Data Processing Addendum
Last updated: August 27, 2026
This addendum applies when you, as a creator, switch on the audience sign-up form in Supportify's polls feature. It covers how Supportify handles the contact information your audience gives you through that form, and nothing else. You accept it by enabling the form in your dashboard; it supplements the Terms of Service.
1. Roles: your list, our storage
The contact list collected through your sign-up form is yours. You decide why it is collected and what happens to it afterwards (you are the "controller", in privacy-law terms). Supportify stores and handles it only on your instructions (as your "processor").
Your instructions are the settings you configure in the dashboard: the consent wording shown to sign-ups, which contact fields are collected and whether they are required, the retention period, and your privacy contact. Changing those settings is changing your instructions.
2. What the list contains
- •Name, if your field settings collect it
- •Email address and/or phone number, per your field settings
- •The exact consent wording each person agreed to, and when they agreed
- •The person's confirmation that they are 18 or older, and when they gave it
3. What Supportify will not do with it
- •No use for any Supportify purpose: no analytics, no product research, no marketing, no profiling
- •No selling, renting, or sharing, except with the subprocessors below
- •No linking contact records to individual votes — the system is built so that “who voted for what” is not recorded against a contact and cannot be produced, for you or anyone else
- •No linking contact records to Supportify user or donor accounts, even where an email address matches
4. People under 18
The sign-up form is shown only after a person confirms they are 18 or older. Anyone who does not confirm can still vote, and no contact record is created for them. Supportify does not knowingly collect contact information from anyone under 18 through this feature.
5. Security
- •Stored encrypted at rest and transmitted encrypted in transit
- •Readable only through your authenticated dashboard export and by Supportify's operator for support and maintenance; there is no public read path
- •Treated as confidential
6. Subprocessors
Supportify uses the following providers to run the service:
- •Supabase (database hosting, on Amazon Web Services) — stores the contact list
- •Vercel (application hosting) — runs the application that collects and serves it
If a provider that handles the contact list is added or replaced, this page will be updated before the change takes effect.
7. Retention and deletion
You choose a retention period (1 to 365 days) when you enable the form. Contact records older than your window are deleted automatically, every day, by the system itself — whether or not the form is currently switched on. Switching collection off does not switch deletion off.
You can export the full list as a CSV from your dashboard at any time. The intended pattern: export what you need, and let the scheduled deletion remove the stored copy.
8. Requests from your audience
If someone asks Supportify to access, correct, or delete their contact record, Supportify will pass the request to your privacy contact and assist you in fulfilling it. If you ask Supportify to delete a specific person's record, it will be done promptly.
9. If something goes wrong
If Supportify becomes aware of a personal data breach affecting your contact list, it will notify your privacy contact without undue delay, and in any case within 72 hours of becoming aware, with what is known at that point.
10. Ending it
This addendum applies for as long as Supportify holds any of your contact list. If you stop using the feature or close your account, you can export first, and the stored list is deleted — by your retention schedule, or within 30 days of an explicit request, whichever comes sooner.
The consent wording shown to your sign-ups is your statement, supplied by you, and honouring it is your responsibility.