Legal

Privacy Policy

Effective: June 9, 2026  ·  Operated by: Osaf Ali Sayed, sole proprietor, Jodhpur, Rajasthan, India

01 · Introduction

FeedbackWorthy is operated by Osaf Ali Sayed, an individual sole proprietor in Jodhpur, Rajasthan, India (“we”, “us”, “our”). This Privacy Policy explains what personal data we collect, how we use it, and your rights in relation to it.

By using FeedbackWorthy at feedbackworthy.com, you agree to the collection and use of information in accordance with this policy.

02 · Data We Collect

We collect the following categories of data:

CategoryWhat we collectWhy
AccountName, email address, hashed password, avatar (optional), OAuth providerTo create and manage your account
WorkspaceWorkspace name, slug, brand colour, logoTo power your testimonial collection experience
TestimonialsReviewer name, email, avatar, text, video, rating — submitted via your public formsCore product functionality — storing the reviews you collect
UsagePages visited, features used, actions taken in the dashboardTo improve the product and understand how it's used
TechnicalIP address, browser type, device type, referring URLSecurity, fraud prevention, debugging

03 · Testimonial Submitters

When someone submits a testimonial through a collection form you have created, their name, email address, and submission content are stored in your workspace. As a FeedbackWorthy user, you are the data controller for your submitters' data. You are responsible for having a lawful basis to collect it and for informing your submitters how their data will be used.

We act as a data processor on your behalf for this data, storing it securely in accordance with this policy.

04 · How We Use Your Data

  • To provide, maintain, and improve the FeedbackWorthy Service
  • To authenticate your account and keep it secure
  • To send transactional emails (account confirmations, billing notifications) via Resend
  • To process your subscription payments through Paddle
  • To analyse usage patterns and improve the product
  • To respond to support requests
  • To comply with legal obligations

We do not sell your personal data to third parties. We do not use your data for advertising purposes.

05 · Third-Party Sub-processors

We rely on the following sub-processors to deliver the Service:

ProviderPurposeData location
SupabaseDatabase, authentication, row-level securityUnited States
CloudinaryImage and video file storage (avatars, logos, video testimonials)United States
ResendTransactional email deliveryUnited States
Lemon SqueezyPayment processing, billing, Merchant of RecordUnited States

Each of these providers has its own privacy policy and data processing terms. We have chosen providers with strong security practices and, where applicable, GDPR-compliant data processing agreements.

06 · Cookies

FeedbackWorthy uses cookies solely for authentication purposes — specifically to maintain your logged-in session via Supabase Auth. We do not use advertising cookies, third-party tracking cookies, or analytics cookies that identify you personally.

07 · Data Retention

  • Account and workspace data is retained for as long as your account is active
  • Cancelling your subscription downgrades your account to the free tier — your data is not deleted
  • If you explicitly request account deletion, all personal data is permanently removed within 30 days
  • Billing records may be retained for longer periods where required by tax or accounting law

08 · Your Rights

Depending on your location, you may have the following rights in relation to your personal data:

  • Access — request a copy of the data we hold about you
  • Rectification — request correction of inaccurate data
  • Deletion — request that we delete your account and associated data
  • Portability — request your data in a machine-readable format
  • Objection — object to certain processing activities

To exercise any of these rights, email us at support@feedbackworthy.com. We will respond within 30 days.

09 · Security

We take reasonable precautions to protect your data, including:

  • All data in transit is encrypted via HTTPS/TLS
  • Passwords are hashed and never stored in plain text
  • Row-level security (RLS) policies in Supabase ensure users can only access their own data
  • We never store payment card details — all payment data is handled by Paddle

No method of transmission over the internet is 100% secure. While we strive to use commercially acceptable means to protect your data, we cannot guarantee absolute security.

10 · Children

FeedbackWorthy is not directed at children under 16. We do not knowingly collect personal data from anyone under 16. If you believe we have inadvertently collected such data, please contact us immediately so we can delete it.

11 · Changes to This Policy

We may update this Privacy Policy from time to time. If we make material changes, we will notify you by email before they take effect. The current version is always available at feedbackworthy.com/privacy.

12 · Contact

Questions about this Privacy Policy or how your data is handled? Email us at support@feedbackworthy.com.