// legal

Privacy Policy

Last updated: April 29, 2026

This Privacy Policy explains how FeedSnap ("FeedSnap", "we", "us", or "our") collects, uses, discloses, and protects information when you use our feedback platform, embeddable widget, dashboard, and related services (collectively, the "Service").

FeedSnap is a B2B SaaS product. Our customers ("Customers") embed our widget on their websites to collect feedback from their own users ("End Users"). For Customer account data we act as a data controller. For End User data submitted through the widget we act as a data processor on behalf of the Customer, who is the controller of that data.

1. Information we collect

1.1 Customer account information

When you create a FeedSnap account we collect:

  • Name and email address
  • A hashed password (we never store passwords in plain text)
  • Organization name and chosen workspace URL slug
  • Role (Admin, Member, Viewer) and team membership
  • Optional profile information you provide

1.2 Billing information

Payments are processed by Stripe. We do not store card numbers or banking details on our servers. We retain only the Stripe customer ID, subscription IDs, plan, billing interval, trial state, and invoice metadata required to operate your subscription.

1.3 End User data captured by the widget

When the widget is embedded on a Customer's site and an End User submits feedback, the widget transmits to FeedSnap:

  • The feedback content the End User typed
  • An annotated screenshot if the End User chose to capture one
  • A DOM-based session replay reconstructed from rrweb events (not a video recording of the screen)
  • Console logs, network request metadata, and JavaScript exceptions captured in the moments leading up to submission
  • Browser user agent, operating system, viewport size, the page URL, and the timestamp of submission
  • Any custom metadata the Customer's site explicitly attaches via window.FeedbackWidget.metadata({…}) — for example a user ID, email, or plan name

The Customer controls what custom metadata is attached and what pages display the widget. FeedSnap does not independently set tracking cookies through the widget and does not use End User data for advertising.

1.4 Usage and log data

For security and to operate the Service we record:

  • IP address and user agent on dashboard sign-in
  • API request logs (endpoint, status code, latency)
  • Webhook delivery logs and Slack message delivery status
  • Aggregate usage counts (feedback submissions per month, storage bytes used)

1.5 Cookies and similar technologies

The dashboard uses strictly necessary cookies for authentication, session management, and CSRF protection. The marketing site loads Google Tag Manager for analytics; you can opt out by blocking it in your browser. The widget itself does not set tracking cookies on End User browsers.

2. How we use information

  • To provide the Service: authenticate users, store and display feedback, run the widget, deliver notifications, and process subscriptions.
  • To improve the Service: understand which features are used and prioritize improvements. We do not sell or rent personal data.
  • To communicate with Customers: send transactional emails (sign-up confirmation, password resets, billing receipts, trial reminders, integration alerts) and product updates you have opted into.
  • To prevent abuse: enforce rate limits, detect fraudulent payment attempts, and respond to security incidents.
  • To comply with legal obligations: respond to lawful requests and enforce our Terms.

If you are in the EEA or the UK, we rely on the following legal bases:

  • Contract: to provide the Service to Customers under our Terms of Service.
  • Legitimate interests: to secure our infrastructure, prevent abuse, and improve the product.
  • Consent: for optional marketing communications and any optional analytics that require it. You can withdraw consent at any time.
  • Legal obligation: to retain certain billing records under applicable tax law.

For End User data submitted through the widget, the Customer determines the legal basis as the controller. Our Data Processing Addendum (available on request) governs that relationship.

4. How we share information

We share information only with sub-processors that help us operate the Service, and only as necessary:

  • Amazon Web Services (S3, EC2): hosting and media storage. Data may be stored in EU or US regions depending on your account settings.
  • Stripe: payment processing.
  • Resend / Amazon SES: transactional email delivery.
  • Slack: only when a Customer voluntarily connects their workspace to receive notifications. The bot token is stored encrypted and used only to post messages to channels the Customer authorized.
  • Meilisearch: self-hosted full-text search. Feedback content is indexed with tenant-level isolation.
  • Google Tag Manager / Google Analytics: on the marketing site only — not in the dashboard or widget.

We do not sell personal data. We may disclose information if required by law, to enforce our Terms, or to protect the rights, property, or safety of FeedSnap, our Customers, or the public.

5. International transfers

Where personal data is transferred outside your jurisdiction, we rely on Standard Contractual Clauses or other lawful transfer mechanisms.

6. Data retention

  • Feedback content and media: retained according to the Customer's plan — 30 days on Free, 365 days on Pro, custom on Enterprise. Older data is automatically purged.
  • Customer accounts: retained for the lifetime of the subscription. After cancellation, account data is retained for 30 days then deleted, except where retention is required for legal or accounting purposes.
  • Backups: encrypted backups are retained for up to 30 days.
  • Logs: security and audit logs are retained for up to 12 months.

7. Your rights

Subject to your jurisdiction, you may have the right to:

  • Access the personal data we hold about you
  • Correct inaccurate data
  • Delete your data ("right to erasure")
  • Export your data in a machine-readable format
  • Object to or restrict certain processing
  • Withdraw consent for processing based on consent
  • Lodge a complaint with your local supervisory authority

Customers can manage most of these directly in the dashboard (export feedback as CSV / JSON, delete projects, delete accounts). For other requests email [email protected]. End Users should contact the Customer whose website they used the widget on; we will assist that Customer in fulfilling the request.

8. Security

We follow industry-standard practices: TLS in transit, encryption at rest for media in S3, hashed passwords using a modern KDF, scoped tenant isolation enforced at the database query level, rate limiting on public endpoints, and HMAC signature verification on outgoing webhooks. No system is perfectly secure; if you believe you have found a vulnerability please email [email protected].

9. Children

The Service is not directed at children under 16. We do not knowingly collect personal data from children. If you believe a child has submitted data, contact us and we will delete it.

10. California residents (CCPA / CPRA)

California residents have the right to know what personal information we collect, the right to delete it, the right to correct it, and the right to opt out of the "sale" or "sharing" of personal information. We do not sell personal information. To exercise your rights email [email protected].

11. Changes to this policy

We may update this Privacy Policy from time to time. Material changes will be communicated by email or in-product notice at least 30 days before they take effect. Continued use of the Service after the effective date constitutes acceptance of the updated policy.

12. Contact

Privacy questions and security reports: [email protected]