Privacy Policy
Last updated: November 3, 2025
Introduction
At BrightTally, we are committed to protecting your privacy and ensuring the security of your personal information. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our polling and survey platform.
Information We Collect
2.1 Personal Information
We collect personal information that you voluntarily provide to us:
- Account Information: Email address, name, and password (when you create an account)
- Profile Information: Display name, profile picture, and preferences
- Payment Information: Billing address, payment method details (processed securely through Stripe)
- Communication Data: Messages you send to our support team
- Poll Content: Questions, options, and responses you create
2.2 Automatically Collected Information
- Usage Data: How you interact with our platform, features used, time spent
- Device Information: IP address, browser type, operating system, device identifiers
- Location Data: General geographic location (country/region level)
- Cookies and Tracking: As described in our Cookie Policy
- Log Data: Server logs, error reports, and performance metrics
- Device Fingerprinting: Browser and device characteristics for fraud prevention (when enabled by poll creators)
2.3 Poll Response Data
- Anonymous Responses: Poll answers and votes (typically anonymous)
- Session Data: Temporary session identifiers to prevent duplicate voting
- Analytics Data: Response patterns, timing, and engagement metrics
- Custom Responses: Any "Other" text responses provided by voters
- Vote Integrity Data: Technical information used to prevent vote manipulation, including:
- Session identifiers tied to your browser session
- IP address records (retained for limited time periods to prevent blocking legitimate users)
- Device fingerprinting data (when poll creators enable device-based tracking)
- Time-based tracking to distinguish legitimate users from suspicious patterns
How We Use Your Information
3.1 Service Provision
- Create and manage your polls and surveys
- Process payments and manage subscriptions
- Provide customer support and respond to inquiries
- Maintain account security and prevent fraud
- Enable team collaboration features (for paid plans)
- Enforce voting limits and prevent vote manipulation through technical tracking methods
3.2 Platform Improvement
- Analyze usage patterns to improve our platform
- Develop new features and functionality
- Optimize performance and user experience
- Conduct research and analytics (using aggregated, anonymized data)
3.3 Communication
- Send important service updates and notifications
- Provide billing and subscription information
- Share product updates and new features (with consent)
- Send marketing communications (with opt-out option)
Information Sharing and Disclosure
4.1 We Do NOT Share Your Poll Data
Your poll data remains private and secure:
- We never sell your poll responses or personal data
- We don't use your poll data for advertising or marketing
- We don't share individual poll responses with third parties
- Only you (and authorized team members) can access your poll data
4.2 Limited Sharing Scenarios
We may share information only in these limited circumstances:
- Service Providers: Trusted third parties who help us operate our platform (hosting, payment processing, analytics)
- Legal Requirements: When required by law, court order, or to protect our rights and safety
- Business Transfers: In the event of a merger, acquisition, or sale of assets
- Consent: When you explicitly consent to sharing
- Emergency: To protect the safety of users or the public
Data Security
We implement comprehensive security measures to protect your information:
- Encryption: Data encrypted in transit (SSL/TLS) and at rest
- Access Controls: Strict access controls and authentication
- Regular Audits: Security assessments and vulnerability testing
- Infrastructure: Secure cloud hosting with enterprise-grade security
- Employee Training: Regular security training for all team members
- Incident Response: Rapid response procedures for any security incidents
Data Retention
5.1 Account Data
- Active Accounts: Data retained while your account is active
- Cancelled Accounts: Data retained for 30 days after cancellation for potential reinstatement
- Inactive Accounts: Free accounts may be deleted after 2 years of inactivity
- Legal Requirements: Some data may be retained longer for legal compliance
5.2 Poll Data
- Active Polls: Retained while polls are active or until you delete them
- Completed Polls: Retained according to your subscription plan limits
- Deleted Polls: Permanently deleted within 30 days of deletion
- Analytics Data: Aggregated, anonymized data may be retained longer
5.3 Vote Integrity Data
- Session Identifiers: Temporarily stored to enforce voting limits during the voting session
- IP Addresses: Retained only for 1 hour for vote integrity purposes, then automatically expunged
- Device Fingerprints: Retained only as long as the poll remains active (when device-based tracking is enabled)
- Historical Vote Records: Poll results data may be retained, but technical tracking data is minimized
Your Privacy Rights
6.1 General Rights
You have the following rights regarding your personal information:
- Access: Request a copy of your personal data
- Correction: Update or correct inaccurate information
- Deletion: Request deletion of your personal data
- Portability: Export your data in a machine-readable format
- Restriction: Limit how we process your data
- Objection: Object to certain types of data processing
6.2 Account Management
- Update your profile information in account settings
- Change your password and security settings
- Manage your subscription and billing preferences
- Control marketing communication preferences
- Delete your account and associated data
6.3 European Users (GDPR)
Additional rights under GDPR:
- Right to data portability
- Right to erasure ("right to be forgotten")
- Right to restrict processing
- Right to object to automated decision-making
- Right to lodge a complaint with supervisory authorities
International Data Transfers
BrightTally is based in the United States. If you are located outside the US, your information may be transferred to, stored, and processed in the United States. We ensure appropriate safeguards are in place for international transfers, including standard contractual clauses and adequacy decisions where applicable.
Children's Privacy
Our Service is not intended for children under 13:
- We do not knowingly collect personal information from children under 13
- If you are under 13, please do not use our Service
- If we learn we have collected information from a child under 13, we will delete it promptly
- Parents can contact us to request deletion of their child's information
Third-Party Services
We use trusted third-party services that have their own privacy policies:
- Stripe: Payment processing - see Stripe's Privacy Policy
- Google Analytics: Website analytics - see Google's Privacy Policy
- Hosting Providers: Secure cloud infrastructure
- Email Services: Transactional and marketing emails
Updates to This Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or other factors. We will notify you of any material changes by:
- Posting the updated policy on our website
- Sending email notifications to registered users
- Displaying prominent notices on our platform
- Updating the "Last Updated" date at the top of this policy
Contact Us
If you have any questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact us:
General Privacy Inquiries
Email: hello@brighttally.com
Support: support@brighttally.com
Data Protection
Email: hello@brighttally.com
This Privacy Policy was last updated on November 3, 2025. We recommend reviewing this policy periodically to stay informed about how we protect your information.