Privacy Policy
1. Who we are
Send the Survey is operated by Mar&Co Management B.V., registered in the Netherlands, Chamber of Commerce (KvK) number 94664404 ("Send the Survey", "we", "us", "our"). You can contact us about privacy at hi@sendthesurvey.com.
This policy explains what personal data we process when you use sendthesurvey.com and the Send the Survey app, why we process it, on what legal basis, who helps us process it, how long we keep it, and the rights you have under the EU General Data Protection Regulation (GDPR) and the Dutch GDPR Implementation Act (UAVG).
2. Our two roles
Send the Survey is used by people who build surveys, such as researchers, students and organisations. In this policy we call them account holders or customers. The people who answer those surveys are respondents. Our role is different for each group.
Account holders. For the personal data of people who create an account with us, and of people invited to join a team, we are the controller. Most of this policy describes that processing.
Respondents. When a customer runs a survey, the customer decides what to ask, who to invite and what happens to the answers. The customer is the controller of the respondent data collected in that survey, and we act as its processor. We handle that data only on the customer's instructions, as set out in our Terms of Service, and never for our own purposes. If you answered a survey, the privacy notice of the person or organisation that ran it governs your answers, and they are the first people to contact with questions or requests about them. Section 4 describes what our service can store about respondents, so you can see what is possible.
There is one exception. If you report a survey to us as abusive, we are the controller of that report.
3. What we collect from account holders
- Account details. Your name, your email address, whether that address has been verified, a profile picture if you add one, and when the account was created. A picture is cropped to a small square in your browser before it is stored with your account. If you sign in with a password, we store it only as a hash, never in readable form.
- Sign-in with Google or Microsoft. If you use one of these, we receive the information described in section 5.
- Sessions. When you sign in, we record the session together with the IP address and the browser description (user agent) of the device you used, and which of your teams you are working in. You can see your active sessions in your security settings and end them there. A session stops working when you sign out or after 30 days.
- Two-factor authentication. If you turn it on, we store the secret for your authenticator app in encrypted form and your backup codes.
- Verification codes and links. When you confirm an email address, change it, reset your password or claim a survey, we store a short-lived code or token. A code to claim a survey is valid for 15 minutes.
- Your surveys. The surveys you build, their settings, the version each response answered, and any participant lists you add. We also store whether you starred a survey, shared it with your team or moved it to the bin. Surveys can contain personal data that you choose to put in them.
- Teams. Every account belongs to at least one team. If you have not joined one, we create a team of your own the first time you need it. We store each team's name, an optional logo, its members and their roles (owner or member). If an owner looks up a logo by entering a website address, our server fetches the icon from that website and stores it with the team. Members of a team can see each other's names and email addresses. A survey stays private to the person who made it until that person shares it with the team. Members can then see it, work on it and see its responses.
- Team invitations. When an owner invites someone to a team, we store the invited email address, the role, whether the invitation is still open, who sent it and when it expires, which is 7 days after it was sent. We email the invitation to that address, and the email names the person who sent it and the team.
- Your team's plan and payments. A plan belongs to a team, not to a person, and only an owner can change it. We store the plan, whether it is active and since when, the number of seats, and the references our payment provider Mollie gives to the team's customer record, payment mandate and subscription. When an owner upgrades, we create a customer record at Mollie with the team's name and the owner's email address, and the payment itself takes place on Mollie's checkout page. Mollie holds the card or bank account details. We do not store card or bank account numbers. The payment history on the plan settings page is read from Mollie when the page opens and is not stored by us.
- Billing details. For invoices, an owner can enter a billing name, a billing email address, a street address, postal code, city and country, whether the team is a business, and a VAT number. We check a VAT number with the European Commission's VIES service and store when it was confirmed. For each payment that succeeds, we create an invoice with these details in our accounting system, Odoo, and store the payment reference and the invoice number.
- API keys. If you create an API key, it belongs to the team you created it in. We store its name, a short visible prefix, its permissions, a hash of the key, who created it, when it was last used and whether it has been revoked. We never store the key itself.
- The AI assistant. If you use the AI assistant in the editor, we send your instruction and the survey you are editing to our AI provider (see section 7) and receive an edited survey back. We never send the responses to your survey. For each request we keep a usage record with your account, the survey, the model, the number of tokens, the cost, whether the request succeeded, and a hashed value derived from your account and IP address that we use to enforce usage limits. The usage record does not contain the text of your instruction.
- Drafts created by AI agents. An AI agent working for you can create a survey draft through our API before you have an account. That draft holds no personal data about you. You claim it by entering your email address and the code we send there, and then you create your account.
Technical data. When your browser connects to our servers it sends your IP address, as it does with any website. We need it to deliver pages to you and to protect the service against abuse.
4. What we collect from respondents
We process the following on behalf of the customer who runs the survey. What is actually stored depends on how the customer set up that survey. If the customer shares the survey with their team, the members of that team can see the answers too.
- Answers. The answers you give. A customer can ask any question, so answers can include personal data such as your name, your email address or anything you type into a free-text field.
- Timing and progress. When you started and finished, how long it took, the time spent on each page, and the page you reached. A response is saved from your first answer, so you can continue later. A response that is started but not finished is kept as an incomplete response.
- Study design. If the survey assigns people to groups or shows questions in random order, we store which group you were in and the order you saw, so the researcher can reconstruct what you were shown.
- Values from the link. A survey link can carry values chosen by the researcher, such as a wave number or a class group, which are stored with your answers. Our survey checks flag link values named after personal identifiers such as an email address, because a link ends up in browser history and server logs.
- Identity. Each survey uses one of three modes.
- Anonymous, the default. There is no participant record, no name and no email address.
- Pseudonymous. An identifier from a recruitment platform such as Prolific or SONA, used to stop the same person taking part twice. No email address is stored.
- Identified. Your email address, supplied by the customer, used to send you a personal one-time link and reminders. It is stored separately from your answers and is never part of the answer data. Depending on the survey's setting, your response carries a pseudonymous code that links it to your participant record, or no link at all, in which case we only record that you completed the survey.
- Link tokens. One-time links and links to resume a survey contain a random token. We store only a hash of that token.
What we do not collect. Respondents never create an account. We do not store a respondent's IP address or device details with their response, and the survey screen sets no cookies and uses no browser storage. Your progress is kept in the link instead, so if you lose the link you lose your place.
Emails to respondents. If a customer invites you by email, we send the invitation and any reminders on the customer's behalf from a Send the Survey address. We only send these emails for accounts whose email address has been verified.
After the survey. A customer can send you on to another website when you finish, for example a recruitment platform that confirms your participation. That website's own privacy policy applies from then on.
Requests about your answers. To access, correct or delete your answers, contact the person or organisation that ran the survey. When a participant record is deleted, the identity is removed and the answers stay in the dataset with nothing that links them to that person. When a customer deletes a survey, it goes to a bin for 30 days and is then deleted together with its answers and participant list. Answers to an anonymous survey cannot be traced to a person, so they cannot be picked out for deletion. If you cannot reach the customer, email us and we will pass your request on.
Reporting a survey. Anyone can report a survey as abusive without an account. We store which survey was reported, the reason you chose, any note you write, and a hashed value derived from your IP address that we use to limit repeated reports. We are the controller of this data.
5. Signing in with Google or Microsoft
You can create a Send the Survey account and sign in with your Google account or your Microsoft account instead of a password.
What we receive. We ask Google or Microsoft only for the basic sign-in permissions called openid, email and profile. Through these we receive your name, your email address, your profile picture and an identifier for your account at that provider. We store that identifier and the sign-in tokens the provider issues together with your Send the Survey account. We do not ask for access to your email messages, contacts, calendar, files or any other data in your Google or Microsoft account.
How we use it. We use this information only to create your Send the Survey account, to sign you in, and to send you emails about your account.
What we do not do. We do not sell this information. We do not use it for advertising, to build profiles or to train AI models. We do not share it with anyone except the processors listed in section 7, who handle it only on our instructions and only to run the service.
Google API Services User Data Policy. Send the Survey's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
Removing access. You can remove Send the Survey's access at any time in the security settings of your Google or Microsoft account. That stops sign-in with that provider but does not delete your Send the Survey account. To delete your account, see sections 9 and 12.
Google and Microsoft handle the sign-in itself as independent controllers, under their own privacy policies.
6. Why we use personal data, and our legal bases
To provide your account and the service. This covers creating your account, signing you in, running your teams, storing and running your surveys, sending emails about your account and sending the invitations you ask us to send. It also covers taking payment for a paid plan, checking a VAT number and issuing invoices. The legal basis is the performance of our contract with you (Article 6(1)(b) GDPR).
To invite people to a team. A person who is invited to a team has no contract with us yet. We store their email address and send them the invitation on the basis of our legitimate interest, and the team's, in letting a team add its members (Article 6(1)(f)).
To keep the service secure and prevent abuse. This covers session records, rate limits, hashed values derived from IP addresses, abuse reports, limits on how much a new account can publish, and the rule that we only send invitations for verified accounts. Surveys can be misused for phishing, so these controls also protect respondents. The legal basis is our legitimate interest in protecting the service, our customers and respondents (Article 6(1)(f)).
To keep the AI assistant within its limits. We keep usage records so that one account cannot use up capacity meant for everyone and so that we can see what the assistant costs. The legal basis is our legitimate interest in running the service sustainably (Article 6(1)(f)).
To process respondent data. We do this as a processor, on the customer's instructions (Article 28). The customer is responsible for having a legal basis for its survey.
To comply with the law. For example, keeping invoices and payment records for paid plans as Dutch tax law requires. The legal basis is a legal obligation (Article 6(1)(c)).
We do not sell personal data, we do not show advertising, and we do not make automated decisions that have legal or similarly significant effects on you.
7. Processors
We use the following service providers to run Send the Survey. Each processes personal data only on our instructions. For respondent data they act as our sub-processors.
| Provider | What they do for us | Where |
|---|---|---|
| Hetzner Online GmbH | Hosting of the application and the database | Germany (EU) |
| Resend | Sending emails, including account emails and survey invitations and reminders | United States |
| Mistral AI | Running the AI assistant in the editor, only when you use it | France (EU) |
| Mollie B.V. | Taking payments for paid plans, and holding card and bank details and payment mandates | Netherlands (EU) |
We will update this list before we add a new provider that processes personal data.
When you choose to sign in with Google or Microsoft, that provider is not our processor. It handles the sign-in as an independent controller.
8. International transfers
Our application and database are hosted in Germany, our payment provider is in the Netherlands and our AI provider is in France, so no transfer outside the European Economic Area arises there. Our email provider, Resend, is in the United States and is certified under the EU-US Data Privacy Framework, which we rely on as the primary safeguard, with the European Commission's Standard Contractual Clauses as a fallback. A copy of the relevant safeguards is available on request at hi@sendthesurvey.com.
If you sign in with Google or Microsoft, those companies may process your sign-in data outside the European Economic Area under their own safeguards.
9. How long we keep data
| Data | How long we keep it |
|---|---|
| Account details, surveys, participant lists and completed responses | For as long as the account exists, or until the survey is deleted through the bin. Completed responses are never deleted automatically, on any plan. |
| Surveys in the bin | 30 days, during which they can be restored. After that a survey is deleted for good together with its responses and participant list. Deleting it for ever from the bin removes it at once. |
| Incomplete responses on the free plan | Deleted 90 days after they were started. On paid plans they are kept with the other responses. |
| Test responses | Until the customer deletes them, which takes one action. |
| Survey drafts that were never claimed | Deleted after 7 days. |
| Verification and claim codes | Valid for a short time only, and removed once used. |
| Team invitations | Valid for 7 days. |
| Team details, billing details and payment references | For as long as the team exists. |
| Abuse reports | For as long as the reported survey exists. |
| AI usage records | For as long as we need them to monitor cost and abuse. |
| Invoices and payment records | For as long as Dutch tax law requires, currently seven years. |
Changing or ending a paid plan does not delete anything. Your surveys and responses stay readable and exportable. When an owner cancels, the subscription stops but the payment mandate at Mollie stays in place, so the team can start again without giving its payment details a second time. Nothing is charged while there is no subscription.
Deleting your account. You can delete your account in your account settings, with your password. This removes your account details, profile picture, sessions, two-factor settings, sign-in connections, your team memberships and the team invitations you sent. It does not remove everything. Surveys you shared with a team stay with that team, with their responses. Surveys you kept to yourself stay stored with their responses and participant lists, but nobody can open them any more. API keys you created stay with the team until an owner revokes them. A team of your own stays too, with its billing details. To have your private surveys, their responses and participant lists, and your own team removed as well, email hi@sendthesurvey.com and we will delete them. Export anything you want to keep first.
10. How we protect data
- All connections to Send the Survey are encrypted (HTTPS).
- Passwords are stored only as hashes. One-time link tokens, resume tokens and API keys are stored only as hashes, so a copy of the database would not hand over working links or keys.
- Two-factor authentication is available for every account.
- Sign-in, sign-up and password reset are rate limited.
- A survey stays private to the person who made it until that person shares it with the team.
- Only a team owner can invite people, change the plan or the billing details, and revoke API keys.
- The database runs on a private network that is not reachable from the internet, on servers in the EU.
- Email addresses in participant lists are kept apart from the answer data, and exports do not include them by default.
No system is perfectly secure, but we work to protect your data and we meet our breach notification duties under the GDPR.
11. Cookies and local storage
Account holders. When you sign in, we set cookies that are strictly necessary to keep you signed in and to complete two-factor authentication. We use them for nothing else. Because they are strictly necessary, the law does not require us to ask for consent.
Respondents. The survey screen sets no cookies and uses no local storage or other browser storage.
No tracking. We do not use analytics or advertising cookies, tracking pixels or third-party tracking scripts. The app serves its fonts from our own servers, so loading it does not contact Google or any other third party.
12. Your rights
Under the GDPR you have the right to
- access the personal data we hold about you and receive a copy,
- have inaccurate data corrected,
- have your data erased,
- restrict our processing,
- object to processing based on our legitimate interest,
- receive your data in a structured, machine-readable format (data portability),
- withdraw consent at any time, where we rely on consent, without affecting processing before withdrawal.
As an account holder you can change your name, picture and email address, delete surveys, and delete your account in your account settings, and you can export your surveys and responses at any time, on any plan. For anything else, email hi@sendthesurvey.com. We respond within one month, as the GDPR requires.
If you are a respondent, please send requests about your answers to the person or organisation that ran the survey, as explained in section 4.
You also have the right to lodge a complaint with the Dutch Data Protection Authority, the Autoriteit Persoonsgegevens, or with the supervisory authority where you live or work.
13. Children
Send the Survey accounts are not directed at children under 16, and you must be 16 or older to create one. If we learn that a child under 16 has created an account, we will delete it. If you believe this has happened, email hi@sendthesurvey.com.
Customers decide who takes part in their surveys. A customer who surveys children is responsible for obtaining any consent the law requires, including consent from a parent or guardian.
14. Changes to this policy
We show the effective date at the top of this policy. If we make a material change to how we use personal data, we will tell account holders before it takes effect, by email or with a notice in the app.
15. Contact and complaints
For any privacy question or request, email hi@sendthesurvey.com. If you are not satisfied with our answer, you can contact the Autoriteit Persoonsgegevens.