Privacy Rights Summary.
Privacy Rights Summary Notice
This Privacy Rights Summary Notice ("Notice") supplements the Ricasso Privacy Policy and applies to United States consumers to the extent rights are available under applicable state privacy laws. Ricasso is operated by ThisIsDisco Ventures, LLC, a Massachusetts limited liability company. Capitalized terms not defined in this Notice have the meanings given in the Privacy Policy or Terms of Service, including "Platform," "Service," "User," "Account," "Collection," and "User Content."
Ricasso may not meet the statutory thresholds for every state privacy law. However, Ricasso intends to provide a practical privacy request process for United States Users. This Notice is intended to summarize categories of personal information, purposes of use, disclosures, retention, sensitive information practices, and consumer rights. Rights may vary by state and may be subject to verification, exceptions, and limitations.
Personal Information Categories
| Category | Examples Ricasso May Collect | Primary Purposes |
|---|---|---|
| Identifiers | Email address, display name, Firebase UID, IP address, user-agent string, account identifiers, app-store entitlement identifiers. | Account creation, authentication, security, support, subscriptions, deletion, legal compliance. |
| Customer Records / Account Data | Account settings, support communications, privacy requests, deletion requests, legal notices. | Providing and supporting the Service, responding to requests, maintaining records. |
| Commercial Information | Subscription tier, entitlement status, obfuscated receipt data, merchandise order information on Shopify, purchase history through app stores or merchandise store. | Providing paid features, processing entitlements, refunds, tax/accounting records, merchandise fulfillment. |
| Internet or Electronic Network Activity | Request metadata, app interactions necessary for operation, server logs, Cloud Function logs, authentication events, status codes. | Security, debugging, performance, fraud prevention, rate limiting, service operation. |
| User Content | Vault records, photos, proof-of-purchase images, notes, collection data, seller/buyer handles, storage notes, event ledger entries. | Providing private collection management, exports, account deletion, support, future user-directed features. |
| Sensitive Personal Information | Serial numbers, purchase price, sale price, storage location notes, proof-of-purchase images, lost/stolen status, buyer/seller handles where sensitive. | Providing the Service to the User; not used for advertising, sale, sharing, AI training, or secondary market research at launch. |
| Geolocation | Ricasso does not request GPS or perform IP-geolocation lookup at launch. Approximate location could be inferred by infrastructure providers from IP address. | Security and network operations by infrastructure providers. |
| Audio, Electronic, Visual, or Similar Information | Photos and images uploaded by the User. | Vault documentation and user-directed collection management. |
| Inferences | Ricasso does not intentionally generate advertising or profiling inferences at launch. Some feature-level preferences may be reflected in user-selected records or tier settings. | Providing user-selected functionality and service operation. |
Sources of Personal Information
We collect information from: (a) you directly; (b) your device, browser, or app interactions; (c) Firebase, Google Cloud, Apple, Google Play, Shopify, Stripe infrastructure, fulfillment providers, and other service providers; (d) eBay and UPC providers when you request feature-directed data; and (e) communications you send to Ricasso.
Business or Commercial Purposes
- creating, authenticating, maintaining, and deleting Accounts;
- providing collection management, vault storage, photos, proof-of-purchase storage, exports, and event ledger functionality;
- processing marketplace comparable requests and UPC lookups;
- validating subscriptions and paid entitlements through Apple and Google;
- operating a separate Shopify merchandise storefront;
- providing customer support, privacy responses, deletion responses, accessibility assistance, and legal notices;
- detecting and preventing fraud, abuse, unauthorized access, and security incidents;
- maintaining logs, backups, tax/accounting records, and legal records;
- enforcing Terms and protecting Ricasso, Users, third parties, and the public;
- developing, testing, and improving the Platform without selling, sharing, or aggregating user collection data for advertising, analytics, market research, AI training, or third-party use at launch.
Disclosures of Personal Information
Ricasso may disclose information to service providers, processors, app stores, merchandise vendors, feature-directed API providers, professional advisors, legal authorities, or business-transfer recipients as described in the Privacy Policy. At launch, Ricasso does not sell personal information and does not share personal information for cross-context behavioral advertising.
Sensitive Personal Information
Ricasso processes sensitive vault information solely as necessary to provide the Service, maintain security, respond to User requests, comply with law, enforce Terms, and protect rights. Ricasso does not use sensitive vault information for targeted advertising, sale, sharing, AI training, third-party market research, or unrelated secondary purposes at launch.
Your Privacy Rights
Depending on your state and applicable law, you may have some or all of the following rights:
- right to know or access the categories and specific pieces of personal information collected about you;
- right to obtain a copy or portable copy of certain personal information;
- right to correct inaccurate personal information;
- right to delete personal information, subject to exceptions;
- right to opt out of sale, sharing, targeted advertising, or certain profiling;
- right to limit certain uses of sensitive personal information where applicable;
- right to appeal certain denied privacy requests where applicable;
- right not to be discriminated against for exercising privacy rights.
How to Submit a Request
You may submit a privacy request by emailing privacy@ricasso.app. Please include your email address associated with your Account and describe the request you wish to make. We may request information necessary to verify your identity and process the request. We will not use verification information for unrelated purposes.
Authorized Agents
Where required by applicable law, you may use an authorized agent to submit a request. We may require proof that you authorized the agent to act on your behalf and may ask you to verify your identity directly with us unless prohibited by law.
Response Timing and Appeals
Ricasso aims to respond to verified privacy requests within thirty (30) days where practicable and within the time required by applicable law. If we need more time, we may notify you as permitted by law. If we deny a request in whole or in part, we will explain the basis for denial where required and provide appeal rights where applicable.
Retention Summary
Ricasso retains information for as long as reasonably necessary to provide the Service, maintain security, respond to requests, comply with law, process subscriptions and refunds, maintain tax/accounting records, resolve disputes, enforce agreements, and protect rights. Active production vault data is deleted upon Account deletion, subject to logs, backups, subscription records, support emails, legal records, and other permitted retention described in the Privacy Policy.
No Sale, No Sharing, No Targeted Advertising
At launch, Ricasso does not sell personal information, does not share personal information for cross-context behavioral advertising, does not use targeted advertising, and does not engage in automated profiling that produces legal or similarly significant effects. There is no sale, sharing, targeted advertising, or covered profiling from which you need to opt out at launch.
Financial Incentives
Ricasso may offer promotions, discounts, trials, founding-lifetime entitlements, press accounts, or other feature access. These offerings are not provided in exchange for the sale or sharing of personal information at launch. Any material financial incentive program subject to state privacy law will be described in a separate notice if implemented.
Changes to This Notice
We may update this Notice to reflect changes in law, data practices, features, vendors, or Platform functionality.
State-Specific Notes
This Notice is intended to be broad enough to support a uniform United States privacy request process. Some state laws apply only if a business meets certain revenue, volume, or data-use thresholds. Ricasso currently expects to remain below many such thresholds during the first year, but voluntarily provides a practical request process to United States Users. Rights may vary based on your state and applicable law.
Categories of Recipients
| Recipient Category | Purpose |
|---|---|
| Infrastructure and hosting providers | Authentication, hosting, storage, database, functions, logs, security, and operations. |
| App stores and billing platforms | App distribution, subscriptions, in-app purchases, entitlements, refunds, and store compliance. |
| Marketplace and UPC API providers | User-directed comparable-data and UPC lookup features. |
| Merchandise and fulfillment providers | Separate Shopify merchandise checkout, payment processing, order fulfillment, returns, and customer service. |
| Professional advisors and legal authorities | Legal compliance, dispute resolution, tax, accounting, DMCA, trademark complaints, law enforcement, and regulatory matters. |
| Business-transfer parties | Potential financing, acquisition, merger, restructuring, bankruptcy, or sale of assets. |
Right to Correct
You can correct many Account and vault fields directly in the app. For information that cannot be corrected directly, you may contact privacy@ricasso.app. We may deny correction requests if we cannot verify the request, if the information is already accurate, if the request is technically infeasible, or if an exception applies.
Right to Portability
CSV export is available at launch for certain vault fields. CSV export may not include photos, proof-of-purchase images, cached marketplace comparable data, UPC cache records, logs, app-store records, support emails, or other categories. Additional export formats, including PDF or insurance-ready reports, are not live at launch unless later made available in the Platform.
Limit Use of Sensitive Information
Ricasso uses sensitive vault information to provide and secure the Service, not for advertising, profiling, AI training, third-party market research, or sale/share at launch. If applicable law provides a right to limit sensitive information, Ricasso already limits use of sensitive vault information to Service-related and legally permitted purposes at launch.
Appeals and Complaints
Where an appeal right applies, you may appeal by emailing privacy@ricasso.app with the subject line “Privacy Appeal.” Depending on your state, you may also have the right to contact your state attorney general or other privacy regulator if you believe your privacy rights have been violated.
Contact Us
If you have general questions about this Notice or wish to exercise privacy rights, please contact:
ThisIsDisco Ventures, LLC33 Geraldine DriveNorwood, Massachusetts 02062Email: hello@ricasso.app
Last Updated: ____________, 2026
Related documents
This document is part of Ricasso's legal framework. See also:
Terms of Service Privacy Policy Privacy Rights Summary Account Deletion Do Not Sell or Share Targeted Ad Preferences Cookie & Tracking Notice Accessibility Statement