Privacy Policy

Last updated: April 16, 2026

Overview

Feedbackola ("we", "us", "our") provides a private feedback platform for local businesses. This policy explains what data we collect, how we use it, and your rights. We keep it plain — no legalese.

Data we collect

Business owners (you): When you create an account, we store your email address, business name, location information, and any preferences you set. We use Supabase for authentication — they store your credentials securely.

Customer feedback: When a customer submits feedback via your QR code, we store the text of their message and optionally their email address (only if they choose to provide it). Feedback is linked to your business and location, not to any Feedbackola account.

Messages: Replies from you and follow-up messages from customers are stored so the conversation thread is accessible to both parties.

Usage data: We collect basic, anonymized analytics (page views, feature usage) to improve the product. We do not use third-party ad trackers.

How we use your data

  • To operate the service — storing feedback, delivering notifications, enabling conversations.
  • To send email notifications (new feedback, customer replies) to the address you provide.
  • To run AI classification (urgency, sentiment, category) on feedback text using Anthropic's Claude. Feedback content is sent to Anthropic's API to generate these tags. Anthropic's privacy policy governs their handling of this data.
  • To improve Feedbackola — aggregate, anonymized usage patterns only.

We do not sell your data. We do not share it with third parties except as described above (Supabase for auth/database, Resend for email, Anthropic for AI).

Customer data (feedback submitters)

Customers who submit feedback via a QR code are not Feedbackola users. Their feedback belongs to the business they submitted it to. We act as a processor of that data on behalf of the business owner.

If a customer wants their feedback deleted, they should contact the business directly. Business owners can delete individual feedback submissions from their dashboard.

Data retention

We retain your data for as long as your account is active. If you delete your account, all associated data — businesses, locations, feedback, and messages — is permanently deleted within 30 days.

Security

All data is stored in Supabase (hosted on AWS) with encryption at rest and in transit. Row-level security policies ensure that owners can only access their own business data. Customer thread access is gated by a unique signed token.

Your rights

You can access, export, or delete your data at any time by contacting us at privacy@feedbackola.com. We'll respond within 5 business days.

Changes to this policy

If we make material changes, we'll notify you by email and update the "Last updated" date above.

Contact

Questions? Email privacy@feedbackola.com.