Privacy Policy
The short version
- We collect your email address only when you join the Oystro waitlist, plus basic technical logs (IP address, browser, pages viewed) that any web server records automatically.
- We use it for one thing: to confirm your signup and tell you when Oystro Standard launches, along with occasional product news you can opt out of at any time.
- We confirm every signup by email (double opt-in). If you do not click the confirmation link, we do not email you marketing.
- We do not sell, rent or trade your email address to anyone, and we do not share it for third-party advertising.
- You stay in control: unsubscribe from any email, or ask us to access, correct or delete your data by writing to [email protected].
1. Who we are
This Privacy Policy is issued by Oystro (“Oystro”, “we”, “us” or “our”), operated from India by George Koshy.
For the purposes of applicable data protection law, we are the controller (and data fiduciary under India's Digital Personal Data Protection Act, 2023) of the personal information described in this policy. Our contact details are set out in Section 15.
2. What this policy covers
This policy applies to the Oystro marketing and teaser website at https://oystro.com and its subdomains (the “Website”), including the waitlist forms, and to email communications we send to waitlist subscribers.
It does not cover:
- The Oystro open-source protocol (Oystro OSS), which is distributed under its own licence through github.com/oystro/oystro-oss. Code you run on your own machines never passes through this Website.
- Any future Oystro product, dashboard or account portal, which will be governed by its own terms and privacy policy when launched.
- Third-party websites, tools or services that we link to (see Section 13).
3. Information we collect
3.1 Information you give us
- Email address and your consent tick — the waitlist forms ask for an email address and an unticked checkbox confirming you have read and agree to this Privacy Policy. Both are voluntary; you can read the whole Website without giving us anything.
- Anything you write to us — if you email our support or privacy address, we keep that correspondence and your return address so we can reply.
We do not ask for, and you should not send us, payment card details, identity documents, or sensitive personal data through this Website.
3.2 Information collected automatically
Like virtually every website, our hosting infrastructure automatically records:
- IP address (which also gives us your approximate country/region),
- browser type and version, operating system and device type,
- the page you came from (referrer) and the pages you view on this Website, with date and time stamps,
- request volume and error data used for security, abuse prevention and reliability.
The waitlist forms are protected by Cloudflare Turnstile, an anti-bot verification challenge. When the form runs, Cloudflare processes your IP address and browser signals to decide whether a human is interacting with the page; we receive only the verification result and never use it for advertising.
This information sits in server and security logs. It is not combined with your email address for advertising purposes.
3.3 Information stored in your browser
We use your browser's local storage for one small thing: to remember your light/dark theme preference (oystro_theme). This data stays on your device, is never transmitted to us, and you can clear it at any time through your browser settings. Email addresses and consent choices are never stored in your browser.
3.4 What we do not collect on this Website
- No precise geolocation, camera, microphone or contacts access.
- No advertising identifiers and no data from social networks or data brokers.
- No payment information — checkout, if and when we launch, will be handled separately by our payment providers.
4. How and why we use your information
| What we do | Why (purpose) | Legal basis |
|---|---|---|
| Process your waitlist signup and send the confirmation email | To deliver what you asked for and verify the address is real | Your consent; performance of a request you made |
| Send the launch announcement, early-access invitation and founding-member pricing | The reason you joined the list | Your consent (withdrawable at any time) |
| Send occasional product news about Oystro | To keep you informed about what you signed up to hear about | Your consent; our legitimate interest in telling interested people about our own product |
| Reply to emails and support requests | To answer you | Legitimate interest; your request |
| Operate, secure and improve the Website; prevent spam, bots, fraud and abuse; produce aggregated, non-identifying statistics | To keep the site safe and working | Legitimate interest (not overridden by your rights) |
| Keep records of your consent and subscription status | To prove, if ever asked, that you agreed — and to honour your opt-outs | Legal obligation; legitimate interest |
| Comply with court orders, lawful requests and applicable law | Because we are required to | Legal obligation |
We will not use your email address for a purpose that is incompatible with the ones above without telling you and, where required, asking for your consent first.
We do not sell personal information, we do not rent or exchange email lists, and we do not disclose information to anyone for that party's own direct marketing.
5. Double opt-in and email consent
We use double opt-in for every waitlist signup:
- You enter your email address, tick the box confirming you have read and agree to this Privacy Policy, and submit the form.
- We send a confirmation message to that address. Your address sits in an unconfirmed state and is not used for marketing while it is unconfirmed.
- You click the confirmation link. Only then is your subscription marked as confirmed and do you start receiving launch and product emails.
- If you never confirm, we remove the unconfirmed address from our active list (see Section 9).
For each signup we record the date and time, the address, the source of the signup, your explicit consent tick (with the version of this policy you accepted), and the IP address associated with the signup (the consent grant). We keep these records so that we can demonstrate consent if a regulator, payment partner or you ever asks.
Every marketing email we send contains a working unsubscribe link, and every message is sent from an identifiable sender with a valid postal address and a way to reach us, as required by anti-spam rules in India, the United States, the United Kingdom and the European Union. Opting out is immediate and permanent: we will keep your address on a suppression list purely so that we remember not to email you again.
8. International transfers
We operate from India. Your information may be processed in India and in other countries where our providers operate — in practice, principally the United States (Cloudflare) and France (Brevo, our email provider). Data protection laws in those countries may differ from the laws where you live.
Where information originating in the European Economic Area, the United Kingdom or Switzerland is transferred to a country without an adequacy decision, we rely on the European Commission's Standard Contractual Clauses (and the UK International Data Transfer Addendum) with the receiving provider, together with the technical and organisational measures those providers apply. A copy of the relevant transfer mechanism can be requested from [email protected].
By submitting your information on this Website you acknowledge that it may be transferred to and processed in these countries as described above. We would not transfer it for any reason inconsistent with this policy.
9. How long we keep your information
| Data | Retention period |
|---|---|
| Confirmed waitlist email address and subscription record | Until you unsubscribe, ask us to delete it, or we end the launch campaign — whichever happens first. If the waitlist is not carried into the launched product, it is deleted within 12 months of the campaign ending. |
| Unconfirmed (pending) email addresses | Removed from our active list within 30 days if the confirmation is not completed. |
| Suppression list (addresses you asked us not to email) | Kept indefinitely, and only for the narrow purpose of honouring your opt-out. It is never used to contact you. |
| Consent and signup records (date, time, source, IP of signup/consent grant, policy version) | Up to 3 years after your last interaction with us, so we can evidence consent and respond to disputes. |
| Server, security and error logs | Up to 90 days, after which they are deleted or aggregated so they no longer identify you. |
| Support and privacy correspondence | Up to 3 years after the matter is closed. |
When a retention period ends, we delete the data or irreversibly anonymise it so it can no longer be linked to you.
10. Your rights and how to exercise them
Depending on where you live, you may have some or all of the following rights. We extend the core of them to every user, wherever you are located, as a matter of policy:
- Access — ask whether we hold your data and get a copy of it.
- Correction — have inaccurate information fixed.
- Deletion — have your information erased, subject to records we must keep by law.
- Withdrawal of consent — withdraw consent at any time, without affecting the lawfulness of processing before withdrawal. On this site, the unsubscribe link in any email is the fastest route.
- Objection and restriction — object to processing based on legitimate interests, or ask us to pause it while a challenge is resolved.
- Portability — receive the data you gave us in a structured, machine-readable format where the right applies (we will supply your email address and signup record as JSON or CSV).
- Opt-out of sale or sharing — under US state privacy laws. We do not sell or share personal information, so there is nothing to opt out of today; we will not disadvantage you for exercising any of these rights.
- Non-discrimination — we will not deny you service or charge you a different price because you exercised a privacy right.
- Lodge a complaint — with your local supervisory authority (see below).
How to make a request
- Email [email protected] with the subject line “Privacy request”.
- Tell us which right you want to exercise and the email address you used to sign up, so we can verify it is you. We may ask for confirmation from that address before releasing or deleting anything — we will never ask for an ID document unless we genuinely cannot verify you otherwise.
- We aim to acknowledge within 72 hours and to respond in full within 30 days. If a request is complex we will tell you within that window and explain why more time is needed.
- If you act through an authorised agent, we will need written permission from you and enough detail to verify the agent's identity.
Supervisory authorities. If you are in the EEA, you may complain to the data protection authority of your country of residence or work. If you are in the UK, to the Information Commissioner's Office (ICO). If you are in India, you may raise a grievance with our Grievance Officer (Section 15) and, if dissatisfied, with the Data Protection Board of India once the applicable provisions of the Digital Personal Data Protection Act, 2023 are in force.
11. Children's privacy
This Website and the waitlist are intended for adults and for professionals evaluating a developer tool. They are not directed at children.
We do not knowingly collect personal information from anyone below the age at which they can give valid consent under applicable law — in India, that is 18 years under the Digital Personal Data Protection Act, 2023, and in other jurisdictions generally 13 to 16 years. If you believe a child has submitted information to us, write to [email protected] and we will delete it promptly and in any event without unreasonable delay.
12. Security
We protect your information with measures appropriate to a small, security-conscious team running a public website:
- Transmission encrypted with TLS, and security headers (HSTS, content-type and framing protections) applied site-wide.
- Third-party API keys held only as server-side environment variables, never in the browser or shipped source.
- Access to subscriber data limited to the people who need it, behind individual accounts with multi-factor authentication.
- Provider-side controls from our hosting and email vendors, including infrastructure-level abuse and bot filtering.
- Collection minimisation: we ask for an email address and nothing more, which keeps the amount of data at risk small by design.
No method of transmission or storage is completely secure. We cannot guarantee absolute security, and you should avoid sending us sensitive or confidential information through this Website or in reply to our emails.
13. Third-party links
This Website links to other sites and services — for example our GitHub organisation, our X and YouTube channels, and other social profiles. Those sites are operated by third parties with their own privacy policies, which we do not control and this policy does not cover. Following a link is at your own discretion, and we encourage you to read the relevant policy before giving anyone your information.
If you interact with us on a social platform, that platform's terms and privacy policy govern the interaction, and the platform may retain your data even after you remove it from their side.
14. Changes to this policy
We may update this policy from time to time. The “Last updated” date at the top of this page always shows when it was last revised, and the current version is always available at https://oystro.com/privacy.html.
For a minor change (clarifications, new providers in an existing category, editorial fixes) we will simply post the updated version. For a material change — for example a new purpose for your data, a new category of recipient, or a shorter retention period — we will notify you before it takes effect, either by email to the address you gave us or through a prominent notice on this Website, and where the law requires it we will ask for your consent to the new terms. If you do not agree with an update, you can unsubscribe or ask us to delete your data, and the change will not apply to processing that already took place.
15. Contact and grievances
Questions, requests and complaints about this policy or about how we handle your information:
| Data controller / fiduciary | George Koshy, operating the Oystro project — [email protected] |
|---|---|
| Privacy / data protection contact | [email protected] |
| Grievance Officer (Information Technology Act, 2000 & Rules; DPDP Act, 2023) | George Koshy, [email protected]. Grievances are acknowledged within 72 hours and resolved within 30 days. |
| General enquiries | [email protected] |
Governing law and forum. This policy is governed by the laws of India, including the Digital Personal Data Protection Act, 2023 and the Information Technology Act, 2000. Subject to any mandatory rights you have in your country of residence, the courts at Mumbai, India shall have exclusive jurisdiction over disputes arising from it. Where EU, UK or other local law gives you the right to bring proceedings in your own courts, that right is unaffected.