
Work Here?
Drizly connects customers with nearby liquor stores through an online platform for ordering beer, wine, and spirits with delivery to the customer’s door. It runs as a marketplace and does not stock inventory; orders are placed online and routed to a local partner store, which completes the delivery. Revenue comes from fees charged to partner stores for using the platform plus a delivery fee added to the customer’s order. The service is differentiated by its focus on alcohol delivery via a dense network of local stores and a promise of fast delivery, often within an hour, fulfilling last-minute or convenience-driven needs. The goal is to make alcohol shopping and home delivery easy and quick by linking customers to nearby stores through a digital platform.
Industries
Consumer Software
Enterprise Software
Company Size
51-200
Company Stage
Acquired
Total Funding
$122.1M
Headquarters
Boston, Massachusetts
Founded
2012
See people who can refer or advise you
Help us improve and share your feedback! Did you find this helpful?
Total Funding
$122.1M
Below
Industry Average
Funded Over
9 Rounds
Career coaching
Equity
Flexible PTO
Charitable giving
Drizly orders
Lifestyle stipend
Affinity groups
Fitness classes
Hackathons
Parental leave
Referral bonus
When does a data breach become "cognizable damage" under U.S. Law. A data breach does not automatically translate into legally actionable damage. In cybersecurity discussions, the term "Cognizable Damage" can be understood as harm that the law recognizes as sufficiently concrete to support regulatory action, compensation, or - depending on the applicable statute - standing to bring a lawsuit. This distinction has become increasingly important in the United States, where there is no single comprehensive federal data-breach law. Instead, organizations must navigate a combination of federal sector-specific laws, Federal Trade Commission (FTC) enforcement and state privacy and breach-notification statutes. Exposure alone may not be Enough One of the most important developments came from the U.S. Supreme Court's 2021 decision in TransUnion LLC v. Ramirez. The Court held that a plaintiff generally needs to demonstrate a concrete injury to establish Article III standing in federal court. A statutory violation by itself does not automatically establish an injury. For cybersecurity victims, this creates an important distinction: the exposure of personal information and actual legally recognizable harm are not necessarily the same thing. However, that does not mean an organization can treat every breach as harmless merely because victims have not yet lost money. What can constitute as Recognizable Harm? A breach becomes considerably more serious from a legal perspective when exposed information results in - or creates a sufficiently established basis for - harm such as identity theft, financial fraud, unauthorized account activity, disclosure of highly sensitive information, reputational injury or other recognized privacy harms. The FTC has, for example, taken enforcement action where exposed personal information was capable of facilitating identity theft and fraud. In one case involving DealerBuilt, the FTC alleged that hackers downloaded information including Social Security numbers, driver's license numbers and financial information. Similarly, the FTC's action against Drizly demonstrates that regulators can focus on security failures themselves, rather than waiting for every affected consumer to demonstrate financial loss. The agency alleged that inadequate security practices resulted in the exposure of information belonging to approximately 2.5 million consumers. The "Risk of Harm" Question This is where U.S. data-breach litigation becomes complicated. The Supreme Court's TransUnion decision indicated that the mere risk of future harm, without more, generally does not establish concrete harm for damages claims. However, sufficiently imminent or substantial risks can have legal significance in other circumstances, particularly when seeking injunctive relief. Consequently, cybersecurity teams should not wait for stolen data to be used before treating an incident seriously. The nature of the compromised information, whether it was actually accessed or exfiltrated, evidence of misuse, and the likelihood and severity of resulting harm can all influence the legal assessment. International Perspective The approach differs internationally. The EU GDPR, for example, treats personal-data breaches through a broader regulatory framework involving security obligations, breach notification and potential compensation for material and non-material damage. Other jurisdictions similarly impose notification duties based on the nature of compromised information rather than requiring a victim to prove financial loss first. For multinational organizations, therefore, "no demonstrated financial loss" should never be interpreted as "no legal exposure." A new Cybersecurity Benchmark Ultimately, a data breach can cross the threshold into cognizable damage when there is a sufficiently concrete connection between the incident and a legally recognized injury - or when applicable regulatory law imposes obligations independent of individual damages. For CISOs and security teams, the lesson is straightforward: preserve evidence, determine exactly what information was accessed or exfiltrated, assess the realistic risk of misuse, document the investigation and involve legal counsel early. In the era of ransomware, identity theft and data sold through criminal marketplaces, the question is no longer simply "Was data stolen?" It is increasingly "What harm can this exposure cause, and what does the applicable law recognize it as legally significant harm?"
How Tovala banks on subscriptions and incrementality - But not ads - to profit from its oven. Thursday, June 25th, 2026 - 3:51 pm Smart TVs, refrigerators and other home appliances may pester you with marketing and perhaps even check your presence in the room using a front-facing camera. But at least the hardware is cheap! That's the promise. Some companies, like the TV manufacturing startup Telly, take it to the logical extreme by offering free televisions in exchange for agreeing to data collection and advertising. Although Telly remains in a years-long pre-order phase. Another startup taking a different approach to the same theory is Tovala, which was founded in 2015 and combines a standalone countertop oven appliance with a weekly meal kit subscription. When asked whether the company plans to enable any retail or brand marketing opportunities, CMO Scott Braun said, "We haven't done anything there from the revenue-generating side, and I'm not sure we will." Likelier, he added, the company would pursue relevant food or condiment-type brand integrations to include their products in meal kits. "The team is toying with a couple partnerships" along those lines. Braun joined Tovala only a month ago, following stints as the marketing leader at the alcohol delivery app Drizly (acquired by Uber) and, most recently, at SimpliSafe. The SimpliSafe business model is particularly apt for the current role, he said, since it makes home security hardware, which likewise was sold at cost or even a loss but made up for in long-term customer acquisition revenue via subscriptions. The Tovala oven would retail as a standalone product for more than $300, Braun said. As of this writing, it sells on Amazon for $350. That's because it is a functional countertop toaster oven. One doesn't need the meal kit subscriptions for it to work. On the Tovala site, though, with the meal kit deliveries bundled in (starting with six weeks' worth of meals over the first six months), the oven goes for $69. Tovala's ability to target and acquire the right customers - those who are going to reliably order meal kits for potentially years to come - is the company's lifeblood. For that reason, he said, the startup is a rigorous tester of marketing channels, with incrementality studies running constantly on old channels like branded search and new formats like podcast ads. The company also allows customers to scan items from a grocery store and use the SKU info to set up a preset cook. Like for a particular type of frozen pizza or if someone recreates a Tovala meal recipe they received with grocery store equivalents (since the oven can steam, broil and bake in particular sequences). Right now, that's just a customer experience benefit. But the advertising and attribution temptation is right there, hanging like an apple in the Garden of Eden. Braun said they were not pursuing these right now. But there are marketing integrations the company will pursue, he said. For instance, there are theoretical partnerships just from the fact of Tovala having a subscription revenue stream. Meal delivery services like Instacart or Uber Eats, home office or education services (to include easy and quick lunches), retail memberships, wellness services and other types of subscription-based businesses could be bundled in interesting ways. "Lots of different partnerships could make more or less sense for us to sync up with," Braun said. "It wouldn't be hard to think of some great fits." Tagged in:
As delivery aggregators look to become go-to destinations for a wider range of on-demand needs, key players are expanding their alcoholic beverage options. Take, for instance, DoorDash. Earlier this month, the company announced the launch of alcoholic beverage delivery in Maryland, following changes to the law in the state that made doing so possible. “We’re thrilled to be bringing alcohol delivery to Maryland, providing even more consumers with a convenient, responsible way to enjoy their favorite drinks at home,” Erik Ragotte, the aggregator’s general manager of alcohol and convenience, said in a statement. “Whether it’s locally brewed craft beers or bottles of beloved wines, we hope that this new offering can showcase the best that Maryland has to offer.”
Drizly will lay off 168 employees between April and September, according to BBJ.
Drizly had already laid off 100 employees the previous year, with some of its features integrated into Uber Eats.
Find jobs on Simplify and start your career today
Industries
Consumer Software
Enterprise Software
Company Size
51-200
Company Stage
Acquired
Total Funding
$122.1M
Headquarters
Boston, Massachusetts
Founded
2012
Find jobs on Simplify and start your career today