Privacy Policy
Last updated: August 26, 2026
This Privacy Policy explains what personal data Queza ("we", "us") collects through the Service, why, and who we share it with.
1. Data we collect
Admin accounts: name and email address, and a hashed password, when you create an account or are invited to a workspace.
Event participants: participants ask questions and vote without creating an account. We assign an anonymous visitor identifier via a signed cookie, used only to prevent duplicate votes and to power aggregate event reports (distinct askers, distinct visitors) — never shown alongside individual questions or votes in any Admin view. If a participant chooses to attach their name to a question, that name is stored with the question.
Billing: workspace subscription and invoice records (plan, status, billing interval, amounts). Card details are entered directly with our payment providers and never touch our servers.
Technical data: IP addresses (used transiently for abuse/rate-limit protection, not stored long-term against an identity), and error/crash reports.
2. Third parties we share data with
- Paddle.com — our payment processor, acting as Merchant of Record for orders; it receives billing contact details and payment information necessary to process a subscription.
- Resend— sends transactional email on our behalf (workspace invites, password resets, payment-failure notices); receives the recipient's email address and name.
- Sentry— error monitoring; may receive technical details of an error (e.g. stack traces) if one occurs while you're using the Service.
- Google Analytics (Google LLC) — traffic and usage analytics on our marketing pages and, for signed-in Admins, the dashboard (not on public event pages); receives page views, whether you were signed in or not, and general technical/location data. Governed by Google's Privacy Policy.
- Railway Corporation — hosts the application and its database.
We do not sell personal data.
3. Cookies
We use a session cookie to keep Admins signed in, and a signed, anonymous visitor-id cookie on public event pages to prevent duplicate votes. We also use Google Analytics, which sets its own cookies to understand site traffic. None of these are used for advertising or cross-site tracking by us.
4. Data retention
We retain workspace and account data for as long as the workspace exists. After a workspace or account is deleted, we remove the underlying data within 30 days, except where we're required to keep records for longer — for example, billing and invoice records are kept for 7 years to meet our accounting and tax obligations.
5. Your rights
Depending on where you live, you may have rights to access, correct, export, restrict, or delete your personal data, and to object to how we process it. To exercise any of these rights, use our contact form. We'll respond within 30 days. If you're not satisfied with our response, you may also lodge a complaint with your local data protection authority.
6. Changes to this policy
We may update this Privacy Policy from time to time; material changes will be notified via the Service or by email.
7. Contact
Questions about this policy can be sent via our contact form.