Privacy Policy

Effective date: March 3, 2026 · Last updated: March 3, 2026

Thrilled LLC (“Thrilled,” “we,” “us,” or “our”) operates the getthrilled.io website and the Thrilled platform (the “Service”). This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you visit our website or use our Service.

1. Information We Collect

Account Information

When you create an account, we collect your name, email address, organization name, and password. If you subscribe to a paid plan, we collect billing information through our payment processor (Stripe); we do not store your full credit card number.

Survey Response Data

When your end users respond to surveys you create through the Service, we collect the data they submit, including NPS/CSAT/CES/PMF scores, free-text feedback, email addresses, and any custom properties you configure. You are the data controller for this information; we process it on your behalf.

Usage Data

We automatically collect standard server logs including IP addresses, browser type, pages visited, and timestamps. We use this data to operate, maintain, and improve the Service.

Cookies

We use only essential cookies required for authentication and session management. We do not use third-party advertising or tracking cookies.

2. How We Use Your Information

  • Provide, operate, and maintain the Service
  • Calculate NPS, CSAT, CES, and PMF scores and generate analytics dashboards
  • Send transactional emails (account verification, survey invitations, NPS alerts, stakeholder digests)
  • Process payments and manage subscriptions
  • Provide AI-powered features (theme tagging, executive digests) using anonymized or pseudonymized response data
  • Monitor for errors and improve Service reliability
  • Respond to support requests

3. Third-Party Service Providers

We share information with the following categories of service providers, solely to operate the Service:

  • Payment processing: Stripe (PCI-compliant payment processing)
  • Email delivery: Postmark (transactional email)
  • Cloud infrastructure: Amazon Web Services (hosting, database, file storage)
  • AI processing: Anthropic (theme analysis and digest generation — no personally identifiable information is sent)
  • Error monitoring: Sentry (application error tracking)
  • Logging: Better Stack (server log aggregation)

We do not sell, rent, or trade your personal information to any third party.

4. Data Retention

We retain your account data and survey response data for as long as your account is active. If you cancel your subscription, your data is retained for 30 days to allow reactivation, after which it is permanently deleted upon request. You may request deletion of your data at any time by contacting us at support@getthrilled.io.

5. Data Security

We implement industry-standard security measures to protect your data, including:

  • Encryption in transit (TLS/HTTPS) and at rest (AES-256 for database storage)
  • Secure password hashing (PBKDF2 with SHA-256)
  • HMAC-signed outgoing webhooks
  • Org-scoped data isolation (each organization can only access its own data)
  • Rate limiting on all public endpoints

6. Your Rights

All Users

You may access, update, or delete your account information at any time through your dashboard settings or by contacting us.

European Users (GDPR)

If you are in the European Economic Area, you have the right to access, rectify, erase, restrict processing of, and port your personal data. You also have the right to object to processing and to lodge a complaint with your local data protection authority. Our legal basis for processing is contract performance (to provide the Service) and legitimate interest (to improve the Service).

California Users (CCPA)

California residents have the right to know what personal information we collect, request deletion, and opt out of the sale of personal information. We do not sell personal information.

7. International Data Transfers

Your data is processed and stored in the United States (AWS us-east-1 region). By using the Service, you consent to the transfer of your data to the United States.

8. Children's Privacy

The Service is not directed to individuals under the age of 16. We do not knowingly collect personal information from children.

9. Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of material changes by email or by posting a notice on the Service. Your continued use of the Service after changes are posted constitutes acceptance of the updated policy.

10. Contact Us

If you have questions about this Privacy Policy, please contact us at:

Thrilled LLC
Email: support@getthrilled.io

← Back to home