Privacy Policy
This Privacy Policy describes how Aboundo ("we," "us," or "our") collects, uses, and discloses information when you use our Service. It covers two distinct relationships: (1) our relationship with you as a Customer (Tenant), and (2) our relationship with your form visitors whose data you collect using the Service.
1. Information We Collect About Customers
When you create an account, we collect:
- Account information: your name, email address, and password (stored as a secure hash).
- Workspace information: your workspace/organisation name.
- Usage data: form configurations, submission counts, login events, and audit logs.
- Billing information: your billing contact details and payment method, processed directly by our payment processor, Stripe. We do not receive or store your full card number or other sensitive payment credentials.
- Integration credentials: if you connect Salesforce, we store OAuth tokens and your Connected App credentials encrypted at rest.
2. Information Collected Through Your Forms (Visitor Data)
When your visitors submit a form you have built using Aboundo, we collect and store the submitted field values on your behalf. We act as a data processor; you are the data controller for this data. You are responsible for:
- Displaying an appropriate privacy notice to your visitors.
- Obtaining any required consent before collecting personal data.
- Ensuring you have a lawful basis for collection under applicable data protection law.
Gated Document forms: if you use a Gated Document form, we also store the file you upload for distribution to your visitors. This file is stored using the same infrastructure as visitor submission data and is subject to the same security measures described in this policy.
3. How We Use Customer Information
- To provide, operate, and improve the Service.
- To send transactional emails (account verification, password reset).
- To send service announcements and, where permitted, product updates.
- To enforce our Terms of Service.
- To comply with legal obligations.
4. How We Use Visitor Data
We use visitor data to provide the Service to you (storing and forwarding submissions, syncing to integrations you have configured). We do not use visitor data for advertising or profiling, and we do not use it for any purpose beyond fulfilling our obligations to you as processor, except as described in Section 5 (Aggregated and De-Identified Data).
5. Aggregated and De-Identified Data
We may create data derived from your and your visitors' use of the Service that has been aggregated and de-identified such that it does not identify you, any individual, or any specific submission, and cannot reasonably be used to do so ("Aggregated Data"). Because Aggregated Data does not identify any individual, it is not personal data and falls outside our data-processor role and the rest of this Privacy Policy. We may use Aggregated Data to operate, support, and improve the Service, and to produce aggregate usage benchmarks and similar analytics, including sharing them publicly or with third parties, provided the Aggregated Data does not identify you or any individual. This mirrors the license described in our Master Subscription Agreement and does not change our role as processor for the underlying Visitor Data described in Section 2.
6. Data Sharing and Third Parties
We do not sell your data or visitor data. We may share data with:
- Salesforce: if you configure the Salesforce integration, submission data is forwarded to Salesforce as your sub-processor. See the DPA for sub-processor details.
- Stripe: to process subscription payments and manage billing for your account with us. When you take a billing action (subscribing, starting a trial, or managing your subscription), we redirect your browser to a page hosted entirely on Stripe's own domain — we do not embed Stripe's checkout or payment fields on our own pages. Stripe collects your billing contact details and payment information directly on that page; this information does not pass through our servers. See Stripe's Privacy Policy for how Stripe handles this data. Stripe does not process the personal data your visitors submit through your forms.
- Email provider (Resend): to send transactional emails on our behalf.
- Infrastructure providers: hosting and database providers operating under appropriate data processing agreements.
- Legal authorities: where required by law or valid legal process.
7. Data Retention
- Customer account data is retained for the duration of your subscription plus 30 days after termination.
- Visitor submission data is retained as long as your account is active, including during any period where your subscription has lapsed for non-payment — a lapse by itself does not result in deletion of your data. On account termination, data remains available for export for 30 days. After that period, it is no longer retained for further use and is removed from our active systems in the ordinary course, except where we are required or permitted to keep it longer (for example, to comply with law or resolve a dispute).
- Audit logs are retained for 90 days.
- Backup archives. The timelines above describe our active production systems. We also maintain automated backup archives for disaster-recovery purposes. We don't selectively remove data from an existing backup archive, since doing so would compromise its integrity for its intended purpose. Instead, once data is deleted from our active systems, it is immediately isolated from production use, and it is permanently overwritten no later than our standard backup rotation schedule, which does not exceed 90 days. See our DPA for more detail.
8. Security
We use industry-standard measures including encryption in transit (TLS), encryption at rest for sensitive credentials, role-based access controls tied to your account's role within the Service, and multi-factor authentication for our personnel's administrative access to production systems and infrastructure. We also maintain a vulnerability management practice for the software components the Service relies on. No system is perfectly secure; if a breach occurs, we will notify you without undue delay and, where feasible, within 48 hours of becoming aware of it, as further described in our DPA.
9. Your Rights
Depending on your location, you may have rights under GDPR, CCPA/CPRA, other US state privacy laws, or other applicable laws to access, correct, delete, or port your personal data. To exercise these rights, contact us at privacy@aboundo.example. For rights requests relating to visitor data submitted through your forms, those requests should be directed to you as the data controller (or, under US state law, the "business") for that data — see Section 2.
10. US State Privacy Rights (California, Colorado, Virginia, Texas, and Other States)
This section is provided to comply with the California Consumer Privacy Act as amended by the California Privacy Rights Act ("CCPA/CPRA," Cal. Civ. Code § 1798.100 et seq., including the disclosures required by § 1798.130), the Colorado Privacy Act ("CPA"), the Virginia Consumer Data Protection Act ("VCDPA"), the Texas Data Privacy and Security Act ("TDPSA"), and similar laws in other US states. Except where noted, it applies to our processing of Customer (account) personal information as described in Section 1; for Visitor Data submitted through your forms, the Tenant that built the form is the "business"/"controller," and Section 2 explains our role.
We do not sell or share your personal information. We do not sell personal information for money or other valuable consideration, and we do not "share" personal information for cross-context behavioral advertising, as those terms are defined under the CCPA/CPRA. We do not use cookies, pixels, or similar technology on our own pages for targeted or cross-context behavioral advertising (see our Cookie Policy). If this ever changes, we will update this policy in advance and provide the opt-out mechanisms the law requires before doing so.
Categories of personal information. In the preceding 12 months, we have collected the following categories of personal information, as defined under Cal. Civ. Code § 1798.140: identifiers (name, email address); customer records information (billing contact and payment details, processed by Stripe as described in Section 6); commercial information (your subscription, plan, and billing history); internet or network activity information (login events, audit logs, and usage data described in Section 1); and professional information (your workspace/organization name). We do not knowingly collect sensitive personal information about our Customers, and we do not use or disclose sensitive personal information for purposes that trigger a right to limit under the CCPA/CPRA. Visitor Data collected through a specific form depends on how the Tenant configured that form; we do not control or curate those categories.
Sources and business purposes. We collect personal information directly from you and automatically through your use of the Service, for the business purposes described in Section 3 (providing and operating the Service, security, billing, legal compliance). We disclose categories of personal information to the service providers described in Section 6 (Stripe, Resend, hosting/infrastructure providers) for those same business purposes, and, where you configure an integration, to that integration (e.g., Salesforce) at your direction.
Your rights. Subject to certain exceptions, you have the right to: know and access the specific pieces and categories of personal information we hold about you; delete your personal information; correct inaccurate personal information; obtain a portable copy of your personal information; opt out of the sale or sharing of your personal information and of targeted advertising (not applicable today, since we do not engage in these practices — see above); limit the use of sensitive personal information (not applicable today, for the same reason); and not be discriminated against for exercising any of these rights, including through denial of service, a different price, or a different quality of service.
How to submit a request. Submit a request at privacy@aboundo.example. Because we operate exclusively online and maintain a direct relationship with our Customers, a single designated method (email) satisfies the CCPA's requirement to offer at least two methods for an online-only business. We will verify your identity, generally by confirming the request comes from the email address on your account, before completing a request that involves accessing or deleting personal information; you may designate an authorized agent to submit a request on your behalf, and we may require the agent to provide proof of authorization and require you to separately verify your own identity.
Appeals. If we decline to act on your request, you may appeal by replying to our decision with "Appeal" in the subject line within a reasonable time. We will respond to your appeal as required by applicable law. If your appeal is denied, Colorado, Virginia, and Texas residents may contact their state Attorney General.
Opt-out preference signals. Some browsers and extensions send an opt-out preference signal, such as Global Privacy Control ("GPC"). Because we do not sell or share personal information or engage in targeted advertising, receiving this signal does not currently change how we handle your data, but we honor it as a valid opt-out request to the extent it would ever apply.
Minors. We do not knowingly sell or share the personal information of consumers we know to be under 16 years of age.
California Shine the Light. California Civil Code § 1798.83 permits California residents to request information about disclosures of personal information to third parties for those third parties' own direct marketing purposes. We do not disclose personal information to third parties for their own direct marketing purposes.
11. International Transfers
For transfers of Visitor Data (the Personal Data we process on your behalf, as described in Section 2) outside the European Economic Area or United Kingdom, we rely on the Standard Contractual Clauses and UK Addendum incorporated by reference in our Data Processing Agreement — see the DPA for the specific module, governing law, and Annex references that apply, rather than a general statement of intent. For our own processing of your Customer account and billing information (Section 1) outside the EEA or UK, we rely on the same Standard Contractual Clauses on substantially the same terms. We are not currently a certified participant in the EU-U.S. Data Privacy Framework, its UK Extension, or the Swiss-U.S. Data Privacy Framework, and are not relying on any of these as a transfer mechanism today.
12. Cookies
We use a single session cookie (kiss_session) to maintain your authenticated session in the admin application. We do not use tracking or advertising cookies. Our public-facing forms do not set cookies by default. See our Cookie Policy for details, including cookies set by Stripe when you're redirected to a Stripe-hosted checkout or billing page, and how we handle opt-out preference signals.
13. Changes to This Policy
We may update this policy. We will notify you by email before material changes take effect. This policy is dated at the top of this page and, consistent with the CCPA/CPRA, will be reviewed and, if needed, updated at least once every 12 months.
14. Contact
Privacy questions: privacy@aboundo.example.