What Rialto records.
This policy covers rialtodata.com, the Rialto dashboard, shared project links, the Rialto site tag and the connected services used by a project.
Effective 31 August 2026
Anonymous by default
The Rialto tag records pageviews, visible click labels, scroll depth, active reading time, referring hostnames, coarse location and events a site owner configures. A random session value stays in tab memory and disappears when the tab closes. A daily visitor hash is regenerated each day.
Identity only where access needs it
Rialto records the email address used for an account or verified project invitation. For verified viewers, it also records project sessions, opened tabs, active time and control clicks so an account owner can understand how a shared dashboard is being used. It does not record typed text or form contents.
Who operates Rialto
Rialto is operated by Fionn Design Limited, trading as Legency Media, an Irish company registered under company number 722903. Our principal place of business is Kilgarve North, Newtown, Abbeyknockmoy, Tuam, Co. Galway, H54 XV58, Ireland. Privacy questions and rights requests can be sent to fionn@legencymedia.com.
Information Rialto handles
Customer website events
The site tag can record page URLs and titles, visible labels on clicked elements, scroll milestones, active seconds, campaign parameters, referring hostnames, coarse country and city information supplied by Cloudflare, and custom event names configured by the customer. Referring URLs are reduced to their hostname before storage.
Rialto does not store visitor IP addresses, keystrokes, form contents or session replay. An IP address and browser information may be used transiently to make a salted daily hash. The address itself is not written to the analytics database. The tag does not track a visitor across unrelated websites.
Consent-based visitor memory
If a site owner enables identity measurement and the visitor provides the required consent, Rialto can set one first-party identifier to recognise the same browser across days. This supports returning-visitor and multi-day journey reporting. Declining it does not remove the anonymous visit from the site's aggregate measurement. The customer is responsible for configuring consent and notices appropriate to its site, audience and jurisdiction.
Accounts, invitations and client activity
We process account email addresses, authentication records, project roles, invitation status and security logs needed to operate the service. A verified project viewer's sessions, tab opens, active time and control clicks can be shown to the project owner. Anonymous share links are not shown as named viewers. Login and invitation links expire after 24 hours. An active dashboard session can remain signed in for up to 30 days.
Project and connected service data
A project can contain a website domain, public page content, content scores, buyer questions, competitors, reports, tasks and settings. If Google Search Console or Google Analytics 4 is connected, Rialto reads the selected property through a Google service account. The requested roles are Search Console Full user and GA4 Viewer. Rialto does not need permission to edit either property. Access can be removed in Google at any time.
AI visibility and research providers
When an AI visibility, content or research feature is used, Rialto may send the relevant public page content, question, prompt and project instructions to the selected provider. Providers currently used by product features can include OpenAI, Anthropic, Google, Perplexity and DataForSEO. Returned answers, source links and analysis may be stored in the project. We do not send unrelated client projects with that request.
How we use information
We use information to provide and secure the service, calculate analytics, run audits and AI visibility checks, create requested reports, support users, improve product reliability, prevent abuse and meet legal obligations. We do not sell personal information or use customer project data for third-party advertising.
Processors and international transfers
Rialto uses Cloudflare for application hosting, storage and network security, Google for connected Search Console and Analytics properties, and Resend for transactional email. OpenAI, Anthropic, Google, Perplexity and DataForSEO process only the inputs needed when their product feature is used. Site and competitor logos are looked up through DuckDuckGo's and Google's favicon services, which receive the domain names involved. Some providers may process information outside the European Economic Area under their contractual and legal transfer safeguards.
Retention and deletion
Raw site events are pruned after 400 days. Project configuration, reports, content findings and connected data are retained while the project is active and for as long as reasonably needed to provide the service, resolve disputes and meet legal obligations. Customers can remove Google access at its source and can ask us to export or delete project data. Deletion may not immediately remove information from limited security logs or backups.
Security and access
Rialto uses secure, HTTP-only session cookies for dashboard authentication, encrypted provider credentials and role-based project access. Anonymous share URLs should be treated as confidential because anyone who receives the link can open the read-only view until it is revoked. Verified invitations are tied to the invited email address.
Your rights
Depending on applicable law, you may have rights to access, correct, delete, restrict or object to processing, receive a portable copy, and complain to a supervisory authority. Contact us at fionn@legencymedia.com. We may need to verify your identity and the project concerned before completing a request.
This marketing website
Rialtodata.com uses the Rialto tag described above. It also uses Google Analytics under consent mode. Analytics storage starts denied and is enabled only after the visitor allows it through the consent control. The site is hosted on Cloudflare Pages and is connected to Google Search Console, which reports Google's own search data.
Pages on this website also load fonts from Fontshare and Google Fonts and a script bundle from jsDelivr. Those services receive standard request data such as the visitor's IP address when the page loads. We are moving these assets to our own domain.
Changes to this policy
We will update this page when the product, providers or legal requirements materially change. The effective date at the top identifies the current version.
Questions
Does Rialto need a cookie banner?
The anonymous tag stores no persistent identifier on the visitor's device. If a customer enables identity measurement across days, that identifier should be activated only with the consent or other lawful basis required for the site and jurisdiction. The site owner remains responsible for its notice and consent setup.
Do you store IP addresses?
No. The address is used to build a daily hash that identifies nobody and is never written down, and the hash regenerates every day so it cannot recognise a person tomorrow.
Is data sent outside the EU?
Potentially. Rialto runs on Cloudflare and selected features can use Google, OpenAI, Anthropic, Perplexity, Resend and DataForSEO. Some providers may process the information needed for that feature outside the European Economic Area under their contractual and legal transfer safeguards.
How do I remove connected Google access?
Remove the Rialto service account from the selected Search Console or GA4 property. The project owner can then clear or replace the connection in Rialto.
How long is data kept?
Raw site events are pruned after 400 days. Project settings, reports and findings are kept while the project is active and for as long as reasonably needed to provide the service, resolve disputes and meet legal obligations.