Scope and our role
This Privacy Policy applies to Rainbow Secure websites, business communications, and cloud identity and access security services operated by GeoACL LLC, doing business as Rainbow Secure.
For website visitors, prospects, and direct customers, Rainbow Secure generally determines why and how personal information is processed. When we process identity, authentication, or activity data on behalf of an organizational customer, that customer generally controls the data and Rainbow Secure acts as its service provider or processor. Requests about customer-controlled accounts should first be directed to that organization.
Information we collect
Contact and commercial information
- Name, business email, phone number, job title, company, and communications.
- Subscription, transaction, and billing information. Payment card data is handled by payment providers and is not intended to be stored by Rainbow Secure.
Account and identity information
- User identifiers, account roles, organization, groups, application assignments, and authentication preferences.
- IP address, browser, device identifiers, approximate location derived from IP, and sign-in context.
- MFA, SSO, risk, session, and policy-event metadata needed to operate security controls.
Usage and support information
- Successful and failed sign-in events, administrative activity, timestamps, security alerts, and product interaction data.
- Support requests, diagnostic information, feedback, and correspondence.
Sources of information
We receive information directly from you; from your employer or organization; through your use of our websites and services; from connected identity providers, applications, directories, and devices that your organization configures; and from service providers that support hosting, communications, billing, analytics, and security.
How we use information
- Provide, administer, secure, support, and improve Rainbow Secure services.
- Authenticate users, apply access policies, detect suspicious activity, and investigate incidents.
- Create activity, audit, and administrative records requested by customers.
- Process subscriptions, respond to inquiries, and send service communications and security alerts.
- Analyze reliability and performance, prevent abuse, and maintain business operations.
- Comply with law, enforce agreements, and protect rights, safety, and service integrity.
We may send product or marketing communications where permitted. You may unsubscribe from marketing messages, but you may continue to receive transactional, account, or security notices.
Legal bases for processing
Where a legal basis is required, we rely on performance of a contract, compliance with legal obligations, legitimate interests such as securing and improving services, and consent where appropriate. The available basis depends on the context and jurisdiction. You may withdraw consent at any time without affecting earlier lawful processing.
How we disclose information
Rainbow Secure does not sell personal information for money. We may disclose information:
- to hosting, communications, analytics, billing, support, and security providers operating under appropriate obligations;
- to your organization and its authorized administrators;
- when required by law or reasonably necessary to protect rights, safety, or service integrity;
- in connection with a merger, financing, acquisition, reorganization, or sale, subject to appropriate safeguards; or
- with your direction or consent.
Some privacy laws define “sale” or “sharing” broadly. Where an applicable analytics or advertising disclosure is treated as a sale, sharing, or targeted advertising, we will provide the legally required choice.
Data retention
We retain personal information only as long as reasonably necessary for the purposes described in this policy, including to provide services, meet contractual retention settings, maintain security and audit records, comply with law, resolve disputes, and enforce agreements.
Retention varies by data type, customer plan and configuration, legal requirements, and the sensitivity and purpose of the information. When information is no longer needed, we delete, de-identify, or securely dispose of it, subject to backup and legal-hold cycles.
Your privacy rights
Depending on your location and subject to legal exceptions, you may have the right to:
- know, access, or confirm the personal information processed about you;
- correct inaccurate information;
- delete information;
- receive a portable copy of certain information;
- object to or restrict certain processing;
- opt out of sale, sharing, targeted advertising, or qualifying profiling;
- withdraw consent; and
- appeal a denied request where applicable.
Submit a request to privacy@rainbowsecure.com. We may verify your identity and authority before responding. Authorized agents may submit requests where permitted. We will not discriminate against you for exercising applicable rights.
If your information is controlled by a Rainbow Secure customer, direct the request to that customer; we will assist it as required by contract and law.
Data security
We use administrative, technical, and organizational safeguards designed for the nature of the information and services, including encryption in transit and at rest where appropriate, access controls, multi-factor authentication, logging, monitoring, and security testing.
No method of transmission or storage is completely secure. Customers and users should protect credentials, enable appropriate MFA, promptly apply updates, and report suspicious activity.
International data transfers
Rainbow Secure is based in the United States. Information may be processed in the United States and other countries where we or our service providers operate. Where required, we use recognized transfer mechanisms and contractual or organizational safeguards intended to protect information across borders.
Children’s privacy
Our websites and services are not directed to children under 13, and we do not knowingly collect personal information directly from them without appropriate authorization. If you believe a child provided information improperly, contact us so we can review and delete it where required.
When an educational organization provisions an account for a student, the organization is responsible for obtaining required authorization and providing notices, and the applicable customer agreement governs our processing.
Related Rainbow Secure domains
This policy applies to Rainbow Secure and GeoACL LLC properties that link to it, which may include:
- rainbowsecure.com
- rSecureOffice.com
- rSecureNote.com
- rainbowpassword.com
- rEncryptFile.com
Third-party websites and services have their own privacy practices. Review their policies before providing information.
Changes to this policy
We may update this policy as our services, practices, or legal obligations evolve. We will post the revised policy and update the “Last updated” date. We will provide additional notice for material changes when required or appropriate.
Contact us
GeoACL LLC d/b/a Rainbow SecureOld Bridge, New Jersey 08857, USA
Privacy and data rights: privacy@rainbowsecure.com
Support: hello@rainbowsecure.com
Website: www.rainbowsecure.com
You may also have the right to complain to the privacy or data protection authority where you live.
Request a demo →