Last updated: 3 March 2026

Privacy Policy

How we collect, use, and protect personal data — for both our customers and website visitors who complete surveys powered by Selge.

1. Who we are and our role

Selge is operated by [OPERATOR_FULL_NAME], [OPERATOR_STREET_ADDRESS], [POSTAL_CODE] [CITY], Germany (“Selge”, “we”, “our”, “us”).

Selge provides an on-site survey widget service (“the Service”) that website operators (“customers”) use to collect feedback from their website visitors. This creates two distinct data processing relationships:

For account and billing data

Selge is the data controller. We determine how and why your registration, billing, and dashboard usage data is processed.

For survey response data (visitor feedback)

Selge is the data processor, acting on behalf of our customer (who is the data controller). Our Data Processing Agreement governs this relationship.

2. Data we collect from customers (dashboard users)

When you create a Selge account and use the dashboard, we collect the following data:

DataPurposeLegal basis
Email addressAccount login, transactional emails (password reset, billing notices)Art. 6(1)(b) GDPR — contract performance
Password (bcrypt hash — never stored in plain text)AuthenticationArt. 6(1)(b) GDPR — contract performance
Billing information (processed by Stripe — we never see your full card number)Subscription management and paymentArt. 6(1)(b) GDPR — contract performance
Survey configuration data (questions, settings, targeting rules)Core service functionalityArt. 6(1)(b) GDPR — contract performance
Dashboard usage data (pages visited, features used)Product improvementArt. 6(1)(f) GDPR — legitimate interest
Error logs and crash reports (via Sentry)Debugging and service stabilityArt. 6(1)(f) GDPR — legitimate interest

3. Data collected via the survey widget (visitor data)

When a visitor completes a survey on a Selge-powered website, the following data is collected. This data is processed by Selge on behalf of our customer (the website operator), who is the data controller for this data.

DataNotes
Survey answersVoluntarily provided by the visitor. May include personal data if the visitor discloses it in open-text fields.
Page URLThe URL of the page where the survey was shown.
Browser type and versionUsed for technical compatibility and dashboard analytics.
Device typeDesktop or mobile — for dashboard analytics.
Country of originDerived from the visitor's IP address at submission time. The full IP address is discarded immediately and never stored.
Session identifierA random ID stored in sessionStorage (not a cookie) to prevent duplicate submissions. Automatically cleared when the browser tab is closed. Cannot track visitors across sessions or sites.

If you are a website visitor who completed a survey on a Selge-powered website and wish to exercise your GDPR rights, please contact the website operator directly. We will assist them in fulfilling your request in accordance with our DPA.

5. Sub-processors

We use the following third-party sub-processors to operate the Service. All are bound by appropriate data protection agreements.

ProviderPurposeLocationSafeguard
Supabase, Inc.Database storage and authenticationEU (Frankfurt, Germany)EU region — no transfer needed
Hetzner Online GmbHApplication hosting, server infrastructure, and widget script deliveryEU (Germany)EU region — no transfer needed
Stripe, Inc.Payment processing (customer billing only — not visitor data)US / EUStandard Contractual Clauses
Anthropic, PBCAI analysis of open-text survey responses (only when AI summary feature is used)USStandard Contractual Clauses
Functional Software, Inc. (Sentry)Error monitoring and crash reportingUSStandard Contractual Clauses
Slack Technologies (Salesforce)Response notification delivery (when Slack integration is enabled)USStandard Contractual Clauses

We will notify customers of any changes to this sub-processor list with at least 14 days notice, giving customers the opportunity to object.

6. Data retention

Data typeRetention period
Account data (email, settings)Duration of active account + 30 days after deletion
Survey response data12 months by default; configurable by the customer
Payment and invoice records7 years (Sec. 147 AO German tax law)
Error logs (Sentry)90 days
Widget session identifiersBrowser session only (sessionStorage — auto-cleared on tab close)

After expiry, data is permanently deleted. When you delete your Selge account, all associated data (projects, surveys, responses) is cascade-deleted within 30 days.

7. International data transfers

Our primary data storage is in the EU (Supabase Frankfurt region). Some sub-processors are located in the United States. For all US-based processors, we rely on EU Standard Contractual Clauses (“SCCs”) as the appropriate transfer mechanism pursuant to Art. 46(2)(c) GDPR.

A copy of the applicable SCCs is available on request at privacy@selge.app.

8. Your rights under GDPR

As a data subject under GDPR, you have the following rights. To exercise any of them, contact us at privacy@selge.app. We will respond within 30 days.

  • Right of access (Art. 15)Request a copy of the personal data we hold about you.
  • Right to rectification (Art. 16)Request correction of inaccurate or incomplete data.
  • Right to erasure (Art. 17)Request deletion of your personal data ("right to be forgotten"), subject to legal retention obligations.
  • Right to restriction (Art. 18)Request that we limit the processing of your data in certain circumstances.
  • Right to data portability (Art. 20)Receive your data in a structured, machine-readable format.
  • Right to object (Art. 21)Object to processing based on legitimate interests. We will cease processing unless we can demonstrate compelling legitimate grounds.

9. Right to complain to a supervisory authority

You have the right to lodge a complaint with a data protection supervisory authority (Art. 77 GDPR). You may contact the supervisory authority in your EU member state of residence or the authority responsible for our place of business:

[STATE_SUPERVISORY_AUTHORITY_NAME]

[AUTHORITY_ADDRESS]

[AUTHORITY_POSTAL_CODE] [AUTHORITY_CITY]

Website: [AUTHORITY_WEBSITE]

Replace with your state authority — e.g. BayLDA for Bavaria, HmbBfDI for Hamburg, BlnBDI for Berlin. Find your authority at: https://www.bfdi.bund.de/DE/Infothek/Anschriften_Links/anschriften_links-node.html

10. Cookies and tracking technologies

The Selge survey widget does not use cookies.

The widget uses sessionStorage only — a browser mechanism that stores data for the current browser tab session and is automatically cleared when the tab is closed. It cannot track visitors across sessions, across tabs, or across websites. No cookie consent banner is required on your website for the Selge widget.

The Selge dashboard application (selge.app) uses strictly necessary authentication session cookies to keep you logged in. These are exempt from cookie consent requirements under the ePrivacy Directive.

11. Changes to this privacy policy

We may update this policy from time to time. We will notify active customers of material changes by email at least 14 days before they take effect. The “Last updated” date at the top of this page always reflects the most recent version.

Continued use of the Service after the effective date constitutes acceptance of the updated policy.

12. Contact

For privacy-related enquiries, data subject rights requests, or to obtain a copy of our Standard Contractual Clauses:

[OPERATOR_FULL_NAME]

[OPERATOR_STREET_ADDRESS]

[POSTAL_CODE] [CITY], Germany

Email: privacy@selge.app

Free to build - pay only when you go live