Privacy

This policy explains how Strata Studio handles information through stratastudio.dev, its customer portal, and connected services.

Effective August 19, 2026

Information we handle

Depending on how you use Strata, we may handle:

  • Contact information and project details you submit, including your name, email address, business, timeline, and message.
  • Account information received from Google, including your name, email address, profile image, and stable Google account identifier.
  • Customer workspace information, including organization membership, support conversations, service activity, agreements, acceptance records, billing contact information, invoice and subscription status, and related audit history.
  • Technical and security information such as IP address, user agent, session records, request metadata, error diagnostics, and security or audit events.

How we use information

We use information to:

  • respond to inquiries and evaluate requested work;
  • authenticate users and provide the correct customer workspace;
  • deliver support, agreements, service records, and billing tools;
  • operate the private owner CRM and its optional Calendar sync;
  • protect the service, investigate failures, and prevent abuse;
  • meet legal, tax, accounting, and contractual obligations; and
  • improve the reliability and usability of Strata services.

Strata does not sell personal information or Google user data, use it for targeted advertising, or use it to train general-purpose machine learning models.

Google user data

Google Sign-In supplies basic identity information so Strata can match you to a provisioned account, create a secure session, and route you to the correct owner or customer workspace. Ordinary portal login requests only identity scopes.

Separately, the Strata owner may choose Connect calendar inside the private CRM. That action incrementally requestscalendar.events.ownedaccess. Google sends event changes from the owner’s primary calendar. Strata immediately ignores events without its hidden CRM identity tag, including personal events and Google booking events, before any CRM read or write. Strata creates, reads, updates, and deletes only its tagged CRM events.

Retained CRM Calendar information may include event title, start and end time, timezone, all-day state, location, the editable Calendar notes section, Google event identifiers, update versions, and synchronization state. CRM-created events are private and Busy. Flexible prospecting uses date-only planned work inside CRM and is not sent to Google Calendar. OAuth access and refresh tokens are encrypted before database storage.

Disconnecting Calendar stops further synchronization and active watch renewal. It does not automatically delete tagged CRM events, a previously created Strata CRM secondary calendar, or corresponding CRM records. Access may also be revoked from the Google Account connections page.

The use of information received from Google Workspace APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

Cookies and local browser storage

Strata uses required cookies for Google OAuth state, authentication, session continuity, and security. Disabling them can prevent portal sign-in or authenticated features from working.

The public site keeps a bounded conversion-event log in your browser’s local storage. It can contain the event type, time, page path, action source, and limited metadata such as whether optional form fields were present or the length of a project description. It does not store the submitted contact-field content in that browser event log. The log is limited to 300 recent events and remains in your browser until it is cleared or replaced.

When information is shared

Strata shares information only as needed to operate the service, honor your request, or comply with law. Service providers may include:

  • Google for authentication, Calendar, and business email;
  • Vercel for application hosting;
  • Neon for managed PostgreSQL storage;
  • Stripe for hosted billing and payment processing;
  • Resend for application email;
  • Sentry for redacted error and reliability diagnostics;
  • Cloudflare for private object storage used by owner operations.

These providers process information under their own terms and privacy commitments. Strata may also disclose information when required by law, to protect rights or security, or as part of a business transaction where appropriate safeguards apply.

Retention and deletion

Strata retains information for as long as needed to provide the service, maintain security and audit history, resolve disputes, and meet legal, accounting, tax, and contractual obligations. Session and OAuth records expire or are revoked according to their security lifecycle. Accepted agreements and related proof records may be retained as durable business records.

You may request access, correction, or deletion of personal information. Some information may need to be retained when law, security, an active agreement, payment records, or another legitimate business obligation requires it.

Security

Strata uses access controls, tenant scoping, database row-level security, encrypted OAuth tokens, signed agreement proof, provider-hosted payment collection, audit records, and operational monitoring. No service can guarantee absolute security, so please report a suspected issue promptly.

Your choices and contact

You may disconnect Google Calendar from the CRM, revoke Google access from your Google Account, clear browser storage, or contact Strata about your information. To make a privacy request or report a concern, email hello@stratastudio.dev.

Strata may update this policy when the service or its data practices change. The effective date above identifies the current version.