Privacy Policy
Last updated: March 31, 2026
1. Overview
Stroby (“we,” “us,” or “our”) operates the website stroby.ai and related services (the “Service”). This Privacy Policy explains how we collect, use, disclose, and protect your personal information when you use our Service.
We are committed to protecting your privacy and handling your data transparently. This policy complies with the General Data Protection Regulation (GDPR), the California Consumer Privacy Act (CCPA), the Personal Information Protection and Electronic Documents Act (PIPEDA), and other applicable data protection laws.
2. Information We Collect
2.1 Information You Provide
When you use our onboarding chat or interact with the Service, we collect:
- Identity Information: Your name, email address, and WhatsApp phone number.
- Business Information: Company name, role, product description, target customer, niche, budget, and campaign goals.
- Audience Information: Platform, channel name, audience size, engagement rates, content niche, partnership preferences, and pricing.
- Communication Data: Messages exchanged through our chat interface and WhatsApp.
2.2 Information Collected Automatically
When you visit our website, we may automatically collect:
- Device Information: Browser type, operating system, and device identifiers.
- Usage Data: Pages visited, time spent, clicks, and navigation patterns.
- Log Data: IP address, access times, and referring URLs.
3. How We Use Your Information
We use your information for the following purposes:
- Matching: To power our AI matching engine and connect you with relevant businesses, influencers, or other professionals.
- Communication: To send match suggestions, platform updates, and service-related messages via WhatsApp and email.
- Payments: To process transactions, manage escrow, and handle payouts through Stripe.
- Service Improvement: To analyze usage patterns and improve the platform experience.
- AI Training: To train and improve our AI matching algorithms using anonymized and aggregated data that has been stripped of personally identifiable information.
- Legal Compliance: To comply with applicable laws, regulations, and legal processes.
4. Legal Basis for Processing (GDPR)
If you are in the EEA or UK, we process your data based on:
- Consent: You consent to data processing when you complete onboarding and agree to these terms.
- Contract Performance: Processing is necessary to provide the Service you requested.
- Legitimate Interests: To improve our Service, prevent fraud, and ensure platform security.
- Legal Obligation: To comply with applicable laws and regulations.
5. Data Sharing & Third Parties
5.1 With Other Users
When we suggest a match, we share relevant Profile information (such as niche, audience description, and general metrics) with the potential match. We do not share your email, phone number, or WhatsApp number with other users unless both parties have explicitly opted in to an introduction.
5.2 Service Providers
We share data with trusted third-party service providers who help us operate the platform:
- Supabase (database hosting) — stores your Profile and platform data.
- Stripe (payments) — processes payments and manages escrow.
- Twilio (messaging) — delivers WhatsApp messages.
- Anthropic (AI) — powers our AI matching and conversational features.
- Vercel (hosting) — hosts the Stroby website and API.
These providers process data only as necessary to perform their services and are contractually obligated to protect your information.
5.3 Legal Requirements
We may disclose your information if required by law, regulation, legal process, or governmental request, or to protect the rights, property, or safety of Stroby, our users, or others.
6. Data Retention
We retain your personal data for as long as your account is active or as needed to provide the Service. If you request account deletion, we will delete your personal data within 30 days, except where retention is required by law or for legitimate business purposes (e.g., resolving disputes, enforcing agreements).
Anonymized and aggregated data used for AI training and analytics may be retained indefinitely as it cannot be linked back to you.
7. Data Security
We implement appropriate technical and organizational measures to protect your personal data, including:
- Encryption of data in transit (TLS/HTTPS) and at rest.
- Access controls limiting data access to authorized personnel.
- Regular security reviews of our infrastructure and third-party providers.
- Secure payment processing through Stripe (PCI DSS compliant).
While we take reasonable measures to protect your data, no method of transmission or storage is 100% secure. We cannot guarantee absolute security.
8. Your Rights
Depending on your location, you may have the following rights regarding your personal data:
- Access: Request a copy of the personal data we hold about you.
- Rectification: Request correction of inaccurate or incomplete data.
- Erasure: Request deletion of your personal data (“right to be forgotten”).
- Portability: Receive your data in a structured, machine-readable format.
- Objection: Object to processing based on legitimate interests or for direct marketing.
- Restriction: Request that we limit processing of your data in certain circumstances.
- Withdraw Consent: Withdraw previously given consent at any time.
To exercise any of these rights, email us at privacy@stroby.ai. We will respond within 30 days.
8.1 California Residents (CCPA)
California residents have the right to know what personal information is collected, request deletion, and opt out of the sale of personal information. We do not sell your personal information.
8.2 Canadian Residents (PIPEDA)
Canadian residents have the right to access their personal information, challenge its accuracy, and withdraw consent for its collection, use, or disclosure, subject to legal or contractual restrictions.
9. Cookies & Tracking
We use minimal cookies and local storage necessary for the functioning of the Service (e.g., saving your onboarding progress). We do not use third-party tracking cookies for advertising. We may use analytics tools to understand how the Service is used, with data collected in an anonymized manner.
10. International Data Transfers
Your data may be transferred to and processed in countries outside your country of residence, including the United States and Canada, where our service providers operate. We ensure appropriate safeguards are in place, such as Standard Contractual Clauses (SCCs) approved by the European Commission, to protect your data during international transfers.
11. Children's Privacy
The Service is not intended for individuals under the age of 18. We do not knowingly collect personal information from children. If you believe we have collected data from a minor, please contact us at privacy@stroby.ai and we will promptly delete it.
12. Changes to This Policy
We may update this Privacy Policy from time to time. If we make material changes, we will notify you via email or WhatsApp at least 30 days before the changes take effect. Your continued use of the Service after the effective date constitutes acceptance of the updated policy.
13. Contact Us
If you have any questions about this Privacy Policy or your personal data, contact us:
- Email: privacy@stroby.ai
- General inquiries: hello@stroby.ai