Effective date: July 20, 2026
Submitto (“Submitto”, “we”, “us”) is operated by Submitto Software Inc., a company incorporated in British Columbia, Canada.
This policy explains what personal information we handle, why we handle it, who we share it with, where it goes, how long we keep it, and the rights and choices you have. We wrote it to be read. If anything is unclear, email us at hello@submitto.io.
One policy covers both of our websites:
A few words we capitalize throughout, because they have a specific meaning:
Our Terms of Service govern use of the service. Organizers subject to GDPR or UK GDPR can also rely on our Data Processing Addendum (DPA), available on request at hello@submitto.io. A short plain-language notice for Submitters appears on every public upload page.
Submitto plays two different legal roles depending on whose information is involved. This distinction shapes the whole policy:
We are the controller of Organizer, account, and site-visitor data. A “controller” is the business responsible for the data — the one that decides what to collect and why. For your account details, your billing records, our security logs, and analytics on the marketing site, that business is us. You deal with us directly about this data.
We are the processor (service provider) of Submitter data. When a Submitter uploads files or types their details into an Organizer’s form, the Organizer is the controller of that information and we are their processor: we handle it only to run their collection, on their instructions. The Organizer decides what their form asks for, who is invited, what emails go out, and who sees the results. We never use Submitter Content for our own marketing, advertising, or profiling, and we never sell it.
What this means if you are a Submitter: if you want your information accessed, corrected, or deleted, the fastest path is the Organizer who invited you — they control that data and have in-app tools to honour your request. You can also contact us at hello@submitto.io: we will pass your request to the Organizer, help them honour it, and honour any rights the law gives you against us directly.
A note for Organizers: you are responsible for having a lawful basis to collect what your form asks for and to email your Submitters. The Terms of Service and the DPA set out this split in detail, including a hard ban on using Submitto to collect certain high-risk categories of data (health or medical records, government-issued ID numbers, payment-card numbers, biometric data, and government-classified or export-controlled material).
The tables below are a complete plain-language inventory, split by these two roles.
| What | What it includes | Why we have it |
|---|---|---|
| Account details | Name, email address, company name, and your password (stored only as a one-way hash — we cannot see it) | Creating and securing your account |
| Consent record | Which version of the Terms and this policy you agreed to, and when | Proving what you agreed to |
| Two-factor authentication (MFA) | Your authenticator-app secret (encrypted at rest), enrolment date, and one-time recovery codes (stored only as hashes) | Optional extra sign-in security (required for our own staff admin accounts) |
| Sign-in records | Session records (we store only a fingerprint of the session cookie, never the cookie value), a short-lived MFA step record, password-reset and email-verification links (stored only as fingerprints), and a rough “last seen” timestamp | Keeping you signed in and letting you recover access |
| Co-manager list | The email addresses of up to 2 people an Organizer invites to co-manage an Event | Granting shared access to an Event |
| Purchase records | Paddle transaction ID, amount, currency, what was bought, and completion/refund timestamps — never card numbers or payment details (see §7) | Fulfilling and accounting for purchases |
| Voucher records | Admin-issued free-Event codes, including the email address the voucher was issued to | Granting and tracking complimentary Events |
| Feedback | Your message, the page you were on, your browser type, a snapshot of your email address, and — if you use the feedback button, in the app or on the read-only viewer — a screenshot of your current browser viewport, captured when you open it, whether or not you have an account | Investigating bugs and improving the product |
| Beta-program records | Applications from our beta period (name, email, company, message) and the related invitation lists | Historical record of beta access |
| What | What it includes | Why it exists |
|---|---|---|
| Roster entries | The details the Organizer’s form asks for — typically first name, last name, email address, and a title — plus any custom fields the Organizer adds (custom fields can include phone numbers, URLs, or anything else the Organizer chooses to ask) | Tracking who is expected to submit what |
| Uploaded files | The files themselves, the original filename you chose, and a renamed copy of the filename built from your form answers — filenames can therefore contain personal details such as your name or company | The core of the service: collecting files for the Organizer |
| File previews | For PDFs and images, a small preview image of the first page, generated by us with all hidden metadata stripped | Letting the Organizer preview files without opening them |
| Unmatched uploads | Uploads that didn’t perfectly match a roster entry, held (with the details you typed) for the Organizer to sort out | Making sure no submission is silently lost |
| Seat-meter records | One record per distinct person who has submitted to an Event, containing the submitted email address (or, where no email was given, the submitted name, title, and custom-field answers) | Billing integrity. Plainly: seats count people who have submitted; an Organizer removing someone from the roster does not free their seat. This is deliberate, to prevent seat-limit abuse |
| Email logs | For every email sent through an Event: the recipient address, subject, the full text of the message, and its delivery status | Showing the Organizer what was sent to whom, and proving it |
| File flags | Problem reports raised on the read-only viewer (a note, plus the reporter’s name and email if they choose to give them) | Letting AV techs and venues report file problems |
| In-progress uploads | A short-lived record of an upload that has started but not finished (removed by a daily cleanup, normally within a day, if abandoned) | Making direct-to-storage uploads safe |
Two points to note:
| What | What it includes | Why we have it |
|---|---|---|
| Audit log | A security ledger of important actions — sign-ins (including failed attempts, with whatever email address was typed), MFA steps, file downloads, co-manager changes, deletions, blocked infected uploads, and billing events — each with the IP address involved | Investigating security incidents and account misuse; this log deliberately survives account and Event deletion, and each entry is automatically deleted 24 months after creation (§9) |
| Rate-limit counters | Short-lived counters keyed to your IP address (and, for some sign-in protections, an email address), counting recent requests | Throttling abuse (login floods, spam submissions); deleted within a day or two of the window closing |
| Bot-challenge data | On signup, on sign-in after repeated failures, and on public upload pages, the Cloudflare Turnstile widget runs in your browser (Cloudflare sees browser signals), and we forward your IP address to Cloudflare to verify the challenge | Blocking bots without passwords or accounts |
| Error telemetry | When something breaks, technical error reports (stack traces and internal record IDs) go to Sentry, our error-monitoring provider. We have configured it not to receive IP addresses, cookies, or session data, and we use no session replay. One known exception: if recording an email bounce fails, the error report can include the affected recipient’s email address | Finding and fixing bugs |
| Email delivery events | Bounce and complaint notices from our email provider (recipient address + subject line) | Not re-mailing dead or hostile addresses |
| Suppression and opt-out lists | Email addresses that have bounced/complained (suppression) or clicked unsubscribe (opt-out) | Making sure “stop emailing me” keeps working — see §5 |
| Breached-password check | When you set a password, we check it against the Have I Been Pwned breach database using a privacy-preserving method: only the first 5 characters of a cryptographic fingerprint ever leave our server — never your password, never your identity | Blocking known-breached passwords |
The marketing site (submitto.io) has no forms and collects nothing directly — the only contact option is an email link that opens your own mail program, and its buttons link to the app. It runs two analytics tools:
Where GDPR or UK GDPR applies, the law requires us to name a legal basis for each purpose. In Canada, the same purposes are ones a reasonable person would consider appropriate, and rest on your express or implied consent; where consent is the basis, you can withdraw it (§14).
| Purpose | Information involved | Legal basis (GDPR/UK GDPR) |
|---|---|---|
| Running the service for Organizers: accounts, Events, dashboards, downloads | Account and Event data | Contract |
| Handling Submitter Content on an Organizer’s behalf | Submitter data (§3.2) | Processed on the Organizer’s documented instructions; the Organizer must hold its own lawful basis |
| Sending email: upload confirmations, invitations and reminders on an Organizer’s behalf, account notices | Names, email addresses, message content | Contract / the Organizer’s instructions; consent where required — the Organizer is responsible for consent to their commercial mail (§5) |
| Security: sign-in protection, bot challenges, rate limiting, audit logging, malware scanning, breached-password screening | Operational data (§3.3), files being scanned | Legitimate interests (keeping the service and the data in it safe) |
| Billing: seat metering, purchase and refund records, tax/financial records | Seat-meter records, purchase records | Contract; legitimate interests (billing integrity); legal obligation (tax and accounting records) |
| Fixing errors and improving reliability | Error telemetry, feedback (including screenshots) | Legitimate interests |
| Marketing-site analytics (submitto.io only) | GA4 / Vercel Analytics data (§3.4, §6) | Legitimate interests — see the cookie-consent note in §6 |
| Legal compliance: lawful requests, breach notification, record-keeping | As required | Legal obligation |
All email from Submitto — including invitations and reminders an Organizer composes — is sent from our own address (do-not-reply@submitto.io), on the Organizer’s behalf. It is visibly Submitto-branded, and it never comes from the Organizer’s own address.
Organizers, not Submitto, choose who receives their invitations and reminders. Under our Terms of Service, the Organizer warrants that they have the consent or other lawful basis required (for example under CASL, Canada’s anti-spam law) to email the people on their roster. We supply the identification footer and the unsubscribe machinery on every commercial message.
The app sets exactly two cookies, both first-party and both strictly necessary:
| Cookie | What it does | How long it lasts |
|---|---|---|
submitto_session | Keeps you signed in | 7 days — or 30 days if you tick “remember me” |
submitto_mfa | Carries the middle step of a two-factor sign-in | 10 minutes |
Both are httpOnly and secure (not readable by page scripts, sent only over HTTPS). The app sets no analytics, advertising, or tracking cookies of any kind.
Two embedded third-party tools may set their own cookies, under their own policies:
The site’s own code sets no cookies. Google Analytics 4, however, sets cookies when the site loads — in standard deployments _ga and a _ga_…cookie, lasting about two years per Google’s documentation. Vercel Web Analytics is described by Vercel as cookie-free.
There is currently no cookie-consent banner on the marketing site; GA4 cookies are set on the first page view.
We never sell personal information. We share it only in these ways:
We also use Have I Been Pwned’s breached-password service as described in §3.3; because only a partial fingerprint prefix is ever transmitted, no personal information reaches them.
We are a Canadian company. Our service providers process data primarily in the United States (malware scanning in particular runs on a US service — no Canadian region exists for it). Exact processing locations per provider are on the subprocessor list, available on request at hello@submitto.io. Wherever data is processed, this policy and our contracts follow it. While your information is in another jurisdiction, it is subject to the laws of that jurisdiction and may be accessible to its courts, law enforcement, and national-security authorities under those laws.
You can ask us for a copy of the safeguards that apply to a given transfer at hello@submitto.io.
The core of our retention story is the Event lifecycle, which is automatic:
Deletion runs on a daily schedule, so “30 days” means “at least 30 days, normally within a day or two after that.”
| Data | How long we keep it |
|---|---|
| An Event and its data (files, roster, email logs, seat-meter records, flags) | Until the Organizer deletes it, or automatically ~30 days after archiving (see above) |
| Email logs (full message copies, §3.2) | Message bodies are automatically removed 12 months after sending; the send record (recipient, subject, delivery status, time) stays until the Event is deleted |
| Audit log (security ledger with IP addresses) | Each entry is automatically deleted 24 months after it was created |
| Organizer account | Until you delete it — deletion is immediate (§10) |
| Purchase and voucher records | Retained as tax and financial records after account/Event deletion |
| Suppression and email opt-out lists | Kept indefinitely, by design — deleting them would restart unwanted email (§5) |
| Feedback (including screenshots) | No automatic deletion today; removed manually, or on request |
| Beta-program records | No automatic deletion; removed manually, or on request |
| Sign-in sessions | 7 days (30 with “remember me”); expired records purged daily |
| Password-reset links | 60 minutes |
| Email-verification links | 24 hours |
| Two-factor sign-in step | Valid for 10 minutes; the record is deleted when used, and expired records are purged daily |
| Rate-limit counters (IP addresses) | Deleted within a day or two of the counting window closing |
| Abandoned in-progress uploads | Removed by the daily cleanup once the abandoned upload is about an hour old — within about a day |
| Database backups | Deleted database records can persist in encrypted backups for up to 7 days, then roll off. Deleted file content is not in backups — file deletion from storage is immediate and unrecoverable |
The email-log and audit-log cleanups above are built and tested; their system switches are turned on in the same release that publishes this policy, so these numbers are true from day one.
When a file is deleted, the file itself — and any preview image we generated from it — is removed from storage immediately.
Organizers can delete an Event, an individual submission, an individual file, or their whole account at any time from inside the app. Account deletion is self-serve (under Account), requires your password, and takes effect immediately — there is no grace period or undo.
When you delete your account, we delete your account, your Events, and their files; Events you co-managed for someone else are not affected (they belong to their owner). Some records we must keep survive: billing records, audit and email logs, and unsubscribe/suppression lists. In plain terms:
Deleted database records can also persist in encrypted backups for up to 7 days (§9).
Submitters do not have accounts, so there is nothing for a Submitter to self-delete; deletion requests route to the Organizer (who has in-app tools to delete a person or a file), or to us, and we will assist (§2, §14).
A summary of our safeguards — no system is perfect, and we do not claim these are:
We do not currently hold formal security certifications (such as SOC 2 or ISO 27001), and we do not claim independent security audits.
You must be at least 18 years old to create an account, and Submitters must also be at least 18 to upload. Organizers are responsible for ensuring the people they invite meet this requirement. We do not knowingly collect personal information from anyone under 18; if we learn that we hold it, we will delete it.
We keep a register of security incidents. If a breach creates a real risk of significant harm, we notify affected individuals and the Office of the Privacy Commissioner of Canada as soon as feasible, as PIPEDA requires. Where GDPR/UK GDPR applies to data we control, we notify the competent supervisory authority within the required timeframe. For Submitter data we process on an Organizer’s behalf, we notify the affected Organizer without undue delay so they can meet their own obligations — this duty is also written into the DPA. In every case we will tell you what happened, what data was involved, and what we are doing about it.
Wherever you live, you can ask us to:
How: email hello@submitto.io. If you are a Submitter, the fastest path is the Organizer who invited you — but you are always welcome to come to us, and we will assist either way. We verify identity before acting on a request, respond within 30 days (one month where GDPR applies), explain any refusal and how to challenge it, and will never penalize you for exercising a right.
We comply with the federal Personal Information Protection and Electronic Documents Act (PIPEDA) and British Columbia’s Personal Information Protection Act (PIPA), including their fair-information principles. You may access and correct your personal information and complain to us using the contacts in §16. If you are not satisfied with our response, you may complain to the Office of the Privacy Commissioner of Canada (priv.gc.ca) or the Office of the Information and Privacy Commissioner for British Columbia (oipc.bc.ca).
If you are a Quebec resident, you additionally have the rights to withdraw consent, to request cessation of dissemination (de-indexing), and to data portability (a machine-readable copy you can take elsewhere), and you may complain to the Commission d’accès à l’information du Québec (cai.gouv.qc.ca). Confidentiality incidents presenting a risk of serious injury are reported to the CAI and to affected individuals. Our person in charge of the protection of personal information is identified in §16.
For Organizer, account, and site-visitor data, the controller is Submitto Software Inc. (§16). For Submitter data, the controller is your Organizer and we are their processor under our DPA. The legal bases for each purpose are in §4. We do no automated decision-making with legal or similarly significant effects.
You have the rights of access (a copy of your data), rectification (correction), erasure (deletion), restriction of processing (pausing use of your data), data portability (a machine-readable copy you can take elsewhere), and objection (telling us to stop a use) under Articles 15–21, the right to withdraw consent at any time without affecting prior processing, and the right to lodge a complaint with your supervisory authority — your local EU data-protection authority, or in the UK the Information Commissioner’s Office (ico.org.uk). If you complain to us directly, we will acknowledge your complaint within 30 days and tell you the outcome.
We have not appointed a Data Protection Officer.
We do not sell personal information or use it for targeted advertising, so there is nothing to opt out of under US state privacy laws; where such a law applies to you, we honour its access, correction, deletion, and appeal rights through the process in §14.1, and we act as a service provider/processor for Submitter data.
We will post changes here with an updated effective date. For material changes we will give Organizers advance notice — by email or a notice in the app — before they take effect. Signup records which version of this policy each account agreed to.
Submitto Software Inc.
Email: hello@submitto.io
Our Privacy Officer is accountable for our compliance with this policy and receives access requests and complaints at the address above.
Complaining to us first is welcome but never required. The regulators for each region are:
Related documents: Terms of Service · Refund Policy: app.submitto.io/refunds · Data Processing Addendum, Subprocessor list and Submitter notice: available on request at hello@submitto.io.