Viewshed

Privacy Policy

Draft — not yet in force. This document is being prepared and has not been finalized. It does not currently form an agreement, and the details it refers to are incomplete.

In short: We handle two kinds of information differently. Account details of the people who run engagement programs are ours to answer for. Survey answers and stakeholder records belong to the organization running the program — we only hold them on its behalf, so requests about them start with that organization.

[LEGAL ENTITY NAME] ([a … limited liability company / corporation]) operates Viewshed from the United States. This policy explains what personal information we handle, why, who else sees it, and the choices you have. It is written for US residents first; if you are in the European Economic Area, the United Kingdom or Switzerland, the additional section near the end applies to you as well.

The two roles we play

This distinction decides who is accountable for what, so it comes first rather than buried in a table at the end.

  • We are the business — the controller — for information about the people who hold accounts: the person who signs up, the colleagues they invite, billing contacts and support correspondence. We decide why and how that is used, and this policy explains it.
  • We are a service provider — a processor — for everything a customer collects using Viewshed: survey responses, interview transcripts, stakeholder lists, uploaded files and published showcase content. The customer organization decides what to ask and whom to contact. We act on its instructions under our Data Processing Agreement, and we do not use that information for our own purposes.
If you answered a survey or received an email from a project. The organization running that project — the city, county, agency, consultancy or community group named on the page — decides what happens to your information. Contact them first. If you cannot identify or reach them, write to [privacy@example.com] and we will route your request to them and help them respond. We generally cannot delete or disclose their records on our own initiative, because they are not ours to give away.

What we collect

Account and workspace information. Name, email address, hashed password, workspace and project names, role and permissions, notification preferences, and the content of support tickets you send us.

Technical and security information. IP address, browser user-agent, request paths, timestamps, and session records. We use these to keep accounts signed in, to apply rate limits, to detect abuse and automated submissions, and to investigate incidents. Sign-in sessions record IP and user-agent so you can review and revoke your own sessions.

Billing information. Plan, billing contact and subscription status. Card details are entered directly with our payment processor and never reach our servers.

Information collected on a customer’s behalf. Survey responses, including any free text a respondent chooses to write; conversations with an AI ambassador; stakeholder records such as name, email, phone, affiliation, tags and notes, which a customer may have imported rather than collected from the person directly; uploaded images and documents; and content published to showcases and portals.

Categories of personal information

US state privacy laws describe personal information by fixed statutory categories. This table uses those categories, for the information we collect as a business— that is, about account holders rather than about a customer’s survey respondents. We collect all of it directly from you or automatically from your use of the Service; we do not buy personal information from data brokers.

CategoryCollectedWhat that means here
IdentifiersYesName, email address, account ID, IP address, cookie identifiers
Customer records (Cal. Civ. Code § 1798.80)YesName and email of an account holder; billing contact. Payment card numbers go directly to our payment processor and never reach us
Protected classificationsNoNot collected by us. A customer may ask about demographics in its own survey — that data belongs to the customer, not to us
Commercial informationYesPlan, subscription status, billing history
Biometric informationNoNot collected
Internet or network activityYesPages requested, timestamps, browser user-agent, session records, rate-limit counters
Geolocation dataNoWe do not collect precise geolocation. IP address implies approximate location. A customer's own survey may ask a respondent to drop a map pin
Audio, electronic, visual informationYesImages and documents uploaded to a workspace; support ticket content
Professional or employment informationYesJob title or affiliation, where a user or a customer's stakeholder record includes one
Education informationNoNot collected
InferencesNoWe do not build profiles or draw inferences about individuals
Sensitive personal informationNoNot collected by us, and not used to infer characteristics. Passwords are held only as one-way hashes and are never readable. A customer may ask a sensitive question in its own survey — see the DPA

We collect each category for the business purposes described in the next section, keep it for the periods described under retention, and disclose it only to the service providers listed below. We do not sell personal information, and we do not share it for cross-context behavioral advertising, as those terms are defined in the CCPA and the other state laws — and we have not done so in the preceding twelve months. We do not collect sensitive personal information about account holders, so there is no right to limit its use to exercise.

Why we use it

PurposeInformation used
Providing the Service and your workspaceAccount, workspace, technical
Keeping accounts and data secure; preventing abuse and fraudTechnical, session, rate-limit records
Billing and collecting feesAccount, billing
Service notices, and product email you can switch offAccount, notification preferences
SupportAccount, ticket content
Meeting legal, tax and accounting obligationsAs required
Handling data a customer collectsResponses, stakeholders, uploads — on the customer's instructions only, see the DPA

We do not use personal information for automated decision-making that produces legal or similarly significant effects, and we do not profile individuals.

AI features

When a customer switches on an AI feature, the relevant text is sent to the AI provider named in our sub-processor list to produce the result. That includes interview conversations, theme extraction, translation and summary drafting.

  • AI features are off by default and a customer chooses to enable them.
  • A person speaking to an AI ambassador is told they are speaking to an AI before the conversation begins.
  • Customer content is not used to train generally available AI models.
  • AI output can be wrong. It is drafting help for a person to check, not an automated decision about anybody.

Cookies and tracking

Viewshed sets a small number of cookies, all of them strictly necessary or functional. There is no advertising cookie, no third-party analytics and no cross-site tracking in the product, which is why you are not asked to consent to a banner.

CookiePurposeLifetime
viewshed_sessionKeeps a signed-in user signed in. Strictly necessary.14 days, extended on use
viewshed_csrfProtects against cross-site request forgery. Strictly necessary.14 days, extended on use
viewshed_rkLets a survey respondent resume a part-finished response on the same device, and prevents the same device accidentally submitting twice. Contains no name or account identifier.Cleared when the response is submitted or the browser is closed
viewshed-themeRemembers a light or dark appearance choice. Functional.Until cleared by the visitor

We honor the Global Privacy Control signal where the law gives it effect. Because we do not sell or share personal information, there is nothing for that signal to switch off — but we treat it as a valid opt-out request regardless.

Who else sees it

We disclose personal information only to the service providers below, who handle it on our instructions under contract and are prohibited from using it for their own purposes, and in the specific situations that follow:

  • Within a workspace. Authorized users see the data in their own workspace according to their role. Cross-organization sharing happens only where a customer invites a partner and that partner accepts.
  • Publicly, when a customer publishes. Showcases, portals, posters, live screens and shared infographics are public by design.
  • Legal process. Where required by law, subpoena, warrant or other valid legal process, to protect rights and safety, or to enforce our terms. Where we are lawfully able to tell the affected customer first, we will, so it can object if it wishes.
  • Corporate transactions. In a merger, acquisition or asset sale, subject to this policy continuing to apply.
ProviderPurposeLocation
Cloudflare, Inc.Application hosting (Workers), file storage (R2), database connection pooling (Hyperdrive), CDN and DDoS protectionUnited States (primary). Requests are served from a global edge network; files are stored in the configured R2 region
Neon, Inc.Managed PostgreSQL databaseUnited States (configured database region)
Anthropic PBCAI features: interview conversations, theme extraction, survey translation, alignment reportsUnited States
Resend, Inc.Transactional and outreach email deliveryUnited States
Stripe, Inc.Subscription billing and payment processingUnited States

Your privacy rights

Residents of California, Virginia, Colorado, Connecticut, Utah, Texas, Oregon, Montana, Delaware, Iowa, Nebraska, New Hampshire, New Jersey, Tennessee, Minnesota, Maryland, Indiana, Kentucky and Rhode Island, and of any other state whose comprehensive privacy law has since taken effect, have the rights below. We extend them to everyone in the United States rather than checking your address first, because sorting people by state to decide who deserves a copy of their own data is not a policy worth operating.

  • Know and access. Ask what personal information we hold about you, the categories, the sources, why we use it and who we disclose it to, and get a copy in a portable format.
  • Correct. Ask us to fix personal information that is inaccurate.
  • Delete. Ask us to delete personal information we hold about you, subject to the exceptions the law allows — such as completing a transaction, security, and legal obligations.
  • Opt out of sale, sharing and targeted advertising. We do none of these, so there is nothing to opt out of. We say so plainly rather than presenting a control that does nothing.
  • No retaliation. We will not deny you service, charge you a different price or give you a lesser experience for exercising a privacy right. We offer no financial incentive in exchange for personal information.
  • Account holders — exercise these in the account settings, which include export and account deletion, or write to [privacy@example.com].
  • Respondents and stakeholders— contact the organization running the project. Every outreach email we send on a customer’s behalf carries a one-click unsubscribe link, which works immediately and without needing an account.
  • Authorized agents may submit a request on your behalf where state law provides for it; we will ask for proof of their authority and may still verify your identity directly.

We respond within 45 days and may extend once by a further 45 days where the request is complex, telling you why. We verify identity before acting — usually by confirming control of the account email — and we will not use the information you provide for verification for anything else.

If we decline your request you may appeal by replying to our decision or writing to [privacy@example.com]with “Privacy appeal” in the subject line. We will respond within 45 days with our decision and the reasons for it. Several state laws require this appeal route, and if we deny the appeal we will tell you how to contact your state Attorney General.

California “Shine the Light.” California residents may ask annually whether we disclosed personal information to third parties for their direct marketing purposes. We do not, and never have.

How long we keep it

  • Account data — for as long as the account is open. After a deletion request we hold it for a 7-day grace period during which the request can be canceled, then anonymize the account in place.
  • Customer-collected data — for as long as the customer keeps it. After a workspace closes, it is available for export for 30 days and deleted within a further 90.
  • Session records — expired sessions are deleted, and the number of live sessions per account is capped.
  • Backups — encrypted backups age out on their own cycle, so deleted data may persist there briefly after removal from the live system.
  • Billing and audit records — as long as tax, accounting and limitations periods require, typically seven years.

How we protect it

  • Passwords are hashed with argon2id. We never store them in a readable form and cannot tell you what yours is.
  • Sessions use opaque tokens stored only as hashes, in cookies that JavaScript cannot read, and can be revoked individually.
  • Data is encrypted in transit. Strict transport security, a content security policy and anti-forgery protection are applied to every request.
  • Every record is scoped to one workspace, and that scoping is enforced in the data layer rather than left to individual screens.
  • Uploads are identified by inspecting their actual bytes, and uploaded SVG files are rebuilt from a safe subset before they are ever served.
  • Rate limits and abuse detection apply to public endpoints.

No system is perfectly secure. If you find a vulnerability, please tell us at [security@example.com] rather than disclosing it publicly, and we will work with you. Where a breach of unencrypted personal information occurs we notify affected people and state authorities as state breach-notification laws require.

Children

Viewshedaccounts are for adults, and the Service is not directed to children. We do not knowingly collect personal information from anyone under 13, and we do not sell or share the personal information of anyone under 16 — we do not do either for anyone of any age. A customer may run a consultation aimed at young people; where it does, that customer is responsible for age-appropriate design and for any parental consent that COPPA, state law or its own rules require. If you believe a child’s personal information has reached us without a proper basis, write to [privacy@example.com] and we will work with the relevant customer to remove it.

Where your information is held

We are based in the United States and our providers hold customer data in the United States, listed above. If you use the Service from outside the US, your information is transferred to and processed in the US, where privacy laws differ from those of your own country.

If you are in the EEA, the UK or Switzerland

These rights are additional to the section above rather than a replacement for it.

  • Our legal bases. Performance of our contract with you, for providing the Service, billing and support; our legitimate interests in running a service that is not trivially abused, for security and rate limiting; consent where we ask for it; and legal obligation for tax and accounting records.
  • Your rights. Access, rectification, erasure, restriction, objection, portability, and withdrawal of consent at any time without affecting what was done before.
  • Transfers.Where personal data leaves the EEA or UK to reach us, we rely on the European Commission’s Standard Contractual Clauses and the UK International Data Transfer Addendum, together with encryption in transit.
  • Complaints.You may complain to your supervisory authority; in the UK that is the Information Commissioner’s Office.
  • We respond to these requests within one month, extendable by two further months for complex requests.

Changes to this policy

We will update this policy as the Service changes, and we review it at least once a year. For material changes we will give notice by email or in the product before they take effect, and the date at the top of this page always shows the current version.

Contact

Privacy questions and requests: [privacy@example.com]. Security reports: [security@example.com]. By mail: [LEGAL ENTITY NAME], [STREET ADDRESS], [CITY, STATE ZIP], United States.