Legal
How Stryde handles information about you, about the people who use it, and about the businesses it helps you find.
Effective
23 August 2026
Last updated
23 August 2026
Stryde is a business-discovery and prospecting platform. It searches public business directories for businesses in an area and category you choose, records what it finds, and gives your team a CRM in which to work those businesses as leads through to a closed sale.
Stryde is developed, operated and one hundred per cent owned by Deeesign Lab (deeesignlab.com), of 728/B, Pannipitiya Road, Pelawatta, Battaramulla, 10120, Sri Lanka. In this policy, Deeesign Lab is referred to as “we”, “us” or “the provider”.
This policy explains what the Services collect, why, who receives it, how long it is kept and what you can ask us to do about it. It applies to everyone who uses Stryde: to individual Users, to the organisations they belong to, and to visitors to our public pages. It is written to be read alongside our Terms of Service and Refund & Cancellation Policy, which use the same defined terms.
Your account. When you sign up, or when an administrator creates an account for you, we collect your email address, your name, and a contact telephone number with its country code. If you request a paid plan we also collect your job title and the name of your organisation. Your password is handled by Supabase Auth and held only as a hash; nobody at Deeesign Lab, and no administrator of your organisation, can read it. We record which organisations you belong to and your role and seat type in each, whether your account is active, when you last signed in, and whether you have confirmed your email address.
Your profile picture. You choose from a fixed set of illustrations that ship with the application. There is no image upload, so we store only which illustration you picked.
User Content. Everything you record while working a lead is stored, including:
Support and correspondence. If you use the public enquiry form we collect your name, email address, telephone number and message, together with your company name and website where you give them. If you submit a bug report from inside the application we collect your description of the problem, your email address, and the technical details described in 2.2.
Billing information. Subscriptions are invoiced and paid by bank transfer. There is no payment gateway in Stryde and we do not collect or store card numbers. What the application holds is the day of the month your organisation is billed on and whether its subscription is currently in good standing. Bank details you send us in order to pay are held in our own business records outside the application.
Stryde collects markedly less of this than most web applications, because it loads no analytics script and no advertising tag. What is collected is the following.
A bug-report screenshot can capture lead and contact data that happened to be on screen. Please consider what is visible before attaching one.
There is an important distinction running through this policy, and this is it.
For each business a search returns, we store the business name, category, address and coordinates, telephone number, email address and website where the source publishes them, social profile links, opening hours, and any rating and review count the source provides. The data provider’s original response is kept alongside the record, and responses are cached briefly so that repeating a search does not repeat the request.
When you ask for one, the Services also make a single server-side request to a business’s own website and record whether it responded, the HTTP status, whether it used HTTPS, the page title, whether the page declares a mobile viewport, and a short list of observations such as “No HTTPS” or “Parked domain”. It reads one page, identifies itself in its user agent, does not crawl the site, and does not store the page content.
This is published business contact information: the details a business has chosen to list so that customers can reach it. Stryde does not crawl the web for personal details about individuals. Where a business is a sole trader or a partnership, however, its published contact details may still constitute personal data under the law that applies to you, and you should treat them accordingly. Section 5 sets out how we handle Business Data in more detail.
We use the information described above to:
We do not sell your personal data, or the data you collect with the Services, to third parties for marketing purposes. We do not share it with data brokers, we do not use it to build advertising profiles, and we do not send you marketing email you did not ask for. We do not contact the businesses in your leads on your behalf; the Services send nothing to them.
Whether we need a legal basis at all, and which bases are available, depends on the law of the jurisdiction you are in. Where a legal basis is required — for example under the EU or UK General Data Protection Regulation, or under Sri Lanka’s Personal Data Protection Act, No. 9 of 2022 — we rely on the following.
Where you enter personal data about other people into the Services — contacts at a prospect business, for instance — you, not Deeesign Lab, decide why and how that data is processed. In GDPR terms you are the controller of that data and we act as your processor. You are responsible for having a lawful basis for holding it.
Stryde processes information about businesses that is published by those businesses or by third-party data providers. Business names, addresses, telephone numbers, websites, categories, opening hours, ratings and similar details may appear in Search Results.
Business Data taken from OpenStreetMap is © OpenStreetMap contributors and is made available under the Open Database License. Business Data taken from the Google Places API remains subject to Google’s terms, including their restrictions on storage, caching and redistribution. Your use of Stryde is subject to those terms as well as to this policy.
If you are a business appearing in Stryde and you want your listing corrected or removed, write to support@deeesignlab.com. We will act on the request in our own directory. Because the information originates with a third-party source, correcting it at that source — Google or OpenStreetMap — is what stops it returning, and we will tell you where the record came from so that you can.
Stryde sets only the cookies it needs in order to work. There are no advertising cookies, no cross-site tracking, no third-party analytics cookies and no tracking pixels, which is why you are not asked to dismiss a consent banner.
| Cookie | Category | Purpose |
|---|---|---|
| sb-<project>-auth-token | Essential | Keeps you signed in. Set by Supabase Auth and refreshed as you navigate. |
| stryde_org | Essential | Remembers which organisation you are working in when you belong to more than one. Checked against your memberships on every request, so it grants nothing on its own. |
| stryde_theme | Essential | Remembers whether you chose the dark or light appearance, so the first page you load is already in it. |
| deeesign_session | Essential | A signed session cookie used only when the application runs in local development mode, without Supabase. Not set on the hosted service. |
Blocking these cookies will stop you signing in. You can clear them from your browser at any time, which signs you out.
Note that the map on the search screen loads its imagery directly from the OpenStreetMap tile servers, so your browser makes a request to OpenStreetMap whenever a map is shown and therefore discloses your IP address to them. That request is governed by OpenStreetMap’s own policy.
Stryde is multi-tenant. Leads, notes, contacts, activity, tasks, projects and search history belong to an organisation, and one organisation cannot see another organisation’s records. Within your own organisation, members share the same lead data; administrators can additionally manage who has access, and on plans that include it, read the activity log.
Bug reports are handled differently. Because a report can include a screenshot of whatever was on your screen, reports and their screenshots are readable only by Deeesign Lab. Administrators of your own organisation cannot read them.
Outside your organisation, we share your information only with the following categories of recipient:
Business Data is shared more widely than your User Content, in one specific way: as described in section 5, the directory of discovered businesses is common to the whole installation. It is not sold, not published as a dataset, and not made available to anyone outside the Services.
These are the third parties that receive data in the course of running Stryde. There are no others: in particular, the application loads no third-party analytics or advertising service.
Supabase
The database, the sign-in system and the private storage bucket that holds bug-report screenshots.
What they receive: Everything the application stores, including your account, your organisation's records and your password hash.
Their privacy policyVercel
Hosting. The application runs on Vercel's Singapore region and its scheduler triggers the daily maintenance run.
What they receive: Requests to the application, including your IP address, and the server logs those requests produce.
Their privacy policyUpstash
A shared counter that enforces per-minute rate limits across every running copy of the application.
What they receive: Either your account identifier or your IP address, held as a counter key for up to one minute.
Their privacy policyResend
Delivering the application's email: confirmation links, password resets, invitations, access decisions, the daily digest and the monthly report.
What they receive: Your email address, your name and the contents of the message being sent to you.
Their privacy policyGoogle Maps Platform (Places API)
Returning the businesses a search finds, where the installation is configured to use Google.
What they receive: The search terms and the location you searched, sent from our server. Your browser does not contact Google.
Their privacy policyOpenStreetMap Foundation
Returning businesses where the installation is configured to use OpenStreetMap, and serving the map imagery on the search screen.
What they receive: Search terms sent from our server, and — because map tiles load directly into the page — your IP address when a map is displayed.
Their privacy policyWe keep information for as long as it is needed for the purpose it was collected for, and then delete it. In practice:
When a subscription ends, your organisation’s data is retained for 30 days so that you can ask for it back or change your mind, and is then permanently deleted from the live service. Export anything you need before that window closes.
Deleted records may persist for a further short period in our database provider’s automated backups, which rotate on their own schedule and are not selectively editable. We do not restore deleted data from a backup in order to use it, and it ages out.
We take technical and organisational measures appropriate to the risk. These include: transport encryption on all connections; passwords held only as hashes by our authentication provider; screenshots stored in a private bucket and served only through short-lived signed URLs; tenant isolation enforced on the server on every request rather than in the browser; role checks and feature checks applied server-side; per-minute rate limits; and audit logging of changes to records and to organisation settings.
No service can be guaranteed secure, and we do not claim otherwise. We make no representation that the Services are impenetrable. You are responsible for keeping your credentials confidential, for not sharing your Account, and for telling us promptly if you believe your Account has been compromised.
Stryde is still in active development. Where we become aware of a personal data breach that is likely to cause harm, we will notify affected Users and any regulator we are required to notify, within the period the applicable law requires.
Deeesign Lab operates from Sri Lanka. The application is hosted in Singapore, and the providers listed in section 8 operate globally, so your information is processed and stored outside your own country and may be handled in jurisdictions whose data-protection law differs from your own.
Where the law that applies to you requires a specific safeguard for such transfers — for example, the standard contractual clauses under the GDPR — we will put an appropriate mechanism in place with the provider concerned before relying on the transfer, and you may ask us what is in place for a given provider.
Depending on where you live, you may have some or all of the following rights over the personal data we hold about you: to be told what we hold and to receive a copy of it; to have inaccurate data corrected; to have data deleted; to restrict how we process it; to object to processing carried out on the basis of legitimate interests; to receive your data in a portable form; and to withdraw consent you have given.
Some of these you can exercise yourself. You can edit your own name and profile at any time, change your password, switch the daily digest off, and delete individual leads, notes and contacts from inside the application. Organisations on plans that include export can download their lead, target and analytics data as CSV; if your plan does not include export and you need a copy of your data, ask us and we will provide it.
For anything else, write to support@deeesignlab.com. We will respond within thirty days, or sooner where the law requires it. We may need to verify your identity first, and we will tell you if we cannot act on a request and why. Exercising these rights costs nothing and we will not treat you differently for doing so.
If your personal data is in an organisation’s User Content because that organisation put it there, we will normally refer your request to them, since they decide what is held and why. We will tell you when we do.
Where the EU or UK General Data Protection Regulation applies to our processing, the following also applies.
Stryde is sold and marketed from Sri Lanka and is not specifically targeted at the European Economic Area or the United Kingdom. This section is included because Users there may nonetheless subscribe. Its presence is not a statement that the GDPR applies to our processing, nor a certification of compliance with it.
Stryde is not marketed in the United States, and we do not assert that any particular state privacy law applies to us. Where one does apply — for example the California Consumer Privacy Act as amended — the following is true of our processing.
Stryde is a business tool sold to businesses. It is not directed at children, it is not designed for them, and it has no features intended for them. You must be at least 18 to hold an Account.
We do not knowingly collect personal data from children. If you believe a child has provided us with personal data, write to support@deeesignlab.com and we will delete it.
Stryde links out to places we do not control: the websites of the businesses in your Search Results, their social profiles, map listings, and the policies of the providers in section 8. Following such a link takes you somewhere governed by that site’s own terms and privacy policy, not by this one. We are not responsible for their content or their practices, and a link is not an endorsement.
The website check described in section 2.3 is the one case where we fetch such a site ourselves. It reads one page, records what it observes, and stores no page content.
We will update this policy as the product changes and as the law requires. The current version always appears at this address, and the “Last updated” date at the top shows when it was last revised.
Where a change materially affects how we handle your information, we will give you notice before it takes effect — by email to your Account address, by a notice inside the application, or both — and where the law requires your consent to the change, we will ask for it. Continuing to use the Services after a change takes effect means you accept the revised policy.
Questions about this policy, or a request about your personal data, should go to:
Deeesign Lab
728/B, Pannipitiya Road, Pelawatta, Battaramulla, 10120, Sri Lanka
+94 76 333 0802
Stryde is developed and one hundred per cent owned by Deeesign Lab. Stryde, its source code, its design and the wording of this policy are © 2026 Deeesign Lab. All rights reserved. This does not affect your organisation’s ownership of its User Content, or the licences that govern the third-party Business Data described in section 5.