Privacy Policy

Last updated: 28 July 2026

Feedinbox asks a website's visitors one question when they leave without buying, and collects general product feedback. This policy explains what we collect, why, and what we deliberately do not collect.

1. Two different groups of people

This policy covers two relationships, and they work differently:

  • Customers. You sign up, create a project, and install our script. We are the controller of your account data.
  • Visitors to a customer's website. If you saw a Feedinbox question on someone else's site, we process that response on their behalf as a processor. That site's own privacy policy governs the relationship, and requests to access or delete a response should go to them. We will help them action it.

2. What we collect

Account information. You sign in with Google. We receive your name, email address, and profile image. We never receive or store your Google password.

Project settings. The project name, optional domain, your widget key, and your configuration: question wording, answer options, timing, and notification preference.

Feedback submissions. The message, the chosen category, an optional email address if the visitor supplies one, the page URL it was sent from, and the browser user agent string.

Why-Not-Buy responses. The selected reason, any optional free text, whatever context you choose to attach in your own code (for example the plan being viewed), a two-letter country code, the page URL, the browser user agent, and a random session identifier used to avoid asking the same person twice.

Billing information. Payments are processed by Dodo Payments, acting as merchant of record. We store only your customer and subscription identifiers, your plan, its status, and the current period end date. We never see or store card numbers.

3. What we do not collect

  • No IP addresses. Country is derived from a network header at the edge and only the two-letter country code is saved. The IP address itself is never written to our database.
  • No tracking cookies. The widget sets no cookies at all.
  • No cross-site tracking or fingerprinting. The widget cannot follow anyone between different customers' websites.
  • No advertising networks, and no selling or renting of data. Ever.

4. What the widget stores in a visitor's browser

The widget uses sessionStorage, not cookies. It writes three short-lived keys, all prefixed feedinbox_: a random session id, and flags recording that the question was already answered or dismissed. Their only purpose is to avoid asking the same person the same question twice.

Because this is sessionStorage, the browser discards all of it when the tab is closed. Nothing persists across sessions or across sites.

5. How we use information

  • To run the service and show you responses in your dashboard.
  • To email you according to the preference you set per project: one email per response, a weekly digest, or none at all.
  • To process payments and manage subscriptions.
  • To respond to support requests.
  • To diagnose faults and keep the service secure and reliable.

We do not use your feedback content or Why-Not-Buy responses to train machine learning models.

6. Who we share it with

We use a small number of infrastructure providers, and only to deliver the service:

  • Vercel for hosting and delivery.
  • Supabase for the database that stores your account, projects, and responses.
  • Resend for sending notification and digest emails.
  • Dodo Payments for checkout, subscriptions, and invoicing.
  • Google for sign-in only.

We may also disclose information where legally required, or as part of a merger or acquisition, in which case we will tell you before your data becomes subject to a different policy.

7. Retention and deletion

We keep data until you delete it or close your account. Deleting a project permanently deletes every feedback submission and Why-Not-Buy response belonging to it, immediately and irreversibly.

To delete your entire account and everything in it, email us at support@feedinbox.com and we will action it. Backups may retain copies for a short period before being rotated out.

8. Your rights

Depending on where you live, you may have the right to access, correct, export, or delete your personal data, and to object to certain processing. You can view everything in your dashboard at any time, and export responses to CSV or PDF on a Pro plan. For anything you cannot do yourself, email us and we will help.

If you are a visitor who answered a question on someone else's website, please contact that website's owner, since the data belongs to them.

9. Security

Data is transmitted over HTTPS and stored on managed infrastructure with access restricted to what is needed to operate the service. No system is perfectly secure, so we aim to collect as little as possible in the first place, which is why we do not store IP addresses or set cookies.

10. Children

Feedinbox is a tool for businesses and is not directed at children under 13. We do not knowingly collect their personal information.

11. Changes to this policy

We may update this policy as the product changes. Any update is reflected in the date at the top of this page, and significant changes will be communicated by email.

12. Contact

Questions about this policy or about your data: support@feedinbox.com.