Privacy Policy
Effective Date: February 26, 2026
SurfBloom, Inc. ("SurfBloom," "we," "us," or "our") respects your privacy and is committed to protecting your personal information. This Privacy Policy explains how we collect, use, disclose, and protect information when you use the SurfBloom platform, website, APIs, or any related services (collectively, the "Service").
By using the Service, you agree to the collection and use of information in accordance with this Privacy Policy. If you do not agree, do not use the Service.
1. Who This Policy Applies To
This Privacy Policy applies to two groups:
- Customers — individuals or businesses that register for and use the SurfBloom platform to manage their marketing, communications, and operations.
- End Users — individuals who receive communications (such as SMS messages, emails, surveys, or review requests) sent by our Customers through the SurfBloom platform. If you are an End User, the business that sent you a message is the controller of your data. Please contact that business directly for questions about how your information is used. This Privacy Policy describes how SurfBloom processes that data on the Customer's behalf.
2. Information We Collect
Information You Provide Directly
- Account registration information, including your name, email address, phone number, business name, business address, and Employer Identification Number (EIN) for messaging compliance registration.
- Payment and billing information processed through our third-party payment provider. SurfBloom does not store full credit card numbers on our servers.
- Contact lists and End User data you upload or collect through the Service, including names, phone numbers, email addresses, tags, notes, and any custom fields you create.
- Content you create through the Service, including messages, workflows, campaigns, survey questions, task descriptions, and AI-generated content.
- Communications you send to us, such as support requests, feedback, and emails.
Information Collected Automatically
- Usage data, including pages visited, features used, workflows created, messages sent, and actions taken within the Platform.
- Device and browser information, including IP address, browser type, operating system, and device identifiers.
- Cookies and similar tracking technologies as described in Section 8 of this Privacy Policy.
- Log data, including access times, error logs, and referring URLs.
Information from Third Parties
- Information received from third-party services you connect to SurfBloom, such as Google Business Profile data, review data from public platforms, and data from integrated messaging providers.
- Information from our messaging infrastructure provider (Twilio) related to message delivery status, carrier responses, and compliance data.
3. How We Use Your Information
We use the information we collect for the following purposes:
- To provide, operate, and maintain the Service, including sending messages, executing workflows, managing contacts, and processing campaigns on your behalf.
- To create and manage your account, process payments, and provide customer support.
- To facilitate A2P 10DLC registration and messaging compliance with carriers and The Campaign Registry (TCR).
- To process your Content through third-party AI providers (Anthropic, OpenAI, Google, xAI) when you use AI-powered features. Only the minimum information necessary to generate the requested content is sent to these providers.
- To monitor messaging activity for compliance with applicable laws, carrier policies, and our Terms of Service.
- To improve and develop the Service, including analyzing usage patterns, troubleshooting issues, and developing new features.
- To send you Service-related communications, including account notifications, billing reminders, security alerts, and product updates.
- To protect the safety, security, and integrity of the Service and our users.
- To comply with legal obligations, respond to lawful requests, and enforce our Terms of Service.
4. How We Share Your Information
We do not sell, rent, or trade your personal information or your End Users' personal information to third parties for their marketing purposes.
We may share your information in the following circumstances:
- Service Providers. We share information with third-party service providers who perform services on our behalf, including Twilio (messaging delivery), cloud hosting providers, payment processors, and AI providers. These providers are contractually obligated to use your information only to provide services to us and in accordance with this Privacy Policy.
- AI Providers. When you use AI-powered features, the content of your prompts and relevant business context is sent to the AI provider you select (Anthropic, OpenAI, Google, or xAI) to generate the requested content. We do not send your full contact database or account information to AI providers.
- Compliance and Legal Requirements. We may disclose your information if required by law, subpoena, court order, or government request, or if we believe in good faith that disclosure is necessary to protect our rights, your safety, or the safety of others, to investigate fraud, or to respond to a government request.
- Business Transfers. If SurfBloom is involved in a merger, acquisition, or sale of assets, your information may be transferred as part of that transaction. We will notify you of any such change by email or prominent notice on the Platform.
- With Your Consent. We may share your information with third parties when you have given us explicit consent to do so.
5. End User Data and Your Responsibilities
When you use SurfBloom to collect and manage End User data, you act as the data controller and SurfBloom acts as a data processor. You are responsible for:
- Providing appropriate notice to your End Users about how their data is collected and used.
- Obtaining all required consents from End Users before collecting their data or sending them communications through the Service.
- Complying with all applicable privacy laws, including applicable state privacy laws, with respect to the End User data you collect and process through the Service.
- Responding to End User requests regarding their personal data, including requests for access, correction, or deletion.
SurfBloom will assist you in responding to End User data requests to the extent the request relates to data processed through the Service.
6. SMS and Messaging Data
When you send SMS or email messages through the Service, we collect and retain the following data for compliance and operational purposes:
- Message content, including the text of sent and received messages.
- Delivery status and carrier responses.
- Opt-in and opt-out records, including the method and timestamp of consent.
- Message logs, including sender, recipient, timestamp, and associated workflow or campaign.
This data is retained for as long as your account is active and for a reasonable period after termination to comply with legal and regulatory requirements. Mobile information collected through the Service is never shared with or sold to third parties for their marketing or promotional purposes.
7. Data Security
We implement commercially reasonable administrative, technical, and physical safeguards to protect your information from unauthorized access, use, alteration, and disclosure. These measures include encryption of data in transit and at rest, access controls, secure cloud infrastructure, and regular security assessments.
However, no method of transmission over the internet or method of electronic storage is completely secure. We cannot guarantee the absolute security of your information. You are responsible for maintaining the security of your account credentials and for any activity that occurs under your account.
8. Cookies and Tracking Technologies
We use cookies and similar technologies to operate and improve the Service. These include:
- Essential Cookies — required for the Service to function, including authentication, session management, and security.
- Analytics Cookies — used to understand how the Service is used so we can improve it. These may include third-party analytics services.
You can control cookie settings through your browser. Disabling essential cookies may prevent you from using certain features of the Service.
We do not respond to Do Not Track signals at this time.
9. Data Retention
We retain your account data and Content for as long as your account is active and as needed to provide the Service.
Upon termination of your account, we retain your data for 30 days to allow for account recovery. After 30 days, your data is permanently deleted from our systems, except where retention is required by law or for legitimate business purposes such as resolving disputes, enforcing our Terms, or complying with legal obligations.
Messaging logs and compliance records may be retained for a longer period as required by applicable telecommunications regulations.
10. Your Rights and Choices
Depending on your location, you may have the following rights regarding your personal information:
- Access. You may request a copy of the personal information we hold about you.
- Correction. You may request that we correct inaccurate or incomplete personal information.
- Deletion. You may request that we delete your personal information, subject to certain exceptions required by law.
- Data Portability. You may request an export of your data in a standard, machine-readable format.
- Opt-Out of Communications. You may opt out of marketing communications from SurfBloom at any time by following the unsubscribe instructions in our emails or by contacting us directly. This does not apply to Service-related communications necessary for the operation of your account.
To exercise any of these rights, contact us at privacy@surfbloom.com. We will respond to your request within 30 days.
11. Children's Privacy
The Service is not intended for use by individuals under the age of 18. We do not knowingly collect personal information from children under 18. If we learn that we have collected personal information from a child under 18, we will take steps to delete that information promptly. If you believe a child has provided us with personal information, please contact us at privacy@surfbloom.com.
12. Third-Party Links and Services
The Service may contain links to third-party websites or integrate with third-party services. This Privacy Policy does not apply to those third-party services. We encourage you to review the privacy policies of any third-party services you access through or in connection with the Service.
13. International Users
The Service is operated from the United States. If you access the Service from outside the United States, your information will be transferred to and processed in the United States. By using the Service, you consent to the transfer of your information to the United States.
14. Changes to This Privacy Policy
We may update this Privacy Policy from time to time. If we make material changes, we will notify you by email or through the Platform at least 30 days before the changes take effect. Your continued use of the Service after the effective date of the revised Privacy Policy constitutes your acceptance of the changes.
The date at the top of this Privacy Policy indicates when it was last updated.
15. Contact Us
If you have questions about this Privacy Policy or our data practices, please contact us at: