Skip to content

Privacy policy

Last updated August 19, 2026

Scope and roles

This policy explains how DeckPeek handles personal information when people visit our website, create or join a workspace, upload and share content, view a shared document, purchase a plan, contact support, or submit an abuse report.

DeckPeek is an independently operated service based in the United States and is responsible for personal information it handles for its own purposes. Privacy questions can be sent to hello@deckpeek.com.

Workspace owners decide which documents to share, which access controls to use, and whether to collect viewer email addresses. For personal information a customer submits or collects through those features, the customer may be the party responsible for deciding how that information is used. Viewers should also review any notice provided by the person or organization that sent the link.

Information we collect

Account and workspace information

We collect names, email addresses, password authentication records, workspace names, roles, invitations, notification preferences, branding settings, connected domains, and account activity. For account security and service insights, we also record successful sign-in times, network addresses, browser or device details, and the approximate country observed by our network when an account is created or used. An observed country may not reflect where someone lives.

Content and sharing information

We store uploaded files and related metadata such as titles, descriptions, file names, types, sizes, versions, folders, share-link settings, access rules, agreements, and download permissions.

Viewer and usage information

When a shared link is opened, we may record opening time, viewing duration, page-level engagement, return visits, browser or device details, referrer, approximate country, and access events. If the sender enables email collection or verification, we also process the viewer’s email address and related agreement acceptance.

First-party product measurement

In the signed-in service, we count daily views of twelve fixed dashboard screen categories and calculate aggregate internal metrics from existing service records, such as account and workspace creation, upload attempts and completions, share-link creation, recipient opens, and completed checkouts. This first-party measurement does not use Google Analytics or add tracking cookies. The daily screen counters contain no account, workspace, session, route, referrer, device, or content identifier, and the internal aggregates do not expose names, email addresses, document titles, file names, viewer identities, or private URLs.

Regional Google Analytics controls

We use Google Analytics on the home, help, guides, pitch deck analytics, pitch deck sharing, security, privacy, terms, and acceptable-use pages and on authenticated dashboard pages, subject to the regional controls described below. Public page views contain only the site origin and page path without query parameters or fragments and the referring site’s origin without its path. On dashboard pages, we use a server-derived pseudonymous user identifier and a broad, sanitized screen name to understand how an account uses product features across sessions. Google Analytics also ordinarily processes browser, device, pseudonymous cookie, and coarse location information.

When analytics is allowed, we also measure completed account signup, creation of a workspace’s first share link, and a verified initial Pro purchase when the buyer returns from checkout. Signup measurement is sent from the dashboard after authentication completes. Purchase events include an invoice transaction identifier to prevent duplicate counting, the currency, the amount excluding tax, and the billing interval. These events follow the same regional analytics controls. Eligible events may wait in this tab for up to fifteen minutes while the dashboard and analytics load. Local delivery markers are retained for up to 180 days to avoid repeat counting and are cleared when analytics is declined.

We do not send Google Analytics names, email or street addresses, workspace, document, link, or folder identifiers, titles, file names, viewer or recipient details, custom domains, query parameters, fragments, private URLs, or more than the referring site’s origin. We do not run Google Analytics on contact or abuse-report forms, authentication or invitation pages, operations pages, recipient previews, or shared document pages.

Billing, communications, and safety

We receive subscription status and transaction identifiers from Stripe, but we do not store full payment-card details. We also process support messages, authentication emails, security events, and abuse reports, including contact details provided by the reporter.

Where information comes from

  • Directly from account holders, workspace members, and viewers.
  • Automatically from browsers, devices, shared-document activity, and our security systems.
  • From workspace owners who invite members or configure viewer access.
  • From service providers such as Stripe, Cloudflare, Google Cloud, and, when enabled under the regional setting or a person’s saved choice, Google Analytics.

How we use information

  • Provide accounts, workspaces, uploads, sharing, and analytics.
  • Apply link protections, verify access, send requested notifications, and prevent unauthorized use.
  • Process subscriptions, maintain plan limits, and provide billing support.
  • Diagnose failures, maintain reliability, understand feature usage, and improve the service.
  • Understand broad country-level account usage without treating an observed network country as someone’s residence.
  • Review successful account access, show recent session activity, and help investigate suspicious sign-ins.
  • Detect fraud, investigate abuse, enforce our policies, protect legal rights, and comply with lawful requests.
  • Communicate about accounts, service changes, and support requests.

How information is shared

Workspace participants. Workspace owners and authorized members can access workspace content, settings, member details, and analytics according to their role. Senders can see viewer information and activity associated with their links.

Workspace-configured webhooks. When a workspace owner or admin enables webhooks, selected activity is sent to the endpoints they configure. Depending on the event, this includes workspace, document, link, and visit identifiers, document titles, and captured viewer email addresses with verification status. Webhook payloads exclude document content, comment text, passwords, and access tokens.

Service providers. Cloudflare provides application, database, object-storage, network, domain, and service-email infrastructure; Stripe processes subscriptions and payment information; Google Cloud supports automated processing for certain uploaded media; and Google Analytics measures eligible public and authenticated dashboard usage when enabled under the regional setting or a person’s saved choice. These providers process information to perform services for us and are subject to their own contractual and legal obligations.

Legal, safety, and business events. We may disclose information when reasonably necessary to comply with law, respond to valid legal process, protect people or rights, investigate misuse, or complete a merger, financing, acquisition, or sale of assets subject to appropriate protections.

Cookies and similar technology

We use cookies and similar storage that are necessary to keep people signed in, remember theme or access state, protect share links, and maintain security. Shared-link access cookies can contain signed access evidence and expire automatically.

We use Cloudflare’s request-country signal to choose the analytics default; this signal can be affected by a VPN or network routing. For visitors detected in the European Economic Area, United Kingdom, or Switzerland, and whenever the country is unavailable, Google Analytics loads only after the person selects “Allow analytics.” In other regions, it may load by default on eligible public and dashboard pages. It may then set first-party cookies whose names begin with _ga.

We do not save an automatic regional allowance as consent. An explicit choice lasts for six months and follows the browser between eligible public and dashboard pages. We keep Google Signals, user-provided data collection, ad storage, and ad personalization off. Anyone can open Analytics preferences and select “No thanks”; doing so prevents future loading and clears available Google Analytics cookies. We do not use advertising cookies.

Retention and deletion

We retain information for as long as needed to provide the service, maintain legitimate business and security records, resolve disputes, and meet legal obligations. Retention depends on the type of record, workspace settings, account status, and whether a safety or legal preservation obligation applies.

Account settings include tools to export account data and request deletion. Deleting a document, workspace, or account removes related records and stored files through the service’s deletion process, except where limited information must be retained for security, billing, fraud prevention, legal compliance, or an active preservation hold. Optional Google Analytics data follows the separate retention period described below rather than the customer-content deletion lifecycle.

First-party daily dashboard screen counters are kept for 180 days. Other internal product totals are calculated from the service records described above and follow those records' deletion lifecycle.

Our separate recent successful-sign-in history keeps no more than 50 events for an account. Session records used to maintain and manage signed-in devices are kept separately. Sessions, the bounded history, and the account’s latest sign-in, last-seen, and signup-country records are included in the account export and deleted with the account, unless a legal preservation obligation applies.

Activity history in a workspace you did not own may retain a snapshot of your name and email until that workspace is deleted, so the workspace can preserve who performed an action. Account exports cover account and workspace metadata; they do not include password hashes, access tokens, or the file bodies of uploaded documents.

Google Analytics event and user-level exploration data is configured for the standard property’s maximum 14-month period, with the period reset when a user returns. Google explains that standard reports based on aggregated data can remain available beyond that period. This optional website and product-usage measurement is separate from the viewer analytics a workspace owner receives for shared documents.

Your choices and rights

Depending on where you live, you may have rights to access, correct, delete, restrict, object to, or receive a portable copy of personal information. You may also have the right to appeal a decision or complain to a data-protection authority.

Account holders can update profile settings, export account data, manage notifications and sessions, and request account deletion from the dashboard. Viewers seeking access to information controlled by a workspace should first contact the sender. You can also contact us for assistance, and we may need to verify your identity before acting on a request.

Anyone can use Analytics preferences to allow, decline, or later withdraw website and dashboard analytics.

Security and international transfers

We use technical and organizational safeguards designed to protect information. No internet service can guarantee absolute security, so use available access controls and avoid uploading information you are not authorized to share. More detail appears on our security page.

We and our providers may process information in countries other than where you live. Where required, we use recognized transfer mechanisms and contractual protections for cross-border processing.

Children

The service is not directed to children under 13, and we do not knowingly collect personal information from a child under 13. The minimum age may be higher where local law requires it. Contact us if you believe a child has provided personal information improperly.

Changes and contact

We may update this policy as the product, providers, or law changes. We will post the new effective date and provide additional notice for material changes when appropriate.

Send privacy questions or rights requests to hello@deckpeek.com or through the contact page. Safety reports should use the dedicated abuse-reporting process.

Contact us about privacy · Report abuse