Privacy Policy
Last updated: June 26, 2026
This Privacy Policy explains how Reckoned Force, LLC (“Reckoned Force”, “we”, “us”), which operates the CensusIO service (“CensusIO”), handles personal data. It covers our website, web application, field collector links, and documentation. It does not cover third-party services you choose to connect.
1. Our two roles
We act in two roles. For data about account holders and visitors (such as your login, billing, and support messages), we are the data controller, and this policy describes what we do. For personal data that appears inside a customer’s survey records (for example, an observer name a field crew entered), the customer’s organization is the controller and we are its processor. If you are a member of the public asking about personal data in an organization’s survey records, contact that organization, which controls that data.
2. Personal data we collect
- Account data: your name, email address, organization name and role, your language and unit preferences, and an optional profile photo.
- Authentication data: sign-in records, sessions, and, if you enable it, a two-factor authentication secret. We support email sign-in links and sign-in through identity providers such as Google and Microsoft.
- Billing data: for paid plans, your billing contact and subscription details. Card payments are handled by Stripe; we do not store full card numbers.
- Support data: messages you send us and their contents.
- Usage and device data: basic technical records such as the IP address and browser type tied to a session, kept for security, and an internal audit log of actions taken in an organization.
- Security and abuse signals: to detect and prevent abuse (such as automated sign-up or email-bombing attempts), we record limited security events, including failed bot-challenge attempts and sign-in link requests, with the email address entered and the IP address. We keep these for a short period (about 30 days) and then delete them.
- Customer Data: the survey records, locations, lab samples, and files an organization stores, which may incidentally contain personal data the organization chose to record. We process this as the organization’s processor.
3. How and why we use data
We use personal data to:
- provide, maintain, and secure the Service, and authenticate you;
- process payments and manage subscriptions;
- respond to support requests and send service messages (such as sign-in links and notifications);
- prevent abuse, investigate security issues, and keep audit records;
- understand and improve the Service using de-identified, aggregated information;
- meet legal, tax, and records obligations.
We do not sell personal data, and we do not use it for advertising.
4. Legal bases (for users in the EU, UK, and similar regimes)
Where the GDPR or a similar law applies, we rely on:
- Performance of a contract, to provide the Service and handle billing;
- Legitimate interests, to keep the Service secure and to improve it;
- Consent, for optional actions such as publishing to the Public Data Layer;
- Legal obligation, for tax, accounting, and records retention.
5. Sub-processors
We use a small set of trusted providers to run the Service:
- Cloudflare, for hosting, compute, the database, and file storage;
- Stripe, for payment processing and subscription billing;
- Resend, for sending transactional email such as sign-in links, invitations, and notifications;
- Integrations you choose to connect (such as KoboToolbox, Esri/ArcGIS, and ODK Central), which receive or send data only when your organization configures them.
Some optional AI-assisted features send the form structure you are designing to an AI model run by our infrastructure provider to generate suggestions. We will give notice before adding a new sub-processor that handles personal data.
6. International data transfers
The Service is hosted on Cloudflare’s network, primarily in the United States. If you are in the European Economic Area, the United Kingdom, or Switzerland, your personal data may be transferred to the United States. Where required, we rely on Standard Contractual Clauses and related safeguards for those transfers.
7. Data retention
We keep account data for as long as your account is active, and after deletion we keep it through a 30-day recovery window before permanent removal. We keep billing records for the periods tax and accounting laws require. We keep security and audit records for a limited period. Survey records held by an organization are retained according to that organization’s instructions and retention obligations, which for government agencies can be permanent.
8. Your rights
Depending on where you live, you may have the right to access, correct, delete, restrict, or object to our use of your personal data, and to receive a copy of it in a portable form. You can update your profile and export or delete your organization’s data from within the Service, and you can delete your own account. To make any other request, contact us using the details below. If your request concerns personal data inside an organization’s survey records, we will direct you to, or work with, that organization as the controller. You also have the right to complain to your data protection authority.
9. California privacy rights
If you are a California resident, you have the right to know what personal information we collect and how we use it, to request deletion or correction, and to be free from discrimination for exercising your rights. We do not sell or share your personal information, and we do not use it for cross-context behavioral advertising. For Customer Data, we act as a service provider to the organization. To exercise a right, contact us using the details below.
10. Cookies
We use a single essential cookie to keep you signed in and to protect your session. We do not use advertising cookies, and we do not load third-party analytics or tracking scripts. Because the cookie we use is strictly necessary to run the Service, it does not require a consent banner.
11. Security
We protect data with measures that include encryption in transit (HTTPS everywhere) and encryption at rest, with sensitive secrets such as integration credentials and two-factor secrets encrypted again at the application level. Each organization’s data is strictly isolated from every other organization. Sessions are stored so they can be revoked immediately, access is controlled by role, field-collector and API tokens are stored only as hashes, two-factor authentication is available, and we keep an append-only audit log. No online service can be completely secure. If we become aware of a breach affecting your personal data, we will notify affected customers and authorities as the law requires.
12. Children
CensusIO is built for professional, agency, and academic users. It is not directed to children, and we do not knowingly collect personal data from anyone under 16. If you believe a child has provided us personal data, contact us and we will remove it.
13. The Public Data Layer
Organizations can choose to publish survey records to a public, open-data layer. Publishing is optional, requires explicit consent at the time of publishing, and is permanent. Once a record is public, it can be copied, indexed, and mirrored by search engines and downstream aggregators, and those copies may persist independently even after a record is withdrawn from CensusIO. If an organization is deleted, its published records are kept but de-identified, with the source shown as “Withdrawn”. Do not publish data you may need to fully retract.
14. Changes to this policy
We may update this policy from time to time. We will post the updated policy with a new effective date, and for material changes we will notify account holders.
15. Contact
For privacy questions or to exercise a right, contact us at support@censusio.com.
Reckoned Force, LLC, Aurora, Colorado, USA.