Privacy Policy

Last updated: November 30, 2025

1. Introduction

Welcome to SurveyReflex ("we," "our," or "us"). This Privacy Policy explains how we collect, use, and protect your information when you use our survey creation and management platform.

By using SurveyReflex, you agree to the collection and use of information in accordance with this policy.

2. Information We Collect

2.1 Account Information

When you create an account, we collect:

  • Name and email address
  • OAuth provider data (if you sign in with Google, GitHub, etc.)
  • Password (encrypted)

2.2 Survey Data

When you create surveys, we store:

  • Survey titles, questions, and options
  • Survey settings and configurations
  • Theme and branding choices

2.3 Response Data

When respondents complete surveys, we collect:

  • Survey answers and responses
  • Submission timestamps
  • IP addresses (for duplicate prevention)
  • Browser and device information

2.4 Payment Information

Payment processing is handled by third-party providers (PayPal, Stripe). We do NOT store your full credit card details. We only store transaction IDs and payment status.

2.5 Usage Data

We automatically collect:

  • Log data (IP address, browser type, pages visited)
  • Cookies and similar tracking technologies
  • Analytics data (survey views, response rates)

3. How We Use Your Information

We use collected information to:

  • Provide and maintain the Service
  • Process payments and manage billing
  • Send you notifications about your account and surveys
  • Improve our platform and develop new features
  • Prevent fraud and abuse
  • Comply with legal obligations

4. Data Sharing and Your Responsibility

🔵 IMPORTANT: You Control Survey Data

SurveyReflex is a platform that enables YOU (the survey creator) to collect information from YOUR survey respondents.

YOU are the data controller for any personal information collected through your surveys. We merely provide the infrastructure.

Your Responsibilities:

  • Obtain proper consent from respondents
  • Comply with applicable privacy laws (GDPR, CCPA, etc.)
  • Inform respondents how their data will be used
  • Handle data securely and responsibly

5. Third-Party Services

We use third-party services that may collect your information:

  • Supabase: Database and authentication
  • PayPal & Stripe: Payment processing
  • Google reCAPTCHA: Spam prevention
  • OAuth Providers: Google, GitHub (for sign-in)

These services have their own privacy policies. We encourage you to review them.

6. GDPR Compliance

⚠️ IMPORTANT: NON-GDPR COMPLIANCE

SurveyReflex is NOT currently GDPR-compliant and does NOT provide GDPR-compliant data processing.

If you are subject to GDPR (EU/EEA users), you should NOT use this platform to collect personal data from EU/EEA residents.

We do NOT provide:

  • Data Processing Agreements (DPAs)
  • Right to erasure for survey respondents
  • Data portability tools
  • GDPR-compliant consent mechanisms
  • EU data residency guarantees

By using our Service, you acknowledge that you understand and accept this limitation.

7. Data Security

We implement security measures to protect your data, including:

  • HTTPS encryption for data in transit
  • Password hashing and encryption
  • Secure database access controls
  • Regular security updates

However, no method of transmission over the internet is 100% secure. We cannot guarantee absolute security.

8. Data Retention

We retain your data for as long as your account is active or as needed to provide the Service. You may delete your account at any time, which will remove your surveys and associated data.

Response data may be retained for analytics and compliance purposes even after survey deletion.

9. Your Rights

You have the right to:

  • Access your personal information
  • Correct inaccurate data
  • Delete your account and data
  • Export your survey data (CSV, Excel, PDF)
  • Opt-out of marketing communications

To exercise these rights, contact us through the Contact page.

10. Cookies and Tracking

We use cookies and similar technologies for:

  • Authentication and session management
  • Remembering your preferences
  • Analytics and performance monitoring
  • Preventing duplicate survey responses

You can control cookies through your browser settings, but some features may not work properly if cookies are disabled.

11. Children's Privacy

SurveyReflex is not intended for use by children under the age of 13. We do not knowingly collect personal information from children under 13. If you believe we have collected information from a child under 13, please contact us immediately.

12. Changes to This Privacy Policy

We may update this Privacy Policy from time to time. We will notify you of significant changes via email or in-app notice. Your continued use of the Service after changes constitutes acceptance of the updated policy.

13. Contact Us

If you have questions about this Privacy Policy or how we handle your data, please contact us:

Contact Support