Quick answer: Rivocard protects user data through five interconnected layers: end-to-end encryption (all data encrypted in transit using TLS and at rest in storage), PCI DSS-compliant payment infrastructure, user funds held in segregated top-tier banking accounts, two-factor authentication via hardware keys, FaceID, and TouchID, and compliance with applicable data protection regulations including GDPR for EU users. Your card details are never stored in plain text. Your personal information cannot be read even by unauthorized access to storage systems. Your wallet balance sits in accounts separate from company funds. This guide explains exactly what data Rivocard collects, how it is protected, and what rights you have over it.

What Data Rivocard Collects

Understanding data protection starts with knowing what data is actually collected. On Rivocard, data collection falls into four categories:

Account data When you sign up, Rivocard collects your email address and a hashed version of your password. Your password is never stored in plain text — it is hashed using a one-way cryptographic function before storage, meaning the original password cannot be recovered from the stored value.

Identity verification data (KYC) If you complete Full KYC or Enhanced KYC, Rivocard collects:

  • Government-issued photo ID (passport, national ID, or driver’s license)
  • A real-time selfie/liveness image matched against the ID
  • Potentially proof of address and source of funds at Enhanced KYC

This data is collected to comply with AML/KYC regulatory requirements. It is processed by identity verification infrastructure and retained as required by applicable financial regulations — typically a minimum of 5 years after account closure.

Transaction data Every deposit, card funding, and purchase generates a transaction record including: amount, timestamp, asset (for crypto deposits), merchant category (for purchases), and card used. This data is required for account functionality, regulatory reporting, and fraud detection.

Device and session data Standard security data collected when you log in: IP address, device type, operating system, and session duration. Used for fraud detection, security monitoring, and account protection (detecting unusual login locations or devices).

How Rivocard Protects Data in Transit

How TLS encryption protects data in transit between your device and Rivocard

Every communication between your device and Rivocard’s servers uses TLS (Transport Layer Security) — the cryptographic protocol that secures HTTPS connections. TLS ensures that:

  • All data you send to Rivocard (login credentials, deposit requests, card funding actions) is encrypted before leaving your device
  • All data Rivocard sends back (card details, wallet balances, transaction history) is encrypted in transit
  • An attacker intercepting network traffic between your device and Rivocard’s servers would receive only encrypted ciphertext — unreadable without the decryption keys

TLS is the same technology that protects online banking, secure email, and any website showing the padlock icon in the browser address bar. On Rivocard, TLS applies to every request — not just login, but all API calls and dashboard interactions.

What this protects against: Network interception attacks (man-in-the-middle attacks), packet sniffing on public Wi-Fi, and unauthorized surveillance of data in transit.

What this does not protect: Your device itself. If malware is installed on your phone or computer, it can capture data before it is encrypted for transmission. Keep your operating system and apps updated to minimize device-level risk.

How Rivocard Protects Data at Rest

Data at rest — stored in databases, on servers, in backups — is encrypted using industry-standard encryption algorithms. This means:

  • Your personal information (email, name, identity documents) is stored in encrypted form
  • Transaction history is stored encrypted
  • Card data (card numbers, CVVs) is stored according to PCI DSS requirements — which prohibit storing CVVs at all post-authorization, and require encrypted storage for card numbers with strict access controls

The practical meaning: If an attacker gained unauthorized access to Rivocard’s database systems, they would encounter encrypted data. Decrypting it without the encryption keys is computationally infeasible with current technology.

CVVs specifically are never stored after a transaction is authorized — they are verified and discarded. This is a hard requirement of PCI DSS and applies to every PCI-compliant card platform.

PCI DSS: The Payment Card Industry Standard

Rivocard operates under PCI DSS (Payment Card Industry Data Security Standard) compliance. PCI DSS is the global security standard mandated by Visa and Mastercard for any entity that processes, stores, or transmits card data.

What PCI DSS requires for data protection specifically:

  • Cardholder data must be protected wherever it is stored
  • CVV values must not be stored after authorization
  • Card numbers (PANs) must be masked when displayed — showing only the last four digits in most contexts
  • Encryption keys must be managed securely with restricted access
  • All access to cardholder data must be logged and monitored
  • Systems storing cardholder data must be regularly tested for vulnerabilities

PCI DSS compliance is validated by independent Qualified Security Assessors (QSAs) — not self-declared. The standard has 12 primary requirements and hundreds of specific technical controls. Operating under it is a rigorous, continuously audited commitment.

Fund Protection: Segregated Banking Accounts

Beyond digital data security, Rivocard protects user financial assets through segregated banking accounts. User funds — the fiat balance resulting from your crypto deposits — are held in top-tier banking accounts that are:

  • Separate from Rivocard’s operational funds: Your balance cannot be used by Rivocard for company operations, investment, or expenses
  • Protected from company insolvency: If Rivocard faced financial difficulties, user funds in segregated accounts would not be part of the company’s assets
  • Held at reputable banking partners: Top-tier banking infrastructure, not unregulated custodians

This structure is a standard requirement for regulated payment institutions. It is the financial-asset equivalent of encryption for data — the primary protection against the most serious risk category (loss of user funds due to platform failure).

Authentication: Protecting Your Account Access

Rivocard two-factor authentication options — hardware key FaceID and TouchID

The security of your account is only as strong as how access to it is controlled. Rivocard supports multiple second-factor authentication methods:

Hardware security keys (FIDO2/WebAuthn) Physical USB or NFC keys (like YubiKey) that must be present to authenticate. This is the most phishing-resistant 2FA method available. Even if an attacker has your username and password, they cannot log in without the physical key in hand.

FaceID (biometric facial recognition) Available on iOS and compatible Android devices. The biometric template is stored in the device’s secure enclave — a hardware-isolated environment that no app, including Rivocard, can access. The biometric data never leaves your device or gets transmitted to Rivocard’s servers.

TouchID (biometric fingerprint) Same secure enclave model as FaceID. Your fingerprint template stays on your device and is never accessible to external systems.

Why 2FA matters for data protection: If your Rivocard password were exposed in a data breach at another service (credential stuffing), 2FA prevents that compromised password from being used to access your Rivocard account. Without 2FA, a leaked password is sufficient for account takeover. With 2FA, the attacker also needs your physical key or biometric — which they do not have.

Your Data Rights as a Rivocard User

Under applicable data protection regulations — GDPR for EU/EEA users, and equivalent frameworks in other jurisdictions — you have rights over your personal data:

Right to access: You can request a copy of the personal data Rivocard holds about you.

Right to correction: You can request correction of inaccurate personal data.

Right to deletion: You can request deletion of your personal data, subject to regulatory retention requirements. Note: financial transaction data and KYC records must be retained for regulatory compliance periods (typically 5+ years after account closure) — these cannot be deleted on request during the mandatory retention period.

Right to portability: You can request your data in a portable format.

Right to object: You can object to certain processing activities, particularly for marketing purposes.

To exercise these rights, use the contact methods provided in Rivocard’s privacy policy. The full privacy policy at rivocard.com contains the complete data handling disclosure, including retention periods, third-party sharing policies, and contact information for data-related requests.

What Rivocard Does Not Do With Your Data

Several data practices that some platforms engage in are worth explicitly addressing:

Rivocard does not sell your personal data. Your email address, identity documents, and transaction history are not sold to data brokers, advertisers, or third parties for commercial purposes.

Rivocard does not use your data for advertising targeting. Your transaction data is not used to build advertising profiles or shared with ad networks.

Your card details are not accessible in plain text. CVVs are discarded post-authorization. Card numbers are stored encrypted with strict access controls. Even Rivocard staff cannot retrieve your full card number from the database in plain text.

Biometric data stays on your device. When you use FaceID or TouchID to authenticate, the biometric processing happens entirely on your device’s secure hardware. Biometric templates are never transmitted to Rivocard’s servers.

What You Can Do to Protect Your Own Data

Six steps to protect your Rivocard account and data

Platform-level security is one half of the equation. User-level security is the other:

Use a unique, strong password. Do not reuse your Rivocard password at any other service. A password manager (1Password, Bitwarden, or your device’s built-in manager) makes this practical. A strong password is 16+ characters, random, and unique to Rivocard.

Enable 2FA immediately. Do this before you make any deposits. Hardware key if you have one; FaceID or TouchID as the next best option. The 30 seconds this takes is the single highest-impact security action available.

Keep your device updated. Operating system and app updates patch security vulnerabilities. An outdated device is the most common vector for mobile account compromise.

Be careful on public Wi-Fi. While Rivocard encrypts all communications, using any financial account on unsecured public Wi-Fi carries risks from other network participants. Use a mobile data connection or VPN for sensitive financial actions.

Never share your login credentials. Rivocard support will never ask for your password. No legitimate support interaction requires sharing your password.

Log out of sessions on shared devices. If you access Rivocard from a shared or public device, log out when done. Do not check “remember me” on shared devices.

FAQs

How does Rivocard protect my personal data?

Rivocard encrypts all data in transit using TLS and all stored data at rest using industry-standard encryption. Card data is handled under PCI DSS compliance — CVVs are never stored post-authorization and card numbers are encrypted with strict access controls. User funds are held in segregated top-tier banking accounts separate from company funds.

Is my card number stored securely by Rivocard?

Yes. Card numbers (PANs) are stored encrypted under PCI DSS requirements with restricted access controls. CVV codes are never stored after transaction authorization — this is a hard PCI DSS requirement. Your full card number is never accessible in plain text even to Rivocard staff.

What data does Rivocard collect when I sign up?

At Basic KYC (email only): your email address and hashed password. At Full KYC: additionally, a government-issued photo ID and real-time selfie. Device and session data (IP address, device type) is collected for security monitoring at all tiers.

Can Rivocard see my biometric data (FaceID, TouchID)?

No. Biometric authentication processing happens entirely within your device’s secure enclave — hardware-isolated from all apps. Biometric templates are never transmitted to Rivocard’s servers. Rivocard receives only an authentication confirmation, not the biometric data itself.

What are my data rights as a Rivocard user?

Under GDPR (EU/EEA users) and equivalent frameworks, you have rights to access, correct, delete, and port your personal data. Note: regulatory retention requirements mean financial transaction records and KYC data must be retained for defined periods (typically 5+ years after account closure) and cannot be deleted during mandatory retention periods. Contact Rivocard via the details in their privacy policy to exercise your rights.

Does Rivocard sell my personal data?

No. Personal data including your email address, identity documents, and transaction history is not sold to data brokers, advertisers, or third parties for commercial purposes.

How long does Rivocard retain my data?

Personal data is retained only as long as necessary for service delivery, legal compliance, and security purposes. Identity verification data submitted for KYC is retained for at least 5 years after account closure to comply with financial regulations. Check Rivocard’s current privacy policy for complete retention schedules.

What is PCI DSS and why does it matter for my card data?

PCI DSS (Payment Card Industry Data Security Standard) is the global security standard mandated by Visa and Mastercard for handling card data. It requires encrypted storage of card numbers, prohibition on storing CVVs post-authorization, strict access controls, and regular security testing. Rivocard’s payment infrastructure operates under PCI DSS compliance, validated by independent assessors.

What should I do to protect my Rivocard account?

Use a unique, strong password (16+ characters, not reused). Enable 2FA immediately — hardware key for maximum security, or FaceID/TouchID. Keep your device operating system updated. Log out of sessions on shared devices. Never share your login credentials with anyone.

Is my wallet balance protected if something happens to Rivocard?

Yes. User funds are held in segregated top-tier banking accounts separate from Rivocard’s operational funds. This means your wallet balance is not part of Rivocard’s company assets and is protected from company financial difficulties.

Get Started

Your data is protected by encryption, PCI DSS compliance, and segregated fund accounts from day one. Create your account →