At a glance
The whole policy in one table — what we handle, why, and what never happens to it. The sections below give the full detail.
| Data | Why we process it | Sold or used for ads? | Kept until |
|---|---|---|---|
| Survey answers & uploaded files | Delivering results to the team that asked | Never | The programme ends or you ask for deletion |
| Contact details a survey asks for | Follow-up about that survey only — no marketing | Never | Same as the answers they came with |
| Staff account data | Sign-in, roles and the audit trail | Never | The account is deleted |
| Technical signals on submit (IP, browser) | Bot protection and duplicate control | Never | Shortly after verification |
| Dashboard page views (staff only) | Improving the product — nothing else | Never | Aggregated; not tied to you over time |
What we collect
Depending on how you use the platform, we process:
- Survey responses — the answers you choose to submit, including any files a survey asks you to upload.
- Bot-protection signals — survey submissions are protected by Cloudflare Turnstile, which runs invisibly (there is nothing to click and no puzzle to solve) and processes technical signals such as your IP address, TLS fingerprint and browser user-agent to tell humans and bots apart. This processing is described in the Cloudflare Turnstile Privacy Addendum linked below. It sets no advertising cookies.
- Duplicate-response control — for surveys limited to one response per person, we store a technical identifier so the same person can't submit twice.
- Contact details — when a survey asks for your name, email address or phone number, those answers are also saved to a contact list, alongside which survey you answered and when, so the team running that program can reach you about it.
- Staff account data — name, email, sign-in credentials (passwords are stored hashed, never in plain text), optional passkeys, and an audit log of administrative actions.
- Emails — we send staff verification codes, sign-in links and invitations through Resend, our email delivery provider.
How we use your contact details
Your name, email address and phone number are used only to contact you about the survey you answered and the program it belongs to — for example to follow up on your response, confirm a place, or share a result you asked for.
They are not used for marketing. We do not send promotional messages, we do not add you to a mailing list, and we do not sell, rent, share or otherwise pass your contact details to anyone outside Jawab for their own use.
Only team members who need them can see these details, and every export of them is recorded in our audit log. You can ask us to remove your contact details at any time, whether or not you keep your survey response.
What we don't do
We do not sell or rent your data, we do not run ads, and we use no advertising trackers anywhere on the platform. Public survey pages carry no analytics at all — if you are answering a survey, nothing on that page measures you.
Usage analytics in the dashboard
Within the signed-in dashboard we measure page views in order to understand how the product is used and to improve it. This is the only purpose: it is never used for advertising, never used to build a profile of an individual, and never used to follow anyone across other websites.
What is measured is the page address visited, an approximate region derived from the network address, and the type of browser and device. Survey responses, contact details, uploaded files and anything else a workspace stores are never included and never leave Oman.
Vercel Web Analytics performs this measurement and stores no identifier on your device. PostHog performs it in more detail and does set a cookie, and because it links what it records to the account, your name and email address are held with it. Where the operator has enabled it, Google Analytics is used in addition and also sets a cookie. All three are limited to the dashboard and the sign-in pages; none of them runs on a public survey.
Where your data lives
Survey responses and account data are stored in our managed database. Files you upload are stored in our object storage. These providers process data on our behalf under their own security and privacy commitments.
Dashboard usage analytics are processed by Vercel, by PostHog in the European Union, and — where enabled — by Google. That processing covers the activity of signed-in account holders only. One event is raised when a survey receives a response: it records which workspace and when, and carries no answers, no identifier for the person who answered, and no network address. No survey response, contact detail or uploaded file is ever sent to any of them.
Cookies
A public survey page sets no cookies at all. In the signed-in dashboard we use strictly necessary cookies — a session cookie that keeps staff signed in, a cookie that remembers your language choice, and device preferences such as reduced motion — plus PostHog's measurement cookie and, where the operator has enabled Google Analytics, its measurement cookie. There are no advertising or cross-site tracking cookies anywhere.
Retention and your rights
Responses and contact details are kept for as long as the related program needs them, then removed. You can ask us to show you, correct, or delete the responses you submitted — and the contact details saved with them — at any time. Deleting a response deletes the contact entry it created.
Security
Data is encrypted in transit (HTTPS), staff access is role-based, and administrative actions are recorded in an audit log.
Changes to this policy
If this policy changes, the "last updated" date on this page changes with it. Significant changes will be highlighted on the surveys affected by them.
Contact
If you have any questions about this page, contact the Jawab team through our official channels, or reach out to the person or programme that shared the survey with you.