1
Who we are
SurveyMarkup is operated by Tim Albash, sole trader, ABN 50 427 523 590. SurveyMarkup is an Australian survey-assistance product and is responsible for personal information handled through this site. For the operator's legal identity or any privacy question, contact tim@surveymarkup.com.au.
2
Overview
The current public beta uses fictional examples only. Server-side customer-file intake and browser selection of real survey files are disabled. Contact details are handled when you submit an enquiry form or choose to send us an email, while demonstration state may be stored locally in your browser where applicable.
3
Information you provide
We may receive information you choose to submit in a contact, services or portfolio enquiry, an account access request, or an email or support message. Do not attach, paste or send a client file during the synthetic public beta.
4
Contact, services and portfolio enquiries
If you use a contact, services or portfolio enquiry form, we collect the name, work email, firm or organisation (optional), topic where shown, and message you provide. We store these details to respond directly to your enquiry — not for a marketing list. The five named UTM campaign tags may also be stored so we can understand which outreach link produced it. Advertising identifiers and unknown query parameters are ignored. Transactional email notices are best-effort and only use the details needed for that enquiry. You can ask us to delete your enquiry details at any time by emailing tim@surveymarkup.com.au.
5
Browser storage
The Map Linework may use browser storage such as IndexedDB to save workspaces, settings or export history locally. To make interrupted writes duplicate-safe, enquiry forms and protected administrator receipt or invitation actions may keep an opaque action ID and a pending, confirmed or unconfirmed-outcome marker in per-tab session storage. A SHA-256 digest of the submitted fields or protected action is kept only when browser hashing is available. These records never store the submitted name, email, firm, message, receipt details or invitation details; they end with that tab session. If per-tab storage is unavailable, the affected write fails closed before sending.
6
Customer-file intake status
Real customer-file intake is disabled during the synthetic public beta. Public demonstrations use bundled fictional content and do not need a client file.
7
Where information is stored
The site and account services run on SurveyMarkup's configured German hosting. Browser-local demonstration data, such as Map Linework workspace state, stays on your device until you clear it. The dormant S3-compatible upload/object-storage path is not available in the synthetic public beta and must be documented again before real-file use is enabled.
8
Third-party services and AI
Map Linework loads CARTO and OpenStreetMap map resources directly in your browser by default. If you select Esri satellite imagery, your browser connects directly to Esri. Those providers receive standard network data such as your IP address plus viewport, zoom and tile requests; they do not receive customer-file content or drawn feature attributes from SurveyMarkup. Optional Google map/search paths remain separately configured. Paid AI is off in the current public release. If Tim later enables it, provider calls run only from the backend through OpenAI's stateless Responses API with bounded findings and metadata; raw client files and complete coordinate datasets are excluded.
9
Payments (when enabled)
No public payment, support-payment or subscription offer is active in the synthetic public beta. Stripe remains an inactive, code-supported processor and receives no checkout data from this public workflow. This policy and the public offer must be updated before any payment path is activated.
10
Cookies and analytics
SurveyMarkup uses session cookies where required for access. Usage analytics are first-party, cookieless and pseudonymous: our server records individual allowlisted event names, a public route identifier, allowlisted coarse properties, a random per-tab session identifier and the server timestamp. It does not accept raw or private paths, query strings, account identifiers, email addresses, file names, file contents or coordinates. No analytics data is shared with a third-party analytics processor, and no advertising trackers are active during public beta.
11
Error diagnostics
Sentry error diagnostics are used only when a deployment has a configured Sentry project. Error reports contain technical context only — browser or server details, app version, and a stack trace — and are scrubbed of file names, file contents, and survey data before they are sent. They never include your uploaded files. Hosting and residency follow the selected Sentry project and must be confirmed for the active deployment; no EU-residency promise is implied by the code alone.
12
Email, sign-in and SMS providers (when enabled)
A configured SMTP provider receives the recipient address, name and transactional message needed for account, pilot, enquiry or payment notices. Optional Google or Microsoft OAuth sign-in sends the standard authorisation request and receives the email identity needed to match an invited account; it never creates an uninvited account. Optional Twilio Verify receives the phone number and delivery metadata needed for SMS account authentication. Each provider's terms and processing region apply only when that feature is enabled.
13
Your rights
You can request access to, or correction of, the personal information we hold about you, and you can ask us to delete it. To exercise these rights or raise a concern, contact tim@surveymarkup.com.au. If you are not satisfied with our response, you can complain to the Office of the Australian Information Commissioner (OAIC).
14
Data responsibility
Do not email, attach, paste or attempt to submit a client file during the synthetic public beta. Use the fictional worked example and bundled demonstrations only.
15
Data retention and deletion
Active customer content remains available until its owner deletes the project or account. Deletion revokes signed-in access immediately and queues active database records, uploads, outputs, project storage, exports and legacy AI artifacts for purge within 24 hours. Encrypted backup copies expire within 30 days. Operational logs have a 30-day maximum only after the host time-retention control is active; real-file intake stays disabled if that control is not active. Security audit records are kept for 12 months and closed enquiries for 12 months. Payment and accounting records are retained separately for at least five years and then reviewed against continuing legal obligations. Browser-local data stays on your device until you clear it. These periods follow required record-keeping obligations and the OAIC principle of destroying or de-identifying personal information when it is no longer needed. See the OAIC APP 11 guidance and ATO record-keeping guidance. You can also contact tim@surveymarkup.com.au.
16
Third-party tools
SurveyMarkup uses self-hosted fonts (Space Grotesk, IBM Plex) and open-source libraries disclosed in the Third-party notices page. No third-party analytics or advertising trackers are active during public beta.
17
Contact
For privacy questions, contact tim@surveymarkup.com.au.