Privacy and data deletion
What RAVE™ stores about the people on your cards, what visitors see, cookies, and how people and customers can delete activity data.
4 min read · Updated Oct 5, 2026
Social proof only works if people trust it, and that includes the people whose activity appears on cards. RAVE™ is built to show as little as possible and to store even less.
What RAVE™ stores about a person
When someone signs up, buys or engages on your site, RAVE™ receives an activity entry from your webhook, the API, the pixel or an import. RAVE™ keeps:
- First name and last initial only. If a source sends a full last name, RAVE™ keeps the first letter and discards the rest before anything is stored. Full last names are never stored.
- A one-way hash of the email, never the email itself. The email is lowercased, trimmed and turned into a SHA-256 hash on arrival. The hash lets RAVE™ remove duplicates, verify imports and honor deletion requests.
- Approximate location: city, region and country, sent by the source or looked up from the IP address when the entry arrives. RAVE™ stores the location, not the IP address.
- The action: for example signup or purchase, plus the offer or content name, the funnel step, the time, and a profile image link if the source sends one.
- A random visitor ID, if the entry came through the pixel.
What visitors see
Cards show at most a first name and last initial, the city and region, what the person did and when, for example "Sarah K. just joined" with "Ultimate Pack!" or "from Austin" below it. You choose the Name format on each campaign's Privacy tab:
| Name format | Example |
|---|---|
| First name + last initial | Sarah K. |
| First name only | Sarah |
| Anonymous | Someone from Austin |
Cards only show activity from the campaign's Lookback window (30 days by default). Emails and full last names never reach the browser.
The pixel and cookies
The RAVE™ pixel sets no cookies. It stores a random visitor ID in the browser's local storage and a few per-visit flags in session storage. It sends RAVE™ the page path, page views, a heartbeat every 30 seconds while the tab is visible (for "viewing now" counts), which cards were shown, hovered or clicked, and whether the visitor later reached your goal.
If you turn on auto form capture for a page, the pixel reads only the email, first name and last name fields when a form on that page is submitted.
The RAVE™ dashboard and website use a sign-in cookie and a first-party cookie that remembers how you found RAVE™. They use no third-party advertising or analytics cookies. The Cookie Notice has the full list, plus suggested text you can add to your own privacy policy.
Deletion requests from visitors
Anyone can delete the activity linked to their email from every website that uses RAVE™, at once, on the public Delete my data page.
Enter the email
The person types their address, for example you@example.com, and asks for a confirmation link.
Check the inbox
RAVE™ emails a one-time link to that address. It works for 24 hours.
Confirm
The link opens a page with a Delete my activity button. Nothing is deleted until it's clicked, so email scanners that open links can't trigger it.
Done
RAVE™ deletes every activity entry matching that email's hash across all RAVE™ customers, plus the page-view, heartbeat and card-interaction records of the visitor IDs linked to them.
This makes sure only the owner of an address can delete its activity. Requests are rate-limited (a few per email address per day). If email sending isn't available, the page asks people to email RAVE™ support instead.
Only entries that included an email can be matched; the site owner can remove others. RAVE™ keeps a record of each request (the email's hash and the times), never the email itself. New activity can be recorded if the person acts again later, and they can repeat the request anytime.
Deleting data through the API
If someone asks you directly, you can delete their entries, and the linked visitor records, from your own workspace with the RAVE™ API. Create a key under Settings → API keys in the workspace (your plan must include the REST API), then send:
curl -X POST https://rave.cxformula.com/api/v1/data-deletion \
-H "Authorization: Bearer rave_live_YOUR_KEY" \
-H "Content-Type: application/json" \
-d '{"email":"you@example.com"}'
The response reports how many activity entries (deleted) and visitor records (visitor_records) were removed. It only affects the workspace the key belongs to.
Legal pages
- Privacy Policy: what RAVE™ collects, retention and your rights.
- Cookie Notice: cookies and browser storage.
- Data Processing Addendum: RAVE™'s commitments as your processor, including sub-processors.
- Terms.
Closing your account
To close your RAVE™ account, cancel your subscription and contact support at the address on the Privacy Policy asking for deletion. After an account is closed, RAVE™ deletes or de-identifies its data within 90 days of the request, except billing, tax and audit records that must be kept, and backups, which roll off on the database provider's schedule.
Related articles
- RAVE™ Alert, Count and Live cardsWhat each RAVE™ card shows, real examples, and how to pick the right card for each page of your funnel.
- How webhooks workEach campaign has its own webhook URL. Point your tools at it, label each signal with ?event=, ?product= and ?step=, and test it.
- How RAVE™ is organized: Platform, Account, WorkspaceRAVE™ has three levels. Your account holds billing and your team; each workspace holds sites, campaigns and data for one brand or client.
Can't find it?
Send us a question, a bug or an idea. It goes straight to the RAVE™ team, and you can follow its status.