Privacy Policy

1. Who we are

Stroma Consulting (Pty) Ltd (Reg. 2026/076918/07) is a South African software company that builds automated web performance diagnostics, based in Johannesburg, Gauteng, South Africa. Full registered address available on written request to hello@stroma.design.

In this policy, "Stroma", "we" and "us" refer to Stroma Consulting (Pty) Ltd.

2. What personal information we collect

We offer two levels of analysis. The information we collect depends on which you use.

2.1 Light Scan (no account or email required)

When you run a Light Scan, we collect the following inputs to perform the analysis:

Light Scans do not require an email address or any other personally identifiable information. We store an anonymous log entry (sanitised URL domain, region, vertical, currency, performance score, grade, bleed index, go/no-go verdict, business metrics if provided, scan mode, operational telemetry such as duration, cache status, error diagnostics, and timestamp) for aggregate market intelligence, benchmarking, and service reliability. URLs are sanitised to domain and path only — query strings, fragments, and other parameters are stripped before storage. No personally identifiable information is retained from Light Scans.

Light Scan results are cached for up to 24 hours to prevent duplicate processing. The cache entry contains only the URL and analysis parameters, not personal data.

2.2 Deep Evidence Report (email required)

When you request a Deep Evidence Report, we additionally collect:

This information is necessary to generate your report and deliver it to you. If you do not provide the required fields, we cannot process your request. Omitting optional business metrics means we will use industry benchmarks instead of your specific data, which may reduce the precision of the revenue-impact estimates.

As part of the Deep Evidence Report, we also run an automated usability audit on your publicly accessible website. This audit evaluates front-end user-experience heuristics (navigation clarity, interaction feedback, cognitive load, touch input quality, visual accessibility) using industry-standard tools. It does not access any private data, user accounts, or backend systems — it analyses only the publicly rendered page in the same way a visitor's browser would.

2.3 What we do not collect

We do not collect or store passwords or government-issued identifiers. If you purchase the Fix Pack, your payment is processed by Paddle, our Merchant of Record — Paddle (not Stroma) collects and handles your card and billing details. Stroma never receives or stores your full payment-card number; we only receive confirmation of a completed purchase. See section 9.

3. Why we collect it

Your information is used to:

By requesting a Deep Evidence Report, you acknowledge that Stroma may contact you about your scan, its findings, and related products. We do not use your information for unrelated third-party marketing, or to build profiles about you or make automated decisions that significantly affect you. We do measure the effectiveness of our own advertising, as described in section 12. If you wish to object to follow-up contact, email hello@stroma.design and we will suppress further communications.

4. Legal basis for processing

Under the Protection of Personal Information Act (POPIA), we process your personal information on the following grounds:

5. Where your data is stored

Your data is processed and stored using the following services:

5.1 Public scan pipeline (Light Scan and Deep Evidence Report)

Service What it receives Purpose
Turso (LibSQL) URL, email, company, role, region, vertical, business metrics (sessions, order value, conversion rate, ad revenue, device-level conversion rates), report status, anonymous scan/report telemetry (performance scores, grade, bleed index, go/no-go verdict, error diagnostics), and an advertising click identifier (Google Click ID / gclid) when you arrive from one of our ads. Name is not stored in the database. Primary database — scan cache, report tracking, token management, anonymous scan and report telemetry, long-term benchmarking
Upstash Redis Report job payload (URL, email, name if provided, region, vertical, business metrics) — all job data automatically expires after 24 hours Transient job queue for report generation pipeline, concurrency control, daily budget tracking. Name exists only in the job payload for email personalisation and is not persisted elsewhere.
Cloudflare R2 Report artifacts (analysis JSON, PDF) — no PII in object keys Long-term storage of completed report data
Cloudflare Turnstile Browser challenge token, IP address Bot protection on scan forms (invisible widget)
Resend Email address, report URL, performance summary Email delivery of report-ready notifications

5.2 Legacy manually-reviewed pipeline

Our legacy pipeline, used for manually reviewed reports, additionally involves:

Service What it receives Purpose
Google Sheets All submitted form fields Submission tracking and workflow management
Google Drive Report files (analysis data, drafts, final PDFs) Report storage and review
Google Docs Report content Editable draft creation and review

The public scan pipeline (Light Scan and Deep Evidence Report) does not use Google Sheets, Google Drive or Google Docs. These services are used only for our legacy manually-reviewed report workflow.

5.3 Website analytics

Service What it receives Purpose
Google Tag Manager Script execution, tag orchestration Event tracking and service integration
Google Analytics Anonymised usage data, IP address, device information Website traffic analysis and performance monitoring
Google Ads Google Click ID (gclid) and, on a Fix Pack purchase, the purchase time and value Measuring the performance of our own advertising campaigns

Turso is operated by Turso Inc (United States). Upstash is operated by Upstash Inc (United States). Cloudflare R2 and Turnstile are operated by Cloudflare Inc (United States). Resend is operated by Resend Inc (United States). Google services are provided by Google LLC (United States). Your data may be processed outside of South Africa. Each provider maintains their own security and privacy practices.

6. Report delivery and access

Deep Evidence Reports are delivered via a secure signed URL emailed to you. These links:

We do not attach reports as email attachments. The report is rendered in your browser via the secure, authenticated link. We do not use Google Drive or Google Docs to deliver public scan reports.

7. International users and the GDPR

If you are based in the European Economic Area (EEA), your personal data is protected under the General Data Protection Regulation (GDPR) in addition to POPIA. The legal basis for processing is consent (Article 6(1)(a)) and legitimate interest (Article 6(1)(f)).

Your data is transferred to the United States via Turso Inc, Upstash Inc, Cloudflare Inc, Resend Inc and Google LLC. Google participates in the EU-US Data Privacy Framework. For other providers, transfers are governed by Standard Contractual Clauses where applicable.

In addition to the rights listed under POPIA below, EEA residents have the right to lodge a complaint with their local data protection supervisory authority and the right to data portability.

8. Third-party data sources used in your report

To generate your analysis, we query the following public data sources using only your submitted URL (no personal data is shared with these services):

All analysis is performed by our own deterministic software. No personal data is sent to any artificial intelligence or large language model service.

9. Who has access to your data

Access to your submitted information is limited to the Stroma founder and any authorised team members involved in report generation and delivery. We do not sell, rent or share your personal information with third parties for their own purposes.

Payments: when you buy the Fix Pack, our reseller and Merchant of Record, Paddle.com Market Ltd ("Paddle"), acts as an independent controller of the payment and billing information you provide at checkout. Paddle processes that information to take payment, issue receipts, handle billing support and remit applicable taxes, under Paddle's Privacy Policy. Stroma receives only the confirmation and limited order details needed to grant your purchase and provide support.

10. Data retention

Data type Retention period Notes
Light Scan results (cache) 24 hours Automatically purged after expiry
Anonymous scan metadata Indefinite Contains no PII; used for aggregate market intelligence only
Full report records (database) Indefinite until deletion requested Report access links expire after 30 days; underlying data retained until you request deletion
Report artifacts (R2 storage) Indefinite until deletion requested Analysis JSON and PDF files; deleted upon request
Job queue data (Redis) 24 hours Automatically expired
Google Sheets rows (legacy pipeline) Indefinite Manual deletion on request

You may request deletion of your personal information at any time by emailing hello@stroma.design. Upon request, we will delete your data from all active systems (database records, stored report artifacts, email records and, where applicable, Google Sheets and Google Drive).

11. Bot protection

We use Cloudflare Turnstile in invisible mode to prevent automated abuse of our scan forms. Turnstile does not use persistent cookies or track users across sites. It processes browser signals and IP address solely to distinguish humans from bots. See Cloudflare's privacy policy for details.

12. Cookies and tracking

We use Google Tag Manager and Google Analytics to understand how visitors interact with our website. This involves the use of cookies to collect anonymised information about your visit, such as the pages you view and the time spent on the site. This data helps us improve our service and user experience.

We also advertise Stroma on Google Ads. Where you accept our cookie banner and arrive from one of our ads, we record Google's click identifier (gclid); if you then purchase the Fix Pack, we share that identifier with the purchase time and value with Google Ads to measure which ads led to a sale. If you decline, we do not record or use it. This is used only to measure our own advertising — not to profile you.

Cloudflare Turnstile, used for bot protection, does not set persistent cookies.

All fonts and assets remain self-hosted on our servers to minimise third-party requests where possible.

13. Your rights under POPIA

As a data subject under the Protection of Personal Information Act, you have the right to:

To exercise any of these rights, email hello@stroma.design. We will acknowledge your request within 7 days and respond substantively within 30 days.

If you believe we have not handled your information appropriately, you may lodge a complaint with the Information Regulator of South Africa:

Information Regulator (South Africa)
JD House, 27 Stiemens Street, Braamfontein, Johannesburg, 2001
PO Box 31533, Braamfontein, Johannesburg, 2017
Tel: 010 023 5200
General Enquiries: enquiries@inforegulator.org.za
POPIA Complaints: POPIAComplaints@inforegulator.org.za
Website: inforegulator.org.za

14. Changes to this policy

We may update this policy from time to time. Material changes will be noted on this page with an updated date. Continued use of the site after changes constitutes acceptance of the revised policy.

15. Contact & Information Officer

For any questions about this policy, how we handle your data, or to contact our Information Officer:

Stroma Consulting (Pty) Ltd
Information Officer: Jonathan Booysen
hello@stroma.design

16. PAIA Manual

In accordance with the Promotion of Access to Information Act (PAIA), our PAIA Manual is available upon request by contacting hello@stroma.design.

← Back to stroma.design