Privacy Policy
Last updated 17 September 2026
This Privacy Policy explains how Peter Kracik, an individual sole proprietor operating Feedhive (“Feedhive”, “we”, “us”), collects, uses and protects personal data when you use Feedhive at feedhive.app(the “Service”) or submit feedback through the Feedhive widget on a website that embeds it. It is written with the EU/UK GDPR and the Swiss Federal Act on Data Protection (FADP) in mind.
1. Data we collect
Account data
When you sign in with Google, GitHub or an emailed link, we collect your name, email address, the provider account identifier and, where provided, your profile image. We never receive your Google or GitHub password.
Feedback data (widget)
When a visitor submits feedback through the widget on a site that embeds it, we store what the submission contains: the feedback text, the page URL, an optional CSS reference to the selected element or selected text, an optional screenshot of the visible page, and technical context (browser and operating-system name, screen and window size, referrer, time of submission). Feedback is submitted without an account and is not linked to a visitor identity by us. Screenshots may incidentally capture personal data visible on the page at the time of capture.
Content data
Projects, their settings and the comments you write on feedback in the dashboard.
Technical data
IP addresses are used transiently to rate-limit sign-ins and feedback submission; in our logs they appear only as short hashes. We use a session cookie for signed-in users and no analytics or advertising trackers. The widget sets no cookies on the sites that embed it.
2. Roles
For account and dashboard data we act as the data controller. For feedback collected through the widget, the owner of the embedding website decides what feedback to collect and why; we process that data on their behalf to provide the Service. Website owners are responsible for informing their visitors about the use of Feedhive where required.
3. How we use data
- To provide the Service: authentication, storing and showing feedback, comments and screenshots.
- To send transactional email: sign-in links only.
- To protect the Service: rate limiting and abuse prevention.
- We do not sell personal data, run ads, or use tracking analytics.
4. Where data lives (subprocessors)
| Provider | Purpose | Location |
|---|---|---|
| Netlify | Application hosting | EU/US |
| Neon | Postgres database | EU (region-pinned) |
| Google Cloud Storage | Screenshot storage | EU (bucket region) |
| Resend | Sign-in email delivery | EU/US |
| Upstash | Rate-limit counters (hashed keys) | EU/US |
Where providers process data outside the EU/Switzerland, transfers rely on the providers’ standard contractual clauses. All traffic is encrypted in transit (HTTPS) and data is encrypted at rest by the providers.
5. Retention and deletion
- Deleting feedback permanently removes it with its screenshots and comments.
- Deleting a project permanently removes all its feedback and screenshots.
- Deleting your account (Settings) permanently removes your account and every project it owns.
- We keep data only while it serves the purposes above; there is no shadow retention.
6. Your rights
Under the GDPR/FADP you can request access, correction, deletion, restriction and portability of your personal data, and object to processing. Most of it you can do directly in the app; for anything else contact [email protected]. If you believe a website using Feedhivecollected your data improperly, contact that website’s owner or us. You may also lodge a complaint with your local supervisory authority.
7. Changes
We will update this policy as the Service evolves and bump the date above. Material changes will be announced in the app.