Surge Playbooks
Privacy policy
What Surge Playbooks collects, why, who else sees it, and how to get it changed or removed. This site is a private library for the Surge team and approved Surge Partners, so almost everything here is about people who have asked for an account.
Last updated 9 September 2026.
Who this is about
Surge Playbooks is operated by Surge Global. It is a library of sector playbooks, case studies and pitch decks used by the Surge team and by approved Surge Partners, together with a console the team uses to run the partner network.
If you want anything in this policy explained, changed or acted on, write to bhanuka@surge.global and a person will answer.
What we collect
When you create an account with an email address and a password:
- Your name and email address.
- Your company, if you give one.
- Your password, stored only as a scrypt hash. We cannot read it and we cannot recover it.
When you sign in with Google instead, Google tells us:
- Your name, your email address and whether Google has verified it.
- The stable account identifier Google uses for you, which is how we recognise you next time even if your address is renamed.
- The URL of your Google profile picture. We store the address and do not display the image.
When you apply to become a Surge Partner, the answers you give us:
- Your company and your role.
- Your LinkedIn address and phone number, if you give them.
- The industries and regions you can open doors in.
- What you write about the relationships you hold, any live opportunity, and why you want to work with us.
When you introduce an opportunity or ask for a playbook:
- The business you are introducing, its industry, its market and its size.
- The name and email address of your contact there, if you give them.
- What you write about the situation, and how urgent it is.
The contact details you give us belong to somebody who has not visited this site and has not agreed to anything here. We use them only to follow up the introduction you made. Only give us details you are entitled to share, and tell that person you have passed them on. If they ask us to remove their details, we will.
As you use the site, we record what happens:
- Which playbooks and decks are opened, which PDFs are downloaded, which links are shared, and when.
- When you sign up and when you sign in.
- The last time your account was active.
- If you are signed in, those records are attached to your account, because knowing which partners are active is the point of keeping them.
- If you are not signed in, they are attached to an identifier we build by hashing your network address together with your browser description, the day's date and a secret. It changes every day and cannot be turned back into an address. We do not store your network address itself.
Because this is a private library, we also keep:
- Notes a member of the Surge team writes about an application or an account.
- A record of every email the site sends you, and whether you asked to stop receiving updates.
- A permanent record of administrative actions: who approved, blocked, changed or deleted an account, and when. It holds the email address of the account concerned, because a record of a deletion that does not say what was deleted is not a record.
What we do not collect
- No payment details. Nothing on this site takes money.
- No advertising or analytics trackers. There is no Google Analytics, no advertising pixel and no third party script of any kind.
- No location data, camera or microphone access. The site tells your browser to refuse those outright.
- Nothing is written to your browser's local storage.
Cookies
Every cookie this site sets is necessary for it to work, which is why you are not asked to accept anything.
- A session cookie that keeps you signed in. It is signed, cannot be read or edited by scripts, and is refused the moment your account is blocked, deleted or has its role changed.
- A short cookie proving an administrator confirmed their password before doing something irreversible. It lasts ten minutes.
- Four temporary cookies during a Google sign in, holding the values that prove the answer coming back belongs to the attempt you started. They last ten minutes and are cleared as soon as you are signed in.
Why we hold it, and on what basis
- To give you the account you asked for and to keep it secure. That is us performing the agreement between us.
- To decide whether to approve a partner application, and to work the introductions partners bring in. That is our legitimate interest in running a partner network, and yours in being paid for what closes.
- To know which playbooks are being used and by whom, so we write the ones that are missing. That is our legitimate interest in a library that earns its keep.
- To send you the emails that make an account work, such as confirming your address and telling you the outcome of your application.
- To keep an administrative record, which is our legitimate interest in being able to answer for decisions about somebody's access.
Partner updates are separate from all of that. Every one of them carries a link that takes you off the list in one click, and we never send them to somebody who has used it.
Who else sees it
Four outside services are involved, and no others:
- Railway, which hosts the site and the database it runs on. Everything described above is stored there.
- Resend, which delivers the email the site sends. It sees the address the message goes to and its contents.
- Google, if you choose to sign in with Google. Google tells us who you are and knows that you signed in here.
- Google Fonts, which serves the two typefaces this site uses. Your browser fetches them from Google's servers, which means Google sees your network address when a page loads, whether or not you have an account.
When you choose a password we check it against a public list of passwords known to have leaked, so we can refuse one that is already in an attacker's dictionary. Your password does not leave this server to do it. We send the first five characters of an irreversible hash of it and compare the answer here, which is a method designed so the service cannot tell which password was being asked about.
We do not sell anything about you, and we do not pass anything to advertisers or data brokers. We would disclose information if the law required it, and we would tell you unless we were prohibited from doing so.
How long we keep it
- Your account and your partner application, for as long as the account exists.
- Records of what was opened, downloaded and shared, for as long as they are useful for understanding which playbooks are worth writing.
- Emails we sent you, as a record of what went out.
- The administrative record, permanently. It is what lets us say who decided what about an account, and it is never edited or deleted.
When an account is deleted we remove the name, the email address, the company, the phone number, the password and the link to any Google account, and the partner application is deleted outright. The introductions that person made are kept and attached to a deleted account, because they are a record of business the company received rather than a record about the person. The administrative record of the deletion keeps the email address.
Your rights
You can ask us to:
- Tell you what we hold about you and give you a copy.
- Correct anything that is wrong. Most of it you can correct yourself by signing in.
- Delete your account and the personal details attached to it, subject to what is described above.
- Stop sending you partner updates. The link at the bottom of every one of them does this immediately, without signing in.
- Stop using your information in a particular way, or object to us using it at all.
Write to bhanuka@surge.global. We do not charge for any of this and we will answer within thirty days. If you are unhappy with the answer, you can complain to the data protection authority where you live.
How it is protected
- Passwords are stored as scrypt hashes and are never written to a log.
- Everything travels over an encrypted connection, and the site tells browsers never to use an unencrypted one.
- Signing out, being blocked, being deleted or having your role changed ends every session you hold, on every device, immediately.
- Administrator sessions expire after thirty minutes of inactivity and twelve hours in total, and anything irreversible asks for the password again first.
- Logs are written through a filter that masks email addresses and refuses to record passwords, tokens or session cookies.
- The number of times anybody can attempt to sign in, sign up or request an email is limited.
No system is perfect. If something goes wrong and your information is affected, we will tell you and the relevant authority as quickly as we can.
Children
This is a business tool. It is not intended for anybody under 18 and we do not knowingly hold information about children. If you believe we do, write to us and we will remove it.
Changes
If this policy changes in a way that matters, we will change the date at the top and tell account holders by email. Continuing to use the site after that means the new version applies.