Privacy
Last updated: 13 September 2026
This page says what Plezo stores about people, who else can see it, how long it is kept, and what you can ask us to do with it.
Who is responsible
Plezo is a trade name of a sole trader registered in the Netherlands at Smakkelaarsveld 79, 3511 EB Utrecht. Chamber of Commerce 50812904, VAT NL001124200B52.
You can reach us through the contact form or at [email protected].
Two different roles
Plezo handles personal data in two ways, and the difference decides who you ask about what.
For visitors to this site, people who write in, and the person who signs a business up, we decide what is collected and why. We are the controller, and this page is your notice.
For customers who answer a survey, and the team inside a business's account, the business decides what is asked and why. They are the controller and we only act on their instructions. If you answered a survey from a shop, a café or a company you bought from, ask them, not us. What we commit to as their processor is written into the terms.
No cookies, no third party
What we store in your browser, what we count, and who else is told.
Plezo sets no cookies at all. There is no advertising, no tracking pixel, no social button and no third party script anywhere on this site, the survey page or the console. The fonts are served by us. Nobody outside Plezo is told that you were here, and there is no consent banner because there is nothing to consent to.
We do count page views on this site, ourselves. When you open one of these pages, your browser tells our own server which page it was, which site you followed a link from if you came from one, and which browser you are using. We look at it to see which pages people read and which ones are not worth keeping.
Nothing in that record names you. So that we can tell one person reading three pages from three people reading one, we turn your IP address, your browser and today's date into a single short code. The date is part of it, so the code is a different one tomorrow and today's reading cannot be joined to any other day's. We erase the IP address after thirty days.
This is the public side of the site, which includes the sign-in and sign-up pages. The survey page, surveys on a business's own website, and the console are not counted at all. None of these records holds your name, your email address, or anything else that points at your account.
The survey page stores nothing in your browser. After you tap a score, the page holds a short code in memory so that the reason you type next is added to the same answer. It is gone when you close the page.
A business can also put a survey on its own website, as a small one in the corner of the page. Once you answer it or close it, your browser remembers that for that survey, in local storage rather than in a cookie, so that it does not ask you again for 90 days. That note stays on your device and is never sent to anybody.
Signing in to the console stores two things in your own browser, also in local storage: a session token, and the name and role we show in the corner of the screen. They are needed for you to stay signed in, they never leave your device except as the token on requests you make, and signing out removes them.
What we hold
What we store depends on how you came to use Plezo.
If you answer a survey
Your score, the reason you gave if the survey asked for one and you wrote it, when you answered, and which of the business's links or QR codes you came through. There is no account, and we do not ask for your name, your email address or anything else about you. We do not store your IP address with your answer. Anything you type as a reason is kept as you typed it, so leave out what you would not want the business to read.
For 24 hours after you answer, the same page can still change your score and add a reason. After that the answer is fixed.
Plezo never sends email and never holds a list of a business's customers. If a survey reached you by email, it came from the business itself, and the address it was sent to is theirs, not ours.
If you answered in Bellbee
Bellbee is our guest-request app for hotels and rentals. A property that uses both can ask its Plezo surveys on its Bellbee guest pages. Your answer then reaches us from Bellbee: your score, your reason if you wrote one, and the name of the page you answered on or of the thing you asked for, such as "Taxi". Nothing that says who you are comes with it: not your room, and not what you asked Bellbee for.
If you write in
The contact form takes your name, your email address, your business if you fill it in, and your message. We store it and email it to ourselves so we can answer. We also record the IP address the message came from, to stop the form being used to send junk.
If you open an account
Your name, email address, the name of your business, and the country your business is registered in, which decides the VAT on your invoices. Your browser also tells us its timezone and we keep it, so "today" in your reports is today where you are. When you put a card on the account we hold the billing details you type, including your VAT number, invoice address and any billing email, and a reference from our payment provider. We never receive your card number.
If a business you work for invited you
Your name and email address, which they entered, and your role. Every time you sign in we record the time and the browser your device reports.
Whenever anything is used
Our server keeps ordinary technical records of requests. We record IP addresses against a small number of events, such as a failed sign in, a signup or a password reset request, so that somebody trying addresses one after another can be slowed down. We also count answers per IP address for a few minutes, so that nobody can flood a survey, but that count is not kept with any answer.
Who else touches it
One product of our own, and three companies each doing one job.
We do not sell personal data, we do not share it for advertising, and we do not use it to train anything. These are the only companies involved in running Plezo:
- Bellbee is our own guest-request app, on this list because a business can connect it so that its guest pages ask Plezo surveys. It learns each survey's name, question and type, and whether it is taking answers, so it can ask it. It never receives answers, comments, the team or the plan. It is a separate account with its own sign-ins, run by us on the same hosting below, and nothing is connected unless the account owner connects it.
- DigitalOcean hosts the site, the API and the database, in Amsterdam.
- Bird, formerly SparkPost, delivers the email we send to the people on an account: invitations, password resets, invoices and notices about the account, and passes contact messages on to us. We send no email to anybody who answers a survey.
- Mollie takes payment. Card details are typed on Mollie's own page and never reach us. Mollie decides for itself what it needs to hold to run a payment business, so for that part it is not acting on our instructions.
Everything is held inside the European Economic Area. If that ever has to change we will say so here and tell account owners first.
We will hand something over to an authority if the law obliges us to, and we will tell the account owner first unless we are forbidden to.
How long it is kept
And how it is protected while we have it.
Surveys, answers and the team are kept while the account is open. When an account closes we keep it readable for ninety days in case the business comes back, then delete it, and an owner can ask us to delete it immediately instead.
A sign in lasts ninety days before it has to be done again. An invitation link stops working after three days, and a password reset link after 24 hours. IP addresses are erased after thirty days, the ones recorded against events, the ones contact messages came from, and the ones behind the page views on this site. Invoices and the figures behind them are kept for seven years, because Dutch tax law requires it, and that obligation outlasts a request to delete an account.
Names, email addresses, the reasons customers write, contact messages, and invoice details are encrypted before they are written to the database, so a copy of the database on its own does not name anybody or say what they wrote. Everything travels over an encrypted connection. Passwords are stored in a form nobody can read back, including us, which is why a forgotten password is reset rather than looked up.
What you can ask for
Your rights, and where to complain if we handle a request badly.
You can ask us for a copy of what we hold about you, to correct it, to delete it, to give it to you in a portable form, or to stop using it in a particular way. Get in touch and we will answer within a month, free of charge.
If you answered a survey, or a business you work for gave you an account, the decisions about that data are theirs and not ours. Ask them first. If you ask us, we will pass it on and help them answer, but we are not allowed to delete their records for you. An answer holds nothing that says who gave it, so to find yours the business will usually need to know roughly when you answered and what you wrote.
If you think we have handled your data badly, tell us and we will try to put it right. You also have the right to complain to a data protection authority. In the Netherlands that is the Autoriteit Persoonsgegevens, and you can go to the one where you live instead.
When this page changes we move the date at the top, and we email account owners when the change matters.