Last updated 7 October 2026
We collect as little as we can and only what we use. If anything here is unclear, write to support@storvexa.com and a person will answer.
Who we are
Storvexa is a software and web development studio that works remotely with clients around the world. In this policy, "we" and "us" mean Storvexa, and "the site" means storvexa.com.
We decide how the personal data described here is used, so we are responsible for it. You can reach us about anything in this policy at support@storvexa.com.
What we collect
We only collect what you give us and what any website receives when you visit it:
- Enquiries. When you send the contact form: your name, email address and message, the service you are interested in, and, if you choose to add them, your phone number, company, budget, currency and timeline.
- Free website audit. The website address you want checked, your name and your email address. To build the report we fetch the public pages of that website, the same way a browser would.
- How you found us. When you send a form, we store the kind of channel that brought you (search, an ad, social media, another site or a direct visit), the referring website, the page you first landed on, and campaign tags in the link, such as utm parameters or ad click identifiers.
- Visitor log. For each visit: your IP address, the approximate location and network provider that belong to it (country, region, city), your browser's user agent, the pages you request, the referring page and the time. Our own team's visits are not recorded.
- Messages to our social accounts. Comments and direct messages you send to our Instagram or Facebook accounts, with your public username, so that we can answer them.
- Emails you send us. Whatever you choose to include, kept in our mailbox so we can reply and keep track of the conversation.
- Launch updates. If you asked to be told when something launches, the email address you gave.
We never ask for sensitive information such as health data, and we ask you not to send it through our forms.
How we use it
We use your information for these purposes and no others:
- To answer you. Reply to your enquiry, prepare a quote, and send you a confirmation that your message arrived.
- To run your audit. Check the website you entered and show you the report. Your request is also saved as an enquiry, so we can follow up if you want help with the fixes.
- To keep the site safe. Tell people from bots, spot attacks such as vulnerability scans, and block addresses that attack the site.
- To understand what works. Count visits, see which pages and channels bring enquiries, and fix errors that visitors run into.
- To show the right language and currency. The approximate country of your IP address chooses the language and the currency of prices when you arrive. You can change the language at any time.
- To measure our ads, only if you agree. See section 7.
We use an AI assistant (Claude, made by Anthropic) to help our team prepare replies to enquiries and social media messages. It sees the message and details such as your first name, company, and the service and budget you chose. It does not receive the email address or phone number from your enquiry.
We do not sell your data, and we do not make decisions about you by automated means that have legal or similarly significant effects.
Our legal grounds
Where data protection law asks for a legal basis, these are ours:
- Steps before a contract, and the contract itself: answering your enquiry, preparing a quote and delivering the work you order.
- Legitimate interests: keeping the site secure, understanding how it is used, replying to messages on social media, and occasional business emails to companies (section 8). We weigh these against your rights, and you can object at any time.
- Consent: advertising cookies and tags from Google and Meta. You can withdraw it whenever you like.
- Legal obligations: keeping business and tax records when we work together.
Who helps us
A few trusted providers process data on our behalf, each only for the job below:
- Hostinger hosts the site, its database and our business mailbox.
- Resend delivers the emails the site sends, such as your enquiry confirmation.
- Cloudflare runs Turnstile, an invisible check that a visitor is a person and not a bot. It sees your IP address and technical signals from your browser.
- ip-api.com turns an IP address into an approximate location and network name. It receives the IP address only.
- Anthropic provides the AI assistant described in section 3.
- Google and Meta receive data only if you accept advertising cookies (section 7). Meta also delivers the messages you send to our Instagram and Facebook accounts.
- Authorities only when the law requires us to share information.
Each provider handles the data under its own privacy policy and its agreement with us. We never sell or rent personal data to anyone.
Cookies and browser storage
We keep cookies to a minimum. These are the ones the site can set, by purpose:
- Session cookie (essential). Remembers your language, currency, how you arrived and your audit report while you browse. It expires when your browsing session ends.
- Form security cookie (essential). A short-lived token that protects our forms against forged submissions. It is removed once the form is sent.
- Consent choice. Remembers for 12 months whether you accepted or declined advertising cookies, so we do not ask on every page.
- Team cookie. Set only in the browsers of our own team after they sign in to the admin area, so their visits are left out of our statistics. Visitors never receive it.
- Browser storage. Your day or night theme choice is kept in your browser's local storage, and a marker that the visitor check has already run stays in the current tab only. Neither is sent to us.
- Advertising cookies. Google's and Meta's own cookies, set only after you click Accept.
You can delete cookies in your browser settings at any time. The site still works without them, although forms need the session cookie.
Advertising and your consent
When we run ads, the site can load Google's advertising tag and the Meta Pixel. They tell us which ads bring people to the site and to our forms. Nothing from Google or Meta loads until you click Accept in the cookie banner; if you decline, it stays that way. When no ads are running, there is no banner and no advertising tag at all.
If you accepted and then send a form, we also report that enquiry to Meta from our server (the Conversions API), so the ad is counted once. Meta receives your email address and phone number in hashed form, your IP address and your browser's user agent. Without your consent, nothing is sent.
While ads are running, you can change your mind at any time with the "Cookie settings" link at the bottom of every page, or the button below. Withdrawing consent stops the tags from loading on your next page view.
Business emails we send
From time to time we write to companies at the business email address they publish on their own website, with a short, specific note about how their website could work better. We use only information the company has made public.
Every such email tells you who we are and how to reply. It carries a standard unsubscribe header, and you can simply reply "no thanks" or "unsubscribe".
Once you ask us to stop, we never write to that address again. We keep only what we need to remember not to contact you.
How long we keep it
We keep data only as long as it serves the purpose it was collected for:
- Enquiries and audit requests: while we are talking and, if we work together, for the length of the project and the records we are required to keep. You can ask us to delete an enquiry at any time.
- Visitor log: as long as it is useful for security and statistics. There is no fixed automatic deletion schedule yet; we remove old records when they are no longer needed, and delete yours on request. Location lookups are cached for 24 hours only.
- Business email opt-outs: for as long as needed to respect your request.
- Cookies: as listed in section 6.
How we protect it
The site runs over HTTPS only. The admin area is closed: there is no public sign-up, and only accounts our team creates can enter. Keys for outside services are stored encrypted, and addresses that attack the site are blocked automatically.
No system is perfectly secure, but if a breach ever puts your data at risk, we will tell you and the relevant authority as the law requires.
Your rights
Depending on where you live, you have some or all of these rights:
- Access: ask for a copy of the personal data we hold about you.
- Correction: have inaccurate data fixed.
- Deletion: ask us to delete your data.
- Objection and restriction: object to how we use your data, or ask us to limit it, including for business emails.
- Withdrawing consent: at any time, through "Cookie settings" or by writing to us.
- Portability: receive the data you gave us in a common, machine-readable format.
Write to support@storvexa.com to use any of these rights. We answer within 30 days and may ask you to confirm your identity first. Using your rights is free.
You can also complain to the data protection authority where you live, although we would appreciate the chance to put things right first.
Where your data is processed
We work remotely, and our providers run servers in more than one country, so your data may be processed outside the country where you live. We choose providers that protect it with appropriate safeguards, such as standard contractual clauses where the law requires them.
Children
The site and our services are meant for businesses and adults. We do not knowingly collect data from children under 16. If you believe a child has sent us personal data, tell us and we will delete it.
Changes to this policy
When the way we handle data changes, we update this page and the date at the top. If a change is significant, we will make it clearly visible on the site.
Contact us
For any question about your privacy or this policy, write to us. A person reads every message.