Legal

Privacy Policy

How we handle personal data at SurveyHub. Last updated 8 September 2026.

Note for the site owner: this policy describes how the platform actually works, but it has not been reviewed by a lawyer. Have a qualified professional review it against the DPDP Act 2023 and any other law that applies to you before relying on it.

1. Who we are

SurveyHub (“we”, “us”) is a survey and form platform operated by APM Tech. This policy explains what personal data we collect, why, and what you can do about it.

Contact us about privacy at super.admin@survey-hub.in.

2. Two kinds of people this policy covers

It matters which one you are, because we play a different role for each:

  • Account holders — people who sign up and build surveys. We decide how this data is handled, so we are the data controller.
  • Respondents — people who answer a survey someone else created. The account holder who made that survey decides what to ask and why. We only process those answers on their behalf. If you answered a survey and want your response deleted, contact the organisation that sent you the survey; if you cannot reach them, contact us and we will help.

3. What we collect

Account data

  • Name and email address
  • A cryptographic hash of your password — never the password itself
  • Workspace name and your role within it
  • If you sign in with Google or GitHub: your provider account identifier and verified email address. We never receive your password for those services.
  • Two-factor authentication settings, if you enable them

Survey and response data

  • The surveys you create — questions, settings and branding
  • Answers submitted by respondents, including any files they upload (CVs, documents, images)
  • A one-way hash of the respondent’s IP address, used to detect duplicate submissions. We do not store the raw IP address alongside the response.
  • Approximate location, only if the survey creator enabled location collection and the respondent granted permission in their browser.
  • Timestamps for when a response was started and submitted

Billing data

Payments are processed by Razorpay. Your card, UPI or net-banking credentials go directly to them — we never see or store them. We keep only the plan you are on, your billing period, and the payment and subscription identifiers Razorpay returns so we can reconcile your account.

Technical data

  • Authentication tokens stored as cookies in your browser, so you stay signed in
  • Server logs containing request metadata, kept for security and debugging
  • Draft survey answers saved in the respondent’s own browser storage so a half-finished response is not lost. This never leaves their device until they submit.

4. Third parties who process data for us

We keep this list short on purpose. Currently:

  • Razorpay — payment processing
  • Railway — application and database hosting
  • Google and GitHub — optional sign-in, only if you use them
  • OpenStreetMap (Nominatim) — converts coordinates into a place name when a survey collects location. Only latitude and longitude are sent, never a respondent’s identity.
  • Google Ads — measures whether an advert led to a sign-up. See cookies below.
  • An email delivery provider — sends verification, notification and confirmation emails

We do not sell personal data. We do not use your survey responses to train machine-learning models for other customers.

5. AI features

If you use the AI summary feature, the open-text answers you ask it to summarise are sent to a third-party AI provider to generate that summary. Do not run AI summaries over responses containing sensitive personal data you are not comfortable transmitting. This feature is optional and only runs when you explicitly trigger it.

6. Cookies

  • Essential — authentication tokens that keep you signed in. The product does not work without these.
  • Advertising — Google Ads conversion tracking, used to measure sign-ups from our adverts. You can block these in your browser without affecting the product.

Respondents answering a public survey are not required to accept any advertising cookie.

7. How we protect data

  • Every request is scoped to the caller’s workspace, so one customer’s data is not returned to another customer’s session.
  • All traffic is encrypted in transit over HTTPS.
  • Passwords are hashed with a slow, salted algorithm and are never recoverable.
  • Sessions can be revoked centrally, and optional two-factor authentication is available.

No system is perfectly secure. If we become aware of a breach affecting your personal data, we will notify affected account holders without undue delay.

8. How long we keep data

  • Account and survey data: for as long as your account is active.
  • After you delete your account, we remove your surveys and responses within 30 days, except where we must keep records longer for tax or legal reasons.
  • Invoices and payment records: retained as long as tax law requires.
  • Server logs: retained for a limited period, then rotated out.

9. Your rights

You can:

  • Access the personal data we hold about you
  • Correct anything inaccurate — most of it is editable in your profile
  • Export your survey responses at any time as CSV or Excel
  • Delete your account and the data attached to it
  • Withdraw consent for optional processing, such as marketing email
  • Complain to the relevant data-protection authority

To exercise any of these, email super.admin@survey-hub.in. We respond within 1 business day.

10. Children

SurveyHub is not intended for children under 18. We do not knowingly create accounts for them. If a survey you run collects data from minors, obtaining the appropriate consent is your responsibility as the survey creator.

11. Changes to this policy

If we make a material change we will update the date at the top and, for significant changes, notify account holders by email.

12. Contact

Questions about this policy? Email super.admin@survey-hub.in or use our contact page.