Privacy Statement
20-01-2025
This privacy statement applies to all visits to our website (www.secretview.io), our platform (https://platform.secretview.io), the mobile application, the agreement that arises between you and us if you register on our platform as a community member, as well as the assignment you will carry out as a mystery shopper. By visiting the website, platform, or mobile application, you agree to this statement. Changes to this statement will be valid from the moment they are modified, as indicated above with "Last update." When this statement changes, we will notify you accordingly. We, Secret Collect B.V., hereinafter referred to as "Secret View," are responsible for processing personal data as described in this privacy statement. Our contact details are:
Secret View
Velperplein 23A
6811 AH Arnhem
CoC no.: 62351761
Phone: 026 - 20 22 151
Email: support@secretview.io
This privacy statement was originally written in Dutch. In case of a conflict between a translated version of this document and the Dutch version, the Dutch version will always take precedence. This privacy statement may be amended at any time by Secret View. Questions and/or comments about this privacy statement are welcome via the live chat on the platform or via support@secretview.io.
The short version
We consider it important to protect your privacy. Therefore, in this privacy statement, we explain which personal data we process and why we do so. The (personal) data we collect will never be sold or shared with third parties without your explicit consent. Below, you will find a summary of the key points, but we recommend reading the full version carefully!
- We collect all information, including personal data, that you provide to us. Additionally, technical information (such as cookies) is stored to ensure your experience on the website and platform is as comfortable and personalized as possible.
- We store all data on secure servers that are inaccessible to unauthorized persons.
- On the platform, we use various technical mechanisms to automate our processes. Automated decision-making is applied based on profile and experience, for example, to determine the suitability of a mystery shopper for an assignment.
- If you wish to exercise your right to object and/or your right to data portability or have other questions/comments about data processing, please send a specified request to support@secretview.io.
The long read
Personal data we process
We process personal data of the following parties:
- Visitors to the website www.secretview.io;
- Individuals who have registered as members of the community; and
- Contact persons of Secret View's clients.
For each category of individuals, we outline below which personal data we process and for what purposes.
1. Website visitors
We process personal data of visitors to our website www.secretview.io through cookies and similar techniques, such as web beacons.
A cookie is a small text file that is stored in your browser on your computer, tablet, or smartphone upon your first visit to the website. We use functional, analytical, and tracking cookies. Upon your first visit to our website, we informed you about these cookies and requested your consent for their placement.
You can find all information about our cookies in the Cookie Policy.
2. Community members
When you register on our platform as a community member or perform assignments for us, we process your personal data. Below is an overview of the personal data we process:
- First and last name
- Gender
- Date of birth
- Country of birth
- Place of birth
- Address details
- Citizen service number
- Country of issuance of identity document
- Phone number
- Email address
- Other personal data actively provided, such as through a profile on this website, in correspondence, and by phone
- Location data
- Bank account number
- Paid amounts, including expense reimbursements
Without the above data, we cannot execute the agreement.
For our legitimate interest (compliance with laws and regulations), we process data related to complaints or reports of (alleged) unlawful conduct to comply with laws, regulations, and judicial rulings if necessary.
Purpose of processing personal data
We process your personal data for the following purposes:
- Providing the possibility to create an account;
- Assigning an assignment to you;
- Communicating with you in the context of executing an assignment;
- Processing a payment;
- Verifying your age when you register for an age-restricted study, such as the NIX18 compliance check;
- Analyzing your behavior on our website to improve the website and tailor the offering of products and services to your preferences;
- Conducting analyses and anonymized statistics based on your age, income, and other data you have provided to us, enabling us to inform our clients (for example: "mystery shoppers aged 40-45 rate your store the highest");
- Following up on complaints and/or reports;
- Setting up advertising campaigns on social media;
- Fulfilling a legal obligation or a judicial ruling, such as providing data for our tax return and complying with the reporting obligations under the DAC7 legislation and the disclosure obligation (read more at https://www.secretview.io/en/legal/dac7);
- Preventing fraud and abuse.
Further processing of your data
To improve your experience with mystery shopping, your data is processed in an account within our online platform. This ensures that you do not have to re-enter this information for each visit.
Community Approval
Results from research are reviewed for quality before being sent to clients. This review is carried out both automatically using AI and manually by Secret View staff and selected community members known as 'community approvers.' These members are carefully chosen by Secret View. While reviewing, other community members may see your submitted questionnaire. However, measures such as anonymization and a blackout tool minimize the risk of exposing personal data. You are responsible for the information you provide in your responses regarding yourself or others. Community approvers have the authority to adjust and/or improve your responses.
Automated decision-making
We make decisions based on automated processing regarding the scheduling and execution of assignments. These decisions are made by computer programs or systems without human intervention.
Secret View uses the following internally developed software for:
- Managing profiles and accounts
- Viewing all assignments
- Selecting mystery shoppers
- Tracking assignment statuses
- Providing assignment-related information
- Processing payments
Impact on community members
To ensure a smooth transition to automation, each automation step, decision, or action is first presented to an employee or user for confirmation. Once we are confident in the decision-making accuracy, automation proceeds without human intervention. This method ensures a seamless transition for users, enhancing efficiency and usability.
As a community member, you have the right to express your viewpoint regarding an automated decision and to contest it. If you disagree with a decision, you may contact us, and a Secret View employee will personally review it. By agreeing to perform assignments with us, you explicitly consent to this form of automated decision-making.
How long we retain personal data
Secret View does not store your personal data longer than strictly necessary to achieve the purposes for which they are collected. You can delete your account yourself unless there is an ongoing assignment. If you exercise your right to deletion, your profile will be immediately removed from our platform. Other personal data will be deleted upon request via email to mysteryshopping@secretview.io. All personal data will be deleted within two months, except data required to comply with legal obligations. For these data, we adhere to a seven-year retention period due to tax obligations.
3. Contact persons
When a client signs up for our services, we process the following personal data of the client’s contact person. The client has a legitimate interest in this processing, as it enables them to use our services for their business operations.
The following also applies to contact persons who are (co-)owners of the company that engages our services.
We process the following personal data of these contact persons:
- First and last name;
- Company name;
- Telephone number;
- Email address;
- Other personal data actively provided by the contact person, for example, by creating a profile on this website, through correspondence, or via telephone.
Purpose of processing personal data
We process the personal data of contact persons for the following purposes:
- To establish an agreement with the client;
- To facilitate communication regarding the execution of the agreement;
- To process payments;
- To analyze your behavior on our website to improve the website and tailor the offering of products and services to your preferences;
- To follow up on complaints and/or reports;
- To comply with legal obligations or court rulings.
Retention period for personal data
Secret View does not retain your personal data longer than strictly necessary to achieve the purposes for which they were collected. If you exercise your right to deletion, your profile will be immediately removed from our platform. Other personal data will be deleted upon request by sending an email to support@secretview.io. When the agreement with the client ends, all other personal data will be deleted within three months, except for data required to comply with legal obligations. Data necessary to meet legal requirements will be retained for seven years.
4. For all data subjects
The following information applies to all individuals mentioned in this privacy statement.
Sharing personal data with third parties
We do not sell personal data to third parties and will only share it if necessary for the execution of our agreement with you, in the context of our legitimate interest, or to comply with a legal obligation or court ruling.
With companies that process your data on our behalf, we enter into a data processing agreement to ensure the same level of security and confidentiality of your data. We remain responsible for these processing activities.
Companies with which we have a data processing agreement
BDO
Location:
Meander 725, 6825 ME Arnhem
Description:
BDO is the accounting firm that Secret View uses to facilitate payments to community members.
Data shared with BDO:
- Name and address details (N.A.W.-gegevens)
- IBAN (bank account number)
When does this happen?
BDO only receives personal data when an actual payment is made.
Exact Online
Location:
Molengraaffsingel 33, 2629 JD Delft, the Netherlands
Description:
Exact Online is the accounting software that Secret View uses to facilitate payments to community members.
Data shared with Exact Online:
- Name and address details
- IBAN (bank account number)
When does this happen?
Exact Online only receives personal data when an actual payment is made.
Straetus
Location:
Pollaan 43, 7202 BV Zutphen, the Netherlands
Description:
Straetus is a debt collection agency engaged in the event of a payment issue.
Data Shared with Straetus:
- Gender
- Date of birth
- Address details
- Telephone number
- Email address
- Location data
- Bank account number
- Paid amounts, including reimbursements
When does this happen?
When a mystery shopper is required to refund a payment (e.g., by not fully spending the provided amount or canceling the assignment) and fails to do so. After 45 days, the collection process is handed over to Straetus.
Microsoft
Location:
Evert van de Beekstraat 354, 1118 CZ Schiphol, the Netherlands
Description:
Our data hosting is partially managed by Microsoft.
Data Shared with Microsoft:
- First and last name
- Gender
- Date of birth
- Address details
- Telephone number
- Email address
- Other personal data actively provided, such as through profile creation on this website, correspondence, or telephone communication
- Personal data obtained during the identification process
- Personal interests
- Location data
- Bank account number
- Paid amounts, including reimbursements
When does this happen?
Microsoft receives these data on an ongoing basis for data storage purposes. These data are encrypted and therefore not accessible to Microsoft.
Google Cloud
Location:
Google (europe-west-4), Oostpolder 4, 9979 XT Eemshaven, Netherlands
Description:
Our data hosting is partially managed by Google Cloud.
Data shared with Google Cloud:
- First and last name
- Gender
- Date of birth
- Address details
- Telephone number
- Email address
- Other personal data actively provided, such as through profile creation on this website, correspondence, or telephone communication
- Personal data obtained during the identification process
- Personal interests
- Location data
- Bank account number
- Paid amounts, including reimbursements
When does this happen?
Google Cloud receives these data on an ongoing basis for data storage purposes. These data are encrypted and therefore not accessible to Google Cloud.
CM.com
Location:
Konijnenberg 30, 4825 BD Breda, Netherlands
Description:
CM.com enables our employees to contact members of the Secret View community via WhatsApp.
Data shared with CM.com:
- Name
- Telephone number
When does this happen?
These data are used for WhatsApp communication only if the registered user has given permission.
Mollie B.V.
Location:
Keizersgracht 313, 1016 EE Amsterdam, Netherlands
Description:
We use Mollie to send payment requests to community members.
Data shared with Mollie:
- Name and address details (N.A.W.-gegevens)
- IBAN (bank account number)
When does this happen?
In some cases, community members need to refund money due to surpluses in shop credits and/or reimbursements. For more details on refunds, refer to the general terms and conditions.
Mailjet
Location:
4 rue Jules Lefebvre, 75009 Paris, France
Description:
Mailjet enables us to send marketing-related newsletters to individuals who have signed up on our platform.
Data shared with Mailjet:
- Name
- Email address
When does this happen?
These data are used for sending newsletters only if the registered user has given permission.
Postmark
Description:
Postmark enables us to send transactional emails (such as password reset emails) to individuals who have signed up on our platform.
Data shared with Postmark:
- Name
- Email address
When does this happen?
By registering with Secret View, you agree to this processing, as it is necessary for our services.
Crisp.chat
Location:
2 Boulevard de Launay, 44100 Nantes, France
Description:
Crisp is a chat tool that enables us to provide support to users of our services. If you are not logged in, the chat remains anonymous. If you are logged in, Crisp receives the following data:
Data shared with Crisp:
- Name
- Email address
When does this happen?
When the user initiates the chat.
OpenAI
Location:
Address: 1st Floor, The Liffey Trust Centre, 117-126 Sheriff Street Upper, Dublin 1, D01 YC43, Ireland Datacenter: US
Description:
Secret View uses OpenAI for the automation of various processes and analyses. Our agreements with OpenAI ensure that any data sent is used only for the specific task assigned by Secret View and not for model training or enrichment. Where possible, we anonymize and/or limit the data we share. However, the following data may be processed:
Data shared with OpenAI:
- First and last name
- Gender
- Date of birth
- Address details
- Telephone number
- Email address
- Job title
- Other personal data actively provided (e.g., through profile creation, correspondence, or phone communication)
- Personal interests
- Paid amounts, including reimbursements
Data never shared with OpenAI:
Information obtained during identity verification, including:
- Citizen service number
- Country of issuance of identity document
- Photos of an identity document
- Facial photo
- Country of birth
- Place of birth
When does this happen?
Due to the broad application of AI in automation, this may be relevant throughout the entire process, from registration to data analysis at Secret View.
iDenfy
Location:
Barsausko 59, Kaunas, 51423, Lithuania
Description:
iDenfy is a tool we use to securely verify the identity of our community members. This verification is mandatory due to DAC7 and reporting obligations (see: DAC7 Compliance). iDenfy verifies a person's identity by using a combination of an identity document and a photo.
Data shared with iDenfy:
- First and last name
- Gender
- Date of birth
- Country of birth
- Place of birth
- Citizen service number (social security no.)
- Country of issuance of the identity document
- Facial photo
- Photos of an identity document
When does this happen?
As soon as a user completes the identity verification process by submitting the required data via their identity document and photo.
Supahub
Location:
San Francisco, California, US
Description:
Supahub is an advanced customer feedback tool that helps businesses collect, organize, and prioritize customer feedback efficiently. It enables teams to centralize feedback, rank feature requests, and share product updates easily. Key features include in-app widgets for real-time insights, a structured feedback hub, and tools to prioritize requests based on impact and urgency.
Data shared with Supahub:
- First name (if provided by the user)
When does this happen?
As soon as you authorize yourself on the platform, the mentioned data are automatically collected and shared with Supahub to personalize the in-app widget.
Amplitude
Location:
Address (EU Office): Keizersgracht 277, 1016 ED Amsterdam, Netherlands
Headquarters (US Office): 201 3rd Street, Suite 200, San Francisco, CA 94103, United States
Datacenter: EU (AWS Frankfurt)
Description:
Amplitude is a product analytics platform that Secret View uses to understand user behavior.This helps us analyze user interactions and improve the performance of our website and services.
Data shared with Amplitude:
- Origin and source of user traffic
- Viewed pages
- User visit sessions
- Interaction with forms
- Downloaded files
- Clicks and interactions with page elements
- Session replays for behavior analysis
- If provided by the user:
- Geographic and security-related data
- User's preferred language
- Information about the device and browser used
When does this happen?
As soon as the website loads and the cookie banner is accepted, the above data are automatically collected and shared with Amplitude. This allows us to gain real-time insights into user behavior and continuously enhance the website experience.
Meta
Location:
1 Hacker Way, Menlo Park, CA 94025, US
Description:
Meta is the parent company of Facebook, Instagram, and WhatsApp. We use Meta for our recruitment advertisements on social media. Based on our existing community, we create profiles to optimize our recruitment campaigns.
Data shared with Meta:
- Email address
When does this happen?
As soon as a user registers as a community member, their email address is made available for this purpose.
Links
Within Secret View's communication materials, there may be links to other websites that we do not own. We are not responsible for the content and/or privacy protection of these external websites.
We strongly advise you to always read the privacy policy of the respective website before providing any personal data.
Rights of Data Subjects
You have the right to access, correct, deactivate, or delete your personal data. You can do this yourself via the personal settings of your account. If you are still scheduled for assignments, deletion is not possible, but you can deactivate your account. In that case, we will securely store your data for as long as legally required. You also have the right to withdraw your consent for data processing or object to the processing of your personal data by our company. You can request that we provide the personal data we hold about you in a standard format so that you can transfer it to yourself or another organization of your choice.
How to submit a request
To exercise your right to object, data portability, or if you have questions or comments about data processing, send a detailed request to support@secretview.io.
To ensure the request is made by you, we may require identity verification through two-step verification via email and SMS. You will receive two codes that must be verified by Secret View. After verification, we will provide the requested information or process your request.
We will respond as soon as possible, but no later than four weeks after receiving your request.
Additionally, you have the right to file a complaint with the national supervisory authority, the Autoriteit Persoonsgegevens (Dutch Data Protection Authority). You can do so via this link:
Submit a Complaint to the Autoriteit Persoonsgegevens.
How we secure personal data
We take the protection of your data seriously and implement appropriate measures to prevent misuse, loss, unauthorized access, unwanted disclosure, and unauthorized modifications.
Below are our key security measures:
- Keeping infrastructure up to date
- Using security groups
- Encrypting data
- Displaying segmented data
- Using HTTPS for both external and internal communications
- Database backups
- GIT combined with CI/CD for efficient patch management
- Promoting security awareness among both existing and new employees
- Establishing procedures to test, assess, and evaluate security measures
- Creating protocols for handling data breaches and security incidents
- Signing non-disclosure agreements (NDAs)
- Entering into data processing agreements with third parties
- Minimizing the handling of personal data
- Inventorying all data processing activities
- Maintaining a "data vault"
- Limiting the reception of personal data from clients to the absolute minimum
If you suspect that your data is not properly secured or if you have indications of misuse, please contact our customer service or email us at support@secretview.io.
Complaints
You have the right to file a complaint with the Autoriteit Persoonsgegevens (Dutch Data Protection Authority) if you believe that your personal data is not being handled correctly.
Changes to This Privacy Statement
We may update this privacy statement at any time, for example, due to legal changes. We recommend regularly reviewing this statement to stay informed.
Version 20-01-2025