Last updated: June 17, 2026
This Privacy Policy is provided by Dravio Consulting LLC, a Minnesota limited liability company ("Dravio," "we," "our," or "us"). It explains how we handle information across two surfaces:
The website — our marketing site at dravio.co, including the contact form. This describes data we handle today.
The platform — the Dravio business application at dravio.pro, available to business clients. For most personal information that flows through the platform — including a client's own customers and any program participants — the business client is the controller of that data and Dravio acts as their service provider (processor), handling it on the client's behalf and under our agreement with them. Some platform sections below describe practices that apply when you use the platform as a client.
When you contact us (website): the contact form collects your name, email address, your message, and a phone number if you choose to provide one. Our email provider and an anti-spam check process this submission so we can respond.
Automatically (website): our hosting provider logs technical information such as your IP address, browser type, and the pages you request, for security and reliability. We use Google reCAPTCHA on the contact form to prevent abuse; reCAPTCHA collects device and usage signals and is governed by Google's privacy policy. We do not use advertising or cross-site tracking cookies.
When you use the platform as a client: account and contact details (name, email), your business profile and brand information, and content you create or that we generate for you. To provide the service you may also enter data about your own customers and program participants (which can include minors' first names, ages, or grade levels). We hold that data on your behalf as your service provider.
We use information to respond to your inquiries; to provide, operate, secure, and improve the website and platform; to generate content and insights you request; to send service and account notifications; and to meet legal obligations. We process client customers' and participants' personal information only to provide the platform to that client and on their documented instructions.
The platform uses a third-party AI provider (Anthropic) to generate marketing content from the business information you provide. Content sent to the AI provider is processed to return a result to you; under our provider's commercial terms, your data is not used to train their models. We do not sell your data and we do not use one client's data to train AI models for other clients.
We do not sell your personal information, and we do not share it for cross-context behavioral advertising. We share information only with service providers that help us operate, under contracts that limit them to that purpose:
Google Cloud / Firebase (hosting, database, logging, authentication); Twilio SendGrid (email delivery); Google reCAPTCHA (abuse prevention); and Anthropic (AI content generation, platform only). We may also disclose information when required by law or to protect rights and safety. If we ever undergo a business transfer, we will require the successor to honor this policy.
Contact-form and lead information: retained for as long as needed to respond to your inquiry and for related follow-up while there is an active or prospective business relationship; we review it periodically and delete it when it is no longer needed, and you may request deletion at any time. Platform account and business data: kept while your account is active and deleted or anonymized within 90 days of account termination, unless longer retention is required by law. Server and security logs: retained per our cloud provider's standard logging retention; we may keep specific records longer where needed for security or legal reasons.
We aim to protect information with concrete measures rather than vague assurances: data is encrypted in transit (TLS) and encrypted at rest by our cloud provider; credentials and API keys are stored in a dedicated secret-management system and never placed in application code, logs, or message payloads; access follows least-privilege principles; and significant actions are recorded in audit logs. No system is perfectly secure, and we cannot guarantee absolute security.
Our website and platform are intended for businesses, not for children, and we do not knowingly collect personal information directly from children under 13.
Where a business client uses the platform for programs involving minors (for example, youth activities), any information about those minors is provided to us by the business client. That client is responsible for collecting and managing such information lawfully, including obtaining any parental or guardian consent required under the Children's Online Privacy Protection Act (COPPA) and applicable state law; Dravio processes it only as the client's service provider. If you believe a child's information has been provided to us improperly, contact us at privacy@dravio.co and we will work with the relevant business client to address it, including deletion where appropriate.
Depending on where you live, you may have the right to access, correct, delete, or receive a portable copy of your personal information, and to object to or restrict certain processing. To exercise these rights, email privacy@dravio.co; we will verify your request (typically by confirming control of the email address on record) and respond within 45 days. California residents may exercise rights under the CCPA, including the right to know, delete, and opt out of sale — and we confirm we do not sell personal information.
If your request concerns data that a business client manages through the platform (for example, you are that client's customer or a program participant), please contact the business directly, as they control that data; we will assist them in responding.
We operate in the United States, and information we handle is processed and stored in the United States (Google Cloud, us-central1 region). If you access our services from outside the United States, you understand your information will be processed in the United States.
We may update this Privacy Policy as our practices or the law change. We will revise the "Last updated" date above and, for material changes, take reasonable steps to notify you. Continued use of our website or platform after an update means you accept the revised policy.
Questions about this Privacy Policy or our data practices? Contact us at:
Dravio Consulting LLC
privacy@dravio.co