Privacy

Dryvn AI — Privacy Policy

Last updated: 2026-09-25

Dryvn AI Inc. ("Dryvn," "we," "us," "our") is a British Columbia corporation (BC1583686). This Privacy Policy explains what personal information we collect, how we use it, who we share it with, and the choices you have.

It is written to meet Canada's Personal Information Protection and Electronic Documents Act (PIPEDA), British Columbia's Personal Information Protection Act (PIPA), Canada's Anti-Spam Legislation (CASL), and the United States text-messaging requirements that apply to our messaging program (TCPA, the CTIA Messaging Principles and Best Practices, and A2P 10DLC).

Quick summary of the things people ask about most

  • We do not sell personal information.
  • We never share mobile opt-in data or SMS consent with anyone for their own marketing. See Section 5.
  • You can stop our texts at any time by replying STOP, and get help by replying HELP.
  • Message frequency varies. Message and data rates may apply.
  • Your business data belongs to you. We process it to run the service you asked us to run.

1. Who this policy applies to

This policy applies to:

  • Account holders — the businesses and individuals who sign up for Dryvn and the team members they invite.
  • Website visitors — anyone who visits our web properties.
  • End customers of our account holders — the clients, crew members, and contacts whose information a Dryvn account holder puts into the platform, and whose text messages Dryvn sends and receives on that account holder's behalf.

That third group matters, so we will be direct about it. When a contractor uses Dryvn to text their customer about a job, the contractor is the business that holds the relationship and the consent, and Dryvn processes that information on the contractor's instructions. In PIPEDA terms, the account holder is accountable for the personal information it puts into Dryvn; Dryvn acts as its service provider. If you received a text from a business that uses Dryvn and you want your information removed, the fastest route is to reply STOP (which stops messages immediately and permanently until you opt back in) and to contact that business directly. You can also contact us at privacy@dryvn.ca and we will route the request to the account holder and assist.

2. Information we collect

2.1 Information you give us

  • Account information — first and last name, business name, email address, trade or industry, and team size.
  • Mobile phone number — see Section 4.
  • Authentication data — the sign-in identifier from Firebase Authentication (Google sign-in or email/password). We do not store your password.
  • Billing information — handled by Stripe. Dryvn does not receive or store full card numbers.
  • Business records you create — jobs, clients, sites, crew, schedules, estimates, invoices, expenses, documents, and photos.
  • Messages — the content of text messages and emails sent and received through the platform.
  • Support correspondence — what you send us when you contact support.

2.2 Information about your end customers

When you use Dryvn to run your business, you supply information about your own clients and crew: names, phone numbers, email addresses, service addresses, job history, and the content of messages exchanged with them. We process this to deliver the service to you.

2.3 Information collected automatically

  • Technical and log data — IP address, timestamps, device and browser information, and application logs needed to operate, secure, and debug the service. Phone numbers in our operational log lines are stored in hashed form.
  • Consent records — for every SMS opt-in and opt-out we record the date and time, the source, the exact consent wording that was shown, the phone number, the consent type (transactional or marketing), and, for web opt-ins, the IP address.
  • Website analytics — on our public website, optional analytics records page visits and limited interaction events only after you select “Accept analytics.” You can change this choice at any time using “Privacy choices” in the footer.

2.4 Information we do not collect

We do not run advertising pixels or third-party marketing tags on our application. Optional analytics on the public website is controlled by the privacy choice described above. We do not collect government identification numbers, biometric data, or precise device location.

3. How we use information

  • To provide the service — running jobs, crews, scheduling, estimates, invoices, expenses, documents, and the messaging that ties them together.
  • To send the messages you or your account holder asked for.
  • To authenticate you and keep accounts secure.
  • To process payments and manage subscriptions.
  • To provide support and respond to your questions.
  • To monitor, debug, and improve reliability and safety of the platform.
  • To keep the records that consent and financial rules require us to keep.
  • To meet legal obligations and enforce our Terms of Service.

We do not use your business data or your end customers' messages to train general-purpose AI models, and we do not sell personal information to anyone.

4. Our text-messaging program

This section describes the messages Dryvn sends to you, the account holder. Messages you send to your own customers through Dryvn are governed by your own consent practices and by Section 7 of our Terms of Service.

4.1 What the program is and who it is from

Messages come from Dryvn AI and relate to your Dryvn account and the business operations you run in it.

4.2 What messages you will receive

  • Account and service (transactional) messages — job updates, crew and schedule notifications, estimates, invoices, payment reminders, security and account notices, and replies to commands you text us.
  • Marketing and promotional messages — product news, tips, and offers — only if you separately opted in to those.

4.3 How we obtain consent

Consent is express and it is recorded.

  • At signup, mobile messaging consent is presented as two separate checkboxes — one for account/service messages, one for marketing messages. Neither is checked by default, and SMS consent is never a condition of creating or using a Dryvn account.
  • By invitation, a team member follows a personal link, reads the consent page, and must explicitly accept before any phone number or messaging opt-in can be submitted. Simply opening the link does not grant consent.
  • Every opt-in and opt-out is written to a consent record with a timestamp, the exact wording shown, and the source, and every change is appended to an immutable consent audit trail.

4.4 Frequency, rates, and how to stop

  • Message frequency varies, based on your account activity and the notifications you have enabled.
  • Message and data rates may apply. Dryvn does not charge you for receiving a text; your mobile carrier may.
  • To stop: reply STOP to any message. STOP is an opt-out, not a pause — we stop sending, and our system blocks further sends to that number until you opt back in. UNSUBSCRIBE, CANCEL, END, and QUIT are handled the same way.
  • To get help: reply HELP, or email support@dryvn.ca.
  • To resume: reply START.
  • Carriers may also apply their own filtering. Opt-out handling is enforced in our sending path, so it cannot be bypassed by a retry.

5. SMS opt-in data is never shared or sold

Mobile information, SMS opt-in data, and consent are never sold, rented, or shared with any third party or affiliate for that third party's own marketing or promotional purposes.

This exclusion applies to every other sharing category described in this policy. Information may be disclosed to subcontractors and service providers that perform support services for us — for example, the telecommunications provider that physically delivers a message — strictly so that we can operate the service you asked for, and under contract. No mobile opt-in information or consent data is shared for marketing.

We also do not sell personal information of any kind.

6. How your messages are processed by AI

Dryvn is an AI-operated platform, so we will be specific about what that means.

  • When a text message arrives, its content is sent to Google's Vertex AI service inside our own Google Cloud project so a model can understand the request and produce a reply.
  • The models we use are Google Gemini and Anthropic Claude, both accessed through Google Cloud Vertex AI under Google Cloud's terms — not through consumer AI products.
  • What is sent is the message content and the limited business context needed to answer it (for example, the job or client the message refers to).
  • Your data is not used to train these models. Google Cloud does not use Vertex AI customer data to train its foundation models.
  • Vertex AI processing may occur in Google data centres outside Canada, including in the United States. See Section 8.

If you would prefer that a particular conversation not run through the AI pipeline, contact support@dryvn.ca — but note that AI processing is how the core product works, so this may limit what the service can do for you.

7. Who we share information with

We share personal information only with service providers who need it to run Dryvn, under contract, and only for the purposes described here. Subject always to Section 5, our processors and sub-processors are:

Always in use

  • Google Cloud Platform — Application hosting, database, file storage. Receives: All application and business data.
  • Google Vertex AI — AI processing of messages and requests. Receives: Message content and related business context.
  • Google Firebase — Authentication and web hosting. Receives: Sign-in identifiers, email address.
  • Twilio — Sending and receiving text messages. Receives: Phone numbers and message content.
  • Stripe — Payment and subscription processing. Receives: Billing details, payment method (held by Stripe).
  • Google Workspace (Gmail) and SendGrid — Email delivery. Receives: Recipient email addresses and email content.

In use only if you connect them

These are optional integrations. Nothing flows to them unless you authorize the connection from inside your account, and you can disconnect at any time.

  • Intuit QuickBooks Online — Accounting sync. Receives: Customers, invoices, payments, expenses.
  • Zoho — CRM sync. Receives: Contact and business records.
  • Google Calendar — Scheduling sync. Receives: Appointment and schedule data.
  • Microsoft (Outlook, Calendar, SharePoint/OneDrive) — Email, calendar, and file sync. Receives: Messages, appointments, files you sync.
  • Plaid (Dryvn Life) — Bank account connection. Receives: Financial account and transaction data.
  • Spotify (Dryvn Life) — Media connection. Receives: Listening activity.
  • ElevenLabs — Voice features, where enabled. Receives: Voice audio.

We may also disclose information where required by law, to respond to a valid legal request, to protect the rights or safety of Dryvn or others, or in connection with a merger, acquisition, or sale of assets — in which case we will give notice as required and the receiving party remains bound by this policy.

We do not share information with data brokers, advertising networks, or affiliates for their own purposes.

8. Where your information is processed

Dryvn is a Canadian company. Our infrastructure runs on Google Cloud in the us-west1 region (Oregon, United States), and our service providers — Google Cloud, Google Vertex AI, Firebase, Twilio, Stripe, and the optional integrations above — process and store data on infrastructure located in the United States and, for some providers, in other countries.

By using Dryvn you understand that your personal information may be processed and stored outside Canada, and that while it is there it may be accessible to the courts, law enforcement, and national security authorities of that country under that country's law. We use contractual and technical safeguards with these providers to protect your information to a standard comparable to what PIPEDA and BC PIPA require. Questions about our use of service providers outside Canada can be directed to the Privacy Officer in Section 14.

9. How long we keep information

  • Account and business records — for as long as your account is active, and for a reasonable period afterward to allow reactivation, resolve disputes, and meet tax and financial record-keeping obligations.
  • SMS consent and opt-out records — kept for a minimum of five years, and in practice indefinitely, because we must be able to prove that an opt-out was honoured. Opt-out records in particular are never deleted; deleting them would put us at risk of messaging someone who asked us to stop.
  • Message content — retained for as long as the associated account and business records are retained.
  • Billing records — as required by financial record-keeping law and by our payment processor.
  • Operational logs — retained on a rolling basis for security and debugging.

Deletion outside these rules is handled as an individual request — see Section 10. We do not currently run automatic bulk deletion on a fixed schedule, and we would rather say so than publish a retention promise we do not keep.

10. Your privacy rights and how to use them

Subject to applicable law, you may:

  • Access the personal information we hold about you and be told how it has been used and who it has been disclosed to.
  • Correct information that is inaccurate or incomplete.
  • Withdraw consent, subject to legal and contractual restrictions and reasonable notice. Withdrawing consent for essential processing may mean we can no longer provide the service.
  • Opt out of marketing at any time — reply STOP to texts, or use the unsubscribe link in any marketing email. Unsubscribe links stay live for at least 60 days after the message is sent, and we act on them within 10 business days, as CASL requires.
  • Request deletion of your personal information, subject to the records we are required or permitted to keep (notably SMS opt-out records, and financial records).
  • Complain about how we have handled your information.

How to exercise them: email privacy@dryvn.ca or write to the address in Section 14. We will acknowledge your request and respond within 30 days, as PIPEDA requires, or tell you if we need an extension and why. We may need to verify your identity before we act, so that we do not disclose your information to someone else.

If you are not satisfied with our response, you may complain to the Office of the Privacy Commissioner of Canada (priv.gc.ca) or to the Office of the Information and Privacy Commissioner for British Columbia (oipc.bc.ca).

If your information is in Dryvn because a business that uses Dryvn put it there, see Section 1 — contact that business first, and we will help.

11. How we protect information

We use administrative, technical, and physical safeguards appropriate to the sensitivity of the information, including:

  • Tenant isolation. Customer data is separated at the database level by organization, enforced by PostgreSQL row-level security policies rather than by application code alone.
  • Encryption in transit. Traffic to and from our services uses TLS.
  • Encryption at rest. Data stored in Google Cloud is encrypted at rest by Google Cloud's default encryption. In addition, credentials for the optional integrations listed in Section 7 are encrypted at the field level with AES-256-GCM using a key wrapped by Google Cloud KMS.
  • Secret management. Application credentials are held in Google Cloud Secret Manager, not in source code.
  • Access controls. Role-based permission checks govern what each user in an organization can see and do.
  • Audit logging. Significant actions are written to a tamper-evident, hash-chained audit log, and compliance events to an append-only log that cannot be updated or deleted.
  • Consent audit trail. Every consent change is recorded immutably.
  • Breach register. We maintain the record of security-safeguard breaches that PIPEDA s.10.3 requires, whether or not an incident meets the reporting threshold.

What we do not claim. Dryvn does not currently hold SOC 2, ISO 27001, PCI DSS, or HIPAA certification, and we do not describe our security as "bank-level." We also do not currently offer multi-factor authentication on dashboard sign-in. We would rather tell you what we actually have. No method of transmission or storage is completely secure; if a breach creates a real risk of significant harm, we will notify affected individuals and the Privacy Commissioner as PIPEDA requires.

12. Children

Dryvn is a business tool intended for use by adults. It is not directed at children, and we do not knowingly collect personal information from anyone under the age of majority in their province or state. If you believe a child has given us personal information, contact privacy@dryvn.ca and we will delete it.

13. Cookies and similar technologies

We keep this simple: we do not use advertising cookies, analytics trackers, or third-party marketing tags in the Dryvn application.

What we do use:

  • Essential browser storage — Firebase Authentication stores a session token in your browser so you stay signed in. Without it you cannot use the app.
  • Local storage for drafts — some forms save what you have typed locally in your browser so a page reload does not lose it. This stays on your device.
  • Web fonts — some pages load fonts from Google Fonts, which means your browser makes a request to Google to fetch them.

Because we do not run advertising or analytics trackers, there is no tracking cookie to opt out of. You can block or clear browser storage through your browser settings, but signing in will not work without the essential session storage.

14. How to contact us

Dryvn AI Inc. 45235 Mountview Way, Chilliwack, British Columbia, V2R 1T3, Canada

Privacy Officer (access, correction, deletion, complaints): privacy@dryvn.ca
General support and messaging help: support@dryvn.ca

We have a designated Privacy Officer accountable for our compliance with PIPEDA and BC PIPA. Address privacy requests to privacy@dryvn.ca and they will reach that person.

15. Changes to this policy

We may update this policy. When we do, we will change the "Last updated" date at the top and post the new version here. If a change materially affects how we use your personal information, we will give you notice and, where the law requires it, ask for your consent again. Continued use of Dryvn after an update means you accept the revised policy.

Our Terms of Service (/terms) describe the rules for using Dryvn, including your responsibilities as the sender of messages to your own customers.