Privacy Policy
Last updated: March 7, 2026
WebsiteFeedback.ca ("we", "us", or "the Service") is a web-based tool that lets users review and annotate websites by proxying web pages and overlaying a comment system. This policy explains what data we collect, how we use it, and your rights.
1. Data We Collect
Data you provide directly
- Account information: Email address, password (hashed), and display name when you create an account.
- Payment information: Processed by Stripe — we do not store credit card numbers or payment card details. We store your Stripe customer ID and subscription status.
- Comments: The text of any comments you post, along with an optional author name you choose to enter.
- Page URL and coordinates: The URL of the page being reviewed and the x/y position where you placed a comment pin.
- URLs submitted for review: When you enter a URL to proxy, we fetch that page on your behalf.
- File attachments: Images or files you attach to comments, stored in Supabase Storage.
- Team information: Team name and member email addresses for collaboration features.
Data collected automatically
- Server logs: Our web server may log your IP address, user agent string, and request timestamps as part of standard operation.
- Timestamps: Comments are stored with a creation timestamp.
Data we do not collect
- We do not store credit card numbers or payment card details (handled by Stripe).
- We do not use advertising cookies or third-party tracking pixels.
- We do not use analytics or tracking scripts.
2. How We Use Your Data
- Comments are stored in our database (hosted on Supabase/Postgres) and displayed to anyone viewing the same reviewed page.
- Proxied content is fetched from the target website and relayed to your browser in real time. We do not store copies of proxied web pages.
- Server logs are used for debugging, security monitoring, and abuse prevention.
3. Data Storage and Security
Comment data is stored in a PostgreSQL database hosted by Supabase. We use industry-standard security practices to protect your data, but no method of transmission or storage is 100% secure.
4. Third-Party Services
We use the following third-party providers:
- Supabase — database hosting (comment storage), authentication, and file storage
- Stripe — payment processing (see Stripe's privacy policy)
- Google — OAuth authentication (when you choose to sign in with Google)
- Hosting provider — application server hosting
- Google Fonts — web font delivery
Each provider has their own privacy policy governing their handling of data.
5. Data Retention
Comments are retained until they are deleted by a user or until we remove them for policy violations. Server logs are retained for a limited period for operational purposes.
6. Your Rights
You may request deletion of comments you have posted by contacting us. Since we do not collect personal account information, we cannot verify ownership of anonymous comments, but we will make reasonable efforts to assist with deletion requests.
To request data deletion, contact us at contact@websitefeedback.ca.
7. Children's Privacy
The Service is not intended for use by anyone under the age of 13. We do not knowingly collect personal information from children under 13. If you believe a child has provided us with personal information, please contact us so we can take appropriate action.
8. Changes to This Policy
We may update this Privacy Policy from time to time. Changes will be posted on this page with an updated "Last updated" date. Continued use of the Service after changes constitutes acceptance of the revised policy.
9. Contact
If you have questions about this Privacy Policy, contact us at contact@websitefeedback.ca.