Privacy Policy
Effective date: September 2, 2026
This policy explains what personal data gothamCulture LLC (“we,” “our,” or “SurveyCraft”) collects when you use SurveyCraft — either as a survey respondent or as an account holder — why we collect it, how we use it, who we share it with, and the rights you have over it.
For European Economic Area (EEA) and United Kingdom respondents, this policy is our notice under Articles 13 and 14 of the General Data Protection Regulation (GDPR). It applies regardless of where you are located.
1. Who is the data controller
The controller of your personal data is:
gothamCulture LLC115 Broadway, 5th Floor
New York, NY 10016
United States
Email: chris.cancialosi@gothamculture.com
gothamCulture LLC is established in the United States and does not currently have a designated representative in the European Union under GDPR Article 27. EEA residents may still exercise all rights described in this policy by contacting us at the address above.
2. What we collect and why
From survey respondents we collect:
- The answers you submit — always. These are the point of the survey.
- Technical signals (IP address, browser user-agent, device type) — only when the survey creator has not enabled “Anonymous responses.” We use these solely to detect abuse and duplicate submissions. If the survey is anonymous, none of these are stored.
- A deletion token (a random string) — shown to you on the thank-you screen. Save this if you may want to erase your response later.
- Any files you upload in response to a file-upload question. Stored with unguessable URLs in Vercel Blob storage.
From account holders (people who create surveys) we collect: name, email address, hashed password, authentication logs, billing information (via our payment processor), and any content you produce in SurveyCraft (surveys, branding, team roles).
3. Legal basis (GDPR Article 6)
We process personal data on the following bases:
- Legitimate interests (Art. 6(1)(f)) for collecting survey responses on behalf of a survey creator, for abuse prevention (rate limiting, ballot-stuffing checks), and for providing the service to account holders.
- Contract (Art. 6(1)(b)) for delivering the SurveyCraft service to account holders.
- Legal obligation (Art. 6(1)(c)) for retaining limited records we are required to keep.
You can object to any processing based on legitimate interests by contacting us at the email above.
4. How long we keep it
Survey responses are retained for the period set by the survey creator (configurable per survey in the survey settings). Once that period passes, a daily job permanently deletes responses along with all answers tied to them. If a creator has not set a retention period, responses are kept until the survey or the creator's account is deleted.
Account-holder records are kept for the life of the account. When an account is deleted, its records are removed from the live database immediately and fall out of our database provider's retained change history within 7 days, after which they cannot be recovered.
When a Leadership Mosaic 360 report is generated, we keep a copy of it for 60 days so that it can be re-issued if it is asked for again. A report can name a small number of the raters who contributed to it, so this copy is kept for the same 60 days that rater responses are kept in identifiable form — no longer. After that a daily job deletes the stored file permanently.
5. Who we share it with
We do not sell personal data. We share it only with processors that help us run SurveyCraft:
- Vercel Inc. — hosting, application compute, and storage for files uploaded in response to a survey.
- Neon Inc. — the managed PostgreSQL database that holds survey and account data.
- Supabase Inc. — the normative comparison database used to generate Mosaic reports. It holds aggregated, pseudonymised scores only: no names, no email addresses, and no open-text comments.
- Upstash, Inc. — rate-limiting cache.
- Stripe, Inc. — payment processing for purchases. Card details are submitted directly to Stripe and never reach our systems.
- Resend, Inc. — transactional and survey invitation email delivery.
- Anthropic PBC — powers three features that send text to Anthropic's Claude API:
- auto-translation of survey content, when a survey creator uses it. This sends the questions and answer options the creator wrote, not respondent answers.
- an optional check a survey creator can run to estimate whether a free-text answer was AI-generated. This does send respondent free-text answers.
- the written summaries in Leadership Mosaic and Culture Mosaic reports. This sends raters' free-text comments.
- Cloudflare, Inc. — the anti-bot challenge on our public purchase and signup forms (Turnstile).
- Google LLC — Google Analytics (see section 9) and, where an account holder chooses to sign in with Google, the authentication itself.
- Usercentrics GmbH (Termageddon) — the cookie-consent banner and the record of your consent choice.
- Have I Been Pwned — password strength screening at account creation and password change. Only the first five characters of a SHA-1 hash of the password are sent, which is not enough to identify or reconstruct it. The password itself, and the full hash, never leave our systems.
Application error logs are kept in our own database and hosting logs. We do not send them to a third-party error-monitoring service, and we mask email addresses before they are written to a log.
6. International transfers
Personal data is stored and processed in the United States and in other countries where our sub-processors operate. For transfers out of the EEA or UK, we rely on the European Commission's Standard Contractual Clauses or equivalent safeguards, as published by each sub-processor.
7. Your rights
You have the right to access, correct, delete, port, and object to the processing of your personal data. EEA/UK residents also have the right to lodge a complaint with their local supervisory authority.
Survey respondents: use the deletion link shown on the thank-you screen to erase your response yourself. For any other request, email chris.cancialosi@gothamculture.com.
Account holders: use the Settings → Data & privacy section to export or delete your account data.
8. Security
Data is encrypted in transit (TLS) and at rest. Access to production systems is restricted and logged. We run a rate limiter that is required to be online in production, and we do not allow uploaded files to be served from guessable URLs.
9. Cookies and analytics
Some of our cookies are strictly necessary: they keep you signed in and protect against cross-site request forgery. These are set without consent because the service cannot work without them.
We also use Google Analytics to understand how the service is used. Analytics cookies and device identifiers are not strictly necessary, so they are not set until you accept them. Every storage category is set to “denied” by default before Analytics loads, which means Analytics runs in a cookieless mode — sending anonymous usage pings and storing nothing on your device — unless and until you consent.
A cookie-consent banner is presented on first visit and records your choice. Accepting analytics cookies upgrades Google Analytics out of cookieless mode; declining leaves it there.
We do not use cookies for advertising or cross-site tracking, and we do not sell or share personal information for cross-context behavioural advertising.
10. Changes to this policy
If we make material changes we will update the “effective date” above and, for account holders, notify by email.