Privacy Policy
Transparent, developer-first privacy grounded in zero-retention ephemeral edge compute.
1. Overview & Our Zero-Retention Architecture
At Stanza (“Stanza,” “we,” “us,” or “our”), privacy is not an afterthought or an enterprise policy add-on—it is the foundational architecture of our platform. We operate high-velocity microservices for mission-critical enterprise workflows (EDI X12, ISO 20022, GS1, DSCSA, Peppol, VAT, LEI).
Our transformation pipelines run exclusively inside ephemeral Cloudflare Workers V8 isolates. Every transformation is engineered as a deterministic mathematical function (f(x) = y):
- 0 Bytes of Request Body Stored: Inbound transactional payloads exist in volatile isolate RAM for the milliseconds required to compute transformations, after which the isolate memory is immediately discarded.
- 0 Database Writes for Payloads: No databases (SQL, NoSQL, or KV) or object stores (S3/R2) are attached to data transformation pipelines.
- 0 Outbound Network Leaks: Transformation engines execute pure compute with zero third-party subrequests.
2. Information We Collect
We collect only the minimal data required to provision, authenticate, and bill for API access:
A. Account & Identity Data: When you sign up or log in via one-time magic code, we record your email address and generate an internal customer identifier (e.g. cus_...).
B. Authentication Credentials: When you generate API keys (nk_live_...), we hash them using one-way SHA-256 before storing the hash in Cloudflare D1. We cannot read or recover your plaintext API keys.
C. Usage Telemetry & Quota Counters: We maintain integer counters tracking the aggregate number of requests made under your account per billing period to enforce tier limits and calculate overage.
D. Edge Routing Metadata: Cloudflare edge nodes record standard HTTP transit metadata (client IP address, timestamp, HTTP method, path, response status, latency, and user-agent) for DDoS mitigation and security monitoring. Request and response bodies are excluded.
3. Information We NEVER Collect
- Transactional Data: We never log, persist, or inspect financial transactions, medical records, EDI envelopes, or invoice contents.
- Credit Card & Payment Data: All payment transactions are processed directly by Stripe under PCI-DSS Level 1 compliance. We never store, process, or transmit full credit card numbers, CVVs, or banking credentials.
- Targeted Tracking & Profiling: We do not sell, rent, or monetize developer data or payload contents to advertisers or third-party data brokers.
4. Cookies & Local Storage
We believe in cookie minimalism. We do not use third-party advertising cookies, social media tracking pixels, or cross-site fingerprinting scripts.
Our services use only a single, first-party cookie:
nk_session: A cryptographically signed HMAC token containing your customer ID and session expiration timestamp. It is markedHttpOnly,Secure, andSameSite=Lax, and is used strictly to keep you logged into the developer dashboard.
5. Sub-processors & Third-Party Services
To deliver resilient, global edge infrastructure, we work with a vetted list of sub-processors:
| Sub-processor | Role / Purpose | Location / Security |
|---|---|---|
| Cloudflare, Inc. | Edge compute isolates, Anycast routing, DDoS mitigation, D1 database, Turnstile bot verification | Global (330+ cities), SOC 2 Type II, ISO 27001 |
| Stripe, Inc. | Payment processing, subscription billing, customer invoicing | United States & Global, PCI-DSS Level 1 Certified |
| Amazon Web Services (AWS), Inc. | Enterprise HIPAA Plane infrastructure, BAA-covered ephemeral compute isolates, unproxied DNS-only routing (secure.api.stanzaapi.com) | United States, HIPAA BAA Eligible, SOC 1/2/3, ISO 27001, FedRAMP High |
| Resend, Inc. | Transactional email delivery for one-time verification codes | United States, SOC 2 Compliant |
6. Data Sovereignty, GDPR & International Transfers
For European Union and UK users, processing of account metadata is conducted under GDPR Article 6(1)(b) (performance of a contract) and 6(1)(f) (legitimate interest in security and fraud prevention).
Requests originating in Europe are routed and executed directly inside European Cloudflare data centers (Frankfurt, Paris, London, Amsterdam). International transfers of account metadata are governed by standard contractual clauses (SCCs) and robust encryption standards.
7. California Privacy Rights (CCPA / CPRA) & Global Data Subject Rights
Under the California Consumer Privacy Act of 2018, as amended by the California Privacy Rights Act of 2020 (“CCPA / CPRA”), California residents are entitled to specific statutory disclosures:
- We Do Not Sell or Share Personal Information: In the preceding 12 months, Stanza has not sold, shared for cross-context behavioral advertising, or rented any personal information of consumers, including minors under 16 years of age.
- No Sensitive Personal Information Processing: Stanza does not use or disclose sensitive personal information for purposes other than performing the core micro-API services.
- Right of Access & Portability: You may request disclosure of the specific pieces of personal information collected about you.
- Right to Deletion: You may request deletion of your account, email address, customer ID, and hashed API keys.
- Non-Discrimination: We will never discriminate against you, alter pricing, or deny services for exercising your California privacy rights.
- California Shine the Light (Cal. Civ. Code § 1798.83): We do not disclose personal information to third parties for direct marketing purposes.
Zero Retention of Payloads: Because all transformation payloads exist exclusively in transient V8 isolate RAM and are never persisted to disk or databases, there is zero payload data stored to disclose or delete.
8. Contacting Our Data Privacy Team
To exercise any privacy rights, request account deletion, or ask questions regarding this Privacy Policy, contact our privacy operations team directly at:
Email: support@stanzaapi.com
Security Portal: stanzaapi.com/compliance