Legal
Privacy Policy
Effective date: on public launch · Last updated: August 5, 2026
This policy covers providers, their clients, people who send an inquiry through a provider profile, and visitors to ravanika.com. Privacy questions are welcome any time via the contact form.
1. Who we are and accountability
This policy describes how Ravanika Tech Inc. (BC incorporation number BC1602142, 233–1641 Lonsdale Ave, North Vancouver, BC V7M 2J5) handles personal information. It is provided for general information and is not legal advice.
Ravanika has a designated Privacy Officer who is accountable for our compliance with Canadian privacy law and is the contact for any privacy question, request, or complaint: Sam, Privacy Officer — privacy@ravanika.com.
2. What we collect, by who you are
Different people interact with Ravanika differently, and we collect different things from each.
- Providers — account details (name, email, sign-in credentials managed by our authentication provider), professional registration number and a verification link, practice settings (fees, session types, languages, availability), profile content, and billing information handled by our payment processor.
- Access requests — everything submitted on the Request Access form: name, email, location, profession, registration status and regulatory body, licence or registration number (or an explanation), a verification link, practice type, services offered, plan interest, and your message.
- Clients of providers — the records a provider enters into their own workspace: contact details, session history, payments, notes, and assessment results. See section 6 — for these records the provider is the custodian and Ravanika processes them on the provider’s behalf.
- Prospective clients who send an inquiry through a public profile — your name, email, phone number, preferred session type and time, and your free-text message, which may describe why you are seeking support. This is the most sensitive information the public site touches. It is sent over an encrypted connection to our backend, stored in our database, and visible to the provider you contacted (and to Ravanika staff administering the service). Your IP address is stored only as a salted one-way hash used for rate-limiting, and that hash is deleted after 30 days. Your inquiry itself remains in the provider’s workspace until they delete it or their account closes.
- Website visitors — standard server and security logs, including IP addresses, kept by our hosting and edge providers for security and rate-limiting. The public site does not currently use third-party analytics or advertising cookies.
3. How we use information
We use personal information to provide and secure the service: operating provider workspaces, displaying provider-approved public profiles, delivering inquiries to the provider they were addressed to, processing payments, verifying access requests, sending the messages a provider chooses to send, preventing abuse, and meeting legal obligations. We do not sell personal information, and we do not use client or inquiry content for advertising.
4. Service providers and sub-processors
Ravanika runs on established infrastructure providers, which process data on our behalf:
- Hosting and edge: Cloudflare (backend, database, file storage, bot protection, inbound email routing) and Vercel (website and workspace hosting).
- Authentication: Clerk (provider sign-in).
- Payments: Stripe (billing; Ravanika does not store card numbers).
- Email delivery: Resend (transactional email).
- SMS delivery: Twilio (provider-initiated SMS).
5. Storage location and cross-border transfer
Information handled by Ravanika may be stored or processed outside Canada, including in the United States, by the providers listed above. While outside Canada, it may be accessible to the courts, law enforcement, and national-security authorities of those jurisdictions under their laws. If you have questions about how a particular category of information is stored, contact the Privacy Officer.
6. Client records: the provider is the custodian
When a provider enters client information into their workspace, that provider is the custodian of those records and Ravanika processes them only on the provider’s instructions — storing and displaying them so the workspace works. Ravanika does not use client records for its own purposes and does not contact a provider’s clients except when the provider explicitly triggers a message.
For providers, this means Ravanika is a tool within your own record-keeping obligations, not a replacement for them: your regulator’s or association’s rules on records, consent, and confidentiality continue to apply to what you store here. Payment records can be exported from the workspace at any time. For a copy of your other records, contact us and we will provide them, as described in section 8.
7. Retention
Provider account and workspace data is kept while the account is active, and is not deleted automatically when a subscription ends. If you want your workspace data removed, or a copy of it, contact us. Access-request submissions are kept while relevant to onboarding decisions. Where we are not yet operating in your country, your submission is held on a waiting list for up to 24 months from the date you sent it, so we can tell you when we open there; after that it is deleted unless you have become a provider or asked us to keep it, and you can ask us to delete it sooner at any time. Inquiry IP hashes are deleted after 30 days; the inquiries themselves follow the workspace they were delivered to. Billing records are kept as long as tax and accounting law requires. Security logs are retained on our infrastructure providers’ standard short-term schedules.
8. Access, correction, and withdrawal of consent
You may ask what personal information we hold about you, request a correction, or withdraw consent to further collection and use (subject to legal and contractual limits — withdrawing consent may mean the service cannot be provided). Write to the Privacy Officer at privacy@ravanika.com. We respond within 30 days. If your request concerns records held in a provider’s workspace, we will refer you to that provider, who is the custodian of those records — and we will help them fulfil the request.
9. Safeguards
Information is encrypted in transit (TLS) and encrypted at rest (AES-256) by our infrastructure providers. Access to production data is limited to what is needed to run the service: provider workspaces are isolated by account, backend routes require authentication, and public endpoints are rate-limited and bot-protected. No system is perfectly secure, and we do not claim otherwise — but we design so that the most sensitive data has the fewest paths to it.
The database holding workspace records supports point-in-time recovery for the previous 30 days through our infrastructure provider, which allows a database to be restored to an earlier state. Recovery options for uploaded files and generated documents, which are held in object storage, are more limited than for the database.
10. Breach notification
If a breach of security safeguards creates a real risk of significant harm to you, we will notify you and the Office of the Privacy Commissioner of Canada as required by law, and we will tell the affected providers so they can meet their own obligations for records in their custody.
11. Provider-controlled SMS
Ravanika does not automatically send SMS messages to clients. Client-facing SMS messages are sent only when a provider chooses to send them, and consent should be confirmed before sending.
12. Public provider profiles
Only provider-approved public fields appear on a provider profile. Phone and email are not shown publicly unless the provider chooses to make them public.
13. Children
The service is not directed at minors, and minors may not sign up for accounts directly. Providers who work with young clients hold and manage those records as custodians under their own professional obligations.
14. Changes and contact
If this policy changes materially, we will post the updated version here with a new date and notify providers in the workspace. Questions, requests, and complaints go to the Privacy Officer:
Ravanika Tech Inc. · 233–1641 Lonsdale Ave, North Vancouver, BC V7M 2J5 · privacy@ravanika.com (Privacy Officer)