Privacy Policy

Last Updated: November 12, 2025

Submittable Holdings, Inc. and its affiliates (“Submittable,” “we,” “our,” and/or “us”) are committed to protecting the privacy of individuals who visit and use our websites (including https://www.submittable.com) or services that link to this privacy policy (collectively, our “Services”). This Privacy Policy explains how we collect, use, and disclose personal information from users of our Services (“End Users”). 

Personal Information” (also referred to as “personal data” under the General Data Protection Regulation (GDPR), UK GDPR, and similar laws) means any information that identifies, relates to, describes, or can reasonably be linked to an identified or identifiable individual. 

We provide submission management software to organizations (“Organization Customers”). In this role, we process Personal Information submitted by End Users at the direction of our Organization Customers. For purposes of this Privacy Policy, a “Submission” means any content, data, document, or other information that an End User provides through our Services at the direction of an Organization Customer (e.g., applications, forms, resumes, essays, or other materials). The types of information collected depend on how an Organization Customer configures and uses the Services. Because Organization Customers control the content of Submissions, certain categories of Personal Information or Sensitive Personal Information may only be collected when an Organization Customer elects to collect them.

When we process Personal Information in Submissions, we act as a data processor, service provider, or subcontractor on behalf of our Organization Customers, which are the entities responsible for determining the Personal Information we collect and how that Personal Information is used and disclosed. Personal Information that End Users provide to Organization Customers through Submissions is collected and controlled by the Organization Customer. Submittable processes Submissions only on the Organization Customer’s instructions and for limited purposes such as hosting, maintenance, support, security, and other services described in this Policy and our agreements with Organization Customers. This Privacy Policy describes how we process Personal Information in Submissions; however, our processing of your Personal Information is also subject to our agreements with our Organization Customers, and therefore our use and disclosure of such Personal Information may be subject to additional restrictions. End Users should review the Organization Customer’s privacy policy for details and submit privacy requests about Submissions to that Organization Customer (we will assist them as required by law/contract).

In addition, this Privacy Policy describes the Personal Information that we collect, use, disclose, and process for our own business purposes, for example when you visit our website at https://www.submittable.com

By using or accessing the Services, you agree to the collection, use, and disclosure of your Personal Information as described in this Privacy Policy. In addition, your use of the Services is also subject to our Submitter Terms of Use and Customer Terms of Service, as applicable. Where applicable, we indicate whether and why you must provide us with your Personal Information, as well as the consequences of failing to do so. If you do not provide your Personal Information when requested, you may not be able to use the full extent of our Services if that information is necessary to provide you with the Services or if we are legally required to collect it.

If you are a California resident, please also review our California Resident Privacy Notice for details about the categories of Personal Information we collect, use, and disclose, and the rights available to you under California law.

I. Personal Information We Collect

We collect Personal Information in four main contexts:

  • When we process Submissions on behalf of our Organization Customers, who act as the controllers/businesses for those data. 

  • When you provide information to us directly for our own business purposes. 

  • When you use our Services.

  • When we receive information about you from third parties. 

A. Information We Collect on Behalf of Our Organization Customers

As described above, we process the Personal Information and Sensitive Personal Information contained in Submissions only on behalf of and at the direction of our Organization Customers, and in accordance with our contracts with them. We do not use Submission data for our own independent purposes, but we may access and process it as necessary to provide, maintain, secure, and support the Services to our Organization Customers. Organization Customers determine which categories of information are collected through their Submissions. Submittable processes those categories only as instructed and as necessary to provide the Services to our Organization Customers, subject to our contractual and legal obligations. Submittable does not control the content of Submissions, and some categories of Personal Information (including Sensitive Personal Information under U.S. state laws or Special Category Data under GDPR) are only collected if an Organization Customer chooses to collect them through its use of the Services. 

  • Examples: Depending on the Organization Customer’s configuration, Submissions may include identifiers (such as name, email address, or phone number), demographic details, professional or educational records, or other information provided by End Users. 

B. Information We Collect for Our Own Business Purposes

We also collect certain Personal Information directly from End Users, prospective customers, and visitors to our websites for Submittable’s own business purposes. Examples include: 

  • Account Registration and Profile Information: When you create an account, we collect your name, email address, login credentials, and any optional information you choose to add, such as a mailing address or phone number. 

  • Payment Information: If you make a purchase or add a payment method to your account, your payment card details (such as card number, expiration date, and billing address) are collected and processed directly by our third-party payment processor. Submittable does not receive or store your full payment card information. We may, however, receive limited information from the payment processor, such as the last four digits of your card, transaction date, and status, which we use for recordkeeping, fraud prevention, and account management. 

  • Communications: When you contact us (e.g., for customer support), we collect your name, contact details, and the content of your message. When you communicate with us online, third party vendors receive and store these communications on our behalf. When we send you emails, we may use embedded pixels or other technologies to track information about your receipt and interaction with our emails, such as whether and when you open them, whether you access any links included in our emails, how long you read our emails, whether you forward our emails and to whom, your Location Information (described below), and your Device Information (described below), to learn how to deliver a better customer experience and improve our Services. 

  • Marketing Preferences: If you sign up for marketing communications, we collect your email address and information about your interests.

  • Careers: If you apply for a job with us, we collect the information you choose to provide as part of your application, such as your contact details, resume, employment history, and any other information you include. If you apply through a third-party platform (such as LinkedIn or Greenhouse), we will collect the information you make available to us through that platform. We use this information to process and evaluate your application, communicate with you during the recruitment process, and comply with applicable legal obligations. If we use automated tools in the recruitment process, we do so only to assist human decision-makers; we do not rely solely on automated tools to make final hiring decisions. Applicants will receive additional notice where required by law.

C. Information We Collect When You Use Our Services

When you use our Services, we automatically collect certain Personal Information, for example:

  • Device Information. Details about the device and software you use to access our Services, including your internet protocol (IP) address, browser type, operating system version, and basic network data.

  • Usage Information. How you interact with the Services, such as browsing behavior, action history, requests made, log and performance data, diagnostic reports, pages viewed, searches conducted, referring and exit pages, and timestamps.

  • Location Information. Your general location, inferred from your IP address or device settings.

  • Cookies and Similar Technologies. We and our partners use cookies, beacons, pixel tags, and similar technologies (“Cookies”) to distinguish you from other users, improve your experience, and analyze usage of the Services:

  • Types of Cookies We Use:

    • Strictly Necessary/Functional Cookies. Enable basic functions such as page navigation, login, and remembering preferences (e.g., language or region). These are essential to the operation of the Services.

    • Analytical/Performance Cookies. Collect information about how the Services are used, such as pages visited, traffic sources, and error reports. We may use third-party analytics providers such as Google Analytics, which may also collect information about your use of other websites and apps.

    • Advertising/Targeting Cookies. Deliver relevant advertisements, measure campaign effectiveness, and personalize content. These Cookies may involve sharing information with advertising partners and may constitute a “sale” or “sharing” of Personal Information for targeted advertising under U.S. state privacy laws.

  • Your Choices:

    • In jurisdictions where required (such as the EU and UK), we obtain your consent before setting non-essential Cookies. You may withdraw or adjust your consent at any time through our cookie banner or your browser settings. 

    • In the U.S., residents of California and certain other states may opt out of the sale or sharing of Personal Information for targeted advertising by using our cookie banner, exercising the rights described in the Your Rights and Choices section, or sending us a request through the contact details provided. Where required by law, we also recognize browser-based opt-out preference signals (such as the Global Privacy Control). 

    • Most browsers also allow you to block or delete Cookies. If you do so, some features of the Services may not function properly.

  • Retention: Cookies may be stored for varying periods depending on their purpose. Some expire when you close your browser (session Cookies), while others remain on your device until they expire or are deleted (persistent Cookies).

  • For additional detail about the types of Cookies we use, their purposes, and your options for managing them, please see the Appendix: Cookies and Similar Technologies at the end of this Privacy Policy.

D. Information We Receive from Third Parties

We may also receive Personal Information from third-party sources: 

  • Third-Party Services. If you interact with our pages or content on third-party platforms, such as Facebook (Meta), X (formerly Twitter), Instagram, YouTube, or LinkedIn, we and other users may see the information you make publicly available on those platforms.

  • Partners. We may receive additional information from data providers, business partners, or marketing partners, and combine it with information we already maintain about you.

II. How We Use Personal Information

We use Personal Information for the following purposes, which are consistent with applicable laws such as the GDPR, UK GDPR, the California Consumer Privacy Act (as amended by the CPRA), and other U.S. state privacy laws:

  • To Provide and Operate the Services. Account management, authenticating access, processing Submissions, transactions, payments, and customer support.

Legal basis (GDPR/UK GDPR): Performance of a contract (Art. 6(1)(b)); legitimate interests (Art. 6(1)(f)) when supporting Organization Customers.

  • To Secure and Maintain the Services. Fraud prevention, protecting security and integrity, debugging, monitoring, and resolving issues.

Legal basis: Legitimate interests (Art. 6(1)(f)); legal obligations (Art. 6(1)(c)).

  • To Improve and Develop the Services. Usage analysis, diagnostics, research, testing, and product development.

Legal basis: Legitimate interests (Art. 6(1)(f)).

  • To Personalize Your Experience. Customizing features, recommendations, and content.

Legal basis: Legitimate interests (Art. 6(1)(f)); consent (Art. 6(1)(a)) where personalization involves profiling with legal or similarly significant effects.

  • For Marketing and Communications. Sending newsletters, promotions, customizing ads, and analyzing campaign performance (with consent where required).

Legal basis: Consent (Art. 6(1)(a)) for direct marketing where required; legitimate interests (Art. 6(1)(f)) where permitted by law. 

  • To Use De-identified and Aggregated Information. Creating de-identified or aggregated datasets and using or disclosing them for our business purposes, such as analytics, research, or improving the Services.

Legal basis: Outside the scope of GDPR and U.S. state privacy laws once data is properly de-identified/aggregated; legitimate interests (Art. 6(1)(f)) while in the process of de-identifying. 

  • To Comply with Legal and Regulatory Obligations. Responding to lawful requests, recordkeeping, enforcing agreements, and protecting rights. 

Legal basis: Legal obligations (Art. 6(1)(c)); legitimate interests (Art. 6(1)(f)) for establishing and defending legal claims.

  • With Your Consent. For other purposes you agree to, which you may withdraw at any time. 

Legal basis: Consent (Art. 6(1)(a)).

We may use automated tools, including machine learning, to support functions such as fraud detection, service improvements, or personalization. These tools do not replace human decision-making in ways that produce legal or similarly significant effects.

We only rely on our or a third party’s legitimate interests to process your Personal Information when these interests are not overridden by your rights and interests.

III. How We Disclose Personal Information

We disclose Personal Information in the following ways, or as otherwise disclosed to you at the time of collection.

  • When Acting as a Service Provider/Contractor. We disclose Submission data only to the relevant Organization Customer and to subprocessors who support the Services. In this role, we act solely on behalf of Organization Customers. 

  • When Acting as a Business. We may disclose Personal Information for our own purposes to:

  • Affiliates for internal administration and to provide or improve the Services.

  • Vendors and Service Providers for hosting, payment processing, IT support, and customer service.

  • End Users and Organization Customers when you provide information in a form created by an Organization Customer, that entity can view it, even if you do not submit the form.

  • Marketing. We do not disclose Personal Information to non-affiliated companies for their direct marketing without your consent.

  • Analytics Partners such as Google Analytics, which may also collect data about your use of other websites and apps. You can learn more about Google’s practices by visiting https://www.google.com/policies/privacy/partners/.

  • Advertising Partners who use cookies, pixel tags, and similar technologies to show you ads tailored to your interests. Some partners are members of industry opt-out programs (see the section “Your Rights and Choices”).

  • Legal and Compliance to comply with law or legal processes, enforce our agreements, or protect rights, property, or safety.

  • Corporate Transactions in connection with mergers, acquisitions, financings, or sales of all or part of our business.

  • With Consent in other circumstances with your permission.

IV. Your Rights and Choices

Depending on where you live, you may have certain rights under applicable privacy and data protection laws. We respect these rights and provide ways for you to exercise them, subject to any legal limitations or exceptions. 

A. Rights Under GDPR and UK GDPR (European Economic Area (EEA) and United Kingdom (UK)) 

If you are located in the EEA or UK, you have the following rights regarding your personal data: 

  • Access and Portability: The right to obtain confirmation about whether we process your personal data, access a copy of the data, and receive it in a portable format. 

  • Rectification: The right to correct inaccurate or incomplete personal data. 

  • Erasure (“Right to be Forgotten”): The right to request deletion of your personal data in certain circumstances (e.g., when it is no longer needed for the purposes collected). 

  • Restriction: The right to request that we limit processing of your personal data in certain situations. 

  • Objection: The right to object to processing based on our legitimate interests, and to object at any time to processing for direct marketing. 

  • Withdraw Consent: Where processing is based on consent, the right to withdraw your consent at any time. We will apply your preferences going forward and this will not affect the lawfulness of the processing before you withdrew your consent.

  • Lodge a Complaint. The right to lodge a complaint with a supervisory authority, including in your country of residence, place of work or where an incident took place. 

B. Rights under U.S. State Privacy Laws

If you are located in the United States and depending on your U.S. state residency, you may, at any time, exercise certain rights, as described below: 

California Residents. If you are a California resident, please see our California Resident Privacy Notice.

Other Covered States. Residents of certain other U.S. states have rights under their state privacy laws. These rights generally include the ability to request access to Personal Information, deletion, correction, and portability of Personal Information, as well as the right to opt out of the sale or “sharing” of Personal Information for targeted advertising.

These rights currently apply to residents of: 

  • Colorado, Connecticut, Utah, and Virginia, and 

  • Delaware, Indiana, Iowa, Kentucky, Maryland, Minnesota, Montana, Nebraska, New Hampshire, New Jersey, Oregon, Rhode Island, Tennessee, and Texas (with effective dates ranging from 2024 to 2026).

(These state laws are substantially similar but may include unique provisions, such as consent requirements for processing certain data, limits on the use of sensitive information, or obligations to honor universal opt-out signals.)

Exercising Rights. The scope of these rights and the mechanisms for exercising them vary by state. For California residents, please see our California Resident Privacy Notice. For residents of other states, you may exercise your rights by contacting us as described in the section “How to Exercise Your Rights.”

C. Choices About Marketing and Cookies

  • Marketing Communications. You can opt out of receiving marketing emails by clicking the “unsubscribe” link in those emails or by contacting us (see the “Contact Us” section). 

  • Cookies and Online Tracking. You can manage cookie preferences through your browser settings or by using cookie management tools where offered. In some regions, you may also be presented with a cookie consent banner. For additional detail about the types of Cookies we use, their purposes, and your options for managing them, please see the Appendix: Cookies and Similar Technologies at the end of this Privacy Policy.

D. How to Exercise Your Rights

You may exercise your rights by contacting us via: 

We will verify your request consistent with applicable law. If you use an authorized agent to submit a request, we may require proof of authorization and verification of your identity. 

E. Limitations

These rights may be subject to legal limitations or exceptions. For example, we may retain certain information to comply with law, prevent fraud, or for other legitimate purposes.

V. Third Parties

Our Services may link to websites, applications, or services that we do not own or control. This Privacy Policy does not apply to those third parties, and we are not responsible for their privacy practices. If you choose to use these third-party services, any Personal Information you provide will be governed by their privacy policies. We encourage you to review those policies before sharing information.

VI. Data Retention

We retain Personal Information for as long as necessary to fulfill the purposes described in this Privacy Policy, unless a longer period is required by law. Retention periods vary depending on the type of information, our relationship with you, and applicable legal requirements (such as tax, accounting, or litigation hold obligations). When Personal Information is no longer needed, we delete or de-identify it in accordance with our data retention policies.

VII. Information Security

We use technical, organizational, and physical safeguards designed to protect Personal Information. However, no method of transmission or storage is completely secure, and we cannot guarantee absolute security of your information.

VIII. Children’s Privacy

Our Services are not directed to children under 18, and we do not knowingly collect Personal Information from them. If we become aware that we have collected Personal Information from a child under 18, we will delete it. If you believe a child has provided us with Personal Information, please contact us at privacy@submittable.com

If you are located in the EEA or UK, please note that the minimum age for valid consent to online services may be different (up to 16), depending on your country.

IX. International Data Transfers

Our Services are hosted in the United States. If you access the Services from outside the United States, your Personal Information may be transferred to and processed in the United States and other countries that may not provide the same level of data protection as your home jurisdiction. 

For transfers from the EEA, UK, and Switzerland, we rely on appropriate safeguards such as the European Commission’s Standard Contractual Clauses (or UK Addendum, where applicable). In some cases, we may rely on your consent or the necessity of the transfer to perform our contract with you. To request more information about these safeguards, or to obtain a copy of the contractual safeguards we use for such transfers (if applicable), please contact us (see the section “Contact Us”).

X. Update Your Information

You can update your account and profile information through your profile settings or by writing or emailing us at our contact information provided below.

XI. Changes to This Privacy Policy

This Privacy Policy may be revised from time to time. We will post any adjustments to the Privacy Policy on this page, and the revised version will be effective as of the last updated date. If we materially change the ways in which we use or disclose Personal Information previously collected from you through our Services, we will attempt to notify you of the changes through our Services, by email (sent to the email address specified in your account), or other means.

XII. Contact Us

If you have any questions or concerns about this Privacy Policy or our privacy practices, or if you would like to exercise your rights, you can reach us at: 

Data Protection Officer. Submittable’s designated Data Protection Officer (DPO) is Jamie Iguchi, legal@submittable.com

Appendix: Cookies and Similar Technologies

Strictly Necessary and Security

Name

Provider

Purpose / Description

Duration / Expiry

Type

@@scroll|/*

Gatsby

Stores scroll position for each page so that when a visitor navigates within the site and returns, their previous position is restored. No personal data is stored or transmitted.

Session

Strictly Necessary / Functional

_cfuvid

Cloudflare

Identifies unique visitors to assist rate-limiting and distinguishing users behind the same IP

Session or up to 30 minutes

Strictly Necessary / Security

__cf_bm

Cloudflare

Distinguishes between human users and bots to help protect the site from abusive or automated traffic

30 minutes of inactivity

Strictly Necessary / Security

__Secure-3PAPISID

Google Ads & Identity (Google LLC) / third-party

Used by Google for security, fraud prevention, and advertising personalization. Helps build a profile of visitor interests for targeted advertising across Google services.

Persistent (often 6 months to 1 year)

Security / Advertising

AEC

Google (Google LLC)

Helps confirm requests in a browsing session are from the same user (anti-cross origin)

Session

Security / Functional

redirect_www_to

Submittable

Used internally by Submittable’s SaaS platform to recognize returning users or organizational accounts when navigating between Submittable’s marketing site and the main application, improving navigation and login continuity. No data is shared externally.

Session

Strictly Necessary / Functional

Performance and Functional

Name

Provider

Purpose / Description

Duration / Expiry

Type

_ga

Google Analytics (Google LLC)

Assigns a unique ID to distinguish website users

2 years

Performance / Analytics

_ga_#

Google Analytics (Google LLC)

Distinguishes unique users (client identifier) within GA4

2 years

Performance / Analytics

_gid

Google Analytics (Google LLC)

Distinguishes users on a per-day basis

24 hours

Performance / Analytics

__hs_cookie_cat_pref

Hubspot

Stores user cookie consent preferences by category (analytics, marketing, etc.)

6 months

Functional / Consent

Intercom-session

Intercom

Tracks the current chat / session state

Session

Functional

Advertising, Marketing, and Analytics

Name

Provider

Purpose / Description

Duration / Expiry

Type

_clck

Microsoft Clarity (Microsoft Corporation)

Persists the Clarity User ID and preferences to attribute returning visitors

1 year

Analytics

_clsk

Microsoft Clarity (Microsoft Corporation)

Aggregates multiple pageviews into one session recording

1 day

Analytics

_cltk

Microsoft Clarity (Microsoft Corporation)

Tracks user interactions (clicks, scroll, etc.)

Session

Analytics / Functional

_fbp

Facebook (Meta Platforms, Inc.)

Sets a unique identifier to deliver, measure, and improve ads across Facebook

3 months

Advertising / Marketing

_gcl_au

Google Ads (Google LLC)

Used to experiment with ad conversion efficiency across sites

90 days

Advertising / Marketing

_gcl_ls

Google Ads (Google LLC)

Stores ad click information to help attribute conversions

90 days (persistent)

Advertising / Marketing

_uetsid

Bing / Microsoft Advertising

Tracks user interactions within a single browsing session for Microsoft Advertising analytics and conversion measurement

30 minutes (session)

Advertising / Marketing

_uetsid_exp

Bing / Microsoft Advertising (Microsoft Corporation)

Stores the expiration timestamp for the corresponding _uetsid cookie

(same as _uetsid)

Advertising / Marketing

_uetvid

Bing/Microsoft Advertising

Tracks visitors across websites to tailor ads to user preferences.

13 months (persistent)

Advertising / Marketing

_uetvid_exp

Bing / Microsoft Advertising (Microsoft Corporation)

Stores the expiration timestamp for the _uetvid cookie, which is used to track visitors across websites and deliver more relevant advertising.

(same as _uetsid)

Advertising / Marketing

_zitok

Zoominfo

Stores a unique identifier for user tracking

1 year

Marketing / Advertising

__hssc

Hubspot

Tracks sessions and whether to increment session counter in __hstc

30 minutes

Analytics

__hssrc

Hubspot

Indicates whether the browser has restarted (to start a new session)

Session

Analytics / Session

__hstc

Hubspot

Main analytics tracking cookie (tracks first, last visit, number of sessions)

6 months

Analytics

__ptq.gif

HubSpot

Records anonymous page view data

Session

Analytics

AnalyticsSyncHistory

LinkedIn

Tracks timing of syncs (e.g. with analytics or ad cookies)

30 days (persistent)

Analytics / Marketing

ANONCHK

Microsoft / Bing / Clarity

Verifies that ad clicks are genuine (ensures MUID transfer / integrity for Microsoft’s ad systems)

10 minutes (short-lived)

Advertising / Marketing

bcookie

Linkedin Ad Analytics

Ensures optimal ad delivery and tracking on LinkedIn’s domain

1 year

Advertising / Marketing

bscookie

Linkedin Ad Analytics

Used for LinkedIn sign-in and social plugins across sites

1 year

Functional / Advertising

c.gif

Microsoft Clarity (Microsoft Corporation)

Sends usage data (page views, events) back to Clarity servers

Session

Analytics

CLID

Microsoft Clarity (Microsoft Corporation)

Identifies when a user was first seen by Clarity on any site

1 year

Analytics

hubspotutk

Hubspot

Identifies a visitor for deduplication and tracking across sessions

6 months

Analytics / Marketing

IDE

DoubleClick / Google Ads (Google LLC)

Measures conversions and ad effectiveness across websites

~1 year

Advertising / Marketing

li_sugr

Linkedin

Used to probabilistically match user identity for ad targeting

Persistent

Advertising / Marketing

lastExternalReferrer

Facebook (Meta Platforms, Inc.)

Records the last external website that referred the visitor to a page containing Facebook technology, used for ad attribution and performance measurement

Session or short-lived (typically deleted when the browser session ends)

Advertising / Marketing

lastExternalReferrerTime

Facebook (Meta Platforms, Inc.)

Stores timestamp of last external referral

Session

Advertising / Marketing

lidc

LinkedIn

Helps manage data center selection for LinkedIn’s services

1 day

Marketing / Functional

MR

Microsoft Clarity (Microsoft Corporation)

Used by Microsoft to reset or refresh the MUID cookie, ensuring consistent ad delivery and accurate measurement of advertising performance across Microsoft domains.

7 days

Advertising / Marketing

NID

Google Ads (Google LLC)

Stores preferences and profile info for personalized ads

6 months

Advertising / Marketing

sb

Facebook (Meta Platforms, Inc.)

Helps Facebook identify browsers securely for login authentication, account recovery, and fraud prevention, and may also be used for advertising measurement and personalization

2 years (persistent)

Advertising / Marketing

SID

Google (Google LLC)

Identifies signed-in Google account sessions for analytics / ads purposes

2 years

Analytics / Advertising

SIDCC

Google (Google LLC)

A variant related to cross-domain / same-site checks

1 day

Analytics / Advertising

SM

Microsoft Clarity (Microsoft Corporation)

Session cookie to enable session-level behavior tracking

Session

Analytics

SRM_B

Microsoft Advertising (Microsoft Corporation)

Unique identifier for ad server interactions via Atlas / Bing

180 days

Advertising / Marketing

test_cookie

DoubleClick / Google Ads (Google LLC)

Checks whether the browser supports cookies (for ad serving)

Session

Advertising / Marketing

UserMatchHistory

LinkedIn

Stores information for LinkedIn’s ad targeting and matching

Persistent

Advertising / Marketing