Privacy Policy

Effective Date: June 1, 2026 · Operator: RavRic Solutions LLC

1. Who We Are

RavRic Solutions LLC ("we," "our," "us") operates VenturePath (https://pathfinder.ravricsolutions.com), an AI-powered course recommendation platform. Our mailing address and primary point of contact for privacy inquiries is privacy@ravricsolutions.com.

2. Age Requirement

VenturePath is intended exclusively for users who are 18 years of age or older. We do not knowingly collect personal information from individuals under 18. If we discover that we have inadvertently collected information from a minor, we will delete it immediately. If you believe a minor has registered, contact us at privacy@ravricsolutions.com.

3. Information We Collect

3.1 Information You Provide Directly

  • Account registration: Full name, email address, date of birth (for age verification), password (stored as a one-way cryptographic hash — never readable)
  • Career Profile (quiz): Personal values, schedule, family situation, financial goals, risk tolerance, skill set, constraints, learning preferences — used solely to generate personalized course recommendations
  • Payment: Billing transactions are processed by Stripe. We receive only the last 4 digits of your card number and a transaction ID — never your full card number, CVV, or expiration date

3.2 Information Collected Automatically via Cookies and Technology

When you use VenturePath, we automatically collect the following technical data points through cookies, server logs, and browser APIs. We disclose each data point and the business purpose below:

Data PointSourcePurposeShared?
Session tokenCookie (httpOnly)Keep you logged inNo
CSRF tokenCookieSecurity — prevent cross-site request forgeryNo
IP addressServer logSecurity, fraud prevention, IP-based geographic regionAggregated only
Browser type & versionUser-Agent headerCompatibility, device segmentation for analyticsAggregated only
Operating system & versionUser-Agent headerDevice segmentationAggregated only
Device type (mobile/tablet/desktop)User-Agent headerUI optimization, audience analyticsAggregated only
Screen resolutionJavaScript APIUI optimization, device profilingAggregated only
Browser languageAccept-Language headerLocalization, audience demographicsAggregated only
TimezoneJavaScript APIScheduling features, audience demographicsAggregated only
Referral source / UTM parametersURL query parametersMarketing attributionAggregated only
Pages visited & sequenceServer log + JavaScriptProduct improvement, funnel analysisAggregated only
Session duration & click patternsJavaScriptUX improvement, engagement analyticsAggregated only
Course categories viewed/clickedServer logContent recommendations, interest segmentationAggregated only
Feature usage eventsJavaScriptProduct analyticsAggregated only
Geographic region (country, state, city)IP geolocation — not GPSAudience segmentation, regulatory complianceAggregated only

4. How We Use Your Information

  • Service delivery: Account management, course recommendations, membership access, customer support
  • Payment processing: Billing, receipts, refunds (via Stripe)
  • Product improvement: Understanding how users interact with features to improve them
  • Security and fraud prevention: Detecting and preventing unauthorized access
  • Communications: Service updates, receipts, newsletters (if you opt in)
  • Legal compliance: Responding to lawful requests from regulatory or law enforcement authorities
  • Aggregated data products: See Section 5

5. Aggregated Data Products and Data Sharing

We do not sell your name, email address, financial account information, Social Security number, or any data that directly identifies you as an individual.

We do create and sell aggregated, anonymized data products — statistical summaries and enriched behavioral profiles that describe groups of users (e.g., "adults aged 25–34 in the southeastern US who are interested in e-commerce courses and have medium risk tolerance"). This aggregated data:

  • Cannot be used to identify you personally
  • Is derived from the behavioral and technical data points listed in Section 3.2
  • May include interest categories, device type, geographic region, engagement patterns, and financial goal ranges
  • Is processed using AI-assisted analysis to enrich and improve its quality before sharing
  • Is sold to third-party data brokers and analytics companies in exchange for compensation

This practice is legal under applicable US federal and state privacy laws because the data does not constitute "personal information" as defined under statutes including the California Consumer Privacy Act (CCPA), Virginia Consumer Data Protection Act (VCDPA), Colorado Privacy Act (CPA), Connecticut Data Privacy Act (CTDPA), and Utah Consumer Privacy Act (UCPA). Aggregated data that cannot reasonably be used to identify an individual is expressly excluded from the definition of personal information in each of these laws.

You may opt out of your data being included in aggregated data products by emailing us at privacy@ravricsolutions.com with subject line "Data Aggregation Opt-Out." Opting out will not affect your ability to use the Service.

Categories of Third Parties We Share Data With:

  • Data brokers and analytics companies — aggregated behavioral data (as described above)
  • Stripe — payment processing (PCI-DSS Level 1 certified)
  • Plaid — bank account linking for ACH payments (when you choose this option)
  • Email delivery providers — for transactional emails and newsletters
  • Law enforcement or courts — when legally required

6. Security Measures

We take data security seriously and have implemented the following controls to protect your information:

  • Encryption in transit: All data transmitted between your browser and our servers is encrypted in transit using industry-standard protocols
  • Password security: Passwords are stored using industry-standard one-way cryptographic hashing — we cannot recover your password, only reset it
  • Financial token encryption: Third-party access tokens are encrypted before storage
  • Multi-factor authentication: We support authenticator apps, email one-time codes, and hardware security keys
  • Payment data: We do not store card numbers, CVV, or expiration dates. Card data is handled exclusively by Stripe (PCI-DSS Level 1 certified)
  • Access controls: Administrative access requires MFA and is restricted to authorized personnel
  • Security monitoring: Our infrastructure is monitored by an automated security operations system with 24/7 alerting
  • Vulnerability management: Quarterly internal and annual third-party penetration testing
  • Data backups: Encrypted daily backups of all production data

No method of electronic transmission or storage is 100% secure. We will notify affected users promptly in the event of a data breach as required by applicable law.

7. Cookies and Tracking Technology

We use three tiers of cookies. You may set your preference using the banner that appears on your first visit, or at any time by clicking "Cookie Preferences" in the footer.

  • Required: Authentication session, CSRF protection, cookie consent preference. These cannot be disabled — the service cannot function without them.
  • Functional: Your preferences and settings. Disabling means preferences will not persist between sessions.
  • Analytics & Behavioral: The full set of data points in Section 3.2. Disabling opts you out of behavioral data collection and inclusion in aggregated data products.

To opt out of all non-required cookies: use the cookie banner, use your browser's "Do Not Track" setting, or clear cookies and decline on next visit.

8. Data Retention

  • Account data: Retained for the duration of your account plus 3 years after deletion (for legal and tax compliance)
  • Payment records: Retained for 7 years (IRS requirement)
  • Career profile data: Retained while your account is active; deleted within 30 days of account deletion
  • Server logs: Retained for 90 days
  • Aggregated data products: Once data has been aggregated and anonymized, the resulting product is not subject to deletion requests as it contains no personal information

9. Your Privacy Rights

Depending on your state of residence, you may have the following rights. To exercise any of these rights, email privacy@ravricsolutions.com with your request. We will respond within 45 days.

  • Right to know/access: Request a copy of the personal information we hold about you
  • Right to delete: Request deletion of your personal information (subject to legal retention requirements)
  • Right to correct: Request correction of inaccurate personal information
  • Right to opt out of data sale: Opt out of your data being included in aggregated data products sold to third parties
  • Right to data portability: Request your data in a machine-readable format
  • Right to non-discrimination: We will not deny service, charge higher prices, or provide lower quality service because you exercised any privacy right

California residents (CCPA): You have the rights listed above plus the right to know the categories of personal information sold or disclosed for a business purpose. We do not sell personal information as defined under CCPA.

Virginia, Colorado, Connecticut, Utah residents: You have the right to opt out of the processing of your personal data for purposes of targeted advertising and profiling that produces legal or significant effects. Contact us to exercise this right.

10. Children's Privacy

VenturePath is not directed to individuals under 18 years of age. We do not knowingly collect personal information from children under 18. If you are under 18, do not use this service. If we learn we have collected information from a child under 18, we will delete it immediately and terminate the account.

11. Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of material changes by email or by prominent notice on our website at least 30 days before the change takes effect. Your continued use of VenturePath after that date constitutes acceptance of the updated policy.

12. Contact Us

For privacy-related questions, requests, or complaints:

RavRic Solutions LLC
Privacy Officer: Ricardo Benlizar
Email: privacy@ravricsolutions.com
Website: https://pathfinder.ravricsolutions.com