← Submitto

Terms of Service

Last updated July 20, 2026

Effective date: July 20, 2026

These Terms of Service (“Terms”) are a contract between you and Submitto Software Inc., a company incorporated in British Columbia, Canada (“Submitto”, “we”, “us”). They govern your use of the Submitto service at app.submitto.io.

By creating an account or using the service, you agree to these Terms. If you are using Submitto for an organization, you confirm you have authority to agree on its behalf, and “you” includes that organization.

These Terms incorporate by reference:

  • our Privacy Policy — /privacy
  • our Refund Policy — /refunds
  • our Data Processing Addendum (DPA), for Organizers subject to the GDPR or UK GDPR — available on request at hello@submitto.io
  • our Subprocessor list — available on request at hello@submitto.io

Together, these documents are the entire agreement between us (see Section 22).

1. Definitions

  • “Organizer” — the account holder; our customer. Organizers create Events and invite Submitters. (In the app itself, Organizers are called managers or owners.)
  • “Submitter” — a person who uploads files or information through an Organizer’s public link. Submitters do not create accounts and are not our customers.
  • “Event” — an Organizer’s collection workspace in the app (called an “event” in the product even when used for non-event file collection).
  • “Content” — the files and information Submitters or Organizers put into an Event.
  • “Activation” — the one-time purchase that unlocks collection on a single Event. Submitto is pay-per-event; there are no subscriptions.
  • “Co-managers” — up to 2 additional accounts an Organizer can grant manager access by email.
  • “Viewer links” — read-only share links to a sanitized view of an Event.

These Terms are an agreement between Submitto and the Organizer. Submitters are not party to these Terms, but anyone who uses the service — including through a public upload link or Viewer link — must follow the acceptable-use rules in Sections 8 and 9. A short plain-language notice for Submitters appears on every public upload page.

2. Who can use Submitto (18+ for everyone)

  • You must be at least 18 years old and able to form a binding contract to hold an account.
  • Submitters must also be at least 18 years old. Submitto may not be used to collect files or information from anyone under 18. You are responsible for making sure the people you invite or otherwise permit to submit meet this requirement.

3. Your account and its security

Setting up. You must give accurate information when you sign up and keep it current. You must verify your email address before you can create an Event.

Keeping it safe. You are responsible for everything done through your account. You agree to:

  • choose a strong password (the app requires at least 12 characters including a letter, a number, and a symbol, and screens new passwords against known data breaches);
  • keep your password and sign-in credentials confidential;
  • tell us promptly at hello@submitto.io if you suspect unauthorized access.

Optional two-factor authentication (MFA). You can turn on authenticator-app two-factor sign-in in your account settings, with one-time recovery codes. We recommend it. Changing your password signs you out of all other sessions, and you can also sign out everywhere else from your account page.

Account limits. Accounts are subject to fair-use limits on the number of Events and total storage.

4. Co-managers and Viewer links

4.1 Co-managers

  • You can grant manager access to up to 2 co-managers per Event, identified by their email address.
  • Co-managers can manage the Event as you can — viewing and downloading Content, emailing Submitters, and changing settings. Purchases for an Event (Activations, seat top-ups, and add-ons) must be made by the Event’s owner — see Section 5.1; vouchers can be applied only by the owner (Section 5.6).
  • Adding a co-manager notifies them by email. They need their own Submitto account with a verified email address to access the Event. Access follows the email address you enter — check it carefully.
  • You are responsible for your co-managers’ actions on your Events as if they were your own. You can remove a co-manager at any time.

4.2 Viewer links

  • Every Event has a read-only Viewer link you can share with people who need to see progress without managing anything (for example, an AV technician or venue staff). The view is sanitized: it hides Submitter email addresses, original filenames, and other personal details, showing display names and cleaned filenames only. Link holders can view the Event, download its files, and flag file problems.
  • Viewer links do not expire on their own. A Viewer link stays valid until you regenerate it; regenerating immediately and permanently invalidates the old link.
  • Anyone who has the link can use it. It is your responsibility to share Viewer links carefully — treat a Viewer link like a key, and regenerate it if you think it has leaked. Downloads through Viewer links are rate-limited and logged.

5. Paying for Submitto

5.1 Pay-per-event — no subscription

Submitto charges one-time fees only. There is no subscription and nothing recurring. You pay to activate an individual Event, and optionally for seat top-ups and feature add-ons on that Event. Current prices are the prices shown at checkout and on our pricing page. Checkout is offered in Canadian dollars (CAD), US dollars (USD), or euros (EUR); an Event’s first purchase sets that Event’s currency, and all later purchases for the same Event are made in it.

Purchases for an Event must be made by the Event’s owner: only purchases made from the owner’s account are fulfilled, and vouchers can be applied only by the owner (Section 5.6).

5.2 Activation

  • An Activation unlocks file collection on one Event. Until an Event is activated, you can build and configure it, but it cannot accept files: Submitters who open its link are told the event is not active yet.
  • Activation prices are tiered by the number of Submitters you expect (from “1–25” up to “251–500”, with additional seats beyond 500 sold in batches of 50). The tier or batch total you buy sets the Event’s seat allowance (Section 6); every purchase grants a stated, finite seat allowance.
  • The Activation price covers the forms your Event has at the time of purchase (if your Event has more than one form when you buy, the checkout price includes a charge for each form beyond the first). Adding more forms later requires an extra-form add-on (Section 5.5).

5.3 Paddle, our merchant of record

Purchases are processed by Paddle, our merchant of record — Paddle is the seller of the transaction, hosts the checkout, handles payment details (we never see card numbers), and calculates and remits applicable sales taxes. Paddle appears on your card statement and emails you the official receipt. In the app, we keep a read-only purchase history and can show a payment confirmation for each purchase (it is a confirmation, not a tax invoice — the invoice comes from Paddle).

5.4 Seat top-ups

  • If your Event needs more seats than its current tier allows, you buy a seat top-up to a larger tier. You pay only the difference between the larger tier’s price and what you have already paid for that Event (in the same currency).
  • Top-ups only go up: you can move to a larger tier, never a smaller one, and there is no credit or automatic refund for moving down. A legacy Event that already has no seat cap (from before finite tiers) cannot top up further. Top-ups are only available on an activated Event.

5.5 Feature add-ons

Two optional one-time add-ons are available per Event, at the prices shown at checkout:

  • Extra form — each purchase raises the number of forms your Event can have by one.
  • Multi-file-type — without it, each form has one upload box; with it, forms on that Event can have up to three upload boxes. It can be bought once per Event.

Add-ons can only be bought on an activated Event, and add-ons grant no seats.

5.6 Discounts and vouchers

  • We may offer promotional discounts (for example, a first-purchase discount). Eligibility is determined at checkout. A discount is applied at most once per account, and a later refund of the discounted purchase does not restore your eligibility.
  • We may issue vouchers that comp a single free Event Activation with a stated seat allowance. A voucher is tied to the recipient’s email address, can be applied only by the Event’s owner, is single-use, and may be revoked before it is used. Vouchers and comped Activations have no cash value; as $0 grants there is no payment to refund. Add-ons and seat top-ups are not included in a voucher: if you later add seats to a comped Event, you pay the full price of the larger tier.

6. Seats — how the meter works

A seat is counted for each individual person who submits to an Event, however identified (by their email address where given, otherwise their name and other identity fields). Sharing or reusing identity details so that multiple people count as one Submitter is gaming the seat meter (Section 8).

Plainly put:

  • One person, one seat. The same person can submit multiple times, or many files, and still uses one seat on that Event.
  • Seats count people who have submitted; removing someone does not free their seat. The seat count only goes up. This is deliberate anti-abuse protection: without it, a tier could be endlessly recycled by deleting Submitters and collecting from new ones on the same purchase.
  • Uploads that arrive without matching anyone on your roster (drop-box style submissions) also use seats.
  • Seats are counted per Event — the same person submitting to two of your Events uses one seat on each.
  • At the cap, collection stops. When an Event has used all its seats, new Submitters are blocked (their submission is refused in full — nothing is half-saved) until you buy a seat top-up. Existing Submitters’ files are unaffected. The app warns you as an Event approaches its cap.

By purchasing an Activation or top-up you accept this metering model, including that deleting a Submitter never frees a seat.

7. Refunds, and what a refund does

Our Refund Policy (posted at the link above) governs refunds and is part of these Terms. In summary — if anything below differs from the Refund Policy, the Refund Policy is what counts:

  • You may request a refund within 14 days of purchase; requests are reviewed and refunds are issued in accordance with Paddle’s Refund Policy. After 14 days — statutory rights aside — purchases are non-refundable, though we review later requests in good faith.
  • Vouchers and comped ($0) Activations involve no payment, so there is nothing to refund.
  • Approved refunds are processed by Paddle back to your original payment method.

The effect of a refund inside the app — this happens automatically and you should understand it before requesting one:

  • Refunding an Activation re-locks the Event: it immediately stops collecting new files. Files already collected are not automatically deleted; access normally continues until the Event’s normal deletion timeline (Section 11), though where a purchase is refunded or charged back we may limit continued access to Content collected under it.
  • Refunding a seat top-up lowers the Event’s seat allowance back to what the remaining purchases cover. Seats already used are never un-counted — if the Event has already used more seats than the lowered allowance, it simply stops accepting new Submitters.
  • Refunding a feature add-on removes what it granted for future use (for example, new forms or extra upload boxes can no longer be added). Content already created is not automatically deleted, but features beyond your remaining purchases may stop being provided.
  • A refund applies to the whole purchase: there is no partial or pro-rated treatment inside the app. Any refund on a purchase removes everything that purchase granted.
  • A refund is final in the app: a refunded purchase cannot re-activate on its own. If a refund or chargeback is later reversed, the Event is not automatically re-activated — contact us and we will restore it manually where appropriate.
  • A refund does not restore a used promotional discount (Section 5.6).

Chargebacks. A chargeback or other payment reversal is treated the same way as a refund, including re-locking the Event.

8. Acceptable use

Use Submitto only to collect files and information you are authorized to collect, and only for lawful purposes. You must not, and must not allow anyone acting for you to:

  • upload or solicit malware, infringing material, or any unlawful content, or content you have no right to collect or share;
  • collect the prohibited categories of data listed in Section 9;
  • use the email tools to send spam or messages the recipients have not agreed to receive (Section 10);
  • attempt to access other users’ data, probe or bypass security or rate limits, or disrupt or overload the service;
  • attempt to game the seat meter or any billing control;
  • misrepresent who you are or who you are collecting for.

How we enforce this:

  • Malware scanning. We scan uploads for malware. If a file is detected as malicious, the upload is rejected, the file is deleted from storage, and the attempt is logged. Scanning is best-effort, not a guarantee: very large files, periods of scanner unavailability, and volume limits can mean a file is stored unscanned. You should still treat downloaded files with normal caution.
  • Abuse review. We monitor abuse signals (for example, patterns that suggest seat-meter gaming, repeated infected-upload attempts, or unusual failed-login volumes) and a human reviews flagged accounts.
  • Action we may take. We may remove Content, close a form or Event, suspend or restrict an account, or terminate access for violations (Section 15). Where the law requires it, we may report unlawful content to authorities.

We also use standard protective measures such as bot challenges and rate limits on public endpoints; do not attempt to circumvent them.

9. Prohibited data — hard ban

You may not use Submitto to collect, ask for, or store:

  • health or medical records;
  • government-classified or export-controlled material;
  • payment-card numbers;
  • government-issued ID numbers (SIN, passport, driver’s licence);
  • biometric data.

This ban applies to what you ask Submitters for on your forms and to what you upload yourself. Submitto is not designed or offered as a compliant home for these data categories, and our DPA excludes them from the scope of processing. If prohibited data ends up in your Event, that is your responsibility (see the indemnity in Section 14): you must delete it promptly, and we may delete it and suspend the Event or your account.

10. Emailing your Submitters (anti-spam / CASL)

Submitto includes tools to email the people on your Event’s roster: invitations, scheduled reminders, targeted sends, individual messages, and automatic upload confirmations.

How the machinery works:

  • All mail is sent from Submitto’s own email address (currently do-not-reply@submitto.io) on your behalf, visibly branded as sent through Submitto. You cannot send from your own address through Submitto.
  • Every promotional or reminder email (“commercial” mail) automatically carries Submitto’s legal name and sender identification and a working unsubscribe link, including one-click unsubscribe support in major mail clients.
  • Unsubscribes are platform-wide and permanent. When a recipient unsubscribes, they stop receiving commercial mail from all Organizers and Events on Submitto, the choice is checked both when a send is queued and again at send time, and there is no re-subscribe or override — if you try to email someone who unsubscribed, the app refuses and tells you. This is a feature, not a limitation: it is how “stop emailing me” keeps working.
  • Suppression cannot be overridden. Addresses that hard-bounce or mark our mail as spam are suppressed platform-wide, and no Organizer can force mail to them.
  • Automatic upload confirmations are transactional (a receipt for the Submitter’s own action) and are not affected by unsubscribes, though they are still blocked for suppressed addresses. Confirmation templates are receipts and must not contain promotional content — they carry no unsubscribe link.
  • Test sends go only to your own address.

Your responsibilities. You warrant that, for every person you email through Submitto:

  • you have their consent, or another lawful basis under Canada’s anti-spam legislation (CASL) and any other law that applies to you or your recipients, for them to be emailed on your behalf;
  • their address was obtained lawfully;
  • the message content you write (templates, subjects, and message bodies are yours) is accurate, lawful, and not misleading.

We provide the identification, unsubscribe, and suppression machinery; the decision to email a particular person, and the basis for it, is yours.

11. Event lifecycle, retention, and deletion

The following retention schedule is part of these Terms. Plan around it — it ends in permanent deletion.

  • Event dates lock 5 days after creation. You can edit an Event’s start and end dates for 5 days after creating it; after that they are fixed (other details stay editable).
  • After the Event’s end date, it is automatically archived. An archived Event is hidden from your main list but all of its data is kept and it remains available under your archived Events. You can also archive an Event manually at any time.
  • 30 days after archiving — whether automatic or manual — the Event and all of its Content are permanently deleted. This includes the collected files and the Event’s data. Deletion is permanent and cannot be undone by you or by us.
  • We email a warning to your account email address about 3 days before deletion. The warning goes to the Event’s owner (not to co-managers).
  • Unarchiving stops the clock. If you unarchive an Event, the deletion countdown stops; if it is archived again later, a fresh 30-day countdown (with a fresh warning) begins.
  • Timing is approximate: lifecycle steps run on a daily maintenance job, so each step happens on or shortly after its scheduled day — never before the 30 days are up.

Download your files in time. You are responsible for downloading any files you want to keep before deletion. Files can be downloaded from your dashboard while the Event exists (including while it is archived, and including after a refund re-lock). Residual copies of deleted database records can persist in our backups for up to 7 days; deleted file bytes are not retained in backups.

You can also delete an Event, an individual Submitter’s entry, or an individual file yourself at any time; those deletions are likewise permanent.

12. Your Content, our service — ownership and licences

  • You and your Submitters own the Content. We claim no ownership of any files or information placed into an Event.
  • You grant us a limited, non-exclusive, worldwide, royalty-free licence to host, store, copy, scan (for malware), process, display, and transmit Content solely to operate and provide the service, to comply with law, and to enforce these Terms. This is a hosting licence, nothing more: we do not use your Content for advertising, and we do not sell it. The licence ends when the Content is deleted from the service, subject to the backup and retention timelines described in these Terms and the Privacy Policy.
  • You are responsible for the Content you collect. If you collect personal information from other people through Submitto, you are responsible for having a lawful basis to do so and for handling it appropriately. Our Privacy Policy explains our role; for Organizers subject to the GDPR or UK GDPR, the DPA (Section 13) governs our processing of Submitter personal data on your behalf.
  • Our service and IP. Submitto and its licensors own the service itself — the software, its design, and the Submitto branding. We grant you a limited, non-exclusive, non-transferable right to use the service in accordance with these Terms. You may not copy or modify the service, reverse engineer it (except to the extent the law lets you despite this clause), scrape it, or resell it or offer it to others as your own.
  • Feedback. If you send us feedback or suggestions, we may use them without restriction or obligation to you; this does not apply to your Content.

13. Privacy, data protection, and subprocessors

  • Our Privacy Policy (posted at the link above) explains what personal information we collect and how we handle it. In short, we act as the party responsible for your account data (the “controller” — the business responsible for the data), and as a service provider (“processor”) for the Submitter data you collect through your Events.
  • DPA. If you are subject to the EU GDPR or UK GDPR, our Data Processing Addendum, available on request at hello@submitto.io, is incorporated into these Terms and governs our processing of Submitter personal data on your behalf. If the DPA and these Terms conflict on personal-data processing, the DPA prevails.
  • Subprocessors. We use the service providers listed in our Subprocessor list, available on request at hello@submitto.io, to run the service (hosting, database, file storage, email delivery, payments, error monitoring, malware scanning).

14. Indemnity

You will defend and indemnify Submitto (that is, cover our losses, damages, and reasonable legal costs) against third-party claims and regulatory penalties arising from:

  • your Content, or the Content you solicit or receive from Submitters through your Events;
  • your breach of the prohibited-data ban in Section 9;
  • your breach of the email warranty in Section 10, including CASL complaints or enforcement about mail you initiated;
  • the actions of your co-managers or of people acting on your behalf;
  • your violation of these Terms or of applicable law.

We will notify you of any such claim and let you control the defence where reasonable, provided you do not settle in a way that admits our fault or imposes obligations on us without our consent.

15. Suspension and termination

By us. We may suspend or restrict your account or an Event, or remove Content, if we reasonably believe you have breached these Terms (including acceptable use, the prohibited-data ban, or the email rules), if your use creates risk for the service or other users, or if the law requires it. Where practicable we will notify you and give you a chance to fix the problem; for serious or urgent cases we may act first. We may terminate your account for material breach.

By you — self-serve account deletion. You can stop using Submitto at any time and delete your account yourself from your account page. Deletion requires your password, takes effect immediately, and is permanent:

  • we delete your account, your Events, and their files;
  • Events you co-manage but do not own are untouched;
  • some records we must keep survive (billing records, audit and email logs, unsubscribe/suppression lists); audit entries and stored email bodies age out automatically on the schedules in the Privacy Policy.

Before deleting your account, download any files you want to keep — there is no recovery afterwards. Deleting your account does not by itself create a refund entitlement; the Refund Policy governs refunds.

What survives. Sections that by their nature should survive termination do survive, including Content ownership and licence wind-down (Section 12), indemnity (Section 14), warranty disclaimer (Section 17), limitation of liability (Section 18), governing law (Section 21), and general terms (Section 22), along with any unpaid obligations.

16. Beta and preview features

We may offer features labelled beta, preview, early access, or similar. These are provided as-is for evaluation: they may change, break, or be withdrawn at any time, may be subject to extra limits, and are excluded from any commitments elsewhere in these Terms to the extent they conflict. Tell us about problems — that is what beta features are for.

17. Warranty disclaimer

The service is provided “as is” and “as available”, without warranties of any kind, whether express, implied, or statutory, including implied warranties of merchantability, fitness for a particular purpose, and non-infringement (the default guarantees the law would otherwise read in — that a service is of reasonable quality, fit for its purpose, and does not infringe others’ rights) — to the maximum extent the law allows.

Without limiting that:

  • we do not promise the service will be uninterrupted, error-free, or secure;
  • we do not promise that malware scanning will catch every malicious file (Section 8);
  • we may change, suspend, or discontinue features, with notice where the change is material to something you have paid for;
  • you are responsible for keeping your own copies of files you cannot afford to lose (Section 11).

Nothing in these Terms excludes warranties or rights that cannot be excluded by law.

18. Limitation of liability

To the maximum extent the law allows:

  • neither party is liable for indirect or consequential damages — including lost profits, lost revenue, lost data (beyond our retention commitments in Section 11), or loss of business — even if advised of the possibility;
  • our total liability for all claims under or relating to these Terms is capped at the greater of the amounts you paid (through Paddle) for the Event(s) giving rise to the claim in the 12 months before the claim arose, and CAD $100.

Nothing in these Terms limits liability that cannot be limited by law, including liability for fraud or wilful misconduct.

19. Availability and changes to the service

We work to keep Submitto available and improving, but we do not commit to a service-level agreement or uptime guarantee. We may perform maintenance, and we may add, change, or remove features. If we discontinue the service entirely or remove a capability that is material to an Event you have paid for and not yet finished collecting on, we will give reasonable notice and work with you on a fair resolution (see the Refund Policy).

20. Changes to these Terms

We may update these Terms from time to time. If we make material changes, we will give notice before they take effect — by email to your account email address, a notice in the app, or both — along with the new effective date. Your continued use of the service after the effective date means you accept the updated Terms. If you do not agree, stop using the service and delete your account before the changes take effect.

21. Governing law and disputes

These Terms are governed by the laws of British Columbia, Canada, and the federal laws of Canada that apply there, without regard to conflict-of-laws rules. The courts of British Columbia have exclusive jurisdiction over any dispute arising out of or relating to these Terms or the service, and each of us submits to that jurisdiction. These Terms do not require arbitration: disputes go to court.

Before starting a formal proceeding, please contact us at hello@submitto.io — most problems can be fixed faster informally.

22. General terms

  • Entire agreement. These Terms, together with the Privacy Policy, Refund Policy, DPA (where it applies), and Subprocessor list, are the entire agreement between you and Submitto about the service, and replace any earlier discussions or terms.
  • Order of precedence. If documents conflict: the DPA prevails on personal-data processing; the Refund Policy prevails on refund matters over the summary in Section 7; otherwise these Terms prevail.
  • Severability. If any part of these Terms is found unenforceable, the rest stays in effect, and the unenforceable part is replaced with an enforceable term that comes closest to the original intent.
  • No waiver. If we don’t enforce a provision, that is not a waiver — we can enforce it later.
  • Assignment. You may not assign or transfer these Terms without our written consent. We may assign them in connection with a merger, acquisition, or sale of assets, or to an affiliate, with notice to you.
  • Force majeure. Neither party is responsible for delay or failure caused by events beyond its reasonable control (for example, outages of underlying infrastructure providers, natural disasters, or government action), except for your payment obligations.
  • No third-party beneficiaries. These Terms are for you and us; they do not create rights for anyone else (Submitters’ privacy rights are addressed in the Privacy Policy and DPA, not through these Terms).
  • Notices. We send notices to your account email address; keep it current. You can send notices to us at the contact details below.

23. Contact

Submitto Software Inc.
Email: hello@submitto.io