What we collect, and what we do not want.
We publish this because our clients work under HIPAA, under federal grant terms, and under state privacy law. You should be able to see how we handle information before you send us any.
Start with the part that matters most.
Do not send us protected health information
We do not need it, we do not want it, and we are not built to hold it.
Our work never requires the name, record, or identifying detail of a single person a program serves. We measure outreach in aggregate counts: how many people contacted the program, through which channel, at what cost. That is all the reporting requires and all we ask for.
If you are a HIPAA covered entity, settle in writing at contracting whether we are a Business Associate. Where we never receive individual-level data, we typically are not, and a scope statement saying so protects both of us.
Please do not submit patient information, protected health information, or personally identifiable participant data through any form on this site.
If you send it by accident, tell us and we will delete it and confirm in writing.
What this site collects
Through the Reach Audit and Blueprint forms: your name, role, organization, work email, phone if you provide it, funding source, program type, service area, whether you track qualified referrals, your next reporting or renewal deadline, spending authority, and anything you add in the open field.
All of it is organizational information about a program. None of it is about the people that program serves.
Why we ask for what we ask for
Every field earns its place or it would not be there.
Funding source tells us which allowable-use language your award uses. Service area is the largest driver of scope and price. Program type determines which measurement track applies. Your referral answer tells us whether the first month of work is analysis or building the tracking that does not exist yet. The deadline drives sequencing. Spending authority tells us what to prepare.
We do not sell, rent, trade, or share any of it. There is no list.
Where it goes
Formspree processes our form submissions and delivers them to us by email. They are a third-party service with their own privacy terms.
The submission then lives in our email and in our internal project tracker, which is access-restricted to STRIVE3 staff working on your engagement.
Nobody else sees it. Not a partner, not a prime, not a mailing list.
How long we keep it
- If you become a client
- For the length of the engagement plus seven years, or the period your grant terms require, whichever is longer. Grant-funded work carries records obligations and we hold to them.
- If you do not
- Two years, then deleted. Procurement cycles in this field run long and a conversation in 2026 is often a project in 2028.
- If you ask us sooner
- We will delete it, and we will confirm when it is done.
Third-party services on this site
Named plainly, because you should not have to inspect our code to find out.
- Formspree
- Receives form submissions.
- google analytics
- Collects data about visitors’ behavior on the site, such as pages viewed, time spent, device and browser type, and how they arrived at the site.
- Google Fonts
- Serves the typefaces used across the site. This means your browser requests files from Google, and Google receives your IP address in the process.
- unpkg.com
- Serves the two mapping libraries that draw the reach map, with the same effect.
We are working to bring the fonts and libraries onto our own servers so that visiting this site requires no third-party request at all. When that is done, this section will say so.
See it, correct it, or have it deleted
You do not need to cite a statute or explain why.
Email info@strive3.com and ask us to show you what we hold, correct it, or delete it. We will respond within five business days.
Federal and state client considerations
If you contract with us under a federal award, a state contract, or a settlement-funded agreement, that agreement’s data handling terms control and supersede this page. We build to whichever standard is stricter.
Our deliverables are produced to WCAG 2.1 Level AA. Where an engagement requires a Business Associate Agreement, a data use agreement, or a security plan, we execute one before work begins rather than after.
Changes to this page
Last updated: August 26, 2026.
We will date any material change here rather than quietly revising.
The Virginia Consumer Data Protection Act applies to businesses processing the personal data of 100,000 or more consumers a year. We are well under that threshold. Publishing this page is a choice, not a compliance requirement.
