Privacy Policy
Last updated: 1 August 2026
Elstrand is a reporting service operating from Singapore. This policy explains what personal data we hold, why, and what you can ask us to do about it. It is short because we hold very little.
What we collect
Three things, and nothing else.
1. Business contact details of prospective clients. Name, work email address, job title and company. Collected from public sources: company websites, public business directories, public professional profiles. Used to contact businesses about our service.
2. Correspondence with clients and enquirers. Emails you send us and we send you, and anything you tell us in them.
3. Enquiry form submissions. If you request a free visibility check, we collect the website address you enter, your work email, your brand name, what you sell, the revenue range you select, and a phone number if you choose to give one.
Those entries are stored in a Cloudflare D1 database hosted in the Asia-Pacific region, served from Singapore. We store only the fields you typed, plus the date and the two-letter country code Cloudflare attaches to the request. We do not store your IP address, your browser, your device, or any identifier that would let us recognise you again. To have a submission deleted, email the address at the bottom of this page and it is removed the same day.
Billing details are handled by Stripe, not by us. See Payments below.
What we do not collect
We want to be specific about this, because most privacy policies describe collection that never happens.
- No tracking cookies. The only cookie this site sets is the one that keeps you signed in to your account, and only if you sign in.
- No analytics that identify you. Since 22 August 2026 this site uses Cloudflare Web Analytics, which sets no cookies and counts page views, referrers and countries in aggregate. It tells us how many people read a page. It does not tell us who they are and it does not follow anyone between sites. We do not use Google Analytics or any equivalent that does.
- Advertising pixels and trackers: none.
- No access to any client's systems. We never receive logins to a client's website, content management system, analytics, ad accounts or ecommerce platform. Our service does not require it and we do not ask for it.
- Customer data belonging to our clients: never received. We never receive lists of a client's customers.
- Card and bank details: never seen. Stripe collects and stores these. We never see full card numbers.
Everything we measure comes from asking public questions to publicly available AI assistants and recording the answers.
Where prospect data comes from, and why we may email you
If you received a cold email from us, your business contact details were collected from a public source, usually your company's own website.
Singapore. Under section 4(5) of the Personal Data Protection Act 2012, business contact information (your name, position, business address, business phone number and business email) collected and used for a business purpose falls outside the Act's data protection provisions. Consent is not required for this category, and none is claimed.
United Kingdom and European Union. Where a recipient is located in the UK or EU, we rely on legitimate interest under Article 6(1)(f) of the GDPR, as contemplated by Recital 47 for direct marketing. We contact corporate entities about a service relevant to their business. You can object at any time and we will stop.
We do not claim you consented. At first contact you have not consented to anything, and saying otherwise would be untrue.
To stop hearing from us, reply to any email and say so. We will remove you and keep a suppression record so we do not contact you again by mistake. We act on these within 10 business days and usually the same day.
California
The CCPA and CPRA do not apply to Elstrand. We meet none of the three qualifying thresholds. We are far below the revenue threshold, we do not handle the personal information of 100,000 or more California consumers, and we do not sell or share personal information at all.
We state this rather than listing California rights we are not obliged to provide.
How we use client data
If you become a client, we use your brand name, product names and category to run the monitoring that produces your report. Most of what we analyse is public commercial information about businesses, not personal data about people.
We use your email address to send you your report, your invoices, and anything you have asked us about. We do not use client information to train any model, and we do not sell or share it with anyone.
Payments
Payments are processed by Stripe. When you subscribe, Stripe collects your card and billing details directly. Elstrand never receives or stores them. Stripe holds this data under its own privacy policy: stripe.com/privacy
You can manage your card, view invoices, change plan or cancel through the Stripe billing portal, which we link from every invoice and from your reports.
How long we keep things
| Data | Kept for |
|---|---|
| Prospect contact details, no reply | 12 months, then deleted |
| Prospect contact details, opted out | Email address only, kept indefinitely on a suppression list so we do not contact you again |
| Enquiry form submissions | 12 months |
| Client correspondence | Duration of the engagement, then 5 years |
| Client reports and underlying query data | Duration of the engagement, then 5 years |
| Billing records | 5 years, as required for tax and accounting records |
We do not keep anything indefinitely except the suppression list, which exists to protect you rather than us.
Your rights
Under the Singapore PDPA, you may ask what personal data we hold about you and ask us to correct it. Note that business contact information used for business purposes sits outside these provisions, so in practice there is often nothing that attaches.
Under the UK and EU GDPR, if you are located there, you may request access, correction, erasure, restriction, portability, and you may object to processing. Objecting to marketing is absolute. We stop, immediately and permanently.
To exercise any of these, email the address below. We will respond within 30 days.
Data protection contact
Elstrand's data protection contact, as required by section 11(5) of the Personal Data Protection Act 2012:
Emails reach a person in Singapore. We aim to reply within one business day.
Data leaving Singapore
We use three providers, and we have deliberately kept the enquiry data in region.
- Cloudflare hosts this website and the database holding enquiry form submissions. That database is provisioned in the Asia-Pacific region and served from Singapore, so form submissions do not leave the country in normal operation.
- Google Workspace handles email, and Stripe handles payments. Both store data on infrastructure outside Singapore.
Under section 26 of the PDPA, we are required to ensure that data transferred abroad receives comparable protection. All three providers operate under standard contractual protections that meet this requirement.
For the UK and EU subset of data, transfers out of the UK or EU are covered by the providers' own transfer mechanisms.
Changes to this policy
We will update the date at the top when this policy changes. If a change materially affects clients (how we use your data, who we share it with, or how long we keep it) we will email active clients at least 30 days before it takes effect. Minor changes such as clarified wording are made without individual notice.