Stryde

Legal

Privacy Policy

How Stryde handles information about you, about the people who use it, and about the businesses it helps you find.

Effective

23 August 2026

Last updated

23 August 2026

1. Introduction

Stryde is a business-discovery and prospecting platform. It searches public business directories for businesses in an area and category you choose, records what it finds, and gives your team a CRM in which to work those businesses as leads through to a closed sale.

Stryde is developed, operated and one hundred per cent owned by Deeesign Lab (deeesignlab.com), of 728/B, Pannipitiya Road, Pelawatta, Battaramulla, 10120, Sri Lanka. In this policy, Deeesign Lab is referred to as “we”, “us” or “the provider”.

This policy explains what the Services collect, why, who receives it, how long it is kept and what you can ask us to do about it. It applies to everyone who uses Stryde: to individual Users, to the organisations they belong to, and to visitors to our public pages. It is written to be read alongside our Terms of Service and Refund & Cancellation Policy, which use the same defined terms.

2. Information we collect

2.1 Information you provide

Your account. When you sign up, or when an administrator creates an account for you, we collect your email address, your name, and a contact telephone number with its country code. If you request a paid plan we also collect your job title and the name of your organisation. Your password is handled by Supabase Auth and held only as a hash; nobody at Deeesign Lab, and no administrator of your organisation, can read it. We record which organisations you belong to and your role and seat type in each, whether your account is active, when you last signed in, and whether you have confirmed your email address.

Your profile picture. You choose from a fixed set of illustrations that ship with the application. There is no image upload, so we store only which illustration you picked.

User Content. Everything you record while working a lead is stored, including:

  • leads and clients, with their pipeline status, priority, deal value, colour tag, contact dates, follow-up dates and outreach notes
  • notes you write against a business
  • contacts: the name, job title, telephone number, WhatsApp number, email address and notes for a person at a business, entered by you
  • logged interactions: calls, messages, meetings and emails you record as having happened, with the date and your summary
  • tasks, follow-up dates, calendar events and their attendees, monthly targets, projects, and the payments you are expecting from your own clients
  • businesses you add by hand, and businesses you import from a file

Support and correspondence. If you use the public enquiry form we collect your name, email address, telephone number and message, together with your company name and website where you give them. If you submit a bug report from inside the application we collect your description of the problem, your email address, and the technical details described in 2.2.

Billing information. Subscriptions are invoiced and paid by bank transfer. There is no payment gateway in Stryde and we do not collect or store card numbers. What the application holds is the day of the month your organisation is billed on and whether its subscription is currently in good standing. Bank details you send us in order to pay are held in our own business records outside the application.

2.2 Information collected automatically

Stryde collects markedly less of this than most web applications, because it loads no analytics script and no advertising tag. What is collected is the following.

  • Server logs. Our hosting provider records the requests your browser makes, including your IP address, the time, the page requested and your browser’s user-agent string. This is ordinary web-server logging and we do not build profiles from it.
  • Rate-limit counters. To stop one client overwhelming the service, we count requests per minute against either your account identifier or, if you are not signed in, your IP address. The counter is held in a shared cache and expires within one minute.
  • Usage inside the application. We record your search history, including who ran each search, what was searched for, where, and how many results came back; an activity log of changes made to businesses, leads and organisation settings, recording the acting user, the field changed and its value before and after; and which sections of the product you have opened, so that “new since you last looked” markers work.
  • Device information, on bug reports only. When you choose to submit a bug report we capture the page you were on, your browser’s user-agent string, your screen size and your platform, and — only if you tick the box — a screenshot of what was on your screen at that moment. This is not collected as you browse; it is collected when you press the button.

A bug-report screenshot can capture lead and contact data that happened to be on screen. Please consider what is visible before attaching one.

2.3 Business Data displayed by Stryde

There is an important distinction running through this policy, and this is it.

  • Information about Users is information about you and your colleagues: your account, and the User Content your organisation creates. You gave it to us.
  • Business Data is information about the businesses Stryde finds for you. The businesses did not give it to us and are usually not aware the Services exist.

For each business a search returns, we store the business name, category, address and coordinates, telephone number, email address and website where the source publishes them, social profile links, opening hours, and any rating and review count the source provides. The data provider’s original response is kept alongside the record, and responses are cached briefly so that repeating a search does not repeat the request.

When you ask for one, the Services also make a single server-side request to a business’s own website and record whether it responded, the HTTP status, whether it used HTTPS, the page title, whether the page declares a mobile viewport, and a short list of observations such as “No HTTPS” or “Parked domain”. It reads one page, identifies itself in its user agent, does not crawl the site, and does not store the page content.

This is published business contact information: the details a business has chosen to list so that customers can reach it. Stryde does not crawl the web for personal details about individuals. Where a business is a sole trader or a partnership, however, its published contact details may still constitute personal data under the law that applies to you, and you should treat them accordingly. Section 5 sets out how we handle Business Data in more detail.

3. How we use information

We use the information described above to:

  • provide the Services: run searches, return and display Business Data, check prospect websites, and operate the CRM in which you save and work those businesses
  • create and administer your Account, authenticate you, keep you signed in, and let administrators manage who has access to an organisation
  • send the email the Services depend on: confirmation links, password resets, invitations, decisions on access requests, and the daily digest and monthly report where these are enabled
  • invoice your organisation, record the day it is billed on, and manage subscription status
  • respond to support requests, enquiries and bug reports
  • keep the Services secure and available: enforce rate limits, detect and investigate abuse, fraud and unauthorised access, and diagnose faults
  • understand how the product is used in aggregate, and improve it
  • meet our legal and regulatory obligations

We do not sell your personal data, or the data you collect with the Services, to third parties for marketing purposes. We do not share it with data brokers, we do not use it to build advertising profiles, and we do not send you marketing email you did not ask for. We do not contact the businesses in your leads on your behalf; the Services send nothing to them.

4. Legal bases for processing

Whether we need a legal basis at all, and which bases are available, depends on the law of the jurisdiction you are in. Where a legal basis is required — for example under the EU or UK General Data Protection Regulation, or under Sri Lanka’s Personal Data Protection Act, No. 9 of 2022 — we rely on the following.

  • Performance of a contract. Creating and running your Account, providing the Services, and invoicing your organisation.
  • Legitimate interests. Securing the Services, preventing abuse and fraud, keeping an audit trail of changes, understanding usage in aggregate, improving the product, and processing Business Data so that the Services can do what they exist to do. Where we rely on legitimate interests we have considered whether those interests are overridden by the rights of the people concerned.
  • Consent. Where you give it — for example, by attaching a screenshot to a bug report, or by leaving the daily digest switched on. You may withdraw consent at any time, which does not affect processing already carried out.
  • Legal obligation. Keeping accounting records and responding to lawful requests from authorities.

Where you enter personal data about other people into the Services — contacts at a prospect business, for instance — you, not Deeesign Lab, decide why and how that data is processed. In GDPR terms you are the controller of that data and we act as your processor. You are responsible for having a lawful basis for holding it.

5. Business and publicly available information

Stryde processes information about businesses that is published by those businesses or by third-party data providers. Business names, addresses, telephone numbers, websites, categories, opening hours, ratings and similar details may appear in Search Results.

  • We do not own, control or represent the businesses that appear in Search Results, and we claim no ownership of their names, logos or trade marks.
  • The appearance of a business in Stryde does not mean it is a customer, partner, affiliate or endorser of Deeesign Lab or of you, and it does not mean the business is seeking the services you intend to offer.
  • Business Data is obtained from third-party data providers and publicly available sources, identified in section 8. We did not compile it ourselves and we cannot verify it.
  • Business Data may be incomplete, out of date or wrong. We do not guarantee its accuracy, and you should confirm anything that matters before you act on it.
  • The directory of businesses is held once and shared across the whole installation, so a business discovered by one organisation’s search may appear in another organisation’s Search Results. Nothing you write — your leads, notes, contacts, statuses or outreach records — is shared in this way.

Business Data taken from OpenStreetMap is © OpenStreetMap contributors and is made available under the Open Database License. Business Data taken from the Google Places API remains subject to Google’s terms, including their restrictions on storage, caching and redistribution. Your use of Stryde is subject to those terms as well as to this policy.

If you are a business appearing in Stryde and you want your listing corrected or removed, write to support@deeesignlab.com. We will act on the request in our own directory. Because the information originates with a third-party source, correcting it at that source — Google or OpenStreetMap — is what stops it returning, and we will tell you where the record came from so that you can.

6. Cookies and similar technologies

Stryde sets only the cookies it needs in order to work. There are no advertising cookies, no cross-site tracking, no third-party analytics cookies and no tracking pixels, which is why you are not asked to dismiss a consent banner.

CookieCategoryPurpose
sb-<project>-auth-tokenEssentialKeeps you signed in. Set by Supabase Auth and refreshed as you navigate.
stryde_orgEssentialRemembers which organisation you are working in when you belong to more than one. Checked against your memberships on every request, so it grants nothing on its own.
stryde_themeEssentialRemembers whether you chose the dark or light appearance, so the first page you load is already in it.
deeesign_sessionEssentialA signed session cookie used only when the application runs in local development mode, without Supabase. Not set on the hosted service.

Blocking these cookies will stop you signing in. You can clear them from your browser at any time, which signs you out.

Note that the map on the search screen loads its imagery directly from the OpenStreetMap tile servers, so your browser makes a request to OpenStreetMap whenever a map is shown and therefore discloses your IP address to them. That request is governed by OpenStreetMap’s own policy.

7. How we share information

7.1 Your data and your User Content

Stryde is multi-tenant. Leads, notes, contacts, activity, tasks, projects and search history belong to an organisation, and one organisation cannot see another organisation’s records. Within your own organisation, members share the same lead data; administrators can additionally manage who has access, and on plans that include it, read the activity log.

Bug reports are handled differently. Because a report can include a screenshot of whatever was on your screen, reports and their screenshots are readable only by Deeesign Lab. Administrators of your own organisation cannot read them.

Outside your organisation, we share your information only with the following categories of recipient:

  • Service providers who process data on our behalf and on our instructions: our hosting, database, authentication, storage, email and rate-limiting providers. They are listed individually in section 8.
  • Data providers who receive your search terms in order to return results. They receive the query and the location, sent from our server, and not your identity.
  • Our own staff, who can access the underlying database in order to operate, support and repair the Services.
  • Professional advisers — lawyers, accountants and auditors — where they need it to advise us, and under a duty of confidence.
  • Authorities, where we are legally required to disclose, or where disclosure is necessary to establish or defend legal claims or to protect someone’s safety.
  • An acquirer, if Deeesign Lab or the Stryde business is sold, merged or reorganised. We would tell you before your information became subject to a different privacy policy.

7.2 Business Data

Business Data is shared more widely than your User Content, in one specific way: as described in section 5, the directory of discovered businesses is common to the whole installation. It is not sold, not published as a dataset, and not made available to anyone outside the Services.

8. Third-party services

These are the third parties that receive data in the course of running Stryde. There are no others: in particular, the application loads no third-party analytics or advertising service.

Supabase

The database, the sign-in system and the private storage bucket that holds bug-report screenshots.

What they receive: Everything the application stores, including your account, your organisation's records and your password hash.

Their privacy policy

Vercel

Hosting. The application runs on Vercel's Singapore region and its scheduler triggers the daily maintenance run.

What they receive: Requests to the application, including your IP address, and the server logs those requests produce.

Their privacy policy

Upstash

A shared counter that enforces per-minute rate limits across every running copy of the application.

What they receive: Either your account identifier or your IP address, held as a counter key for up to one minute.

Their privacy policy

Resend

Delivering the application's email: confirmation links, password resets, invitations, access decisions, the daily digest and the monthly report.

What they receive: Your email address, your name and the contents of the message being sent to you.

Their privacy policy

Google Maps Platform (Places API)

Returning the businesses a search finds, where the installation is configured to use Google.

What they receive: The search terms and the location you searched, sent from our server. Your browser does not contact Google.

Their privacy policy

OpenStreetMap Foundation

Returning businesses where the installation is configured to use OpenStreetMap, and serving the map imagery on the search screen.

What they receive: Search terms sent from our server, and — because map tiles load directly into the page — your IP address when a map is displayed.

Their privacy policy

9. Data retention

We keep information for as long as it is needed for the purpose it was collected for, and then delete it. In practice:

  • Account and User Content are kept for as long as your organisation subscribes, and are deleted 30 days after a subscription ends. See section 9.1.
  • Cached data-provider responses expire automatically 7 days after they are stored, and are purged by the application.
  • Password-reset and email-confirmation links expire in thirty minutes and twenty-four hours respectively. The records behind them are held as one-way hashes and deleted 30 days after they expire.
  • Business Data from Google is held under two separate limits. The provider’s verbatim response is discarded after 7 days. The business record itself — name, address, telephone, website and the rest — is removed within 30 days of the last time we fetched it, unless a search returns it again, which refreshes it in place rather than duplicating it. Records that no organisation has saved are deleted outright. Google’s own terms permit a place identifier to be kept indefinitely and cap other content at thirty days, and these limits are set to stay inside that.
  • Business Data from OpenStreetMap is licensed under the Open Database License, which permits us to keep it with attribution, so it is retained in the shared directory while it remains useful to the Services.
  • Bug reports and their screenshots are kept while they are useful for diagnosing the fault reported and for recognising it if it returns. They have no automatic expiry at present, so if you want a report or its screenshot removed, ask us and we will delete it.
  • Invoices and accounting records are kept for as long as Sri Lankan tax and company law requires, which is longer than the periods above and applies even after an account is deleted.

9.1 Deletion after cancellation

When a subscription ends, your organisation’s data is retained for 30 days so that you can ask for it back or change your mind, and is then permanently deleted from the live service. Export anything you need before that window closes.

Deleted records may persist for a further short period in our database provider’s automated backups, which rotate on their own schedule and are not selectively editable. We do not restore deleted data from a backup in order to use it, and it ages out.

10. Data security

We take technical and organisational measures appropriate to the risk. These include: transport encryption on all connections; passwords held only as hashes by our authentication provider; screenshots stored in a private bucket and served only through short-lived signed URLs; tenant isolation enforced on the server on every request rather than in the browser; role checks and feature checks applied server-side; per-minute rate limits; and audit logging of changes to records and to organisation settings.

No service can be guaranteed secure, and we do not claim otherwise. We make no representation that the Services are impenetrable. You are responsible for keeping your credentials confidential, for not sharing your Account, and for telling us promptly if you believe your Account has been compromised.

Stryde is still in active development. Where we become aware of a personal data breach that is likely to cause harm, we will notify affected Users and any regulator we are required to notify, within the period the applicable law requires.

11. International data transfers

Deeesign Lab operates from Sri Lanka. The application is hosted in Singapore, and the providers listed in section 8 operate globally, so your information is processed and stored outside your own country and may be handled in jurisdictions whose data-protection law differs from your own.

Where the law that applies to you requires a specific safeguard for such transfers — for example, the standard contractual clauses under the GDPR — we will put an appropriate mechanism in place with the provider concerned before relying on the transfer, and you may ask us what is in place for a given provider.

12. Your rights

Depending on where you live, you may have some or all of the following rights over the personal data we hold about you: to be told what we hold and to receive a copy of it; to have inaccurate data corrected; to have data deleted; to restrict how we process it; to object to processing carried out on the basis of legitimate interests; to receive your data in a portable form; and to withdraw consent you have given.

Some of these you can exercise yourself. You can edit your own name and profile at any time, change your password, switch the daily digest off, and delete individual leads, notes and contacts from inside the application. Organisations on plans that include export can download their lead, target and analytics data as CSV; if your plan does not include export and you need a copy of your data, ask us and we will provide it.

For anything else, write to support@deeesignlab.com. We will respond within thirty days, or sooner where the law requires it. We may need to verify your identity first, and we will tell you if we cannot act on a request and why. Exercising these rights costs nothing and we will not treat you differently for doing so.

If your personal data is in an organisation’s User Content because that organisation put it there, we will normally refer your request to them, since they decide what is held and why. We will tell you when we do.

13. European and UK users

Where the EU or UK General Data Protection Regulation applies to our processing, the following also applies.

  • Deeesign Lab is the controller of your Account data and of information collected through our public pages. For User Content your organisation enters, your organisation is the controller and we are its processor.
  • The legal bases we rely on are set out in section 4, and the recipients of your data in sections 7 and 8.
  • You have the rights described in section 12, and the right to lodge a complaint with your national supervisory authority.
  • Where processing is based on consent you may withdraw it at any time. Where it is based on legitimate interests you may object, and we will stop unless we have compelling grounds to continue.
  • International transfers are addressed in section 11.

Stryde is sold and marketed from Sri Lanka and is not specifically targeted at the European Economic Area or the United Kingdom. This section is included because Users there may nonetheless subscribe. Its presence is not a statement that the GDPR applies to our processing, nor a certification of compliance with it.

14. United States privacy laws

Stryde is not marketed in the United States, and we do not assert that any particular state privacy law applies to us. Where one does apply — for example the California Consumer Privacy Act as amended — the following is true of our processing.

  • We do not sell personal information, and we do not share it for cross-context behavioural advertising. We have not done so in the preceding twelve months.
  • The categories we collect, the purposes we collect them for, and the categories of recipient are set out in sections 2, 3, 7 and 8.
  • You may request access to, correction of, or deletion of your personal information, and you may ask what we have disclosed, by writing to support@deeesignlab.com. We will not discriminate against you for making a request.
  • We do not use or disclose sensitive personal information for purposes that require an opt-out to be offered.

15. Children’s privacy

Stryde is a business tool sold to businesses. It is not directed at children, it is not designed for them, and it has no features intended for them. You must be at least 18 to hold an Account.

We do not knowingly collect personal data from children. If you believe a child has provided us with personal data, write to support@deeesignlab.com and we will delete it.

16. Third-party websites

Stryde links out to places we do not control: the websites of the businesses in your Search Results, their social profiles, map listings, and the policies of the providers in section 8. Following such a link takes you somewhere governed by that site’s own terms and privacy policy, not by this one. We are not responsible for their content or their practices, and a link is not an endorsement.

The website check described in section 2.3 is the one case where we fetch such a site ourselves. It reads one page, records what it observes, and stores no page content.

17. Changes to this policy

We will update this policy as the product changes and as the law requires. The current version always appears at this address, and the “Last updated” date at the top shows when it was last revised.

Where a change materially affects how we handle your information, we will give you notice before it takes effect — by email to your Account address, by a notice inside the application, or both — and where the law requires your consent to the change, we will ask for it. Continuing to use the Services after a change takes effect means you accept the revised policy.

18. Contact

Questions about this policy, or a request about your personal data, should go to:

Deeesign Lab

728/B, Pannipitiya Road, Pelawatta, Battaramulla, 10120, Sri Lanka

support@deeesignlab.com

+94 76 333 0802

19. Ownership

Stryde is developed and one hundred per cent owned by Deeesign Lab. Stryde, its source code, its design and the wording of this policy are © 2026 Deeesign Lab. All rights reserved. This does not affect your organisation’s ownership of its User Content, or the licences that govern the third-party Business Data described in section 5.