1. Data Controller
PollsLive ("we", "us", "our") operates the website and service at pollslive.com (the "Service"). We act as the data controller for personal data processed through the Service. For any privacy matter, contact [email protected] or use our contact form.
2. Data We Collect
Account data: name, email address, password hash (for credential sign-in) or Google account identifier (for OAuth sign-in), workspace membership, and billing status.
Poll content: questions, options, themes, slide decks, and published poll configurations you create.
Vote & participation data: selected options, nicknames you choose in live sessions, and timestamps. To prevent duplicate voting without requiring login, we set an HttpOnly signed voter cookie and combine it with a hashed IP address on the server. We do not store raw IP addresses in vote records, and we do not use canvas fingerprinting.
Contact submissions: when you use our contact form, we store your name, email, selected category, subject, message, and any files you attach, together with a hashed IP address and browser user agent for abuse prevention. We use this solely to handle your request.
Lead capture (optional): if you enable lead capture on a poll, we store respondent contact fields you configure (for example email or name) and delivery status to your destinations.
Pulse AI chat: when you use the Studio assistant, we store conversation transcripts needed to continue the chat and improve support quality.
Usage & technical data: pages visited, feature usage, outbound mail delivery logs, and security logs used to operate, secure, and improve the Service.
3. How We Use Data
- Provide, maintain, and improve the polling Service
- Authenticate creators and manage workspaces
- Process subscriptions and prevent payment fraud
- Display real-time and aggregated poll results
- Respond to support, billing, and privacy requests
- Detect, prevent, and investigate abuse and security incidents
4. Legal Bases (GDPR)
Where the GDPR applies, we process personal data under the following legal bases: performance of a contract (providing the Service to account holders), legitimate interests (securing the Service, preventing abuse, and answering enquiries), legal obligation (tax and accounting records), and consent where required (for example, non-essential analytics).
5. Third Parties
- Whop - payment processing and subscription management, acting as Merchant of Record
- Google - optional single sign-on (OAuth) for account access
- Cloudflare - DNS, CDN, bot protection (Turnstile), and a secure tunnel to our infrastructure
- Groq (optional) - primary AI inference for Pulse chat and generation when configured
- Google Gemini (optional) - AI inference fallback when configured
- Cerebras (optional) - AI inference fallback when configured
- Cloudflare Workers AI (optional) - AI inference fallback when configured
- OpenRouter (optional, global) - AI routing when configured for staging or fallback
- MXroute - transactional email delivery (account, billing, and product mail)
- Hostinger - EU-based hosting for our application, database, and cache
A full, current list with each provider's purpose, the data it handles, and its location is on our Sub-processors page. We do not sell personal data to third parties.
7. Data Security
Traffic is encrypted in transit via TLS. Passwords are stored only as salted hashes, and we hash IP addresses used for anti-abuse signals. Access to production systems is restricted, and our database and cache are not exposed to the public internet. No system is perfectly secure, but we work to protect your data using appropriate technical and organisational measures.
8. International Transfers
Our application infrastructure is hosted in Europe. Some processors (for example, Whop, Google, Cloudflare, and OpenRouter) may process data outside your country. Where personal data is transferred internationally, we rely on appropriate safeguards such as Standard Contractual Clauses.
9. Retention & Deletion
Account data is retained while your account is active. Contact-form submissions and their attachments are retained only as long as needed to resolve your request and to meet legal obligations, then deleted. You can export your data or permanently delete your account yourself at any time from Studio → Account & privacy, or by emailing [email protected]. Account deletion removes your profile, the workspaces you own, and their polls, votes, and live sessions, and cancels any Whop subscriptions for those workspaces. Whop (our Merchant of Record) may retain billing records as required by payment and tax law. Vote aggregates may be retained in anonymised form for published poll statistics.
10. Your Rights
Depending on your jurisdiction (including under the GDPR), you may have the right to access, correct, delete, restrict, or port your personal data, and to object to certain processing. You also have the right to lodge a complaint with your local supervisory authority. You can action access, portability, and erasure yourself from Studio → Account & privacy; for any other request, contact us and we will respond within the timeframes required by law.
11. US State Privacy Rights
If you are a resident of California (CCPA/CPRA) or another US state with a comprehensive privacy law (such as Virginia, Colorado, Connecticut, or Utah), you have the right to know what personal information we collect, to access and delete it, to correct inaccuracies, and to opt out of the "sale" or "sharing" of personal information and of targeted advertising.
We do not sell or share your personal information as those terms are defined under US state laws, and we do not use it for cross-context behavioural advertising. You may exercise your access, deletion, and portability rights from Studio → Account & privacy or by emailing [email protected]. We will not discriminate against you for exercising these rights.
12. Children's Privacy
PollsLive is not directed at children under 13, or the higher minimum age that applies in your country (16 in parts of the EU, including the Netherlands), and we do not knowingly collect their personal data. Contact us if you believe a child has provided personal information and we will delete it.
13. India & Other Regions
If you are in India, we handle your personal data in line with the Digital Personal Data Protection Act, 2023 (DPDP Act) and its Rules. You have the right to access, correct, and erase your personal data, the right to grievance redressal, and the right to nominate another person to exercise your rights on your behalf. To raise a grievance, contact [email protected] with "DPDP grievance" in the subject and we will respond within the timelines required by law; if you are not satisfied with our response, you may escalate to the Data Protection Board of India. In all other regions, we apply the safeguards described in this policy - GDPR-level protections - to everyone who uses the Service, wherever you are.
14. Changes to This Policy
We may update this policy from time to time. Material changes will be posted on this page with a revised "Last updated" date. Continued use of the Service after changes take effect constitutes acceptance of the updated policy.
15. Contact
Privacy requests: [email protected] - or use our contact form and choose "Privacy / GDPR".