At UXCam, we respect your privacy. We adopted Privacy by Design and by Default as a way of thinking and acting in favor of your privacy upfront and building privacy into our services.
We wrote this privacy statement to help you understand your rights, our obligations and outline how data is treated when you interact with our website https://uxcam.com/, UXCam App, and UXCam Software Development Kit (“SDK”).
The terms “we”, “us”, “our”, “UXCam” refer to “UXCam Inc”, a Delaware company, and its affiliate UXCam GmbH, a German company.
We’d like to summarize our approach to privacy in a few commitments to you:
Clearly express our privacy statement and keep it up to date – last updated November 16th, 2021.
Make sure to implement practices, procedures and systems to comply with data protection law, and carry out all processing operations in strict compliance.
Explain in plain language the type of information and the legal basis for processing personal data.
Inform you of the purpose for which your information is collected, stored, used, and disclosed.
Inform you on your rights to information, access, rectification, deletion, portability, objection.
Do our best not to let you down. If you have any questions regarding our privacy practices, please contact us at firstname.lastname@example.org. If you have any questions about this privacy notice, how we handle your personal data, or you want to exercise any GDPR rights, please contact our Data Protection Officer (DPO). DPO contact details are as follows: TechGDPR DPC GmbH Address: Heinrich-Roller Str. 15, 10405 Berlin, Germany Email: email@example.com
Make sure our third parties are as diligent as we are.
Make sure UXCam is in check as a third party itself.
From the data protection perspective, we act as a data processor for the information collected through the SDK and UXCam App, and as data controllers for the information collected through our website.
You can contact us at:
UXCam GmbH Badstraße 20 13357 Berlin
UXCam Inc 315 Montgomery St, 10th Floor San Francisco, CA, 94104
Contact form: When you contact us via the contact form, we collect the following information:
First and last names
Quote request: When you request pricing, we collect the following information:
First and last names
Downloading our e-book When you download our e-book in our resource section on the website, we collect the following information:
First and last names
Start a free trial If you decide to start a free trial, we collect:
Working email address
Request a demo If you want to request a demo, we will collect:
Company email address
First and last names
Chatbot If you want to schedule a demo, request pricing, or download an e-book via the chatbot, we will collect:
First and last names
UXCam for startups request form If you apply to the startup program, we will collect the following information:
Company email address
First and last names
UXCam partners form If you want to become a partner and filled out the form, we will collect:
Company email address
First and last names
Events When you participate in one of our events, we collect the following information:
The applied legal basis for the above-mentioned activities is our legitimate interests (GDPR Art. 6.1.f)
We will use this information to send offers (marketing and sales emails) that are relevant to you. You can opt out at any time by clicking the appropriate button in our emails to you.
We may share this information with third parties, with whom we have data protection agreements and with whom we have carried out an appropriate assessment.
We will store this information for a period of 3 years (unless you become our customer, in which case, the data will be stored until you continue to use our services). At the end of this period, we will send you a final communication requesting your consent to receive email marketing and if we do not receive a response within 5 days, we will completely delete your data from all our databases.
Newsletter When you subscribe to our newsletter through the website and give us consent to send marketing messages to the email you registered your account with, we send you personalized offers, discounts, and updates. We use this information to prepare, personalize (by including your name) and send our newsletter to you. This processing takes place under the legal basis of consent (GDPR Art. 6.1.a).
You can withdraw consent at any time by contacting us directly. Please note that the withdrawal will not affect the lawfulness of processing based on consent before it was revoked. You can also opt out of email newsletter subscriptions by clicking the unsubscribe link provided in our emails to you.
Applicants Our website offers a page for anyone to apply for an open job position at UXCam. For us to consider your application, we collect your first, last name and email, LinkedIn profile, phone (optional), location (optional), and resume. We assess this information against the job requirements for our recruitment purposes only. The applied legal basis for these activities is our legitimate interests (GDPR Art. 6.1.f)
We will store CVs and related job data for a period of 1 year and a half. Notwithstanding the foregoing, if we keep such information for a longer period of time, we will ask for your consent.
Your personal data will be shared with colleagues within UXCam where it is necessary for the processing purposes set out above. This includes, for example, your line manager for their management of you and the HR department for recruiting purposes.
As a third party When UXCam is integrated as a service, we collect the following information:
Account creation For using our services, you need to create an account at UXCam App. For this purpose, we will collect your email address and password.
We will use this information to:
create and maintain your user account, including securing access to it by password;
allow you to access the UXCam app implementing the SDK;
contact you regarding the work of UXCam and/or your account;
provide you with technical support;
based on your consent, to send you marketing emails;
We will store your account data for as long as you use our services and have the account. We will delete your data 365 days after your last user session. We will also delete the data of your users.
SDK: UXCam SDK is integrated into our customers' mobile app codebase. During the clients’ use of the UXCam SDK, we collect the following data from the end-user device:
Consistent random pseudo ID for every end-user
Device details: type, version, model, operating system (OS)
Geographic location (country only)
Time zone of the device
Screens visited by the end-user (screens only from the customer mobile app which was integrated with the UXCam SDK in their codebase)
Session (opening times of the app) with the end-user activity
Interaction patterns by the end-user on customers’ app (screen actions, gestures: taps, scrolls)
Information provided by the customer (except information customer chooses to block from being sent to UXCam)
Note. Provided you disclose to us the personal information of another person (e.g., your client’s = end-users), you are responsible for obtaining that person's consent to process their personal information in accordance with this notice. At the end, you decide what data you wish to record and store. We capture the whole screen, so financial information on the app could be recorded. We provide API methods to hide PII and sensitive information. For more information please visit our Hide Sensitive Data and Protecting user privacy sections.
We use this data for debugging, quality management, and app improvement purposes as well to provide customers with insights about app user experience and behavior in the form of statistics.
We process this data on behalf of our customers, or in other words, as processors.
Therefore, we will store this information for the period chosen by our customers, which will depend on the plan they have contracted:
Data associated with the Free tier is retained for 1 month;
Data associated with the Growth tier is retained for 3 months by default, but can be retained for as long as 24 months upon request of the customer;
Data associated with the Enterprise tier is retained for 12 months by default, but can be retained for as long as 24 months upon request from the customer; and
Data associated with any other Tiers is retained for 3 months by default, but can be retained for as long as 24 months upon request of the customer.
Please, note that in some cases the length of data retained under any UXCam plan other than the free tier can change upon the request of UXCam's customer (the data controller).
Customer support We provide our customers with different types of support depending on the purchased plan.
Support can be provided via email, video call, corporate chat, and chat function via the UXCam app.
To provide such service, we collect the following data:
access to the account and therefore access to the dashboard (in case of troubleshooting)
The applied legal basis for these activities is the performance of the contract (GDPR Art. 6.1.b). In case we record the call, we will ask for your prior consent.
We will store this information for as long as you use our services and have the account. If that is no longer the case, we will fully delete the data after 1 year after the last user session.
Feedback From time to time, we ask our clients how we’re doing and provide relevant feedback regarding our SDK or UXCam App. We use this information to improve our services and analyze our efficiency in marketing and product efforts, including by creating statistics of inquiries.
We will store your communications with us for our legitimate interests (GDPR Art. 6.1.f) for a period of 3 years after the deactivation of your account.
Onboarding questions When you start using our services, we collect the following information.
We use this information to contact the key stakeholders working on your app. We will store your communications with us for our legitimate interests (GDPR Art. 6.1.f) for a period of 1 year after the deactivation of your account.
Our Website and Services are hosted in the United States of America.
If you are accessing the Website and/or Services from the European Union, with laws or regulations governing personal data that differ from United States laws, please note neither EU law nor GDPR requires hosting data in the EU. Instead, what is required is that UXCam must provide “appropriate safeguards” for data that it hosts and processes on its US servers (see Art 46 of the GDPR). UXCam offers a Data Processing Addendum (DPA) to provide such adequate safeguards, which includes, where applicable, Standard Contractual Clauses implemented by Commission Implementing Decision (EU) 2021/914 of 4 June 2021as an annex.
For all of our clients, a Data Processing Agreement is incorporated into our Master Service Agreement. If you want to review or receive a signed copy of our DPA, please find it here. In any case, you can request it at firstname.lastname@example.org
We will retain documents containing personal data:
to the extent that we are required to do so by law;
if we believe that the documents may be relevant to any ongoing or prospective legal proceedings; and
in order to establish, exercise or defend our legal rights (including providing information to others for the purposes of fraud prevention and reducing credit risk)
We engage with selected third-party companies and individuals to perform services complementary to our own, namely – cloud storage, data analytics, payment processing, support, consulting, development, marketing, advertising, e-mail distribution, and data security; as well as our business, legal and financial advisors (collectively, “third parties“).
To give you the most privacy guarantees and data protection assurance – we carefully reviewed and vetted our third parties. To ensure compliance with data protection requirements on international transfers, the Standard Contractual Clauses (SCC) as adopted by the European Commission are signed with these providers.
Our third-party service providers do not have any right to use the information we share with them beyond what is necessary to assist us.
Cookies are small pieces of text sent by your web browser by a website you visit. A cookie file is stored in your web browser and allows us or a third party to recognize you and make your next visit personalized and easier, recognizing your device and storing some information about your preferences or past actions. Cookies can be "persistent" or "session" cookies. Session cookies are deleted at the end of the session, whereas persistent cookies remain stored in the device until they expire.
A distinction is made between first-party cookies and third-party cookies. First-party cookies originate from the respective web service or application used (i.e. UXCam App), while third-party cookies originate from other companies (e.g., web traffic analysis) for our advertising and marketing efforts.
Strictly necessary cookies
These cookies are necessary for the website to function and cannot be switched off in our systems. They are usually only set in response to actions made by you that amount to a request for services, such as setting your privacy preferences, logging in or filling in forms. You can set your browser to block or alert you about these cookies, but that will cause some parts of the site to not work. These cookies do not store any personally identifiable information.
These cookies allow us to count visits and traffic sources so we can measure and improve the performance of our site. They help us to know which pages are the most and least popular and see how visitors move around the site. If you do not allow these cookies, we will not know when you have visited our site and will not be able to monitor its performance.
We also use marketing cookies that deploy a cookie when a user interacts with marketing communications, such as a marketing email or a marketing-based landing page on our website. This cookie collects personal information such as your name, which pages you visit on our website, how you arrived at our website. Collected information is used to evaluate the effectiveness of our marketing campaigns or to provide better targeting for marketing.
The placement of analytical, and marketing cookies takes place under the legal basis of visitors’ consent (GDPR Art. 6.1.a); necessary cookies for our website to operate and do not require consent but are placed under our legitimate interests (GDPR Art. 6.1.f) or are legitimized by the necessity to perform the contract (GDPR Art. 6.1.b).
The following cookies are used on UXCam's website:
|test_cookie||.doubleclick.net||Advertisement||The test_cookie is set by doubleclick.net and is used to determine if the user's browser supports cookies.||15 minutes|
|__hstc||.uxcam.com||Analytics||This is the main cookie set by HubSpot, for tracking visitors. It contains the domain, initial timestamp (first visit), last timestamp (last visit), current timestamp (this visit), and session number (increments for each subsequent session).||1 year 24 days|
|hubspotutk||.uxcam.com||Analytics||This cookie is used by HubSpot to keep track of the visitors to the website. This cookie is passed to HubSpot on form submission and used when deduplicating contacts.||1 year 24 days|
|_gcl_au||.uxcam.com||Analytics||Provided by Google Tag Manager to experiment advertisement efficiency of websites using their services.||3 months|
|__cf_bm||.hubspot.com||Functional||This cookie, set by Cloudflare, is used to support Cloudflare Bot Management.||30 minutes|
|__hssc||.uxcam.com||Functional||HubSpot sets this cookie to keep track of sessions and to determine if HubSpot should increment the session number and timestamps in the __hstc cookie.||30 minutes|
|__hssrc||.uxcam.com||Necessary||This cookie is set by HubSpot whenever it changes the session cookie. The __hssrc cookie set to 1 indicates that the user has restarted the browser, and if the cookie does not exist, it is assumed to be a new session.||session|
|undefined||.uxcam.com||Other||No description available.||never|
We run a tight ship on data protection at UXCam. We use SSL encryption to protect sensitive information online and do everything in our power to protect user information offline. We perform staff training on the value of personal information, and we also have internal data protection documents that everyone abides by. Rest assured, not all staff get access to data – only selected personnel with the highest admin privileges. When they do – it is to continue assisting you in making the most out of UXCam. On a day-to-day basis, we use 256-bit SSL encryption to add extra levels of security.
We are PCI compliant and respect and protect your financial information. When you subscribe, you will be redirected to a third party where you can independently complete your purchase.
You have to know what you’re signing up to, and we’re being very open about it. If you require additional and personalized help understanding UXCam’s privacy statement or the services – we are very happy to hear from you via email. Please email us at email@example.com.
You may exercise GDPR rights regarding your personal data. In particular, you have the right to:
Object against the processing of your information. If we process your information for our legitimate interests (e.g., for direct marketing emails or for our marketing research purposes), you can object against it. Let us know what you object against, and we will consider your request. If there are no compelling interests for us to refuse to perform your request, we will stop the processing for such purposes. If we believe our compelling interests outweigh your right to privacy, we will clarify this to you.
Access your information. You have the right to know what personal data we process. As such, you can obtain the disclosure of the data involved in the processing, and you can obtain a copy of the information undergoing processing.
Verify your information and seek its rectification. If you find that we process inaccurate or out-of-date information, you can verify the accuracy of your information and/or ask for it to be updated or corrected.
Restrict the processing of your information. When you contest the accuracy of your information, believe we process it unlawfully, or want to object against the processing, you have the right to temporarily stop the processing of your information to check if the processing was consistent. In this case, we will stop processing your data (other than storing it) until we are able to provide you with evidence of its lawful processing;
Delete your personal data. If we are not under the obligation to keep the data for legal compliance and your data is not needed in the scope of an active contract or claim, we will remove your information upon your request.
Transfer your personal data to another organization. Where we process your personal data on the legal basis of consent you provided us or on the necessity to perform a contract, we can make, at your request, your data available to you or to an organization of your choosing.
We are required to get back to you within 1 month. Should the request be complex or taking into account the number of requests, we may extend it two further months, but we will inform you accordingly.
Lodge a complaint with a supervisory authority:
If you believe that our use of personal information violates your rights, or if you are dissatisfied with a response you received to a request you formulated to us, you have the right to lodge a complaint with the competent data protection authority of your choice.
Available authorities in Europe can be found here:
UXCam is registered with the Berliner Data Protection Authority, which can be contacted here :
Maja Smoltczyk, Berliner Beauftragte für Datenschutz und Informationsfreiheit Friedrichstraße 219, 10969 Berlin, Germany Telefon: +4930138890, firstname.lastname@example.org
This service is intended for users over 18. If you suspect that your account or this service is being used by minors, then write to us immediately at email@example.com.
We may disclose any information in response to a legal request, such as a subpoena, court order, or government demand; to investigate or report illegal activity, or to enforce our rights or defend claims. We may also transfer your information to another company in connection with a corporate restructuring, such as a sale or merger.
We are committed to keeping you informed of how data is being handled. If we make material changes to this document, we will notify you by sending an email to you. We will also update the “last updated” date at the top; in the commitments section. If we let you know of changes through email communication, then the date on which we send the email will be deemed to be the date of your receipt of that email.