Last updated: January 31, 2025
Surface ("we," "our," or "us") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our platform and services.
This policy applies to all Surface services. Please note that different roles have different data implications:
By using Surface, you consent to the data practices described in this policy.
Account Information:
Profile/Creator Data:
Analytics Data:
Lead Capture Data (on behalf of Creators):
Payment Information:
Technical Data:
For users in the European Economic Area (EEA), United Kingdom, and Switzerland, we process personal data based on the following legal grounds under GDPR Article 6:
| Processing Activity | Legal Basis |
|---|---|
| Account creation and management | Contract performance (Art. 6(1)(b)) |
| Processing payments | Contract performance (Art. 6(1)(b)) |
| Hosting and displaying your pages | Contract performance (Art. 6(1)(b)) |
| Analytics and service improvement | Legitimate interest (Art. 6(1)(f)) |
| Security and fraud prevention | Legitimate interest (Art. 6(1)(f)) |
| Marketing communications | Consent (Art. 6(1)(a)) |
| Lead capture processing | Consent (Art. 6(1)(a)) via Creator |
| Legal compliance | Legal obligation (Art. 6(1)(c)) |
Legitimate Interest Assessment:
Where we rely on legitimate interests, we have conducted balancing tests to ensure our interests do not override your fundamental rights and freedoms. Our legitimate interests include:
You have the right to object to processing based on legitimate interests. See Section 9 for how to exercise this right.
To Provide the Service:
To Improve the Service:
To Communicate:
For Security:
For Legal Compliance:
Important Distinction
When Creators use lead capture, they become data controllers for the leads they collect. Surface is a data processor acting on their behalf.
What This Means for Leads:
Surface's Processing:
| Data Type | Retention Period |
|---|---|
| Account data | Until account deletion |
| Profile content | Until deletion + 30 days backup |
| Analytics data | 24 months (rolling) |
| Lead data | Until Creator deletes or account closed |
| Lead submission logs | 1 hour (spam protection only) |
| Handle redirects | 180 days after handle change |
| Payment records | 7 years (legal requirement) |
After Account Deletion:
GDPR Rights (EU Users):
EU Supervisory Authorities:
If you are in the EEA and believe we have not adequately addressed your concerns, you have the right to lodge a complaint with your local data protection supervisory authority. A list of EU data protection authorities can be found at edpb.europa.eu.
CCPA Rights (California Residents):
How to Exercise Your Rights:
Surface is based in the United States, and your data may be processed in the US or other countries where our service providers operate.
For data transferred from the EU/EEA, we rely on:
By using Surface, you consent to the transfer of your data to the United States and other jurisdictions.
We implement security measures to protect your data:
While we strive to protect your information, no system is 100% secure. You are also responsible for protecting your account credentials and notifying us of any suspected unauthorized access.
Surface is not intended for users under 18 years of age. We do not knowingly collect personal information from minors. If we discover that we have collected data from a minor, we will delete it promptly.
If you are a parent or guardian and believe your child has provided us with personal information, please contact us at privacy@surface.page.
Surface may contain links to third-party websites and integrate with third-party services (such as Stripe for payments). These third parties have their own privacy policies that govern their collection and use of your information.
Surface is not responsible for the privacy practices of third parties. We encourage you to review the privacy policies of any third-party services you use.
Surface does not engage in automated decision-making or profiling that produces legal effects or similarly significantly affects you (as defined in GDPR Article 22).
Automated Processing We Do Use:
If you believe an automated system has made an error affecting your account, please contact us at support@surface.page for human review.
We may update this Privacy Policy from time to time. If we make material changes, we will notify you via email or through the Service at least 30 days before the changes take effect.
Your continued use of Surface after any changes constitutes acceptance of the updated policy. Previous versions of this policy are available upon request.
If you have questions about this Privacy Policy or our data practices, please contact us: