Privacy Policy

Effective date: April 25, 2026

1. Introduction

Dravow LLC (“Dravow,” “we,” “us,” or “our”) operates the Dravow platform (dravow.com), a service that connects powersports ambassadors with brands for sponsorship and affiliate marketing. This Privacy Policy explains what information we collect, how we use it, and the choices you have. By using Dravow, you agree to the collection and use of information in accordance with this policy.

Data Controller

Dravow LLC
1652 Petersburg Dr
Chubbuck, ID 83202
United States
support@dravow.com

2. Information We Collect

Account information

When you register, we collect your name, email address, and password (stored as a secure hash). Business users also provide a company name. This information is used to create and manage your account.

Profile information

Ambassadors may provide a display name, profile image, biography, location, riding disciplines, and links to social media profiles. Businesses may provide a company description, logo, industry category, and sponsorship criteria. This information is used to power your public profile and the platform’s discovery features.

Social media data

When you connect a social account (Instagram, TikTok, YouTube, Facebook), we request read-only access to your public channel or profile data. We store OAuth access tokens (encrypted at rest using AES-256) to periodically sync this data. We do not post to your accounts and do not access private messages. See Section 5 below for platform-specific details about Instagram and Meta.

Application and messaging data

We store the content of applications and messages sent between ambassadors and businesses on the platform. This content is visible to both parties in the conversation and to Dravow for support and safety purposes.

Payment information

Subscription payments are processed by Stripe. We do not store your full payment card details — only a reference to your Stripe customer record and subscription status. Stripe’s privacy policy governs how your payment data is handled.

Usage data

We may collect information about how you interact with the platform, including pages visited, features used, and actions taken. This helps us improve the Service.

3. How We Use Your Information

Dravow is a multi-sided marketplace. Ambassadors connect their social media accounts so brands can evaluate them as potential sponsorship partners, and brands access ambassador performance data to make sponsorship decisions and track affiliate program results. We use the information we collect to:

  • Create and manage your account and provide access to the Service.
  • Calculate and display your Dravow Ambassador Score (DAS) based on synced social media statistics, so brands can evaluate ambassadors for sponsorship opportunities.
  • Display ambassador performance metrics (such as follower counts, engagement rates, and reach) to brand users on the platform, so brands can make informed sponsorship decisions.
  • Enable ambassadors and businesses to discover each other and exchange applications for sponsorships and affiliate partnerships.
  • Process subscription payments and manage billing.
  • Attribute affiliate sales to ambassadors and calculate commissions.
  • Send transactional emails such as application status updates, account notifications, and receipts.
  • Respond to support enquiries and resolve disputes.
  • Detect and prevent fraud, abuse, and violations of our Terms of Service.
  • Improve, personalise, and develop new features for the platform.

4. How We Share Your Information

We do not sell your personal information. We share your information only in the following circumstances:

  • With other platform users, as necessary to facilitate applications and partnerships. Specifically, ambassador profile data and synced social media metrics (including Instagram performance data) are visible to brand users browsing the Dravow platform for sponsorship purposes.
  • With service providers who assist us in operating the platform, including Stripe (payments), Supabase (database hosting, located in the United States), Vercel (cloud infrastructure), Resend (transactional email), Inngest (background jobs), and Upstash (caching). These providers are contractually bound to protect your data.
  • If required by law, court order, or governmental authority.
  • In connection with a merger, acquisition, or sale of assets, in which case users will be notified.

We do not share your data with advertisers and do not use your data for advertising purposes.

5. Meta and Instagram Integration

Dravow integrates with Meta’s Instagram Graph API so ambassadors can authorize Dravow to access their Instagram professional account data. This integration is the basis for displaying ambassador reach and engagement to brand users for sponsorship decisions.

What we access

When an ambassador connects their Instagram account through Meta’s secure OAuth flow, Dravow requests the following permissions:

  • instagram_business_basic — grants access to: account ID, username, account type, profile picture URL, follower count, follows count, media count, name, biography, website, and the user’s media (post ID, caption, media type, media URL, permalink, thumbnail URL, and timestamp).
  • instagram_business_manage_insights — grants access to account-level insights including reach, profile views, and accounts engaged over a 28-day window, as well as media-level insights including impressions, reach, engagement, saves, and video views.

We do not request, receive, or store private messages, comments authored by other users, or data about followers’ identities.

How we use Instagram data

Instagram data is used solely to (a) calculate the Dravow Ambassador Score, (b) display the ambassador’s current performance metrics on their Dravow profile so brands can evaluate them for sponsorship, and (c) provide ambassadors with their own performance dashboard. Instagram data is not used for advertising, not shared with third parties beyond what is necessary to operate the platform, and not sold.

Storage and retention

Current Instagram values (latest follower count, latest profile fields, latest media list) are kept for as long as the ambassador’s Instagram account remains connected to Dravow. Each periodic sync overwrites the previous values.

Historical performance snapshots (time-series records used to display growth trends, e.g., follower count over time) are retained for up to 13 months. Snapshots older than 13 months are automatically deleted by a scheduled job.

When you disconnect or delete

When an ambassador disconnects their Instagram account from Dravow, the OAuth access token is revoked and deleted immediately, and all current Instagram data is removed from the ambassador’s profile within 30 days. Historical performance snapshots associated with that account are also deleted within 30 days.

If an ambassador deletes their Dravow account entirely, all Instagram data associated with that account (current and historical) is deleted within 30 days.

Meta-initiated deletion

Dravow honors data deletion requests initiated by Meta on behalf of users. Meta can submit a signed deletion request to https://www.dravow.com/api/auth/instagram/deletion, and Dravow will delete the corresponding user’s Instagram-derived data within 30 days. See Section 10 for the user-facing deletion request process and visit /data-deletion for full instructions.

Compliance

Dravow’s use of Instagram data is governed by Meta’s Platform Terms and Developer Policies. Nothing in this Privacy Policy overrides those terms.

6. Third-Party Store Integrations

Dravow connects with third-party e-commerce platforms so brands can operate affiliate programs through their existing online stores. Currently, we integrate with Shopify; additional platforms may be added in the future.

Shopify integration

When a brand connects their Shopify store to Dravow, they authorize us (via Shopify’s OAuth flow) to read order and product data from their store. We receive webhook notifications when paid orders are placed, and we read the discount codes used on those orders to attribute sales to ambassadors.

What we store

We store only the information necessary to attribute affiliate conversions: order identifier, order value, discount code, and the commission earned by the associated ambassador. We do not store customer-identifying information such as customer names, email addresses, shipping addresses, phone numbers, or payment details. Customer data exists in the brand’s Shopify account; Dravow does not retain or replicate it.

How we use it

This information is used solely to calculate and display commission earned by ambassadors and to provide brands with affiliate program analytics (gross sales attributed, conversion counts, commission owed). It is not used for advertising or shared with third parties beyond what is required to operate the platform.

When a brand disconnects

When a brand uninstalls Dravow from their Shopify store or manually disconnects, we immediately revoke the stored OAuth access token and remove the store connection from our systems. Historical affiliate conversion records are retained for bookkeeping and ambassador payout records, as described in the Data Retention section.

7. Data Retention

Account and profile data: retained for as long as your account is active. If you delete your account, we will delete or anonymise your personal information within 30 days, except where we are required to retain it for legal or compliance purposes.

Social media OAuth tokens: deleted immediately when you disconnect a social account.

Instagram historical performance snapshots: retained for up to 13 months, then automatically deleted (see Section 5).

Affiliate conversion records: retained as long as necessary for bookkeeping and ambassador payout records.

8. Data Security

We take reasonable technical and organisational measures to protect your information from unauthorised access, alteration, disclosure, or destruction. OAuth access tokens for connected social accounts are encrypted at rest using AES-256. Passwords are hashed and never stored in plain text. All data is transmitted over HTTPS. Data is stored on infrastructure located in the United States.

No method of transmission or storage is 100% secure. If you become aware of a security concern, please contact us at support@dravow.com.

9. Cookies and Tracking

We use essential cookies to maintain your login session and to support security features such as CSRF protection during OAuth flows. We do not use tracking cookies for advertising purposes, and Dravow does not run advertising or analytics trackers on its website. You can control cookies through your browser settings; however, disabling essential cookies will prevent you from logging in.

10. Your Rights and Choices

Depending on your location, you may have the right to:

  • Access a copy of the personal information we hold about you.
  • Correct inaccurate or incomplete information.
  • Request deletion of your account and associated personal data, including all Instagram data we have synced.
  • Withdraw consent for social account data syncing by disconnecting the account at any time from your Dravow account settings.
  • Object to or restrict certain processing of your data.
  • Lodge a complaint with a supervisory authority if you believe your rights have been violated.

To request data deletion, you have three options:

  1. Self-service: Disconnect Instagram from your Dravow account settings, or delete your Dravow account entirely from settings. Both actions trigger automatic deletion of associated data within 30 days.
  2. Email request: Email support@dravow.com from your registered email address with the subject ‘Data Deletion Request.’ We will confirm receipt within 5 business days and complete deletion within 30 days.
  3. Detailed instructions: See /data-deletion for full instructions and the Meta-initiated deletion endpoint.

We will respond to all rights requests within 30 days.

Residents of California (CCPA), the European Economic Area, the United Kingdom, and other jurisdictions with comparable laws have the rights described above as a matter of law. Dravow extends these rights to all users regardless of jurisdiction.

11. Children’s Privacy

Dravow is not directed at children under the age of 18. We do not knowingly collect personal information from anyone under 18. If you believe we have inadvertently collected such information, please contact us and we will delete it promptly.

12. Changes to This Policy

We may update this Privacy Policy from time to time. If we make material changes, we will notify you by email or by displaying a prominent notice on the platform before the changes take effect. The updated policy will include a revised effective date at the top of this page.

13. Contact

If you have questions, concerns, or requests regarding this Privacy Policy or how we handle your data, please contact us at:

Dravow LLC
1652 Petersburg Dr
Chubbuck, ID 83202
support@dravow.com