Privacy Policy
Last updated: September 10, 2026
Who we are
BeeNPS ("we", "us") provides account-level NPS software for business customers. Questions about this policy or any privacy request can be sent to hello@beenps.com.
Data we process on behalf of our customers
Our customers upload contact information about their own customers — typically names, work email addresses, company/domain associations, and seat counts — and BeeNPS sends surveys to those contacts and stores their responses (scores and comments). For this data we act as a processor (GDPR Art. 28): our customer is the controller, decides why and how the data is used, and we process it only on their instructions and to provide the service.
If you received a BeeNPS survey, the company that sent it controls your data. We will refer any access, correction, or deletion request to them, and we delete contact data promptly when a customer removes it or asks us to.
Data we collect as a controller
For our own customers' accounts we collect sign-up details (name, email), billing information, and standard usage and log data needed to operate, secure, and improve the service. We do not sell personal data and we do not use survey respondent data for advertising.
Subprocessors
We use a small set of infrastructure providers to run BeeNPS: Vercel (hosting), Neon (database), Clerk (authentication), Stripe (payments), and Resend (email delivery). Each processes data only as needed to provide its service to us, under a data processing agreement.
Retention and deletion
We keep data for as long as the customer's account is active. When an account is closed, or on a verified deletion request, associated personal data is deleted from production systems within 30 days and from backups on their normal expiry cycle.
Your rights
Depending on where you live (including under the GDPR), you may have rights to access, correct, export, restrict, or delete your personal data. Contact us — or the company that surveyed you — at hello@beenps.com and we will respond within the legally required timeframe.
Security
Data is encrypted in transit and at rest, access is limited to personnel who need it to operate the service, and we notify affected customers without undue delay if a breach affects their data.
Changes
We will post any changes to this policy on this page and update the date above. Material changes are announced to account owners by email.
Draft — have counsel review before relying on it.