Privacy Policy
Last updated: September 10, 2026
This policy explains what the company operating soFunnels ("soFunnels", "we", "us") does with personal data. It covers two different things, and the difference matters: the data we hold about you, our customer, and the data you collect from your own visitors and buyers using our software. For the first we are the controller. For the second you are the controller and we are only your processor.
1. Two roles, and which one applies
We are the controller of the data we hold about you as our customer: your account details, your billing records, your support messages and how you use the product. Sections 2 to 8 describe that.
You are the controller of the data your funnels collect: your leads, form submissions, contacts, buyers and visitor analytics. We process it only on your behalf and on your instructions, which are the actions you take in the product. Section 9 describes that, and sets out the obligations we accept as your processor.
The practical consequence: if one of your leads asks to be deleted, they should ask you, not us, and you can act on it yourself inside your workspace. If we receive such a request directly, we will forward it to you rather than acting on it ourselves.
2. What we collect about you
Account data. Your name, email address, company name if you give one, and a cryptographic hash of your password. We never store your password itself and cannot read it.
Billing data. Your subscription status, plan, billing interval, renewal dates and invoice history, plus the customer and subscription identifiers issued by our payment processor. We never see or store your card number, expiry date or security code. Those are entered directly into our payment processor and never reach our servers.
Integration credentials. If you connect your own payment processor, email sending account or advertising accounts, we store the credentials needed to operate that connection. Sending passwords are encrypted at rest and decrypted only for the moment of a send.
Usage and technical data. Sign-in times, IP address at sign-in, browser and device information, pages used in the product, and error logs. We use this to run and secure the Service and to find faults.
Support data. Anything you send us in an email or support conversation.
We do not knowingly collect data from anyone under 18, and the Service is not offered to them.
3. Why we use it, and our lawful basis
To provide the Service, including authenticating you, serving your funnels, and operating the connections you configure. Lawful basis: performance of our contract with you.
To bill you and keep the financial and tax records we are required to keep. Lawful basis: contract, and legal obligation.
To send service email: account confirmation, password resets, billing notices, security alerts and material changes to the Service or these policies. These are not marketing and you cannot unsubscribe from them while you hold an account. Lawful basis: contract.
To keep the Service secure, detect abuse and fraud, enforce our Terms of Service, and defend legal claims. Lawful basis: our legitimate interests in operating a safe service, and legal obligation.
To improve the product using aggregated and usage data. Lawful basis: legitimate interests.
To send product marketing, where you have opted in or where we may lawfully email an existing customer about similar services. You can opt out at any time from the link in any such email, and doing so does not affect service email.
We do not sell your personal data, and we never have. We do not share it with advertising networks or data brokers, and we do not use your business data or your customers' data to train anyone's models.
4. Who we share it with
We share personal data only with sub-processors that make the Service work, each bound by a contract to protect it and to use it only on our instructions. The current categories are:
Hosting and infrastructure, to run the application and its databases. Payment processing, to take your subscription payment and to operate the checkouts you build. Email delivery, to send transactional mail. Content delivery and certificates, to serve your pages securely. Advertising platforms, but only where you yourself have configured a conversion tracking connection, and only with the data your configuration sends.
We may also disclose data where we are legally required to, to enforce our terms, or to protect the rights and safety of our customers or the public. Where we are permitted to tell you about such a request, we will.
If our business is acquired or merged, data may transfer to the acquirer as part of that transaction. It stays subject to this policy, and we will notify you before it happens.
A current list of named sub-processors is available on request from [email protected].
5. How long we keep it
While your account is open, we keep your account and workspace data so the Service works.
After you close your account, workspace data is retained for 30 days so that an account closed by mistake can be restored, and is then permanently deleted. Backups containing it are cycled out within a further 90 days.
Billing and tax records are kept for as long as the law where we operate requires, typically six to ten years. These cannot be deleted on request.
Security and abuse logs are kept for up to 12 months.
We recommend exporting anything you need before closing your account. Contacts, form submissions and orders each export to CSV from inside your workspace at any time.
6. How we protect it
Traffic is encrypted in transit with TLS. Passwords are stored as one-way hashes. Stored sending credentials are encrypted at rest. Visitor IP addresses in analytics are hashed with a secret salt rather than stored raw.
Every workspace is isolated: each record carries the account that owns it, and every query is scoped to the signed-in account, so one customer cannot read another customer's data.
Access to production data is limited to the people who need it to operate the Service. State changing requests are protected against cross-site request forgery, and sensitive endpoints are rate limited.
No system is perfectly secure, and we do not claim otherwise. If a breach affecting your personal data occurs, we will notify you and the relevant supervisory authority without undue delay, and within 72 hours of becoming aware of it where that obligation applies to us.
7. Cookies and tracking on our own site
We use a session cookie to keep you signed in, and a security token to protect forms against cross-site request forgery. Both are strictly necessary and cannot be switched off while you use the Service.
We store a small marker in your browser so that page views generated by you, on your own published funnels, are not counted in your own analytics.
We do not run third-party advertising or cross-site tracking cookies on our marketing pages.
Cookies set on pages you publish are your responsibility, including any cookie banner or consent mechanism your visitors' jurisdiction requires. If you enable a conversion tracking connection to an advertising platform, you are the one making that disclosure to your visitors.
8. Your rights, and where your data is held
Depending on where you live, you may have the right to: access the personal data we hold about you; correct it; delete it; restrict or object to how we use it; receive it in a portable format; and withdraw consent where our use rests on consent. Under the GDPR you may also complain to your local supervisory authority.
If you are in California, you may request disclosure of the categories and specific pieces of personal information we have collected, request its deletion, and are entitled not to be discriminated against for exercising those rights. We do not sell or share personal information as those terms are defined by the CCPA and CPRA.
To exercise any of these rights, email [email protected] from the address on your account. We respond within 30 days, and may need to verify your identity first. Account and workspace data is also exportable directly from your dashboard without contacting anyone.
International transfers. Our providers may process data outside the country you live in, including in the United States. Where data leaves the European Economic Area or the United Kingdom, it is transferred under appropriate safeguards, usually the European Commission's Standard Contractual Clauses together with the UK Addendum.
9. Data your funnels collect, where we are your processor
When your visitors submit a form, buy something, or are counted in your analytics, that personal data is yours. We process it only to provide the Service to you.
As your processor we undertake to: process that data only on your documented instructions; keep it confidential and bind our staff to confidentiality; apply the security measures in section 6; engage sub-processors only under equivalent written obligations and remain responsible for them; assist you with data subject requests, breach notifications and impact assessments so far as we reasonably can; notify you without undue delay if we become aware of a breach affecting your data; and delete or return that data at the end of your subscription in line with section 5. This section is intended to serve as our data processing agreement with you; a separate signed agreement is available on request.
As the controller, you are responsible for: having a lawful basis for collecting the data your funnels collect; giving your visitors your own privacy notice; obtaining any consent your visitors' jurisdiction requires, including for cookies and for advertising conversion tracking you enable; honouring your own visitors' access and deletion requests; and not putting special category data, payment card numbers or other highly sensitive data into fields not designed for it.
Card details entered by your buyers go directly to your payment processor from the buyer's own device. They never reach our servers, and we could not disclose them if we were asked to.
10. Changes to this policy
We may update this policy. The date at the top always shows when it last changed. For material changes we will give you at least 30 days notice by email or through the Service before they take effect.
11. Contacting us
For privacy questions, access or deletion requests, a copy of our sub-processor list or a signed data processing agreement, contact [email protected]. For anything else, [email protected].
The controller of your personal data is the company operating soFunnels, and this policy is governed by the law of the jurisdiction in which soFunnels is established.