Harvv
How it worksWhat we findCase studiesGuidesFree auditPricing
Sign in Start free
How it worksWhat we findCase studiesGuidesFree auditPricingSign in

Harvv legal

Privacy Policy

Last updated: August 26, 2026

This Privacy Policy describes how Olivas Venture Capital LLC d/b/a Harvv ("Harvv," "we," "us," or "our") collects, uses, and protects information in connection with the Harvv behavioral analytics platform ("Service").

1. Information We Collect

1.1 Account Information

When you create an account, we collect your name, email address, company name (optional), and a password (stored as a bcrypt hash — we never store plaintext passwords).

1.2 Professional Profile Data

We enrich signup data with publicly available professional profile information from sources such as Apollo.io to improve your experience. This may include your job title, company name, industry, company size, and LinkedIn profile URL. This data is publicly available and is used solely for product personalization and segmentation. You may view and request correction of this data at any time.

1.3 Behavioral Telemetry (End-User Data)

The Harvv pixel collects structured behavioral signals from visitors to websites where it is installed. By design, the pixel does NOT collect:

  • Keystroke content or form field values
  • Clipboard content or selected text content
  • DOM content, page text, or screenshots
  • Session replay or video recordings
  • Raw IP addresses. IP addresses are processed transiently (for rate limiting, bot filtering, and country-level geolocation) and are never stored raw in analytics records. Limited operational and security logs (account activity on harvv.com, consent records, email delivery diagnostics) store only a keyed, salted, non-reversible hash
  • Names, email addresses, or any PII of end users

The pixel DOES collect:

  • Click targets and coordinates (which element was clicked)
  • Scroll position, scroll velocity, and bucketed reading-vs-skim distance (kinematic only, no DOM text)
  • Hover duration on interactive elements
  • Time spent on page (visible tab time only)
  • Page URL pathname (not query parameters)
  • Device type and connection speed (from browser APIs)
  • JavaScript error messages and file/line references
  • HTTP response status codes from network requests
  • Performance timing: page load metrics, including LCP element type (image vs text vs other), the asset URL path of an image LCP element (a static public asset on the site's own page; the query string is stripped), and a structural CSS selector identifying the LCP element (tag, id, and class path only; the element's text content is never included)
  • Word count of the primary content body — count only, never the text
  • Meta-tag audit on public pages: title length + truncated title (200 chars), meta-description length + truncated description, count of H1 tags + truncated first H1, presence flags for og:title/description/image/canonical/noindex, and counts of any duplicate og: tags. Defense-in-depth scrubs emails/phones from any text shipped, and the audit is skipped entirely on URLs that match auth patterns (/login, /signup, /account, /admin, /dashboard, /app, /billing, /settings, /profile, /checkout, /cart, /orders, /reset-password, /forgot-password, /wp-admin) or pages flagged with data-harvv-private
  • JSON-LD schema detection: count of structured-data blocks and the @type keywords (e.g. "Article", "Product", "FAQPage") — schema.org constants only, never the schema content itself

All behavioral data is captured as abstract, structured telemetry. It describes how users interact with elements, not what those elements contain.

1.4 Cookies and Identifiers

On harvv.com properties we use exactly one first-party cookie: _pxv, a randomly generated visitor identifier with a 2-year expiry. We use no third-party cookies and no cross-site trackers. Customer sites that install the pixel set the same _pxv cookie on their own first-party domain; that cookie is scoped to their domain only and is never read by harvv.com.

1.4.1 Cookie Banner & Consent

When you first visit a harvv.com property, a cookie banner appears with three options: Accept all, Reject non-essential, or Customize. Reject is one click — the same number as Accept (per the French CNIL ruling and the broader EU 2024+ "consent parity" requirement). If you have Global Privacy Control enabled in your browser we honor it automatically and never show the banner. Your choice is stored in localStorage.harvv_consent_v1 for 365 days, after which we re-prompt. You can change your choice at any time by clearing site data or contacting jordan@harvv.com.

For audit purposes we record every consent choice in our consent_log table with: a SHA-256 hash of your IP address (salted with the current date — the raw IP is never stored), your browser user-agent (capped at 200 characters), the country code from edge-CDN headers, the consent version, the choices you made, the source of the choice (banner / customize panel / GPC auto-decline), and the page URL where the choice was made. This is the minimum data required to demonstrate Article 7 GDPR consent compliance and is retained for the life of your visit relationship to harvv.com.

1.4.2 Consent-Aware Capture on Customer Sites

On websites that install the Harvv pixel, the pixel can operate in consent-aware mode. When enabled for a site, the pixel detects the site's consent mechanism (the Shopify Customer Privacy API, or any consent banner wired to Google Consent Mode) and behaves as follows:

  • Consent declined: nothing is transmitted for that visitor. Not a reduced ping; zero bytes. Nothing is written to the visitor's device.
  • Consent pending: events are held in the browser's memory only. Nothing is transmitted and nothing is written to the device. If the visitor declines or leaves without deciding, the held events are discarded.
  • Consent granted: the session transmits normally, and identifiers are written only after consent resolves.
  • No consent mechanism present: the pixel operates according to the site owner's configuration. The site owner is responsible for deploying a consent mechanism where the laws that apply to their visitors require one.

Even outside consent-aware mode, the pixel honors an analytics-storage denial from Google Consent Mode by switching to in-memory identifiers with no cookies and no device storage.

1.5 Payment Information

Payment processing is handled by Stripe, Inc. We do not store credit card numbers or bank account information. See Stripe's Privacy Policy.

2. How We Use Information

  • To provide the Service: Detect UX issues, generate fix recommendations, produce reports
  • To improve the Service: Anonymized, aggregated data is used to improve detection accuracy and build the fix pattern library
  • To communicate with you: Onboarding emails, issue alerts, weekly digests, product updates (with your consent where required)
  • To personalize your experience: Professional profile data is used to tailor onboarding and fix recommendations to your role
  • To process payments: Billing and subscription management via Stripe

3. Marketing Communications

We send marketing communications only with your explicit consent. You may opt out at any time by:

  • Clicking the "Unsubscribe" link in any marketing email
  • Updating your communication preferences in your account settings
  • Emailing jordan@harvv.com

Transactional emails (password resets, billing confirmations, critical security notices) are not considered marketing and may be sent without separate consent.

4. Data Sharing

We do not sell your data. We share data only with:

  • Stripe — for payment processing
  • Resend — for transactional and marketing email delivery
  • Anthropic — for AI-powered analysis (behavioral data only, no PII)
  • Apollo.io — for professional profile enrichment (your email only)
  • Railway — for hosting infrastructure
  • Meta Platforms, Inc. — Harvv runs paid advertising on Facebook and Instagram via the Meta Marketing API. Our app does not collect or store any data about Facebook or Instagram users; it operates only on advertising assets (campaigns, ad sets, ads, creatives) in Harvv's own ad account. No end-user data flows from Meta to Harvv through this integration. If you believe Harvv holds any personal information about you and want it deleted, see /data-deletion.
  • Google LLC (Google APIs) — When you connect a Google Analytics property to Harvv, we use Google APIs to read aggregated metrics from that property. No Harvv customer data is transferred to Google. See Section 4.1 below for full disclosure of how Harvv accesses, uses, stores, and shares Google user data.

We may disclose data if required by law, court order, or to protect our legal rights.

4.1 Google User Data — Limited Use Disclosure

This section satisfies the Google API Services User Data Policy, including the Limited Use requirements that apply to applications that access certain Google user data scopes.

4.1.1 What Google user data we access

When you authorize Harvv to connect to your Google Analytics 4 ("GA4") account, Harvv requests exactly one OAuth scope:

  • https://www.googleapis.com/auth/analytics.readonly — read-only access to GA4 properties on your Google account.

Using that scope, we call the following Google APIs:

  • Google Analytics Admin API (analyticsadmin.googleapis.com) — to list the GA4 properties on your account so you can select which one to connect. We read property names and account names only; no analytics measurements are retrieved by this call.
  • Google Analytics Data API (analyticsdata.googleapis.com) — once per day, after you have selected a property, we run runReport queries to read aggregated traffic, engagement, and revenue metrics for the connected property. These reports are statistical roll-ups (e.g. "sessions per page," "purchases by device category") and do not contain individual end-user identifiers.

If you additionally connect Google Search Console (a separate, optional connection), Harvv requests one further read-only scope: https://www.googleapis.com/auth/webmasters.readonly. Using it, we call the Search Console API once per day to read aggregated search performance for your verified property (queries, clicks, impressions, average position). These are statistical roll-ups and contain no individual end-user identifiers. This scope is only requested if you start the Search Console connection; the GA4 connection alone never requests it.

Harvv does not request or use any Google API scope beyond the two read-only scopes described above. We never access Gmail, Calendar, Drive, Photos, Contacts, YouTube, your Google profile beyond your sign-in email, or any restricted scope.

4.1.2 Why we access this data

The only purpose of the Google Analytics connection is to provide user-facing features inside the Harvv dashboard:

  • Attach a revenue or conversion-rate impact to each detected UX issue (e.g. "this broken button costs ~$240 per week").
  • Compare traffic-source quality (paid social vs. organic) joined with Harvv-measured friction signals.
  • Surface device, browser, and landing-page conversion gaps that customers can act on.

None of these features work without the connected GA4 data, which is why we request the scope. Use of the scope is limited to providing these prominent user-facing features.

4.1.3 How we store and protect Google user data

  • Your Google OAuth refresh token is stored encrypted at rest in our PostgreSQL database (managed by Railway, AES-256). It is scoped to your Harvv site row and is never sent to any third party.
  • Aggregated reports retrieved from the Data API are stored in a ga4_syncs row tied to your site and kept for as long as your site is active in Harvv. When you disconnect, they are retained for a grace period so you can reconnect without losing history, and are permanently deleted within 90 days; deleting the site removes them within the same window.
  • All access to Google APIs happens server-to-server over TLS from Harvv's backend.
  • No raw, user-level GA4 data leaves Google's infrastructure — Harvv only retrieves the aggregated report rows necessary to display the features above.

4.1.4 How we share Google user data

Harvv does not sell, rent, or transfer Google user data to any third party for advertising or commercial purposes. Specifically, in accordance with the Google API Services User Data Policy:

  • We do not transfer or sell Google user data to third parties such as advertising platforms, data brokers, or information resellers.
  • We do not use Google user data to serve ads, including retargeting, personalized advertising, or interest-based advertising.
  • We do not use Google user data to determine credit-worthiness or for lending purposes.
  • We do not allow humans to read your Google user data, except (a) with your explicit affirmative consent for a specific support request, (b) when required to comply with applicable law or regulation, (c) for internal aggregated security operations and abuse-prevention, or (d) where the data has been de-identified and aggregated such that it cannot be associated with an individual user.
  • We do not use Google user data to develop, train, or improve generalized machine-learning or AI models. The data is used solely to display the features described in Section 4.1.2 to you, the connected customer.

4.1.5 How to revoke access and delete data

You can revoke Harvv's access to your Google Analytics data at any time, in either of two ways:

  1. Inside Harvv — Settings → Integrations → "Disconnect." This deletes the refresh token immediately. Stored ga4_syncs rows for your site are retained for a grace period so you can reconnect without losing history, then permanently deleted within 90 days.
  2. Through Google directly — Visit myaccount.google.com/permissions, find "Harvv," and click Remove access. Google will invalidate the token and Harvv's next scheduled sync will fail; the corresponding stored data is cleared within 90 days.

You can also email jordan@harvv.com from the email on the connected account and we will revoke + purge manually within 7 business days.

4.1.6 Compliance with the Google API Services User Data Policy

Harvv's use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.

5. Data Retention

Behavioral telemetry data. Raw event-level telemetry is kept in our live database for approximately 30 days, after which it is moved to a compressed archive. The archive keeps each day of raw events for 13 months by default, and never more than 24 months: a site owner can shorten that window in their site settings, and a value above the ceiling is reduced to it, not honored. Both clocks are enforced by scheduled deletion, and the archive's expiry rule is checked against the storage bucket on every run rather than assumed. The aggregated statistics, detected issues, and reports that power your dashboard are kept for the life of your account; they do not contain individual events. Conversion outcomes (order id, value, currency, payment method category) are kept durably for the life of your account.

Retention schedule. In one place: raw events, approximately 30 days live and 13 months archived (24 months maximum); per-site aggregates, issues, and reports, the life of your account; de-identified cross-customer benchmarks, indefinitely, because they cannot be tied to a site or a visitor; our own security audit log, 7 years.

Deletion and termination. When you delete a site or close your account, your raw events (live and archived), sessions, and reports are deleted or returned to you within 90 days. The first 30 days are a recovery window in case the deletion was accidental; after it, deletion is permanent and includes the archive. Routine deletion on this schedule is suspended only under a documented legal hold. You may request immediate deletion by contacting jordan@harvv.com.

Google user data (aggregated GA4 and Google Search Console reports retrieved on your behalf, and your encrypted Google OAuth refresh token) is retained only while the integration is connected to your site. The encrypted refresh token is deleted immediately when you disconnect. The aggregated reports are retained for a grace period so you can reconnect without losing history, and all stored Google user data is permanently purged within 90 days of disconnection, revocation from Google directly, or site deletion. We do not maintain backups of Google user data beyond Railway's standard 7-day database snapshots, which are also overwritten on their normal rotation.

6. Your Rights

6.1 All Users

  • Access your data at any time through your dashboard
  • Export your data via the API
  • Delete your account and all associated data
  • Opt out of marketing communications

6.2 California Residents (CCPA/CPRA)

California residents have the right to know what personal information we collect, request deletion, and opt out of the sale of personal information. We do not sell personal information. To exercise your rights, contact jordan@harvv.com.

6.3 European Economic Area Residents (GDPR)

If you are in the EEA, you have additional rights including the right to access, rectification, erasure, restriction of processing, data portability, and objection. Our legal basis for processing is legitimate interest (providing the Service) and consent (marketing communications). Contact our Data Protection contact at jordan@harvv.com.

6.4 End Users of Websites Using Harvv

If you are an end user (visitor) of a website that uses Harvv, the website operator is the data controller. Harvv acts as a data processor. Contact the website operator for data access or deletion requests. The Harvv pixel does not collect PII and supports cookieless mode.

7. Security

We implement industry-standard security measures including:

  • Encryption in transit (HTTPS/TLS for all connections, including all Google API calls)
  • Encryption at rest (Railway-managed database encryption; OAuth refresh tokens stored encrypted)
  • Password hashing (bcrypt with cost factor 12)
  • JWT-based authentication with expiring tokens
  • Rate limiting on all endpoints
  • No PII in behavioral data by architectural design
  • Defense-in-depth scrubbing of email addresses, phone numbers, and credit-card-shaped strings from any text the pixel ships
  • Least-privilege Google OAuth scopes (read-only: analytics.readonly for GA4, webmasters.readonly if you also connect Search Console)

If we become aware of a breach affecting your personal information or Google user data, we will notify affected users without undue delay and, where required by law, file the appropriate regulatory notifications.

8. Children's Privacy

The Service is not intended for children under 13. We do not knowingly collect data from children. If you believe we have collected data from a child, contact us immediately.

9. Changes to This Policy

We may update this Privacy Policy periodically. Material changes will be communicated via email at least 30 days before taking effect. The "Last updated" date at the top reflects the most recent revision.

10. Contact

Olivas Venture Capital LLC d/b/a Harvv
Denton County, Texas
Privacy inquiries: jordan@harvv.com
General: jordan@harvv.com

Harvv

The behavioral pixel for sites you ship to real users. Harvv finds what is broken, explains it in plain English, and hands the answer to your AI.

Product

How it works What we find Pricing Docs Free audit

Learn

Case studies Guides Harvv vs Clarity Clarity & privacy

Company

Contact Trust & security Privacy Terms
© 2026 Harvv Zero PII. Every number on this site is measured, not modelled.