Last updated: August 16, 2026
This Privacy Policy explains how IVRIS Tech handles personal information when you visit ivristech.com, use the public tools at tools.ivristech.com, use the GTM Preflight application at app.ivristech.com, receive an IVRIS email, or contact us (together, the “Services”).
IVRIS Tech is currently operated by Mahesh Sirvi from Pune, Maharashtra, India (“IVRIS,” “we,” “us,” or “our”). For privacy questions or requests, email hello@ivristech.com.
1. The short version
- We collect the information needed to provide the feature you choose, such as your work email, account details, campaign scope, public URLs, standards, findings, comments, and reports.
- The UTM Linter and Source/Medium Normalizer process pasted campaign data in your browser. That campaign data is not uploaded to IVRIS by those two tools.
- The Web Form Audit sends the public URL you choose to our scanning service. It does not log in to your CRM or submit your form. Temporary audit results expire after seven days.
- The authenticated GTM Preflight workspace stores the campaign and report information you choose to save.
- We use a small set of infrastructure, email, hosting, and privacy-limited analytics providers identified below. We do not sell personal information.
- The UTM Linter and Source/Medium Normalizer downloads are created immediately in your browser. They do not ask for or collect an email address.
- You can ask to access, correct, export, or delete your personal information by emailing us.
2. Our role
IVRIS is the controller of account, website, support, billing, and product-usage information that we decide to collect for our own Services.
When an organisation places Customer Content in a workspace to assess its own campaigns, that organisation may be the controller of personal information in that content and IVRIS acts as its service provider or processor. Customers are responsible for having authority to submit that information and for giving any notices required to their users or contacts. A data processing addendum is available for a paid customer when required; contact us before sharing regulated personal data.
3. Information we collect
Information you provide
- Account and access information: work email address, authentication events, workspace membership, role, and plan or access status.
- GTM Preflight content: workspace, campaign and project names; public landing-page and campaign URLs; selected channels; campaign standards; launch dates; check results; evidence; finding status, owner, due date, comments, resolution notes; and saved reports or exports.
- Public-tool information: the public URL submitted to the Web Form Audit, technical observations produced by the check, and an email address only when you ask us to deliver a Web Form Audit report by email.
- Commercial and support information: name, work email, organisation, selected plan, message, and information included in an access, support, billing, security, partnership, or contact request.
- Editorial information: newsletter details, comments, or guest-post material if you choose to submit them.
Please do not submit passwords, access tokens, payment-card data, government identifiers, health data, special-category or sensitive personal data, private internal URLs, or personal information that is unnecessary for the check.
Information collected automatically
Our hosting and security systems may receive IP address, request time, browser and device type, requested route, response status, security signals, and similar technical information. Short-lived rate-limit records use an IP address or anonymous identifier to prevent abuse. We do not put campaign URLs, email addresses, pasted CSV contents, or free-text Customer Content into product analytics events.
The main WordPress website offers optional Google Analytics 4, delivered through Google Tag Manager, to understand aggregate traffic, content use, enquiries, newsletter signups, and campaign attribution. We do not load Google Tag Manager or Google Analytics and do not send measurement requests to them before a valid stored or current explicit analytics choice. Choosing Accept analytics grants analytics storage only; advertising storage, advertising user data, and advertising personalization remain denied. Public tool pages use a randomly generated, hashed anonymous identifier stored in browser local storage and send a limited set of allow-listed product events to PostHog. The authenticated app uses memory-only PostHog analytics with allow-listed event names and closed-value properties; it does not attach your email, campaign name, URL, report text, or comments to those events. Product analytics uses no session recording or advertising-pixel data.
4. How each product surface handles data
UTM Linter and Source/Medium Normalizer
Pasted or uploaded campaign data is evaluated in your browser and is not uploaded to IVRIS by these two tools. Their Review-Ready CSV and full-audit CSV downloads are generated immediately in your browser. No email address or account is required for those downloads.
Web Form Audit
We receive the public URL you submit and use an isolated browser service to inspect the public page and its form-related technical evidence. We do not use your credentials, access your CRM, fill or submit the form, or confirm CRM receipt. The audit job and result expire after seven days. If you request email delivery, the related email-delivery record expires after 30 days.
GTM Preflight application
We store the account, workspace, campaign scope, standards, runs, findings, comments, ownership information, and reports that authorised users create or save. Tenant access is restricted through account authentication and row-level database policies. Reports saved from a temporary Web Form Audit become durable workspace records and do not inherit the public seven-day expiry.
Saved Customer Content remains until an authorised user deletes it, the account or workspace is closed, or you ask us to delete it, subject to backup, security, dispute, and legal-record needs. Self-service account deletion is not yet available; email hello@ivristech.com for closure or deletion.
5. Why we use information
We use information to:
- create and authenticate accounts and preserve the route you intended to visit;
- run the requested check, save workspace records, generate reports and exports, and deliver requested emails;
- provide onboarding, support, security, billing, and service communications;
- protect the Services, enforce rate limits, investigate failures or abuse, and maintain reliability;
- understand feature usage through limited analytics and improve the Services;
- respond to contact, partnership, editorial, and commercial requests;
- send optional marketing only where you have chosen to receive it or another lawful basis permits it; and
- comply with law, protect rights, and establish or defend legal claims.
6. Legal bases
Where a legal basis is required, we rely on:
- Contract or steps before a contract to provide an account, requested tool, report, support, onboarding, or paid Service;
- Legitimate interests to secure and operate the Services, prevent abuse, diagnose failures, measure privacy-limited product use, improve the product, and respond to business inquiries, balanced against your rights;
- Consent for optional marketing or another use where consent is requested; you may withdraw it at any time; and
- Legal obligations and legal claims where processing is required by law or reasonably needed to protect rights.
7. Service providers and disclosures
We use service providers only for defined operational purposes. Current main providers include:
- Cloudflare: content delivery, security, Workers, queues, key-value storage, rate limiting, and isolated browser execution for the Web Form Audit;
- Supabase: account authentication and the GTM Preflight database, currently configured in the United States;
- Resend: sign-in, requested-report, and other transactional email delivery;
- PostHog: privacy-limited product analytics using allow-listed events without Customer Content or direct account identifiers;
- Hostinger and WordPress: hosting and operating the main website and editorial pages;
- Google: Google Tag Manager, Google Analytics, and font delivery on relevant public pages; and
- FormSubmit: delivery support for messages submitted through the main website contact flow.
We may also disclose information to professional advisers, authorities, or other parties when reasonably necessary to comply with law, protect rights or safety, investigate fraud or security issues, or complete a genuine financing, reorganisation, merger, or sale. If a business transfer occurs, we will require the recipient to continue protecting personal information under this Policy or provide notice of a material change.
We do not sell personal information. We do not use product or tool data for cross-context behavioural advertising. We do not give Customer Content to data brokers.
8. Retention
- UTM Linter and Source/Medium input and CSV: handled in your browser; IVRIS does not create a server-side delivery record for these downloads.
- Web Form Audit job and temporary result: seven days.
- Web Form Audit email-delivery record: 30 days.
- Rate-limit records: generally between 20 minutes and two hours, depending on the endpoint.
- Authenticated account and saved workspace data: until deleted, the account or workspace is closed, or deletion is requested, subject to reasonable backup, security, dispute, and legal-record requirements.
- Support and commercial correspondence: for as long as reasonably needed to resolve the request, maintain business records, and establish or defend claims.
- Optional marketing contact: until you unsubscribe, object, or ask us to delete it, with a minimal suppression record retained where needed to honour the choice.
- Tax, order, and payment records: for the period required by applicable law after paid ordering begins.
Backups and provider logs may take additional time to cycle out. During that period, they are isolated from ordinary product use and retained only for recovery, security, or legal purposes.
9. Cookies and browser storage
The authenticated application uses secure session mechanisms needed to keep you signed in. Public tools may store a hashed anonymous analytics identifier and short-lived interface preferences in local or session storage. On the main website, the first-party ivt_analytics_consent_v1 cookie stores whether optional analytics was granted or denied for up to 180 days across ivristech.com and its subdomains. Only after analytics consent, the first-party ivt_attr_v1 cookie may retain first- and last-touch campaign attribution for up to 90 days, alongside Google Analytics cookies.
You can decline or change your choice at any time using Analytics settings. Declining or revoking optional analytics clears the attribution and Google Analytics cookies that this website can delete and prevents Google tags from loading on later pages; it cannot undo requests already sent while consent was active. If your browser sends a Global Privacy Control signal, optional analytics stays off and a previous stored grant is replaced with a denied choice, so a fresh explicit acceptance is required after the signal is removed. You can also block or clear browser storage in your browser. Essential authentication may not work if required cookies are blocked. Product checks and account access do not depend on advertising cookies. See Google’s Privacy Policy for its handling of Analytics data.
10. Security
We use measures designed for the current service, including encrypted network transport, secure and HTTP-only app session cookies, strict same-origin account access, separate public-tool and authenticated-app domains, tenant-scoped database access with row-level security, least-authority service credentials, restricted analytics event schemas, rate limits, and time-limited public audit records.
No internet service can guarantee absolute security. Use a work email you control, protect sign-in links and codes, submit only the information needed for a check, and contact hello@ivristech.com promptly if you suspect a security or privacy issue.
11. International processing
IVRIS operates from India, while several providers process information through infrastructure in the United States and other countries. Those countries may have different privacy laws. Where required, we use contractual or other lawful safeguards provided by the relevant service arrangement and applicable law. Contact us if your organisation needs transfer or data-processing details before using paid Services.
12. Your choices and rights
Depending on your location and the context, you may have rights to:
- ask whether we hold personal information about you and obtain a copy;
- correct inaccurate or incomplete information;
- delete information or close an account;
- restrict or object to certain processing;
- receive portable information where applicable;
- withdraw consent without affecting earlier lawful processing;
- unsubscribe from marketing; and
- raise a grievance or complain to the privacy authority available in your jurisdiction.
Email hello@ivristech.com with the subject “Privacy request.” We may need to verify your identity and authority before acting. If your organisation controls the relevant workspace data, we may direct the request to that organisation or work with it to respond. We will not discriminate against you for exercising a privacy right.
13. Third-party information submitted by customers
Campaign URLs, CRM-import data, form-field names, comments, or other Customer Content may refer to other people. The customer submitting that information is responsible for determining whether it is necessary and lawful, giving required notices, and responding to those individuals. IVRIS does not use that information to contact or profile those people.
14. Children
The Services are for business users and are not directed to children. We do not knowingly collect personal information from anyone under 18. Contact us if you believe a child has provided personal information so we can investigate and delete it where appropriate.
15. Changes to this Policy
We may update this Policy when the Services, providers, or legal requirements change. We will post the new date and provide reasonable notice of a material change where appropriate. We will not use previously collected information for a materially incompatible new purpose without an appropriate legal basis and notice.
16. Contact and grievances
Ivris Tech
Operated by Mahesh Sirvi
Pune, Maharashtra, India
Email: hello@ivristech.com
Contact page: https://ivristech.com/contact/
Use the subject “Privacy grievance” if you are unhappy with how a request was handled. We will review and respond in accordance with applicable law. You may also contact the relevant data-protection authority in your jurisdiction.
Services proposal intake
Services intake privacy update: .
When you submit a Services proposal request, we collect the name, work email, optional organisation and website, selected service or services, problem or constraint, context, and consent acknowledgement that you choose to provide. The form does not subscribe you to marketing, and Services enquiry text is not sent to Google Analytics.
WordPress records the submitted enquiry in encrypted form and commits an encrypted notification job at the same time. A confirmation means that the request was recorded for review; it does not promise a response time or that IVRIS will accept the proposed work. Hostinger and WordPress host and operate the encrypted Services enquiry and notification queue. Zoho Mail delivers the operational notification to an IVRIS-controlled mailbox.
Services proposal retention
The encrypted WordPress enquiry record is retained for up to 90 days. The encrypted queue payload is erased after confirmed mail handoff. A failed or dead-letter encrypted queue payload is retained for no more than 30 days, and non-content delivery status is retained for up to 30 days.
The notification email delivered through Zoho Mail is commercial correspondence and is retained under this policy’s existing rule that information is kept only for as long as reasonably needed. It is not covered by the 90-day encrypted WordPress-record limit. You may request deletion or exercise a privacy right by emailing hello@ivristech.com; no mailbox-deletion response time is promised here.
Duplicate-prevention fingerprints expire after 24 hours and are purged within 48 hours. Rate-limit keys contain keyed hashes rather than submitted email addresses or raw IP addresses, expire with their enforcement windows, and are purged within 24 hours. Encrypted Services enquiry records may remain in rotating hosting backups until those backups expire and are not restored for ordinary business use.