Understand how we use and protect your data

We are transparent about the data we collect, we know it's personal, so we keep it safe.

Userpace obtains Personal Data about you from various sources to provide our Services and to manage our Sites. "You" may be a visitor to one of our websites, a user of one or more of our Services ("User" or "Userpace User"), or a customer of a User ("Customer").

If you are a Customer, Userpace will generally not collect your Personal Data directly from you.
We provide in-depth details in our Data Processor Privacy section.

Your Data

Personal Data that we collect about you.

Personal Data is any information that relates to an identified or identifiable individual. The Personal information we collect and provided to us directly through our services will always be (made) apparent from the context in which you provide the data. In particular:

  • Upon Signup
    When you register for a Userpace account we collect your full name, email address, and account log-in credentials.
  • Online Form
    When you fill-in our online form to contact our support or sales team, we collect your full name, work email, country, and anything else you tell us about your project, needs and timeline.
  • Emails and Survey
    When you respond to Userpace emails or surveys we collect your email address, name and any other information you choose to include in the body of your email or responses.
  • Phone Call
    If you contact us by phone, we will collect the phone number you use to call Userpace and may collect additional information in order to verify your identity.

If you are a Userpace User, as part of your business relationship with us, you may provide your organization contact and financial details, such as name, postal address, telephone number, and email address and tax number.

You may also choose to submit information to us via other methods, including:

  • General Communication
    in response to our marketing campaigns or other communications, online and offline.
  • Brand Communication
    when reacting on social media, online forums or review websites.
  • Special Offers
    through participation in an offer, program or promotion .
  • Commercial Inquiry
    in connection with an actual or potential business relationship with us
  • In-person meeting
    by giving us your business card or contact details at trade shows, meetup or other events

Information that we collect automatically on our Services.

Our Services use cookies, our own and other technologies to function effectively. This also to help us analyze your use of our services and diagnose technical issues. These technologies record information about your use of our services, including:

  • Browser and device data We collect technical details such as IP address, device type, operating system, browser name and version, screen resolution, device manufacturer and model, browser language and network provider;
  • Usage data We may track browsing history and navigation on our services using data collection such as time spent on the pages, pages visited, links clicked and the pages that led or referred you to our services.

For these purpose, we developed our own tracking technology to ensure none of your Personal Data leaves our systems. Within this scope, we make sure to send anonymised or limited information to other 3rd party services, indicated below.

Entity NameEntity TypeEntity Country
Google AnalyticsWeb AnalyticsUnited States
SessionStackWeb App Error Recording European Union
SentryError Tracking United States

How We Use Personal Data

Our products and services

We rely on numerous legal grounds to ensure that our use of your Personal Data is compliant with applicable laws. Our use of Personal Data is primarily dedicated to facilitate the business relationships we have with our Users, and to pursue and fulfil our legitimate business interests, as established in our Privacy Policy. When necessary, and requested, we also use Personal Data to comply with our regulatory and other legal obligations.

Marketing and events-related communications

We may send you email marketing communications about Userpace products and services, invite you to participate in our events or surveys, or otherwise communicate with you for marketing purposes, provided that we do so in accordance with the consent requirements that are imposed by applicable law. When we collect your business contact details through our participation at trade shows or other events, we may use the information to follow-up with you regarding an event, send you information that you have requested on our products and services and, with your permission, include you on our marketing information campaigns.

Interest-based advertising

You may see our ads on other websites or mobile apps because we participate in advertising networks. Ad networks allow us to target our messaging to users based on a range of factors, including demographic data, users’ inferred interests and browsing context (for example, the time and date of your visit to our Sites, the pages that you viewed, and the links that you clicked on). This technology also helps us track the effectiveness of our marketing efforts and understand if you have seen one of our advertisements.

We work with Google AdWords and other advertising networks. To learn how to opt out of behavioral advertising delivered by Network Advertising Initiative member companies, please visit the Network Advertising Initative. At the moment, there is no industry standard for recognizing Do Not Track browser signals, so we do not respond to them.

How We Disclose Personal Data

Userpace does not sell or rent Personal Data to marketers or unaffiliated third parties.
We only share your Personal Data with trusted entities, as outlined below.

Onvey (our Legal Entity, editing the Services)

We share Personal Data with other Onvey entities in order to provide our Services and for internal administration purposes.

Service providers

We share Personal Data with a limited number of our service providers. We have service providers that provide services on our behalf, such as identity verification services, website hosting, data analysis, information technology and related infrastructure, customer service, email delivery, and auditing services.

These service providers may need to access Personal Data to perform their services. We authorize such service providers to use or disclose the Personal Data only as necessary to perform services on our behalf or comply with legal requirements. We require such service providers to contractually commit to protect the security and confidentiality of Personal Data they process on our behalf. Our service providers are predominantly located in the European Union and the United States of America.

Entity NameEntity TypeEntity Country
MailjetEmail Service ProviderFrance, European Union
Google LLCHosting Service Provider European Union, United States
IntercomCustomer ServiceUnited States

Business partners

We share Personal Data with third party business partners when this is necessary to provide our Services to our Users. Examples of third parties to whom we may disclose Personal Data for this purpose are banks and payment method providers (such as credit card networks) when we provide payment processing services, and the professional services firms (ie: Lawyers, Accountants or Auditors) that we partner with to deliver Userpace.

Entity NameEntity TypeEntity Country
PayPal / BraintreePayment Provider European Union, United States

Our Users and third parties authorized by our Users

We share Personal Data with Users as necessary to maintain a User account and provide the Services. We share data with parties directly authorized by a User to receive Personal Data, such as when a User authorizes a third party application provider to access the User’s Userpace account using Userpace API or Integrations. The use of Personal Data by an authorized third party is subject to the third party’s privacy policy.

Corporate transactions

In the event that we enter into, or intend to enter into, a transaction that alters the structure of our business, such as a reorganization, merger, sale, joint venture, assignment, transfer, change of control, or other disposition of all or any portion of our business, assets or stock, we may share Personal Data with third parties for the purpose of facilitating and completing the transaction.

Compliance and harm prevention

We share Personal Data as we believe necessary: (i) to comply with applicable law, or payment method rules; (ii) to enforce our contractual rights; (iii) to protect the rights, privacy, safety and property of Userpace, you or others; and (iv) to respond to requests from courts, law enforcement agencies, regulatory agencies, and other public and government authorities, which may include authorities outside your country of residence.

Our Obligations


We make reasonable efforts to ensure a level of security appropriate to the risk associated with the processing of Personal Data. We maintain organizational, technical and administrative measures designed to protect Personal Data within our organization against unauthorized access, destruction, loss, alteration or misuse. Unfortunately, no data transmission or storage system can be guaranteed to be 100% secure.

If you have reason to believe that your interaction with us is no longer secure (for example, if you feel that the security of your account has been compromised), please contact us immediately.

Product Security Measures

  • 2-factor authentication (2FA)
    If you chose to signup using your Google or LinkedIn account, then you can and should turn on the 2-factor authentication (2FA).
  • Password and Credential Storage
    We enforce a password complexity standard and credentials are stored using a strong encryption protocol.
  • Uptime
    We have a 99% uptime or higher. You can check our services stats at https://userpace.doyoucheck.info/
  • Permissions
    We enable permission levels within the app to be set for your teammates. Permissions can be set to include app settings, billing and user data.

Network and Application Security Measures

  • Data Hosting and Storage
    Userpace services and data are hosted in Google Cloud Platform (GCP) facilities in the Europe, which encrypts all data at rest by default, in compliance with the Privacy Rule within HIPAA Title II.
  • Private Cloud
    All of our servers are within our own virtual private cloud (VPC) with network access control lists (ACLs) that prevent unauthorized requests getting to our internal network.
  • Back-ups
    All our systems are automatically backed-up at least daily, using Google's solutions which guarantee the data integrity and their restoration procedures.
  • Monitoring
    We implemented various internal and external monitoring solutions, for continuous testing, troubleshooting and activity logs management (generation, audit, archive).
  • Encryption

    Userpace is served 100% over https.

    All data sent to or from Userpace is encrypted in transit using 256 bit encryption.

    Our Applications and APIs endpoints are TLS/SSL only and score an “A+" rating on Qualys SSL Labs‘ tests. This means we only use strong cipher suites and have features such as HSTS fully enabled.

Other Security Measures

  • Employee Access, Permissions and Authentication

    Your Personal Data is only accessible to a limited number of personnel who need access to the information to perform their duties.

    Userpace runs a zero-trust corporate network. There are no corporate resources or additional privileges from being on Userpace's network.

    We have Single Sign-on (SSO), 2-factor authentication (2FA) and strong password policies on GitHub, Google Services, Intercom and other Cloud Services to ensure protected access.

  • Employee Confidentiality
    All employee contracts include a confidentiality agreement.
  • Employee Policies
    Userpace has developed a comprehensive set of security policies covering a range of topics. These policies are updated frequently and shared with all employees.
  • Office Security
    While no Personal Data should be made accessible offline, on hard-copies, or on employees devices, we relly on additional preventive security measures regarding our Offices and personnel access. Our building offers 24/7 guard and video surveillance, and only our employees with a personal access cards can access the office.

Data Retention

If you are a Userpace User, we retain your Personal Data as long as we are providing the Services to you. We retain Personal Data after we cease providing Services to you, even if you close your Userpace account, to the extent necessary to comply with our legal and regulatory obligations, and for the purpose of fraud monitoring, detection and prevention. We also retain Personal Data to comply with our tax, accounting, and financial reporting obligations, where we are required to retain the data by our contractual commitments to our financial partners, and where data retention is mandated by the payment methods that we support. Where we retain data, we do so in accordance with any limitation periods and records retention obligations that are imposed by applicable law.

International Data Transfers

We are a global business. Personal Data may be stored and processed in any country where we have operations or where we engage service providers. We may transfer Personal Data that we maintain about you to recipients in countries other than the country in which the Personal Data was originally collected, including to the United States. Those countries may have data protection rules that are different from those of your country. However, we will take measures to ensure that any such transfers comply with applicable data protection laws and that your Personal Data remains protected to the standards described in this Privacy Policy. In certain circumstances, courts, law enforcement agencies, regulatory agencies or security authorities in those other countries may be entitled to access your Personal Data.

If you are located in the European Economic Area ("EEA") or Switzerland, we self-comply with applicable laws to provide an adequate level of data protection for the transfer of your Personal Data to the US.

Your Rights

You have choices regarding our use and disclosure of your Personal Data

1. Opting out of receiving electronic communications from us. If you no longer want to receive marketing-related emails from us, you may opt-out via the unsubscribe link included in such emails. We will try to comply with your request(s) as soon as reasonably practicable. Please note that if you opt-out of receiving marketing-related emails from us, we may still send you important administrative messages that are required to provide you with our Services.

2. How you can see or change your account Personal Data. If You would like to review, correct, or update Personal Data that You have previously disclosed to us, You may do so by signing in to your Userpace account or by contacting us.

3. Your data protection rights. Depending on your location and subject to applicable law, you may have the following rights with regard to the Personal Data we control about you:

  • Right to Withdraw ConsentWhere the processing of your Personal Data is based on your previously given consent, you have the right to withdraw your consent at any time.
  • Exercise of the Rights of the Data SubjectAs described in this page;
  • Right to Be InformedThe right to request confirmation of whether Userpace processes Personal Data relating to you.
  • Right to AccessThe right to request a copy of that Personal Data;
  • Right to RectificationThe right to request that Userpace rectifies or updates your Personal Data that is inaccurate, incomplete or outdated;
  • Right to Erasure ("Right to be Forgotten")The right to request that Userpace erase your Personal Data in certain circumstances provided by law;
  • Right to Restriction of ProcessingThe right to request that Userpace restrict the use of your Personal Data in certain circumstances, such as while Userpace considers another request that you have submitted (including a request that Userpace make an update to your Personal Data); and
  • Right to Data PortabilityThe right to request that we export to another company, where technically feasible, your Personal Data that we hold in order to provide Services to you.
  • Right to Object to ProcessingYou may also have the right to object to the processing of your Personal Data on grounds relating to your particular situation.
  • Right to Object to Automated Individual Decision MakingThe right not to be subject to a decision based solely on automated processing, including profiling, which produces legal effects concerning him or her or similarly significantly affects him or her.

4. Process for exercising data protection rights. In order to exercise your data protection rights, you may contact Userpace as described in the Contact Us section below. We take each request seriously. We will comply with your request to the extent required by applicable law. We will not be able to respond to a request if we no longer hold your Personal Data. If you feel that you have not received a satisfactory response from us, you may consult with the data protection authority in your country.

Do you have a question about your Personal Data Privacy?


For your protection, we may need to verify your identity before responding to your request, such as verifying that the email address from which you send the request matches your email address that we have on file. If we no longer need to process Personal Data about you in order to provide our Services or our Sites, we will not maintain, acquire or process additional information in order to identify you for the purpose of responding to your request.