Legal
Website Privacy Notice
This notice explains how Stevera Technologies, Inc. handles information in connection with this marketing website.
- Effective date
- July 20, 2026
- Last updated
- July 20, 2026
Scope
This Website Privacy Notice ("Notice") describes how Stevera Technologies, Inc. ("Stevera," "we," "us") handles information in connection with the public marketing website at stevera.io (the "Site"): visitors to the Site, and individuals who submit an inquiry through the Site's contact form, along with the communications that result from that inquiry.
This Notice is not necessarily the complete privacy notice governing Stevera OS customer deployments, university-user accounts, athlete-user accounts, banking-partner integrations, financial-product relationships, enterprise customer data, or future mobile or web applications. Those products and relationships are, or will be, governed by separate notices, agreements, and institution-specific requirements — nothing in this Notice should be read as describing those data practices.
Information you provide directly
The Site's contact form asks for your name, work email address, organization, job title, organization type, inquiry type, message, and your agreement that Stevera may contact you regarding the inquiry. The checkbox does not enroll you in newsletters or unrelated marketing. If you correspond with us afterward — by replying to an email, for example — we may receive additional information you choose to include in that correspondence.
Please do not submit sensitive information through the public contact form beyond what it's designed to collect — for example, financial-account details, government identification numbers, passwords, medical information, or student education records. The form is not built or intended to receive that kind of information.
Information collected automatically
When you submit the contact form, our server processes (but does not persistently store in a database) the requesting IP address, in memory, for a short window, solely to apply rate limiting and duplicate-submission detection — protective measures against abusive or repeated automated submissions. This in-memory record does not survive normal server-process turnover and is not written to a database or to our application logs.
Our application logs record only the inquiry type you selected and a randomly generated submission identifier — never your name, email address, organization, or message content.
Vercel, as the Site's hosting and server-execution provider, generates standard operational and security logs that may include IP address, request timestamps, browser or device information, and related technical data.
Resend processes sender and recipient addresses, email content, delivery status, and related message metadata as necessary to deliver the internal inquiry notification and visitor confirmation email. These providers retain information according to their own terms and operational practices. See "Service providers" below.
This website's own code does not set cookies, local storage, or session storage.
Sources of information
We receive information: directly from you, when you submit the contact form or correspond with us; automatically from your browser or device and from the hosting, delivery, and analytics infrastructure described in this Notice; and, occasionally, from a colleague or organization contacting us on your behalf.
How we use information
We use the information described above to: respond to your inquiry; evaluate a requested demonstration, institutional design partnership, banking or strategic partnership, or investor, media, or general inquiry; communicate with you about the topic you raised; operate, secure, and maintain the Site; detect and prevent abuse and duplicate submissions; troubleshoot technical issues; understand aggregate Site usage; maintain appropriate business records; protect our legal rights; and comply with applicable legal obligations.
Legal bases for processing
For visitors in jurisdictions that require a stated legal basis for processing personal information, we rely on one or more of the following depending on the specific processing activity: your consent, where applicable, including your agreement that Stevera may contact you regarding your inquiry; taking steps at your request in connection with a potential business relationship; our legitimate business interests in operating, securing, and understanding use of the Site and in evaluating or pursuing the institutional and business relationships the Site describes; and compliance with our legal obligations. No single legal basis applies to every processing activity described in this Notice.
Service providers
Vercel hosts and deploys the Site, executes its server-side code, and generates operational and security logs in the course of doing so; Vercel also provides the aggregate Web Analytics described below.
Resend delivers the internal inquiry notification to the appropriate Stevera shared inbox and the confirmation email to you, and in doing so processes the sender and recipient addresses and the email content and metadata necessary for delivery.
Google Workspace receives and stores the resulting business-inquiry emails in Stevera's shared inboxes and supports internal collaboration and human follow-up — it is where our team actually reads and replies to your inquiry.
Our domain's authoritative DNS is managed through Cloudflare. Cloudflare is not a form processor and does not receive contact-form content in that role.
Analytics and cookies
Stevera uses Vercel Web Analytics to understand aggregate Site usage. Vercel Web Analytics does not use third-party cookies. It uses an anonymous hash derived from request information for aggregate statistics, and its visitor-session identifier is discarded after 24 hours.
Analytics data may include the page or route viewed, filtered query parameters, referring source, approximate geographic area, browser, operating system, device category, and event timestamp. Stevera does not send contact-form fields, names, email addresses, organizations, messages, or submission identifiers to Vercel Web Analytics.
Stevera does not currently use behavioral-advertising pixels, session replay, browser fingerprinting, or this analytics implementation to track visitors across unrelated websites. We will update this Notice if our analytics or tracking practices materially change.
Transactional email
Submitting the contact form results in two automated emails sent through Resend: an internal notification to the Stevera team (routed to the shared inbox appropriate to your inquiry type, with your work email set as the Reply-To address so our team can reply directly) and a confirmation email to you acknowledging receipt. A Stevera team member may then follow up manually through Google Workspace.
These transactional inquiry emails do not currently use open-tracking pixels or tracked-link rewriting.
Disclosure and sharing
We may disclose information: to the service providers described above, acting on our behalf; within Stevera, to personnel who need it to respond to your inquiry; to our professional advisers where necessary; to comply with legal process or a governmental request; to protect the safety, security, or legal rights of Stevera, our users, or others; in connection with a financing, merger, acquisition, reorganization, or sale of some or all of our business; or at your direction or with your consent.
Sale and targeted advertising
Stevera does not sell personal information. Stevera does not share personal information for cross-context behavioral advertising, and does not use contact-form information for targeted advertising.
Data retention
Stevera retains inquiry and communication information for as long as reasonably necessary to respond to inquiries, maintain appropriate business records, protect our legal rights, resolve disputes, and comply with applicable obligations. Retention periods may vary depending on the nature of the inquiry, the business relationship, and applicable legal requirements.
Security
Stevera uses reasonable administrative, technical, and organizational measures appropriate to the nature of the information involved. No method of transmission or storage is completely secure, and we cannot guarantee that unauthorized access, use, or disclosure will never occur.
If you believe you've found a security issue affecting this Site, please report it to security@stevera.io.
Your privacy choices
Depending on your location and applicable law, you may be able to request access to, correction of, deletion of, or restriction on our use of your personal information, object to certain processing, withdraw previously given consent, or request a copy of certain information. To make a request, contact privacy@stevera.io. We may need to verify your identity before completing a request, and not every listed right will apply to every individual or every jurisdiction.
Children's privacy
This Site is intended for institutional, business, and professional audiences. It is not directed to children, and the public contact form should not be used to submit a child's personal information. This Notice does not address, and should not be read as resolving, privacy requirements for any future athlete-facing or student-record product or feature.
International processing
Stevera and the service providers described in this Notice may process information in the United States and in other locations where they operate. Where applicable law requires additional safeguards for information transferred from your location, we intend to rely on the mechanisms those providers make available for that purpose.
External links
Any third-party website the Site links to is governed by that website's own privacy practices, not this Notice.
Changes to this notice
We may update this Notice from time to time. The Effective Date and Last Updated date above will reflect any material revision.
Contact
Questions about this Notice, or a privacy request, can be sent to privacy@stevera.io. Security reports can be sent to security@stevera.io.
