Harvv
How it worksWhat we findCase studiesGuidesFree auditPricing
Sign in Start free
How it worksWhat we findCase studiesGuidesFree auditPricingSign in

Harvv legal

Privacy Policy

Last updated: September 18, 2026

This Privacy Policy describes how Olivas Venture Capital LLC d/b/a Harvv ("Harvv," "we," "us," or "our") collects, uses, and protects information in connection with the Harvv behavioral analytics platform ("Service").

1. Information We Collect

1.1 Account Information

When you create an account, we collect your name, email address, company name (optional), and a password (stored as a bcrypt hash — we never store plaintext passwords).

1.2 Professional Profile Data

We enrich signup data with publicly available professional profile information from sources such as Apollo.io to improve your experience. This may include your job title, company name, industry, company size, and LinkedIn profile URL. This data is publicly available and is used solely for product personalization and segmentation. You may view and request correction of this data at any time.

1.3 Behavioral Telemetry (End-User Data)

The Harvv pixel collects structured behavioral signals from visitors to websites where it is installed. By design, the pixel does NOT collect:

  • Keystroke content or form field values
  • Clipboard content or selected text content
  • DOM content, page text, or screenshots
  • Session replay or video recordings
  • Raw IP addresses. IP addresses are processed transiently (for rate limiting, bot filtering, and country-level geolocation) and are never stored raw in analytics records. Limited operational and security logs (account activity on harvv.com, consent records, email delivery diagnostics) store only a keyed, salted, non-reversible hash
  • Names, email addresses, or any PII of end users

The pixel DOES collect:

  • Click targets and coordinates (which element was clicked)
  • Scroll position, scroll velocity, and bucketed reading-vs-skim distance (kinematic only, no DOM text)
  • Hover duration on interactive elements
  • Time spent on page (visible tab time only)
  • Page URL pathname (not query parameters)
  • Device type and connection speed (from browser APIs)
  • JavaScript error messages and file/line references
  • HTTP response status codes from network requests
  • Performance timing: page load metrics, including LCP element type (image vs text vs other), the asset URL path of an image LCP element (a static public asset on the site's own page; the query string is stripped), and a structural CSS selector identifying the LCP element (tag, id, and class path only; the element's text content is never included)
  • Word count of the primary content body — count only, never the text
  • Meta-tag audit on public pages: title length + truncated title (200 chars), meta-description length + truncated description, count of H1 tags + truncated first H1, presence flags for og:title/description/image/canonical/noindex, and counts of any duplicate og: tags. Defense-in-depth scrubs emails/phones from any text shipped, and the audit is skipped entirely on URLs that match auth patterns (/login, /signup, /account, /admin, /dashboard, /app, /billing, /settings, /profile, /checkout, /cart, /orders, /reset-password, /forgot-password, /wp-admin) or pages flagged with data-harvv-private
  • JSON-LD schema detection: count of structured-data blocks and the @type keywords (e.g. "Article", "Product", "FAQPage") — schema.org constants only, never the schema content itself

All behavioral data is captured as abstract, structured telemetry. It describes how users interact with elements, not what those elements contain.

1.4 Cookies and Identifiers

On harvv.com properties we use exactly one first-party cookie: _pxv, a randomly generated visitor identifier with a 2-year expiry. We use no third-party cookies and no cross-site trackers. Customer sites that install the pixel set the same _pxv cookie on their own first-party domain; that cookie is scoped to their domain only and is never read by harvv.com.

1.4.1 Cookie Banner & Consent

When you first visit a harvv.com property, a cookie banner appears with three options: Accept all, Reject non-essential, or Customize. Reject is one click — the same number as Accept (per the French CNIL ruling and the broader EU 2024+ "consent parity" requirement). If you have Global Privacy Control enabled in your browser we honor it automatically and never show the banner. Your choice is stored in localStorage.harvv_consent_v1 for 365 days, after which we re-prompt. You can change your choice at any time by clearing site data or contacting jordan@harvv.com.

For audit purposes we record every consent choice in our consent_log table with: a SHA-256 hash of your IP address (salted with the current date — the raw IP is never stored), your browser user-agent (capped at 200 characters), the country code from edge-CDN headers, the consent version, the choices you made, the source of the choice (banner / customize panel / GPC auto-decline), and the page URL where the choice was made. This is the minimum data required to demonstrate Article 7 GDPR consent compliance and is retained for the life of your visit relationship to harvv.com.

1.4.2 Consent-Aware Capture on Customer Sites

On websites that install the Harvv pixel, the pixel can operate in consent-aware mode. When enabled for a site, the pixel detects the site's consent mechanism (the Shopify Customer Privacy API, or any consent banner wired to Google Consent Mode) and behaves as follows:

  • Consent declined: nothing is transmitted for that visitor. Not a reduced ping; zero bytes. Nothing is written to the visitor's device.
  • Consent pending: events are held in the browser's memory only. Nothing is transmitted and nothing is written to the device. If the visitor declines or leaves without deciding, the held events are discarded.
  • Consent granted: the session transmits normally, and identifiers are written only after consent resolves.
  • No consent mechanism present: the pixel operates according to the site owner's configuration. The site owner is responsible for deploying a consent mechanism where the laws that apply to their visitors require one.

Even outside consent-aware mode, the pixel honors an analytics-storage denial from Google Consent Mode by switching to in-memory identifiers with no cookies and no device storage.

1.5 Payment Information

Payment processing is handled by Stripe, Inc. We do not store credit card numbers or bank account information. See Stripe's Privacy Policy.

2. How We Use Information

  • To provide the Service: Detect UX issues, generate fix recommendations, produce reports
  • To improve the Service: Anonymized, aggregated data is used to improve detection accuracy and build the fix pattern library
  • To communicate with you: Onboarding emails, issue alerts, weekly digests, product updates (with your consent where required)
  • To personalize your experience: Professional profile data is used to tailor onboarding and fix recommendations to your role
  • To process payments: Billing and subscription management via Stripe

3. Marketing Communications

We send marketing communications only with your explicit consent. You may opt out at any time by:

  • Clicking the "Unsubscribe" link in any marketing email
  • Updating your communication preferences in your account settings
  • Emailing jordan@harvv.com

Transactional emails (password resets, billing confirmations, critical security notices) are not considered marketing and may be sent without separate consent.

4. Data Sharing

We do not sell your data. We share data only with:

  • Stripe — for payment processing
  • Resend — for transactional and marketing email delivery
  • Anthropic — for AI-powered analysis (behavioral data only, no PII)
  • Apollo.io — for professional profile enrichment (the name and email address on your Harvv account, including when you created the account with Sign in with Google)
  • Railway — for hosting infrastructure
  • Meta Platforms, Inc. — Harvv runs paid advertising on Facebook and Instagram via the Meta Marketing API. Our app does not collect or store any data about Facebook or Instagram users; it operates only on advertising assets (campaigns, ad sets, ads, creatives) in Harvv's own ad account. No end-user data flows from Meta to Harvv through this integration. If you believe Harvv holds any personal information about you and want it deleted, see /data-deletion.
  • Google LLC (Google APIs) — When you connect Google Analytics, Google Search Console, or Google Ads to Harvv, we use Google APIs to read data from the property or account you choose. No Harvv customer data is transferred to Google. See Section 4.1 below for full disclosure of how Harvv accesses, uses, stores, and shares Google user data.

We may disclose data if required by law, court order, or to protect our legal rights.

4.1 Google User Data — Limited Use Disclosure

This section satisfies the Google API Services User Data Policy, including the Limited Use requirements that apply to applications that access certain Google user data scopes.

4.1.1 What Google user data we access

Harvv has four points of contact with a Google account. Each one is optional, each is a separate authorization, and each requests only its own scope. Starting one never requests the scope of another.

Sign in with Google. If you choose to create or sign in to your Harvv account with Google, Harvv requests the openid, email, and profile scopes. We read your name, your email address, and Google's stable account identifier, and use them only to create your Harvv account and sign you in.

Google Analytics 4 ("GA4"). When you connect GA4, Harvv requests exactly one OAuth scope:

  • https://www.googleapis.com/auth/analytics.readonly — read-only access to GA4 properties on your Google account.

Using that scope, we call the following Google APIs:

  • Google Analytics Admin API (analyticsadmin.googleapis.com) — to list the GA4 properties on your account so you can select which one to connect. We read property names and account names only; no analytics measurements are retrieved by this call.
  • Google Analytics Data API (analyticsdata.googleapis.com) — once per day, after you have selected a property, we run runReport queries to read aggregated traffic, engagement, and revenue metrics for the connected property. These reports are statistical roll-ups (e.g. "sessions per page," "purchases by device category") and do not contain individual end-user identifiers.

Google Search Console. When you connect Search Console, Harvv requests one read-only scope: https://www.googleapis.com/auth/webmasters.readonly. Using it, we call the Search Console API once per day to read aggregated search performance for your verified property (queries, clicks, impressions, average position). These are statistical roll-ups and contain no individual end-user identifiers.

Google Ads. When you connect Google Ads, Harvv requests one scope: https://www.googleapis.com/auth/adwords. Google provides a single scope for the Google Ads API and it has no read-only version, so Google's consent screen describes it as the ability to see, edit, create, and delete your Google Ads accounts and data. Harvv only reads. We call the Google Ads API's reporting (search) methods and never call any method that creates, changes, pauses, or removes anything in your Google Ads account. Using this scope, we read, for the account you select:

  • The account's name, currency, and time zone, and, if you connect a manager account, the list of client accounts under it so you can choose one.
  • Campaign names and daily performance figures: cost, impressions, clicks, conversions, and conversion value, including the same figures split by device and network.
  • Your conversion action definitions (name, type, category, status, and counting settings) and their daily totals.
  • Ad click records from Google's click_view report: the Google click identifier (GCLID), the date, and the campaign, ad group, ad, keyword, match type, device, and network of the click. A click record identifies an ad click, not a person. We use it to match an ad click to the visit Harvv recorded on your own site.
  • The account's change history: what was changed, when, the old and new values, and the email address of the Google Ads user who made the change, so that a shift in performance can be lined up with the edit that preceded it.

Harvv does not request or use any Google API scope beyond those listed above. We never access Gmail, Calendar, Drive, Photos, Contacts, YouTube, or any restricted scope.

4.1.2 Why we access this data

The only purpose of these connections is to provide user-facing features inside the Harvv product, shown to you, the customer who connected the account:

  • GA4: attach a revenue or conversion-rate impact to each detected UX issue (e.g. "this broken button costs ~$240 per week"), compare traffic-source quality joined with Harvv-measured friction signals, and surface device, browser, and landing-page conversion gaps you can act on.
  • Search Console: show which searches bring visitors to your pages, next to how those visitors behave once they arrive.
  • Google Ads: show what you spent per campaign next to what the visitors from those campaigns did on your site, report a measured return on ad spend beside the one Google reports, and flag paid traffic that leaves without engaging.

None of these features work without the connected data, which is why we request each scope. Use of each scope is limited to providing these prominent user-facing features.

4.1.3 How we store and protect Google user data

  • Your Google OAuth refresh token is stored encrypted at rest in our PostgreSQL database (managed by Railway, AES-256). Each connection has its own token, tied to your Harvv site or account, and a token is never sent to any third party.
  • Data retrieved from the GA4, Search Console, and Google Ads APIs is stored in our database, tied to your site or account, and kept for as long as the connection is active. When you disconnect, it is retained for a grace period so you can reconnect without losing history, and is permanently deleted within 90 days; deleting the site removes it within the same window.
  • All access to Google APIs happens server-to-server over TLS from Harvv's backend.
  • No raw, user-level GA4 or Search Console data leaves Google's infrastructure. Harvv retrieves only aggregated report rows from those two services. From Google Ads, Harvv retrieves the account-level records listed in Section 4.1.1.

4.1.4 How we share Google user data

Harvv does not sell, rent, or transfer Google user data to any third party for advertising or commercial purposes. Specifically, in accordance with the Google API Services User Data Policy:

  • We do not transfer or sell Google user data to third parties such as advertising platforms, data brokers, or information resellers.
  • We do not use Google user data to serve ads, including retargeting, personalized advertising, or interest-based advertising.
  • We do not use Google user data to determine credit-worthiness or for lending purposes.
  • We do not allow humans to read your Google user data, except (a) with your explicit affirmative consent for a specific support request, (b) when required to comply with applicable law or regulation, (c) for internal aggregated security operations and abuse-prevention, or (d) where the data has been de-identified and aggregated such that it cannot be associated with an individual user.
  • We do not use Google user data to develop, train, or improve generalized machine-learning or AI models. The data is used solely to display the features described in Section 4.1.2 to you, the connected customer.

AI assistant features. Harvv includes an AI assistant you can ask questions about your site, in the dashboard, in Slack if you connect it, and through Harvv's connector for AI assistants (MCP). The only transfers of Google user data outside Harvv happen here, at your direction, and only to answer your question:

  • When you ask the assistant a question whose answer depends on your connected Google data, the figures needed to answer it are sent to Anthropic, PBC, our AI model provider, which processes them on our behalf to generate the reply. Under Anthropic's commercial terms, this data is not used to train its models.
  • If you ask from Slack, the answer is posted to the Slack conversation you asked in.
  • If you connect Harvv to an AI assistant of your own choosing through the MCP connector, the figures you request are returned to that assistant, under your account with its provider.

OAuth tokens are never included in any of these. If you do not use the assistant, none of these transfers occur.

4.1.5 How to revoke access and delete data

You can revoke Harvv's access to your Google Analytics, Search Console, or Google Ads data at any time, in either of two ways:

  1. Inside Harvv — Settings → Integrations → "Disconnect" on the connection you want to remove. This deletes that connection's refresh token immediately. The data already retrieved through it is retained for a grace period so you can reconnect without losing history, then permanently deleted within 90 days. Disconnecting one Google connection does not affect the others.
  2. Through Google directly — Visit myaccount.google.com/permissions, find "Harvv," and click Remove access. Google will invalidate the token and Harvv's next scheduled sync will fail; the corresponding stored data is cleared within 90 days.

You can also email jordan@harvv.com from the email on the connected account and we will revoke + purge manually within 7 business days.

4.1.6 Compliance with the Google API Services User Data Policy

Harvv's use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.

5. Data Retention

Behavioral telemetry data. Raw event-level telemetry is kept in our live database for approximately 30 days, after which it is moved to a compressed archive. The archive keeps each day of raw events for 13 months by default, and never more than 24 months: a site owner can shorten that window in their site settings, and a value above the ceiling is reduced to it, not honored. Both clocks are enforced by scheduled deletion, and the archive's expiry rule is checked against the storage bucket on every run rather than assumed. The aggregated statistics, detected issues, and reports that power your dashboard are kept for the life of your account; they do not contain individual events. Conversion outcomes (order id, value, currency, payment method category) are kept durably for the life of your account.

Retention schedule. In one place: raw events, approximately 30 days live and 13 months archived (24 months maximum); per-site aggregates, issues, and reports, the life of your account; de-identified cross-customer benchmarks, indefinitely, because they cannot be tied to a site or a visitor; our own security audit log, 7 years.

Deletion and termination. When you delete a site or close your account, your raw events (live and archived), sessions, and reports are deleted or returned to you within 90 days. The first 30 days are a recovery window in case the deletion was accidental; after it, deletion is permanent and includes the archive. Routine deletion on this schedule is suspended only under a documented legal hold. You may request immediate deletion by contacting jordan@harvv.com.

Google user data (GA4 and Google Search Console reports and Google Ads account data retrieved on your behalf, and your encrypted Google OAuth refresh tokens) is retained only while the integration is connected to your site. The encrypted refresh token is deleted immediately when you disconnect. The retrieved data is retained for a grace period so you can reconnect without losing history, and all stored Google user data is permanently purged within 90 days of disconnection, revocation from Google directly, or site deletion. We do not maintain backups of Google user data beyond Railway's standard 7-day database snapshots, which are also overwritten on their normal rotation.

6. Your Rights

6.1 All Users

  • Access your data at any time through your dashboard
  • Export your data via the API
  • Delete your account and all associated data
  • Opt out of marketing communications

6.2 California Residents (CCPA/CPRA)

California residents have the right to know what personal information we collect, request deletion, and opt out of the sale of personal information. We do not sell personal information. To exercise your rights, contact jordan@harvv.com.

6.3 European Economic Area Residents (GDPR)

If you are in the EEA, you have additional rights including the right to access, rectification, erasure, restriction of processing, data portability, and objection. Our legal basis for processing is legitimate interest (providing the Service) and consent (marketing communications). Contact our Data Protection contact at jordan@harvv.com.

6.4 End Users of Websites Using Harvv

If you are an end user (visitor) of a website that uses Harvv, the website operator is the data controller. Harvv acts as a data processor. Contact the website operator for data access or deletion requests. The Harvv pixel does not collect PII and supports cookieless mode.

7. Security

We implement industry-standard security measures including:

  • Encryption in transit (HTTPS/TLS for all connections, including all Google API calls)
  • Encryption at rest (Railway-managed database encryption; OAuth refresh tokens stored encrypted)
  • Password hashing (bcrypt with cost factor 12)
  • JWT-based authentication with expiring tokens
  • Rate limiting on all endpoints
  • No PII in behavioral data by architectural design
  • Defense-in-depth scrubbing of email addresses, phone numbers, and credit-card-shaped strings from any text the pixel ships
  • Least-privilege Google OAuth scopes: read-only analytics.readonly for GA4 and webmasters.readonly for Search Console, each requested only if you start that connection. Google Ads has no read-only scope, so Harvv enforces read-only use in its own code and makes no write calls.

If we become aware of a breach affecting your personal information or Google user data, we will notify affected users without undue delay and, where required by law, file the appropriate regulatory notifications.

8. Children's Privacy

The Service is not intended for children under 13. We do not knowingly collect data from children. If you believe we have collected data from a child, contact us immediately.

9. Changes to This Policy

We may update this Privacy Policy periodically. Material changes will be communicated via email at least 30 days before taking effect. The "Last updated" date at the top reflects the most recent revision.

10. Contact

Olivas Venture Capital LLC d/b/a Harvv
Denton County, Texas
Privacy inquiries: jordan@harvv.com
General: jordan@harvv.com

Harvv

The behavioral pixel for sites you ship to real users. Harvv finds what is broken, explains it in plain English, and hands the answer to your AI.

Product

How it works What we find Pricing For agencies Docs Free audit

Learn

Case studies Guides Harvv vs Clarity Harvv vs Cloudflare Clarity & privacy

Company

Contact Trust & security Privacy Terms
© 2026 Harvv Zero PII. Every number on this site is measured, not modelled.