Privacy notice
Last updated 28 September 2026
This notice explains what Darma (“we”) collects through this website, trydarma.com, why, and what we do with it. It covers the website and the requests you send through it. Merchants who use the Darma product are covered by a separate data processing agreement.
What we collect
When you send a form (the audit request or the sample report), we collect:
- your work email
- if you give them: your name, role, store URL, revenue band, subscription app, dispute-rate band, whether you have seen AI agent activity, and your note about your biggest worry
- which headline version of the page you saw, and any campaign tags in the link you followed
Automatically, with each request, we also store:
- a keyed, one-way hash of a shortened version of your IP address. It lets us limit repeated submissions; we never store the address itself
- a salted, one-way hash of your email, so we can find your request if you ask us to delete it
We don’t collect payment details. We don’t use advertising cookies, tracking pixels or third-party trackers.
Why we use it
- to reply to your request and decide whether the audit or a pilot is a fit
- to schedule a call if you ask for one
- to learn which version of the page is clearest, from counts only
- to protect the site and our systems from spam and abuse
We use your information because you asked us to act on it, and because we have a legitimate interest in responding to business enquiries and keeping the site secure. We never sell it or use it for advertising.
How it is stored and protected
Your email, name and note are encrypted (AES-256-GCM) and kept in a separate store from the rest of your answers. Everything travels over encrypted connections (TLS). Only Darma’s founding team can access requests.
Who processes it for us
- Cloudflare hosts and serves this website and protects it from abuse.
- Fly.io runs the service that receives your form.
- Neon runs our database, hosted on Amazon Web Services in the United States (Ohio).
Your information is stored in the United States. Our providers may process it in other countries where they operate, under their own security and privacy commitments.
How long we keep it
We keep your request while we are in touch about the audit or a pilot. We review stored requests at least every 12 months and delete the ones we no longer need, and we delete yours sooner whenever you ask.
Cookies and local storage
This website sets no cookies of its own.
-
Local storage: we save one value in your browser,
darma_variant, which records the headline version you saw (A, B or C) so the page stays the same when you come back. It contains nothing about you and leaves your browser only as part of a form you choose to send. You can clear it at any time in your browser settings. -
Security cookies: Cloudflare may set strictly necessary cookies, such as
__cf_bm, when it screens traffic for automated abuse. They are not used to track you. - Analytics: we don’t run analytics on this site today. If we add them, we will update this notice, and its date, before we do.
Caching
To load faster, your browser and Cloudflare keep copies of this site’s files (styles, scripts, fonts and images). These files are the same for every visitor and contain no personal information. Pages are checked for updates on every visit.
Your choices and rights
You can ask to see the information we hold about you, correct it, or have it deleted, and you can withdraw your request at any time. Email mail@trydarma.com (mail@trydarma.com) and we will reply within 30 days. If you are not satisfied with our answer, you can contact your local data protection authority.
Changes to this notice
When we change this notice, we update the date at the top. Material changes, such as adding analytics, are made here before they take effect.