Last updated: August 4, 2026
The short version
- The contact form collects your name, company, email address, the reason for your inquiry, and whatever you write. It goes to my inbox.
- The site uses Google Analytics to count visits. It does not receive what you type into the form.
- Cloudflare Turnstile checks that form submissions come from a person rather than a bot.
- There are no ads, no advertising pixels, no newsletter, no accounts, and no comments.
- I do not sell or rent anything about you to anyone.
- If you want your message deleted, ask and I will delete it.
The rest of this page is the detail behind those six lines.
Who runs this site
Revaro Group LLC is my consulting practice. I am Ron Grinblat, I work alone, and I run this site myself. There is no staff, no support desk, and no customer database. That is the reason this page can be short and still cover everything.
What follows describes what actually happens to information on revarogroup.com. It is not a statement of compliance with any particular privacy law. I have not had this site assessed against one, and claiming otherwise would be a claim I could not stand behind. If a specific regulation applies to you and you want to know how I handle something, ask me directly and I will tell you.
The contact form
The form on the Contact page asks for your first and last name, your company name, your email address, a reason for the inquiry chosen from a short list, and an optional message. Company name and email address are required because a message without them is one I cannot usefully answer.
Nothing you type is stored in the website. The form plugin has no entries database, so the only copy of your message is the email that reaches my inbox.
Where your message goes
When you submit the form, WordPress hands the contents to Brevo, a transactional email provider, which delivers a notification to my Google Workspace inbox. Your message passes through Brevo’s systems in transit. The reply address on that notification is set to your email address, so when I reply, the reply goes to you rather than back into my own account.
Brevo adds two things to the notification it sends me: an invisible open-tracking image, and link rewriting that routes any links through a Brevo subdomain. Both of those measure the email that arrives in my own inbox, so what Brevo learns from them is about my behavior rather than yours. I mention it because Brevo is a third party standing in the path your message travels, and you should know it is there.
Spam protection on the form
The Contact page runs Cloudflare Turnstile. It is the box that says it is checking whether you are human. To make that judgment, Cloudflare receives your IP address and some technical detail about your browser. It does not read what you type into the form, and I never see what Cloudflare collected.
Two other spam layers run invisibly: a hidden field that automated scripts fill in and people do not, and a token that expires. Neither collects anything about you.
Analytics
As of August 2026 this site uses Google Analytics 4, loaded through Google Tag Manager. Before that date it had no analytics of any kind.
Google Analytics records which pages were viewed and in what order, roughly where the visit came from geographically, down to city level, what device and browser was used, how you arrived at the site, how far down a page you scrolled, clicks on links that lead off the site, file downloads, video plays, and searches run on the site.
It also records that a form was started and that a form was submitted. It does not receive the contents. Google is told an event happened on the Contact page; what you actually wrote goes only to my inbox.
Some things are switched off deliberately. Google Signals is off, which means no cross-device tracking, no advertising audiences, and no ad personalization built from this property. The site runs no advertising and carries no advertising pixels. Analytics is also configured to strip out anything that looks like an email address before storing it.
Analytics data is kept for 14 months, after which Google deletes it. I chose 14 rather than the 2-month default so that one year can be compared against the next.
Cookies, and what the banner does and does not do
Until August 2026 this site set no cookies at all. Comments and trackbacks are switched off, so the cookies WordPress normally sets for commenters never existed here.
Now there are two kinds. Google Analytics sets a pair of first-party cookies used to tell one visit apart from another and to group a series of page views into a single session. The consent banner sets one cookie that remembers which button you pressed, so it does not ask again on every page.
Here is the part most cookie notices leave out. This banner is a disclosure, not a gate. Script blocking is switched off, which means the analytics tag loads when the page loads, whether or not you have answered the banner and whichever button you press. I would rather write that down than imply a control that is not actually there.
If you would prefer not to be counted, a content blocker or a privacy-focused browser will stop it, and I will not do anything to work around one. The reason I have not built a blocking banner is that this site gets a small number of real human visits, and blocking would leave me with numbers too incomplete to read while adding a modal in front of a five-page site. That is a tradeoff I have made in the open rather than quietly.
Server logs
The site is hosted by WPX Hosting. Like every web server, theirs keeps access logs recording IP addresses, timestamps, the pages requested, and browser identifiers. Those logs exist for troubleshooting and security, they are kept on WPX’s own retention schedule rather than one I control, and I look at them only when something is broken.
What this site does not do
- No advertising, no advertising pixels, no retargeting.
- No newsletter and no mailing list. If that changes, this page changes first.
- No visitor accounts and no logins.
- No comments and no user-submitted content of any kind.
- No session recording, no heatmaps, no scroll-tracking software beyond the standard analytics event.
- No payments and no payment processing.
- No selling, renting, or trading of anything you send me.
How long things are kept
Messages sent through the form stay in my email indefinitely, in the same way any business correspondence does, unless you ask me to remove yours. Analytics data is deleted by Google after 14 months. The consent cookie expires after 30 days. Server logs follow WPX’s schedule.
Correcting or deleting what I have
Send a message through the contact form saying what you want removed. I will delete your original message and any reply thread, and I will write back to confirm it is done. This is a one-person practice, so the request goes to the person who can actually carry it out.
One honest limit: I cannot pull your specific rows out of the analytics data, because none of it is attached to a name or an email address. There is no way for me to identify which visit was yours, which is also the reason it is not much use for anything except counting.
Children
This is a business-to-business consulting site. It is not directed at children, and I do not knowingly collect information from anyone under 13. If you believe a child has sent me something through the form, tell me and I will delete it.
When this page changes
If I add something to the site that changes what gets collected, this page gets updated before the change goes live rather than afterward. That is how the analytics went in: the consent notice was running on the site before the tracking tag was installed, in that order, on purpose.
The date at the top of this page is the last time anything here was revised.
Questions
Use the contact form and ask. A question about this page is not an inquiry about consulting work, and I will not treat it as one.