DRAVEON WORKSPACE
Supabase Connected
API healthPRE-PRODUCTION
Draveon OS
DRAVEON LEGAL

Privacy Policy

Effective August 30, 2026. This policy explains how Draveon collects, uses, protects and manages information across the Draveon website, platform, AIRA, integrations and related commercial services.

1. Scope

This Privacy Policy applies to draveon.tech, the Draveon OS platform, AIRA by Draveon, commercial intake forms, pilots, support interactions, authenticated workspaces and integrations that a customer or authorized user chooses to connect. A separate customer agreement, data processing agreement or order form may provide additional terms. If there is a conflict, the signed customer agreement controls for that customer.

2. Information we collect

We may collect information you submit directly, including your name, work email, organization, telephone number, country or region, organization size, product or service interests, inquiry details, support requests and other information you choose to provide.

For authenticated users, Draveon may process account identifiers, organization and workspace membership, roles, permissions, activity records, workflow and operational data, approval history, audit events, integration status and other information needed to operate the service.

We may also collect technical information such as browser and device information, IP-derived security signals, timestamps, request logs, diagnostic data, authentication events and necessary cookies or similar technologies used to provide, secure and improve the service.

3. How we use information

We use information to provide and secure Draveon, authenticate authorized users, manage tenant and workspace access, deliver customer support, respond to commercial inquiries, operate pilots, synchronize approved integrations, maintain auditability, detect misuse, improve reliability and communicate about requested products or services.

We do not sell personal information to advertisers. We do not use Google Workspace data for advertising. We do not use customer private workspace data to train unrelated public advertising profiles.

4. Google Workspace and Gmail data

When an authorized user connects a Google Workspace or Gmail account, Draveon uses Google OAuth. Draveon does not ask for or store the user's Gmail password.

Depending on the permissions approved by the user, Draveon may access basic Google account identity information, read Gmail messages and settings for authorized mailbox synchronization, and send email on behalf of the connected user or approved mailbox. Draveon requests only the scopes needed for the enabled features, including identity, Gmail read-only access and Gmail send access.

Google data is used to support authorized CRM communication history, mailbox synchronization, deterministic association with permitted customer records, user-initiated email actions, and approved Draveon website or support notification workflows. Access is subject to the user's role, tenant, workspace, provider readiness and applicable governance controls.

Draveon is designed to minimize stored email content. Message bodies may be limited to previews by default, while attachments may be retained as metadata unless a customer-authorized feature requires otherwise. OAuth credentials are maintained within the private service boundary and are not exposed to public website visitors.

Draveon's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

5. Service providers and integrations

Draveon may use infrastructure, authentication, database, hosting, email, monitoring and integration providers to operate the service. Current service infrastructure may include providers such as Vercel, Supabase and Google Workspace, together with customer-selected external systems. These providers process information only as needed to deliver the applicable service or integration, subject to their own contractual and security obligations.

6. Data sharing

We may share information with service providers acting on our behalf, with integrations expressly authorized by a customer or user, when required by law, to protect rights and security, or as part of a corporate transaction subject to appropriate safeguards. We do not disclose connected Google user data to third parties for advertising purposes.

7. Security and access controls

Draveon uses administrative, technical and organizational safeguards designed to protect information. Controls may include authentication, tenant and workspace isolation, role-based access, row-level security, private storage, audit logging, approval controls and governed integration readiness. No internet service can guarantee absolute security, so customers should also protect their credentials, devices and connected systems.

8. Retention and deletion

We retain information for as long as reasonably necessary to provide the service, satisfy contractual obligations, maintain security and audit records, resolve disputes and comply with law. Retention may vary by data category and customer agreement. Authorized users can disconnect supported integrations through Draveon settings when available. Requests concerning access, correction or deletion may be sent to support@draveon.tech.

9. International processing

Draveon and its service providers may process information in countries other than the country where a user is located. Where applicable, we use contractual, technical or organizational measures intended to support lawful cross-border processing.

10. Your choices and rights

Depending on applicable law, you may have rights to request access, correction, deletion, restriction or other handling of personal information. You may also withdraw optional marketing consent and disconnect integrations that you control. Certain records may need to be retained for security, legal or contractual reasons.

11. Children

Draveon is an enterprise and business service and is not directed to children. We do not knowingly offer the platform for independent use by children.

12. Changes to this policy

We may update this Privacy Policy as Draveon, applicable law or our service providers change. The effective date at the top of this page will be updated when material revisions are published.

13. Contact

For privacy questions, Google data questions, account requests or other privacy matters, contact Draveon at support@draveon.tech.