedAccountrow, used only to call the LinkedIn endpoints you authorized. - LinkedIn profile:read on demand from OAuth-scoped endpoints you consented to in LinkedIn's authorization dialog — used to learn your writing style.
- Network contacts (
Contact): name, current company, current role, LinkedIn URL, and email when known — sourced from your CRM/LinkedIn import and enriched with public buying signals. - Buying signals (
Signal): event type (job change, funding, hiring), source URL, and a dedup hash. We do not store raw scraped pages. - Drafts (
Draft): AI-generated outreach messages awaiting your approval, including the contact they relate to and the signal or trigger that prompted them. - Tone profile (
Consultant.toneProfile,writingSamples,UserVoiceProfile): the writing style data we extract from samples you provide so drafts sound like you. - Billing state: subscription status, plan, and trial end surfaced from Stripe webhook events onto
Consultant.isSubscribed,plan, andtrialEnd. Card numbers are never sent to or stored by us — they live entirely with Stripe. - Product analytics: page paths and a per-visitor UUID stored in
localStorageby the Polsia analytics pixel, plus the deploy-injected company slug. No advertising identifiers.
4. Why we collect it (purposes and legal bases)
We use the data above to:
- Provide the warm-network reactivation service you signed up for (contract).
- Sign you in, keep you signed in, and protect your account from unauthorized access (contract; legitimate interest in security).
- Read your LinkedIn profile so we can match your writing style, and process the connections export CSV that you choose to upload to seed your prospect list (consent, given in LinkedIn's authorization dialog or by your upload; you may revoke at any time).
- Analyse your writing tone and generate drafts that match it, and route approved drafts to your contacts (contract).
- Process billing via Stripe and reply to support requests (contract; legal obligation for tax/invoicing records).
- Measure aggregate product usage so we can improve Headwaters (legitimate interest; no advertising profiling).
5. How long we keep your data
- Account and consultant profile: for as long as your account is active. Subscription state is preserved across cancellations to handle reactivations.
- Drafts, contacts, and signals: until you delete them or close your account, at which point they are removed from active storage.
- LinkedIn OAuth tokens: until you revoke the connection from LinkedIn or delete your account. We do not extend the token lifetime beyond what LinkedIn grants.
- Authentication sessions: until you sign out or the session cookie expires (better-auth default).
- Analytics events: rolling window as documented by the Polsia analytics product; only the slug and UUID are sent — no PII beyond what the page itself renders.
- Billing records: retained for the period required by applicable tax and accounting law (typically 7 years).
You can request account deletion at any time by emailing sales@revivehq.io.
6. Who we share data with (sub-processors)
We do not sell personal data. We share the minimum needed with these sub-processors:
- Stripe — subscription and payment processing. Card numbers are received and stored only by Stripe; Headwaters never sees them.
- LinkedIn— OAuth sign-in and tone-of-voice profile read. Scope is limited to what you authorize in LinkedIn's dialog and you can revoke at any time. We do not ask LinkedIn for your connections; you upload that export yourself.
- Hosting platform (Render) and Neon Postgres — application hosting and primary data store on shared infrastructure.
- Polsia AI proxy — OpenAI-compatible LLM used for tone analysis and draft generation. Only the fields needed for the task are sent per call. Polsia email proxy — transactional email delivery (welcome, trial-expiry, approval-receipt).
- Analytics — the Polsia analytics pixel records page paths plus a per-visitor UUID; no third-party advertising networks are used.
7. Your rights (GDPR / UK GDPR / EU users)
If you are in the EEA, UK, or a jurisdiction with similar protections, you have the right to:
- Access the personal data we hold about you and receive a copy.
- Rectification of inaccurate or incomplete data.
- Erasure(“right to be forgotten”) of your data, subject to our legal record-keeping obligations.
- Restriction of processing while a dispute is resolved.
- Data portability in a structured, machine-readable format (JSON/CSV on request).
- Objection to processing based on legitimate interest, and the right to opt out of any nurture email at any time.
- Withdraw consent at any time where processing is based on consent (e.g. LinkedIn import).
- Lodge a complaint with your supervisory authority (e.g. your national data protection authority).
Important: this page is a product-grade draft and not legal advice. Before opening paid EU acquisition in earnest, have a lawyer review or replace this policy. An approved URL in the LinkedIn Developer Portal is not a substitute for jurisdictional compliance review.
8. Cookies and similar technologies
We use a very short cookie list:
- better-auth session cookie — keeps you signed in. Strictly necessary; disabling it signs you out.
next-themestheme preference cookie — remembers your light/dark choice. Functional, not advertising.- Polsia analytics — stores a per-visitor UUID in
localStorage; no cross-site tracking, no advertising IDs.
We do not use third-party advertising cookies.
9. International transfers
Data is hosted on shared infrastructure that may be physically located in the United States or the European Union. Where data is transferred from your country to another, we rely on the transfer safeguards required by GDPR (standard contractual clauses, equivalent adequacy mechanisms, or intra-group agreements where applicable). A copy of the relevant safeguards is available on request to sales@revivehq.io.
10. Children
Headwaters is a B2B service meant for adult professionals. It is not directed at children under 16, and we do not knowingly collect personal data from anyone in that age group. If you believe a child has signed up, contact sales@revivehq.io and we will delete the account.
11. Changes to this policy
When we make material changes we will update the “Last updated” date at the top of this page and, where the change is significant, notify active subscribers by email. Continued use of Headwaters after a change is posted signals acceptance of the updated policy; if you disagree, you can stop using the service and request account deletion.
12. Contact us
For any privacy question — access, deletion, portability, or otherwise — write to us at sales@revivehq.io. We aim to acknowledge within 5 business days and to resolve verifiable requests within 30 calendar days, in line with GDPR timelines.