Skip to content
Zurvey
  • Product
  • Templates
  • Pricing
Log inCreate a free form
Menu
  • Product
  • Templates
  • Pricing
Create a free formLog in

Privacy Policy

Last updated September 23, 2026

This policy explains what personal data Zurvey handles, why, who helps us process it, how long we keep it and how you can exercise your rights. It is our comprehensive privacy notice under Mexico’s Federal Law on the Protection of Personal Data Held by Private Parties (LFPDPPP).

Contents

  1. Who we are and how to reach us
  2. Whose data this policy covers
  3. Our role and the form creator’s role
  4. Personal data we collect
  5. How we use personal data
  6. Cookies and analytics on zurvey.co
  7. Google user data
  8. AI form generation
  9. Payments
  10. Who we share personal data with
  11. International transfers
  12. How long we keep personal data
  13. How we protect personal data
  14. Your rights
  15. Children
  16. Changes to this policy

Who we are and how to reach us

Zurvey is operated by Servicios Comerciales Clickbuy, S de RL de CV (“Zurvey”, “we” or “us”), with its address at Av. Ignacio L Vallarta 3300-Piso 2, Vallarta Nte., 44690 Guadalajara, Jalisco, México.

For anything related to privacy, including requests to exercise your rights, write to hello@zurvey.co. Our personal data team handles those requests.

This policy covers:

  • this website, zurvey.co;
  • the Zurvey app at app.zurvey.co; and
  • forms published with Zurvey, at zurvey.co/z/… or on a custom domain connected by a Pro workspace.

Whose data this policy covers

  • Visitors who browse zurvey.co.
  • Account holders: people who create a Zurvey account, belong to a workspace as an Owner, Editor or Viewer, or subscribe to Pro. We also call them creators.
  • Respondents: people who open or answer a form built with Zurvey. Respondents don’t need a Zurvey account.

Our role and the form creator’s role

For accounts, workspaces, billing, support, security and this website, Zurvey decides how and why personal data is used. In the terms of the LFPDPPP, we are the party responsible for that data.

For forms and responses, the creator decides what to ask, why, who in their workspace can see the answers, where they are sent and how long they are kept. We process that content on the creator’s behalf, to provide the service they use. In that role we act as their data processor (persona encargada). Creators are responsible for giving their respondents the information and obtaining the permissions the law requires for their own purposes.

If you answered a form, the creator is the best first contact for questions about how they use your answers. You can still contact us: we will help within our role or pass your request to the creator.

We don’t use respondents’ answers for our own purposes, such as advertising, profiling or training AI models.

Personal data we collect

We don’t ask for sensitive personal data for our own purposes. A creator could choose to ask respondents for sensitive data in a form; in that case the creator must meet the stricter requirements that apply.

When you visit zurvey.co

  • Technical data needed to deliver the site, such as your IP address, browser and device details, the page requested and the time. Cloudflare processes it to serve and protect the site. This website does not keep its own database of visitors.
  • Your analytics choice, saved in your browser. See Cookies and analytics on zurvey.co.
  • Measurement data, only if you accept analytics, described in the same section.
  • Messages you send us, such as an email to hello@zurvey.co, with your address and what you share.

The interactive demo on the homepage runs only in your browser. What you type in it is not sent to us, saved or included in analytics.

When you create and use an account

  • Identity and sign-in. Your name and email address. If you sign in with Google, the basic profile Google shares with us: name, email address, profile photo and account identifier. If you sign in with an email code, the one-time codes we send you, valid for 10 minutes.
  • Sessions and security. Session records, including the IP address and browser user agent used to sign in, sign-in times and security events. Sessions expire after 30 days or when you sign out.
  • Workspaces and activity. The workspaces you belong to, your role, invitations, your plan, usage counters such as storage, AI generations and instant emails, and the date of your last authenticated activity, which we use for the Free inactivity rule.
  • Your content. Forms, questions, logic, calculations, designs, logos and images you upload, and settings.
  • Integrations you connect. Connection details for Google Drive and Google Sheets, webhook destinations, custom domains and payment provider connections, including account identifiers, status and encrypted access tokens.
  • Billing for Pro. Stripe customer and subscription identifiers, plan, billing period, invoice and payment status, amounts and founding eligibility. You enter payment card details on Stripe’s pages; we don’t receive or store full card numbers.
  • Support. Messages and information you choose to share with us.

Before you sign up, the builder keeps your draft in your browser’s storage on your device until you sign in and save it. Clearing your browser data can delete that draft. If you use AI generation before signing up, we set a cookie named __Host-zurvey.ai for 30 days. It holds a random identifier that lets you claim your one generation after you sign up. We don’t use fingerprinting.

When you answer a form

  • Your answers and uploaded files, which are whatever the creator’s form asks for. They may include your name, email address or other personal data if the form requests it.
  • Data needed to run the form and prevent abuse. While you answer, a random session token kept in your browser holds your progress together; your answers stay in your browser until you submit. We use your IP address to compute a keyed hash for rate limits rather than storing it with your response. Cloudflare Turnstile may check your browser for automated activity.
  • Form metrics without answers. We count views, starts and completed submissions so the creator can see results. These counts don’t include your answers and don’t use fingerprinting or session replay.
  • Payments. If a form asks for a payment, you pay through the creator’s connected Stripe or PayPal account. We keep the payment attempt’s status, amount, currency and provider identifiers so the response can be matched with the payment. We don’t receive your full card number.

How we use personal data

Purposes necessary for the service

We use personal data for these purposes, which are needed to provide Zurvey and to keep our relationship with you:

  • creating and managing accounts and workspaces, and signing you in;
  • building, publishing and closing forms, and collecting, storing and showing responses and files to the workspace that owns them;
  • sending responses and files to the destinations a creator connects, such as Google Sheets, Google Drive or a webhook;
  • generating a first draft of a form with AI when you ask for it;
  • processing Pro subscriptions through Stripe, applying plan limits and confirming founding eligibility;
  • sending service emails: sign-in codes, response notifications, and notices about inactivity, storage, integrations, billing and security;
  • preventing and investigating spam, fraud, abuse and security incidents;
  • answering support requests; and
  • complying with legal obligations and enforcing our Terms of Service.

Response notification emails link to the app. They don’t attach answers or files by default.

Purpose that needs your consent

  • Measuring how visitors use zurvey.co with Google Tag Manager and the Google measurement tags it loads. We only do this if you select Accept analytics. Refusing doesn’t affect the demo, links or anything else on the site.

We don’t sell personal data and we don’t send promotional newsletters. If we want to use personal data for a new purpose, we will update this policy and ask for your consent when the law requires it.

Cookies and analytics on zurvey.co

Before you choose, zurvey.co doesn’t load Google Tag Manager or any analytics, and it doesn’t set cookies of its own. Your choice is saved in your browser’s local storage under zurvey.consent, with a version number, until you change it or clear your browser data.

If you select Accept analytics, we load our Google Tag Manager container. Before any tag runs, we tell Google’s tags that analytics storage is granted and that advertising storage, ad user data and ad personalization are denied. Google tags configured in the container, such as Google Analytics, can then set cookies on zurvey.co (for example _ga and _ga_*) and receive:

  • pages you visit, the referring page and the time;
  • device and browser details, and an approximate location that Google derives from your IP address; and
  • a small set of our own events: which call to action you clicked, the type of demo action you used, which template you previewed or selected, and whether you switched between monthly and annual pricing.

We never send what you type, form answers, names, email addresses, workspace identifiers or full URLs with query strings. Google processes this data as our service provider under its own terms. You can read how Google uses information from sites that use its services.

You can change your choice at any time with Privacy choices in the footer of every page. If you withdraw consent, we stop sending our events, tell Google’s tags that analytics storage is denied and delete the Google Analytics cookies the site can reach. A script that already loaded stays in that open page until you reload it.

The Zurvey app and published forms don’t use these marketing analytics tools. They rely on storage needed for the service: a sign-in session cookie on app.zurvey.co (host-only, Secure and HttpOnly), the pre-signup AI cookie described above, browser storage for drafts, and a short-lived session token while someone answers a form.

Google user data

Zurvey requests access to Google user data only for features you choose to use.

Sign in with Google

We request the openid, email and profile permissions. We use your name, email address, profile photo and Google account identifier only to create your account, sign you in and show who you are in your workspace.

Google Drive and Google Sheets

A workspace Owner can connect Google Drive and Google Sheets. We then request the drive.file permission, which lets Zurvey work only with files and folders you pick with Google Picker or that Zurvey creates for you. It does not give Zurvey access to the rest of your Drive. Respondents never need a Google account, and never have to connect Drive to upload a file.

With that permission, Zurvey:

  • creates or uses the folder you choose to store files uploaded to your forms;
  • creates or uses the spreadsheet you choose and writes new responses to a worksheet that Zurvey manages;
  • reads the file details it needs to check a destination and confirm a transfer, such as file name, size and type; and
  • downloads a file from your Drive when someone with access to your workspace asks to download it in Zurvey.

We store an encrypted refresh token, connection details (the Google account’s email and identifier, and the permissions granted), the identifiers of the folder and spreadsheet you chose, and the identifiers and details of files saved to Drive through your forms. Files saved to Drive live in your Drive; Zurvey doesn’t keep a permanent copy of them.

If Drive is disconnected, full or unavailable, Zurvey keeps new uploads in your Zurvey storage when there is space, lets you know, and moves them to Drive once it works again, unless you choose to keep them in Zurvey.

Stopping access. You can disconnect Google in your workspace settings or remove Zurvey from your Google Account permissions. Zurvey then stops accessing your Drive and Sheets for that workspace. Disconnecting doesn’t delete files already in your Drive or rows already written to your spreadsheet.

Sharing and limits. We don’t sell Google user data, use it for advertising, or use it to create, train or improve AI models. It is not sent to our AI provider. We only share it with the service providers that host and run Zurvey, for security purposes such as investigating abuse, or to comply with the law. If Zurvey is part of a merger, acquisition or sale of assets, we will only transfer Google user data after obtaining your explicit prior consent. People at Zurvey don’t read it unless you ask us to, it is needed for security, or the law requires it.

Zurvey’s use and transfer of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

AI form generation

AI generation is optional. When you ask Zurvey to create a form, the description you write and the language you choose are sent to OpenRouter, which passes them to the AI model we have configured. The model’s provider processes that request under OpenRouter’s and its own terms. We ask for the request not to be stored, but we can’t guarantee every provider’s retention practices, so please don’t include personal or confidential information in your description.

AI generation doesn’t receive respondents’ answers, your existing forms, uploaded files or Google data, and Zurvey doesn’t use AI to analyze responses.

We delete your description when the generation finishes or is cancelled. The generated draft is kept for up to 24 hours, or until you add it to a workspace, where it becomes an ordinary draft. Anonymous generation is protected by Cloudflare Turnstile and a daily limit based on a keyed hash of the IP address that changes every day.

Payments

Pro subscriptions are processed by Stripe through Stripe Checkout and the Stripe Customer Portal. Stripe handles your payment details; we receive identifiers, status, amounts and billing periods so we can apply your plan.

Payments inside forms go to the creator’s own Stripe or PayPal account. The creator and the payment provider are responsible for that transaction. Zurvey sends the provider the amount, currency and references needed to create the payment, and keeps its status and identifiers to match it with the response. Refunds are made by the creator from Stripe or PayPal, and Zurvey shows the resulting status.

Who we share personal data with

Service providers

We use these providers, each only for its function:

  • Cloudflare: hosting and delivery of this website, the app and published forms; DNS; security and bot protection (including Turnstile); job queues; and the private network connection to our database.
  • OVHcloud: object storage for files uploaded to forms and assets uploaded by creators.
  • Amazon Web Services (Amazon SES): sending service emails, and receiving delivery, bounce and complaint notices.
  • Google: Sign in with Google, the Google Drive, Google Sheets and Google Picker integrations you connect, and, only with your consent, Google Tag Manager and Google measurement tags on zurvey.co.
  • OpenRouter and the AI model provider it routes to: AI form generation, only when you use it.
  • Stripe: Pro subscription billing. Stripe and PayPal also process form payments through creators’ own connected accounts.

Our database runs on a private server that is reached only through that private connection.

Other people and destinations

  • Your workspace. Owners, Editors and Viewers see the forms, responses and files of the workspaces they belong to, according to their role.
  • Destinations a creator connects. A creator can send responses to Google Sheets, files to Google Drive, and responses to webhook addresses they control. Data sent there is handled by the creator and the destination’s provider.
  • Authorities and legal claims. When the law requires it, when a competent authority orders it, or when it is needed to establish, exercise or defend a legal claim.
  • Business changes. If Zurvey is involved in a merger, acquisition or sale of assets, personal data may be transferred as part of it. We will tell you before your data becomes subject to a different privacy policy.

These communications are necessary to provide the service you asked for, to maintain our relationship with you, or are required by law, which are cases where the LFPDPPP allows them without additional consent. We don’t transfer personal data to third parties for their own marketing.

International transfers

Zurvey is operated from Mexico, and our providers run infrastructure in several countries. Depending on the service, your data may be processed in Mexico, the United States, the European Union or other countries where those providers operate. We choose providers that commit to protecting the data they process for us, and we require the same protection described in this policy.

How long we keep personal data

Data How long we keep it
Account and workspace data While your account is active. Deleted when you delete your account, except records we must keep for legal reasons.
Forms, responses and files stored by Zurvey No expiry because of age while the account is active. They remain until the creator deletes them, subject to storage limits and the Free inactivity rule below.
Files kept in Zurvey because Drive was unavailable Same as any other file stored by Zurvey. They count toward storage.
Items moved to the trash 30 days, unless permanently deleted sooner. They count toward storage while there.
Permanent deletion Access is removed immediately and the active copy is purged within 24 hours. If a problem prevents that, we record it and keep working on it; we don’t report it as complete.
Abandoned uploads Deleted 24 hours after the last activity if they aren’t part of a submitted response or a payment attempt that still needs to be resolved.
Payment attempts that failed, were cancelled or expired, without a submitted response 7 days after the provider confirms that final status. A payment whose status is uncertain is reconciled first; it isn’t deleted by a timer.
AI generation The description is deleted when the generation finishes or is cancelled. The result is kept up to 24 hours unless added to a workspace.
Pre-signup AI cookie 30 days.
Sign-in sessions and email codes Sessions expire after 30 days or when you sign out. Email codes are valid for 10 minutes.
Operational logs 30 days, limited to technical details. Logs don’t include cookies, sign-in codes, tokens, AI descriptions, form content or answers.
Your analytics choice on zurvey.co In your browser until you change it or clear your browser data.
Analytics data, if you accepted According to the retention settings of our Google Analytics property and the expiry of Google’s cookies.
Billing and tax records As long as tax, accounting and other legal obligations require. Periods vary by record and by law.
Support messages As long as needed to resolve your request and keep a record of it.

Inactive Free workspaces

If no Owner or Editor has signed in or worked in a Free workspace for 24 months, its responses and uploaded files are deleted, even if its forms kept receiving responses. Signing in and working in Zurvey as an Owner or Editor restarts the period. Visits, form submissions, webhooks, email opens and activity by Viewers don’t.

We email the workspace’s Owners and Editors 60, 30 and 7 days before the date, and show a warning in the app. On that date the forms are closed, and responses and files stored by Zurvey, including files kept because Drive was unavailable, are deleted as described above. The account and the forms’ structure stay as private drafts without responses. Files in your Google Drive are not deleted. Pro workspaces are not subject to this rule.

What deletion covers

Zurvey doesn’t offer restoring deleted data: once the purge completes, it can’t be recovered from Zurvey. Downloading a file doesn’t delete the original. Deleting data in Zurvey doesn’t delete what was already sent to your spreadsheets, webhook destinations or Google Drive, or the records payment providers keep. Our providers also keep their own operational records under their terms, such as Cloudflare’s request logs, Amazon SES delivery events and Stripe’s payment records.

How we protect personal data

We use administrative, technical and physical measures appropriate to the data we handle. Among them:

  • connections to Zurvey use HTTPS;
  • Google refresh tokens and Drive upload sessions are encrypted before we store them, and AI descriptions and results are encrypted while they are kept;
  • sign-in session cookies are host-only, Secure and HttpOnly, and they are never shared with zurvey.co or published forms;
  • uploaded files are kept in private storage and are downloaded through short-lived, authorized links;
  • the app connects to the database with restricted roles, and workspaces are isolated from one another;
  • webhook deliveries are signed so receivers can verify they come from Zurvey; and
  • our logs leave out cookies, codes, tokens, AI descriptions, form content and answers.

No method of transmission or storage is completely secure. If a security breach significantly affects your rights, we will inform you promptly so you can take steps to protect yourself.

Your rights

You can ask us to:

  • access the personal data we hold about you and how we use it;
  • rectify data that is inaccurate, incomplete or out of date;
  • cancel your data, so that we delete it once any legal retention period ends; and
  • object to a use of your data for a legitimate reason.

These are known in Mexico as ARCO rights. You can also withdraw your consent for analytics at any time with Privacy choices, and ask us to limit how we use or disclose your data.

Many requests can be handled directly in Zurvey: you can remove members, delete responses, files, forms or your account, and disconnect integrations.

How to make a request

Email hello@zurvey.co with:

  1. your name and an email address or other way to reply to you;
  2. a document that proves your identity, or your representative’s identity and authority to act for you;
  3. a clear description of the data and the right you want to exercise, and for a rectification, the correction and any supporting document; and
  4. anything else that helps us find the data, such as your account email or the form you answered.

We will reply within 20 days of receiving your request. If it is granted, we will carry it out within 15 days of our reply. We may extend each period once, by the same length, when the case justifies it, and we will tell you why. Exercising these rights is free; we may only charge justified costs of reproduction or delivery.

If you answered a form, we may ask the creator to act on your request, since they decide how their responses are used. We will not deny a right you have toward Zurvey because a creator is involved.

If you are not satisfied with our answer, or we don’t answer in time, you can file a data protection request with Mexico’s Secretaría Anticorrupción y Buen Gobierno under the LFPDPPP.

If the law of the place where you live gives you additional rights, such as data portability or restricting processing, you can exercise them through the same channel, to the extent they apply.

Children

Zurvey accounts are for adults: you must be at least 18 to create one. Zurvey is not directed to children. A creator who asks minors to answer a form is responsible for obtaining any consent from parents or guardians that the law requires.

Changes to this policy

We will publish any change on this page and update the date at the top. If a change is material, we will tell account holders by email or in the app before it takes effect, and we will ask for consent again when the law requires it.

Questions about this document? Write to hello@zurvey.co.

Servicios Comerciales Clickbuy, S de RL de CV
Av. Ignacio L Vallarta 3300-Piso 2, Vallarta Nte., 44690 Guadalajara, Jalisco, México
Zurvey

Forms and surveys that are simple to build and pleasant to answer.

  • Product
  • Templates
  • Pricing
  • Create a free form
  • Log in
  • Privacy Policy
  • Terms of Service
  • hello@zurvey.co

© 2026 Zurvey. Zurvey is operated by Servicios Comerciales Clickbuy, S de RL de CV.

We’d like to use Google Tag Manager to understand how this site is used. Nothing optional loads unless you accept. The demo and links work either way. Privacy Policy