SurgedeckSign in

Privacy Policy

Last updated 29 July 2026

This page explains what Surgedeck collects and why. It is maintained by the Surgedeck team and describes our current practices.

Data we collect about you (our customer)

  • Account: email address, display name and password (stored hashed, never in plain text).
  • Billing: handled by our payment processor. We store your plan, status and renewal date. We never see or store your full card number.
  • Product data: the funnels, offers, templates, traffic sources and notes you create.
  • Integration credentials: API keys and OAuth tokens for the autoresponders you connect, stored so the app can sync on your behalf.

Data we process on your behalf (your leads)

When someone opts in through a funnel you run, Surgedeck records their email address, the click that brought them, the country reported by our CDN, and any sale attributed to them. You are the controller of that data; we process it to provide tracking and autoresponder syncing to you. You are responsible for having a lawful basis to collect it and for your own privacy notice on your pages.

Tracking and cookies

Click tracking uses a short-lived identifier in the redirect URL and a hashed visitor fingerprint to tell unique clicks from repeats. We do not run third-party advertising or cross-site tracking cookies on this app. Session cookies are used only to keep you signed in.

Who we share data with

  • Our hosting and database provider, to run the application.
  • Our payment processor, to take payment and handle tax and disputes.
  • The autoresponder and affiliate network services you choose to connect.
  • AI model providers, when you use the AI email or page tools — only the prompt content you submit.

We do not sell your data or your subscribers' data.

Retention and deletion

We keep your account data while your account is open, and for up to 30 days after you delete it so it can be restored on request. Billing records are kept longer where tax law requires. To export or delete your data, or to have a subscriber record removed, email support@surgedeck.app and we will action it within 30 days.

Security

Data is encrypted in transit. Database access is restricted per account by row-level access rules so one customer cannot read another's funnels, links or subscribers. Integration credentials are stored in the database and used only by server-side code.

Your rights

Depending on where you live you may have rights to access, correct, export or delete your personal data, and to object to processing. Contact support@surgedeck.app to exercise them.

Contact

support@surgedeck.app