Privacy Policy
Effective September 17, 2026
This Privacy Policy explains how Revion Solutions, Incorporated (“Revion,” “we,” “us”), through its GuardGrid web-governance platform and the guardgrid.ai website (collectively, the “Services”), collects, uses, shares, and protects information. By accessing or using the Services, you consent to this Privacy Policy.
1. Information we collect
Information you provide directly. When you create an account, request a demo, or contact us, we collect your name, email address, phone number, organization, website, billing details where applicable, and the contents of any message you send.
Scan data. To provide the Services, we crawl and analyze the public web pages of domains you submit. We store scan results, accessibility and governance findings, scores, screenshots, and generated reports associated with your account.
Automatically collected data. We collect standard technical information such as IP address, browser type and version, device identifiers, language, referring page, usage logs, and system telemetry. When you submit a form on our website, we record the submission’s IP address and browser user-agent for security and abuse-prevention purposes.
Operational and security logs. We maintain logging for authentication, administrative actions, and access events to operate and secure the Services.
We do not knowingly collect personal information from children (see Section 1a).
1a. Children’s privacy (COPPA)
The Services are not intended for children. No one under 13 years of age may provide any information through the Services, and we do not knowingly collect personal information from children under 13. If you are under 13, do not use the Services or provide any information about yourself, including your name, address, telephone number, or email address. If we learn we have collected personal information from a child under 13 without verified parental consent, we will delete it. We do not knowingly collect personal information from anyone under 16.
2. How we use information
- To operate, maintain, secure, and support the Services
- To generate accessibility scans, scores, and compliance reports
- To process payments and administer accounts
- To troubleshoot issues, improve performance, and develop new features
- To prevent fraud, abuse, and security incidents
- To communicate with you about your account, support requests, and product updates
- To comply with legal obligations and enforce our agreements
We do not sell personal information.
3. Sharing and disclosure
We share information only as reasonably necessary to provide the Services: with authorized subprocessors (such as cloud hosting, payment processing, and website analytics), to comply with applicable law, subpoenas, or court orders, to investigate and prevent security incidents, or to enforce our Terms of Service or legal rights. We do not share personal information with advertisers, and we do not share it for cross-context behavioral advertising. A list of subprocessors is maintained separately and updated periodically (see Section 9).
4. Data retention
We retain information only as long as necessary to provide the Services, satisfy legal or audit requirements, maintain business records, or enforce agreements. Scan results and Compliance Evidence PDFs follow defined retention windows by plan, after which they are purged. Subject to applicable law, you may request deletion or export of your personal information.
5. Data security
We implement administrative, physical, and technical safeguards appropriate to the Services, including authentication controls, encryption in transit, centralized logging, monitoring, vulnerability remediation, and hardened infrastructure. You remain responsible for the security of your access credentials and of the content you host or submit. No method of transmission or storage is completely secure, but we work to protect your information.
6. International transfers
Information processed through the Services may be transferred to or stored in jurisdictions where Revion or its subprocessors operate, including the United States. By using the Services, you consent to such transfers subject to applicable law.
7. Your privacy rights
Depending on your jurisdiction, you may have rights to request access, correction, deletion, restriction, portability, or withdrawal of consent regarding your personal information. To exercise these rights, contact us at info@revion.com. We may take reasonable steps to verify your identity before responding.
8. Cookies and tracking
The guardgrid.ai marketing website is a static site that uses minimal cookies. Two pages embed a third-party widget that the page cannot do without: the booking calendar on /book-demo, provided by Cal.com, and Google reCAPTCHA on our contact form. Every page also carries a live chat, which we operate ourselves rather than buying in from a third party. All three are described in detail below. The GuardGrid application (app) uses essential cookies for authentication and session management. We do not use cookies for advertising, and we do not sell or share personal information for cross-context behavioral advertising.
Consent comes first, with stated exceptions
Only strictly necessary cookies are set before you choose, and the only third parties that
load before you choose are the two named in this section: the Cal.com scheduler on
/book-demo and Google reCAPTCHA on /contact.
Each loads on one page only, each is what that page exists to do, and neither is used to
profile you or to advertise to you. Our own live chat also loads on every page before you
choose; it is run by Revion Solutions, Incorporated rather than a third party, it sets no cookies, and it
is described below. Everything else, analytics included, stays switched off until you
grant that category in our cookie banner. We implement Google Consent Mode v2,
which means analytics, advertising, and personalization storage all start in a
denied state on every visit. If you decline, or simply never choose, no
analytics script is loaded at all and no analytics cookies are set. Your choice is
remembered in a necessary cookie named gg_consent for 180 days and is
reapplied on your next visit.
Scheduling on our demo page (Cal.com)
/book-demo exists for one purpose: to let you book a demo. The page does not function without the booking calendar, so we classify that calendar as strictly necessary and load it for every visitor, on first paint, before and regardless of any choice you make in the cookie banner, including if you reject everything optional. It is not in the Functional category and there is no way to switch it off while still using the page. If you would rather not load it at all, email us at info@revion.com or use the contact form instead and we will arrange a time by hand.
The calendar is served from app.cal.com inside an iframe. We measured what it
loads on this site, on a first visit with no consent cookie present. It contacts
app.cal.com and cal.com, and its frame loads exactly one third
party of its own: Sentry (ingest.us.sentry.io), which Cal.com
uses for error reporting. No advertising, social, product-analytics, or session-replay
service is loaded. It sets the following cookies on the cal.com domain, which
are set by Cal.com and are not readable by us:
| Cookie | Provider | Duration | Purpose |
|---|---|---|---|
__cf_bm | Cal.com (Cloudflare) | 30 minutes | Bot-management token that distinguishes automated traffic from a real visitor. |
__Secure-next-auth.csrf-token | Cal.com | Session (cleared when you close the browser) | Cross-site request forgery token for the booking form. |
__Secure-next-auth.callback-url | Cal.com | Session (cleared when you close the browser) | Return address used if the widget needs a sign-in step. |
Cal.com processes booking details as described in its Privacy Policy. The name, email address, and any notes you type into the calendar go to Cal.com and to us, in order to create the meeting. We chose this provider over the alternatives specifically because its booking frame loads one third party rather than a dozen, and we re-measure that when we change the page.
Bot protection on our contact form (Google reCAPTCHA)
/contact loads Google reCAPTCHA v3 to keep the form from being
abused, and it loads for every visitor before any consent choice, for the same reason: the
form is not safe to operate without it. reCAPTCHA contacts www.google.com and
www.gstatic.com. It is governed by Google’s
Privacy Policy
and Terms of Service,
and Google may set its own cookies on Google domains in the course of scoring the request.
We use the score only to accept or reject a submission.
You can change or withdraw your consent at any time using the link in our footer. Withdrawing consent stops further collection; to remove cookies already stored, clear them in your browser.
Live chat on every page
Every page of this site carries a live chat. It is operated by Revion Solutions, Incorporated, the company behind GuardGrid, and it is our own service rather than a third party's: it is served from chat.revion.com and talks to chat-api.revion.com and chat-ws.revion.com. Like the booking calendar, it loads for everyone as soon as a page opens, before and regardless of any answer to the cookie banner, because a chat that waited for an answer would not be there when somebody needed it.
The chat sets no cookies. It writes nothing to your browser and opens no chat connection until you open the chat. Until then, the page only loads the chat button and its settings from our server. When you open the chat, it keeps two random identifiers in your browser's local storage, one for the conversation and one for the browser, so that a chat survives a page reload and a returning visitor can be told from a new one, together with a marker recording whether a chat is still in progress. Neither identifier is used for advertising, and the chat loads no analytics or tracking product of any kind.
An AI assistant answers first. Conversations may be reviewed by Revion staff, and while a member of staff is handling your chat they can also see what you are typing before you send it, so that they can begin on an answer.
When you ask for a person, the chat asks for your first name, last name and email address, and optionally your telephone number and your company. For every chat, whether or not you ask for a person, we record the IP address you are connecting from, your approximate location (country, region and city), your browser and device type, and the page the chat started on. We use those to send the conversation to the right team, to protect the service from abuse, and to improve it. A visitor who abuses the chat may be blocked, both by browser and by IP address.
We keep chat transcripts for 365 days. Aggregated statistics, which contain no message text, are kept for up to two years. To ask for a copy of your chat data or for it to be deleted, email info@revion.com.
Analytics cookies we use
When you grant the Analytics category, we use Google Analytics 4 to understand how visitors use the site in aggregate, such as which pages are read and how people arrive. It sets the following first-party cookies:
| Cookie | Provider | Duration | Purpose |
|---|---|---|---|
_ga | Google Analytics | 2 years | Distinguishes one visitor from another so visits can be counted, without identifying you personally. |
_ga_HGM9EM8EHE | Google Analytics | 2 years | Keeps track of the current session for this property so a single visit is not counted twice. |
These are the same cookies listed in the Analytics section of our cookie preference center. Google Analytics is configured conservatively: Google Signals is disabled, advertising personalization signals are disabled, and IP addresses are anonymized by Google Analytics 4 by default, a default we do not override. We do not use Google Analytics data for advertising or remarketing. Google processes this data as described in its Privacy Policy, and you can also opt out at the browser level with the Google Analytics opt-out add-on.
What we do not send to analytics
Our analytics measures page views and standard form interactions only. When you use the contact form or the free-scan bar, analytics may record that a form was started or submitted, along with the form’s identifier and the destination page. The contents of form fields are never sent to Google. That means no name, no email address, no phone number, no organization, no message text, and no website address you enter into the scan bar. We do not send any custom event containing personal information, and nothing you type is used as an analytics parameter.
9. Data Processing Agreements and subprocessors
Customers processing personal data through the Services may request a Data Processing Agreement (“DPA”) and notices of updates to subprocessors. Submit requests to info@revion.com.
10. California resident rights (CCPA / CPRA)
California residents may request access to, deletion of, and correction of personal information, and disclosure of the categories of personal information collected. Residents may also opt out of the sale or sharing of personal information. We do not sell or share personal information for cross-context behavioral advertising. We will not discriminate against you for exercising these rights, and we may verify your identity before responding. Submit requests to info@revion.com.
11. GDPR and international privacy rights
Where the GDPR or similar laws apply, you may have rights including access, rectification, erasure, portability, restriction of or objection to processing, and withdrawal of consent. We process personal data only where a lawful basis exists: contract performance, legitimate interest, consent where required, or compliance with a legal obligation. Submit requests to info@revion.com.
12. Changes to this policy
We may update this Privacy Policy periodically. Material changes will be communicated by posting a revised version with a new effective date.
13. Contact
Questions about this policy or our data practices? Email info@revion.com or write to Revion Solutions, Incorporated, 184 South Livingston Ave, STE 9 #306, Livingston, NJ 07039.
This policy is provided for general information and is not legal advice.