Last updated: August 2, 2026

    Privacy Policy

    How we collect, use, and protect your information at SurveyKar.

    1. Information We Collect

    We collect information you provide directly (account details, survey content, responses) and information collected automatically (usage data, device info, cookies).

    2. How We Use Your Information

    We use your information to provide and improve our services, process survey responses, generate analytics, communicate with you, and ensure platform security.

    3. Data Sharing

    We do not sell your personal data. We may share data with service providers who help us operate our platform, and when required by law.

    4. Data Security

    We implement industry-standard security measures including encryption in transit and at rest, row-level security policies, and regular security audits.

    5. Your Rights

    You have the right to access, correct, delete, and export your data. You can also withdraw consent for data processing at any time.

    6. Cookies

    We use essential cookies for authentication and session management. Analytics cookies are optional and can be disabled in your browser settings.

    7. Survey Respondent Metadata

    When a respondent submits a survey, we automatically capture technical metadata to help survey owners understand and secure their responses. This includes the respondent’s IP address, approximate location (city, region, country) derived from that IP, device type, operating system, browser, language, and timezone. This information is stored with the response and is visible to the survey owner. It is used for analytics, fraud and spam prevention, and response verification, and is not sold to third parties.

    8. Google Calendar Data

    If you connect a Google account to SurveyKar’s booking features, we access a limited part of your Google Calendar. This section describes that access specifically, in addition to the general terms above.

    What we access
    With your explicit consent we request two Google Calendar permissions: “freebusy” (calendar.freebusy), which returns only the start and end times of periods you are busy, with no event titles, descriptions, locations, or attendees; and “events” (calendar.events), which lets us create, update, and delete the booking events SurveyKar itself schedules on your primary calendar. We also receive your email address and basic OpenID profile to label the connection. We do not request or receive read access to the contents of your existing calendar events.
    How we use it
    Free/busy times are used solely to hide slots you are unavailable for when someone views your booking page. The events permission is used solely to place a confirmed booking on your calendar and to update or remove that event if the booking is rescheduled or cancelled. Google user data is never used for advertising, profiling, credit or lending decisions, or any purpose unrelated to these booking features.
    Who we share it with
    We do not sell Google user data and we do not transfer it to data brokers, advertisers, or any third party for their own purposes. It is processed only by our own infrastructure providers acting on our instructions as sub-processors (our database and serverless hosting provider), strictly to operate the booking feature.
    How we protect it
    OAuth access and refresh tokens are stored write-only: database privileges prevent any browser or client application from reading them back, and they are used exclusively by trusted server-side functions. All data is encrypted in transit and at rest. Each connection is personal to the staff member who authorised it — other members of your organisation, including administrators, cannot view or use it. Free/busy data is written to a server-only cache that no client can read at all.
    Retention and deletion
    We store the minimum necessary and no copies of your event content. Free/busy times are held in a short-lived cache that is overwritten on each refresh (roughly every two minutes) and is never exposed to any client. For events we create, we retain only Google’s event identifier alongside the booking record, so the event can later be updated or cancelled; it is deleted when the booking or your account is deleted. You may disconnect a Google account at any time from Bookings → Availability, which immediately and permanently deletes both the stored access and refresh tokens and the cached free/busy data for that account. You can additionally revoke SurveyKar’s access directly from your Google Account at myaccount.google.com/permissions.
    Limited Use compliance
    SurveyKar’s use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. We do not use Google Workspace API data to develop, improve, or train generalised artificial intelligence or machine learning models, and we do not transfer such data to any third-party service that does.

    9. Contact

    For privacy-related questions, contact our Data Protection Officer at support@surveykar.com or visit our contact page.