GDPR Compliance
Last updated: 28.08.2026
Straycy OÜ
Registry code:
Registered in Estonia, European Union
Contact: hi@straycy.com
Straycy is built with privacy at its core. As a company registered in Estonia, we are fully subject to the General Data Protection Regulation (GDPR). This page explains how Straycy is designed, what data goes where, and what you need to do to stay compliant as our customer.
The most important thing to understand
Visitor data is stored on your own hosting, not ours
Attribution and lead data recorded by the Straycy plugin is written to the database of your own WordPress installation. It does not pass through our servers and we never hold a copy of it.
Likewise, when the plugin sends a conversion to Meta, Google, Reddit or Snapchat, that request goes from your server directly to the platform. It does not route through us.
This matters for your compliance position: for your visitors’ data, you are the controller and we are not a processor, because we neither receive nor store it. The sections below set out the narrow circumstances in which we do process data on your behalf.
No cross-site tracking or fingerprinting
Straycy’s attribution uses first-party cookies set on your own domain. We do not use cross-site cookies, third-party tracking of our own, or browser fingerprinting to identify your visitors.
Note that the browser tags you choose to enable, such as the Meta Pixel or the Google tag, are third-party scripts operated by those platforms. They load only for the platforms you configure, and only when consent allows. If you prefer to avoid them, you can run server-side conversions alone with browser-side tracking switched off.
Our own systems run in the European Union
The Straycy portal and its database are hosted in the EU, with the database in Frankfurt, Germany. Where any transfer outside the EEA occurs through a sub-processor, it is covered by an appropriate safeguard under Chapter V GDPR.
Roles and responsibilities
| Role | Who | Responsibility |
|---|---|---|
| Data Controller | You, the Straycy customer | You determine the purposes and means of processing your website visitors’ data, which is stored on your own server. You are responsible for your privacy policy, your cookie notice, and obtaining consent. |
| Data Processor | Straycy OÜ | We process personal data on your behalf only in the limited cases listed below: your account, your support requests, and any conversion events you choose to route through our infrastructure. |
| Independent controllers | Meta, Google, Reddit, Snapchat | Advertising platforms decide their own purposes for the conversion data they receive. Your relationship with them is governed by their terms, not ours. |
| Data Subjects | Your website visitors | Individuals whose data is recorded by the Straycy plugin on your website. |
What the plugin records on your server
This data is stored in your own WordPress database. You control it, and you can export or delete it at any time.
| Data type | Examples | Purpose | Storage |
|---|---|---|---|
| Attribution data | UTM parameters, referrer URL, landing page | Lead source identification | Retained with the lead record |
| Ad click IDs | gclid, fbclid, msclkid, rdt_cid | Ad platform attribution | Retained with the lead record |
| Device info | Device type, browser | Analytics context | Retained with the lead record |
| IP address | Hashed with SHA-256 and a per-site salt, never stored raw | Deduplication and match quality | Hash only, not reversible |
| Visitor ID | Random identifier in a first-party cookie | Linking visits to a later submission | Deleted after 30 days if no conversion follows. Configurable in plugin settings. |
| Lead data | Name, email, phone from a form submission | Lead attribution and contact matching | Retained until you delete it |
What we process on our own systems
These are the only cases where personal data reaches Straycy OÜ, and they are governed by our Data Processing Agreement.
| What | Data | Retention |
|---|---|---|
| Your account | Your name, email, profile image, licence key, subscription records, and the URLs of the sites you register | Subscription term plus 30 days |
| Support requests | Anything you choose to send us, such as logs, screenshots or exports | Up to 24 months |
| Server-side conversion forwarding | Conversion events, where you enable a feature that routes them through our infrastructure rather than sending them directly | No longer than 90 days |
Your own name and email as our customer is data for which we are the controller rather than the processor. That processing is described in our Privacy Policy.
Consent management
Straycy respects your visitors’ consent choices. How it behaves depends on your setup.
With a consent tool installed
If your website uses a consent management platform such as CookieYes, Complianz or Cookiebot, Straycy detects consent status automatically. When consent is not granted, Straycy runs in cookieless mode: no cookies are set, no personal identifiers are stored, and only anonymous attribution data such as referrer and UTM parameters is captured.
When the visitor grants consent, full tracking activates without requiring a page reload.
Without a consent tool
If no consent tool is detected, Straycy uses a first-party functional cookie to link page visits to form submissions. Most consent frameworks classify this as functional, because it is required for the attribution service to work at all. No marketing or analytics cookies are set by Straycy itself.
We recommend installing a consent management tool on any site with EU visitors. Consent mode can also be forced on or off in the plugin’s Consent tab, and you remain responsible for making a lawful choice there.
Data subject rights
Your website visitors have the right to access, rectify, delete, restrict or port their personal data. Because that data sits on your server, you are the controller and you are responsible for responding to those requests.
Straycy gives you the tools to do it:
- Deletion: the plugin exposes a right-to-erasure endpoint at
wp-json/straycy/v1/delete-data, restricted to administrators, which removes all records associated with a given email address. - Export: export lead and contact data as CSV from the plugin’s admin screens.
- Access: view everything stored for an individual in the lead and contact detail views.
For data held on our systems, contact hi@straycy.com and we will assist within the timeframes required by the GDPR.
Data retention
- Anonymous visitor sessions: deleted after 30 days by default if no conversion is recorded. Configurable in the plugin’s settings.
- Lead and contact records: retained on your server until you delete them.
- Your account data: retained for the subscription term plus 30 days, during which you can export it. After that we delete it, except records we must keep for legal, tax or accounting purposes.
- Conversion events routed through our infrastructure: no longer than 90 days.
Security measures
- All data transmitted over TLS
- IP addresses hashed with SHA-256 and a per-site salt, never stored raw
- Email addresses and phone numbers hashed with SHA-256 before being sent to any advertising platform. Raw values are never transmitted to them
- Capability checks and nonce verification on the plugin’s administrative REST endpoints
- Portal access protected by Google sign-in, with credentials such as OAuth refresh tokens encrypted at rest and never exposed to your WordPress installation
- IP addresses are not stored by the portal at all. Where one is used transiently for rate limiting, it is not written to persistent storage
- Version-controlled code and reviewed changes
Data Processing Agreement
Our Data Processing Agreement meets the requirements of GDPR Article 28. It covers the scope of processing, data categories, security obligations, sub-processor management, breach notification and assistance with data subject rights. It forms part of our Terms of Service, so it applies automatically to every customer.
If your compliance framework requires a separately signed copy, contact us at hi@straycy.com.
Sub-processors
We use the following sub-processors for our own systems. Each is bound by data protection obligations no less protective than those in our DPA.
| Sub-processor | Purpose | Location |
|---|---|---|
| Vercel Inc. | Portal hosting | EU region. US company. |
| Neon Inc. | Database hosting | EU, Frankfurt. US company. |
| [Payment provider] | Payment processing and invoicing | [To be completed] |
Advertising platforms such as Meta, Google, Reddit and Snapchat are not our sub-processors. They receive conversion data directly from your server, decide their own purposes for it, and act as independent controllers.
We will notify customers at least 30 days before adding a new sub-processor. You may object within that period by contacting us.
Your compliance checklist
As a Straycy customer, here is what you should do:
- Update your website’s privacy policy to describe the attribution data you collect and its transfer to the advertising platforms you have configured
- Install a consent management tool if you have EU visitors
- Include a link to your privacy policy near your forms
- Accept the terms of each advertising platform you connect, since they act as independent controllers of the data they receive
- Respond to data subject access and deletion requests within the statutory timeframe, using the plugin’s export and deletion tools
- Review our Data Processing Agreement, and request a signed copy if your framework requires one
Supervisory authority
As a company registered in Estonia, our lead supervisory authority is the Estonian Data Protection Inspectorate, Andmekaitse Inspektsioon:
Website: www.aki.ee
Email: info@aki.ee
Phone: +372 627 4135
Contact us
For GDPR questions, data subject requests, or a signed DPA:
Straycy OÜ
Registry code: [REGISTRY CODE]
Email: hi@straycy.com