SurveyNow Privacy Policy
Effective Date: 28 December 2025 Last Updated: 05 January 2026
1. Introduction
SurveyNow (hereinafter referred to as “SurveyNow”, “we”, “us”, or “our”) is committed to protecting the privacy and security of your personal information. This Privacy Policy (the “Policy”) describes how we collect, use, disclose, store, transfer, and protect personal information obtained through your access to or use of the SurveyNow website, mobile applications, software platforms, and any related products or services (collectively, the “Service”).
SurveyNow is headquartered in the Republic of South Africa and processes personal information in accordance with the Protection of Personal Information Act, 2013 (Act No. 4 of 2013) (“POPIA”), as well as other applicable data protection laws and regulations in jurisdictions where our users reside. Where SurveyNow determines the purposes and means of processing, we act as the “Responsible Party” under POPIA or the equivalent data controller under other frameworks.
By accessing, registering for, or using the Service, you expressly consent to the collection, use, disclosure, and processing of your personal information as described in this Policy. If you do not agree with this Policy, you must immediately cease using the Service.
We may amend this Policy from time to time. Material changes will be notified by posting the revised Policy on the Service, updating the “Last Updated” date, and, where required by law, obtaining your consent or providing an opt-out mechanism. Your continued use of the Service following such changes constitutes your acceptance of the revised Policy.
2. Definitions
For the purposes of this Policy:
- Personal Information means any information relating to an identified or identifiable natural person, including but not limited to name, email address, telephone number, date of birth, gender, demographic details, survey responses, IP address, device identifiers, location data, and any other data that can directly or indirectly identify you.
- Special Categories of Personal Information means information revealing racial or ethnic origin, political opinions, religious or philosophical beliefs, trade union membership, genetic data, biometric data, health data, or data concerning sex life or sexual orientation.
- Anonymized Data means information that has been irreversibly de-identified such that it no longer constitutes personal information under applicable law.
- Aggregated Data means statistical or summarized information derived from personal information that does not identify any individual.
- Processing means any operation performed on personal information, including collection, recording, organization, storage, adaptation, disclosure, or deletion.
3. Information We Collect
We collect personal information in the following ways:
3.1 Information You Provide Directly
- Account Registration: Full name, email address, password, date of birth, gender, postal address, telephone number, and payment details (where applicable for reward redemption).
- Profile Information: Detailed demographic, lifestyle, household, employment, and preference data used for survey eligibility matching.
- Survey and Pulse Participation: Responses to surveys, polls, engagement tasks, and user-generated content.
- Communications: Inquiries, feedback, support requests, and contest entries.
3.2 Information Collected Automatically
- Technical and Usage Data: IP address, device identifiers (e.g., MAC address, advertising ID), browser type, operating system, geolocation (approximate via IP or precise with consent), referral URLs, pages viewed, time stamps, and interaction patterns.
- Cookies and Similar Technologies: Essential cookies, analytics cookies, performance cookies, and targeted advertising cookies/pixels (subject to consent where required).
3.3 Information from Third Parties
- Verification and fraud prevention providers (identity, device, and location confirmation).
- Third-party survey partners (eligibility and completion data).
- Analytics and advertising partners (aggregated performance metrics).
We adhere to data minimization principles, collecting only information adequate, relevant, and necessary for the purposes outlined below.
4. Purposes and Legal Bases for Processing
We process personal information for the following purposes and on the following legal bases:
| Purpose | Legal Basis |
|---|---|
| Providing and managing the Service (account creation, survey matching, reward issuance, Pulse features) | Performance of contract; legitimate interests |
| Quality assurance, fraud detection, and eligibility verification | Legitimate interests; legal obligation |
| Communicating service updates, support responses, and notifications | Performance of contract; legitimate interests |
| Analyzing usage and improving the Service | Legitimate interests |
| Conducting market research and generating insights | Legitimate interests; consent (where responses contain special categories) |
| Creating and sharing anonymized/aggregated data for research and advertising purposes | Legitimate interests (anonymized data falls outside personal information scope) |
| Sending promotional communications | Consent (opt-in); legitimate interests (existing users, soft opt-out) |
| Complying with legal obligations, enforcing Terms, protecting rights/safety | Legal obligation; legitimate interests |
Special categories of personal information are processed only with your explicit consent or where permitted by law.
5. Disclosure and Sharing of Personal Information
We do not sell personal information to third parties for their independent direct marketing purposes. We disclose personal information only in limited circumstances:
- Survey Sponsors and Research Clients: Pseudonymized profile data and survey responses for eligibility determination, quality control, and market research insights in SurveyNow-managed surveys.
- Third-Party Survey Providers: Full responses and relevant profile data, governed by their respective privacy policies.
- Service Providers and Operators: Hosting providers, analytics platforms, fraud detection services, payment processors, and verification partners—bound by data processing agreements ensuring equivalent protection.
- Anonymized and Aggregated Data: Shared or sold to market research agencies, advertisers, and business partners for trend analysis, audience segmentation, and advertising optimization (irreversibly de-identified).
- Corporate Transactions: In connection with mergers, acquisitions, or asset sales.
- Legal and Safety Reasons: To comply with court orders, laws, or regulations; enforce our Terms of Service; or protect rights, property, or safety.
6. International Data Transfers
Personal information may be transferred to and processed in countries outside South Africa, including jurisdictions that may not provide equivalent data protection. We implement appropriate safeguards, such as standard contractual clauses, binding corporate rules, or adequacy decisions, in compliance with POPIA Chapter 9 and other applicable laws.
7. Cookies and Tracking Technologies
We use cookies, web beacons, pixels, and similar technologies to operate the Service, analyze trends, and deliver personalized content/advertising. Essential technologies are always active; non-essential (analytics/advertising) require your consent via our cookie management banner.
You may manage preferences through our cookie settings tool or your browser. Blocking non-essential technologies may impair functionality.
8. Data Security
We maintain reasonable and appropriate technical and organizational measures—including encryption, access controls, regular security assessments, and employee training—to protect personal information against unauthorized access, alteration, disclosure, or destruction. While we strive for robust security, no method of transmission or storage is completely secure.
In the event of a personal information breach posing high risk, we will notify affected users and relevant authorities without undue delay, as required by law.
9. Data Retention
Personal information is retained only for as long as necessary to fulfill the purposes for which it was collected, to provide the Service, or to comply with legal obligations. Typical retention periods include:
- Active account data: Duration of account activity + 2 years.
- Survey responses: Up to 5 years for research validation.
- Anonymized/aggregated data: Indefinitely.
- Inactive accounts: Data may be deleted after 24 months of inactivity.
Upon expiry, data is securely deleted or anonymized.
10. Your Rights and Choices
Depending on your jurisdiction, you may have the following rights regarding your personal information:
- Access, rectification, or erasure.
- Restriction or objection to processing.
- Data portability.
- Withdrawal of consent (without affecting prior lawful processing).
- Opt-out of direct marketing (immediate effect).
To exercise rights, contact [email protected]. We will respond within 30 days (extendable once by 60 days for complex requests) after verifying your identity. Requests are free unless manifestly unfounded or excessive.
South African residents may lodge complaints with the Information Regulator: https://inforegulator.org.za/
11. Children’s Privacy
The Service is strictly for individuals aged 18 or older (or the age of majority in your jurisdiction). We do not knowingly collect or process personal information from children under 18. If we become aware of such collection, we will promptly delete the information.
12. Third-Party Websites and Services
The Service may contain links to or integrations with third-party websites, surveys, or services. We are not responsible for their privacy practices. We encourage you to review their policies before providing information.
13. Contact Information and Information Officer
For questions, requests, or complaints:
Email: [email protected] Website: https://surveynow.com
Information Officer (POPIA Responsible Party contact):
Email: [email protected]
This Policy forms part of and should be read together with our Terms of Service available at https://surveynow.com/terms-of-service/. In the event of conflict, the provisions most protective of personal information shall prevail.