Privacy Policy

Last updated: 1 August 2026

Elstrand is a reporting service operating from Singapore. This policy explains what personal data we hold, why, and what you can ask us to do about it. It is short because we hold very little.

What we collect

Three things, and nothing else.

1. Business contact details of prospective clients. Name, work email address, job title and company. Collected from public sources: company websites, public business directories, public professional profiles. Used to contact businesses about our service.

2. Correspondence with clients and enquirers. Emails you send us and we send you, and anything you tell us in them.

3. Enquiry form submissions. If you request a free visibility check, we collect the website address you enter, your work email, your brand name, what you sell, the revenue range you select, and a phone number if you choose to give one.

Those entries are stored in a Cloudflare D1 database hosted in the Asia-Pacific region, served from Singapore. We store only the fields you typed, plus the date and the two-letter country code Cloudflare attaches to the request. We do not store your IP address, your browser, your device, or any identifier that would let us recognise you again. To have a submission deleted, email the address at the bottom of this page and it is removed the same day.

Billing details are handled by Stripe, not by us. See Payments below.

What we do not collect

We want to be specific about this, because most privacy policies describe collection that never happens.

Everything we measure comes from asking public questions to publicly available AI assistants and recording the answers.

Where prospect data comes from, and why we may email you

If you received a cold email from us, your business contact details were collected from a public source, usually your company's own website.

Singapore. Under section 4(5) of the Personal Data Protection Act 2012, business contact information (your name, position, business address, business phone number and business email) collected and used for a business purpose falls outside the Act's data protection provisions. Consent is not required for this category, and none is claimed.

United Kingdom and European Union. Where a recipient is located in the UK or EU, we rely on legitimate interest under Article 6(1)(f) of the GDPR, as contemplated by Recital 47 for direct marketing. We contact corporate entities about a service relevant to their business. You can object at any time and we will stop.

We do not claim you consented. At first contact you have not consented to anything, and saying otherwise would be untrue.

To stop hearing from us, reply to any email and say so. We will remove you and keep a suppression record so we do not contact you again by mistake. We act on these within 10 business days and usually the same day.

California

The CCPA and CPRA do not apply to Elstrand. We meet none of the three qualifying thresholds. We are far below the revenue threshold, we do not handle the personal information of 100,000 or more California consumers, and we do not sell or share personal information at all.

We state this rather than listing California rights we are not obliged to provide.

How we use client data

If you become a client, we use your brand name, product names and category to run the monitoring that produces your report. Most of what we analyse is public commercial information about businesses, not personal data about people.

We use your email address to send you your report, your invoices, and anything you have asked us about. We do not use client information to train any model, and we do not sell or share it with anyone.

Payments

Payments are processed by Stripe. When you subscribe, Stripe collects your card and billing details directly. Elstrand never receives or stores them. Stripe holds this data under its own privacy policy: stripe.com/privacy

You can manage your card, view invoices, change plan or cancel through the Stripe billing portal, which we link from every invoice and from your reports.

How long we keep things

DataKept for
Prospect contact details, no reply12 months, then deleted
Prospect contact details, opted outEmail address only, kept indefinitely on a suppression list so we do not contact you again
Enquiry form submissions12 months
Client correspondenceDuration of the engagement, then 5 years
Client reports and underlying query dataDuration of the engagement, then 5 years
Billing records5 years, as required for tax and accounting records

We do not keep anything indefinitely except the suppression list, which exists to protect you rather than us.

Your rights

Under the Singapore PDPA, you may ask what personal data we hold about you and ask us to correct it. Note that business contact information used for business purposes sits outside these provisions, so in practice there is often nothing that attaches.

Under the UK and EU GDPR, if you are located there, you may request access, correction, erasure, restriction, portability, and you may object to processing. Objecting to marketing is absolute. We stop, immediately and permanently.

To exercise any of these, email the address below. We will respond within 30 days.

Data protection contact

Elstrand's data protection contact, as required by section 11(5) of the Personal Data Protection Act 2012:

javier@elstrand.com

Emails reach a person in Singapore. We aim to reply within one business day.

Data leaving Singapore

We use three providers, and we have deliberately kept the enquiry data in region.

Under section 26 of the PDPA, we are required to ensure that data transferred abroad receives comparable protection. All three providers operate under standard contractual protections that meet this requirement.

For the UK and EU subset of data, transfers out of the UK or EU are covered by the providers' own transfer mechanisms.

Changes to this policy

We will update the date at the top when this policy changes. If a change materially affects clients (how we use your data, who we share it with, or how long we keep it) we will email active clients at least 30 days before it takes effect. Minor changes such as clarified wording are made without individual notice.