Privacy Policy
Effective date: 2026-08-19
1. Who we are and what this covers
This policy explains what data Featurewall ("we", "us") collects when you use the Service (featurewall.site, including public boards, changelogs, and embeddable widgets), why, and the rights you have. We are the data controller for account data. For feedback content submitted to your board by your users, you are the controller โ we process that content on your instructions as a processor.
2. Data we collect
- Account data: email address, password (hashed โ never stored in plain text), plan, consent records (Terms/Privacy acceptance timestamp + version), and billing identifiers issued by Stripe.
- Usage data: technical logs (IP address, user agent, request metadata) used for security, abuse prevention, and rate limiting. Logs are retained for a limited period.
- Feedback content: posts your users submit (title, body, optional display name) and the changelog entries you publish. Submitter email addresses are used ONLY to send status-change notifications the submitter explicitly opted into, and are never published or exposed in public API responses.
- Cookies: a strictly necessary session cookie (signed, HttpOnly, SameSite=Lax), a CSRF token cookie, and an anonymous voter cookie (HttpOnly, SameSite=Lax) that prevents duplicate votes without identifying you. No tracking or advertising cookies are used, and no consent banner is required for strictly necessary cookies.
- Payment data: we never store card numbers. Card details are entered directly with our payment processor (Stripe) and never pass through our servers.
3. Purposes and legal bases
- Providing the Service (account, hosting, boards, voting, changelogs, widgets) โ performance of a contract (our Terms).
- Sending notification emails you opted into โ consent (withdrawable via the unsubscribe link in every email).
- Security, abuse prevention, and rate limiting โ legitimate interest.
- Billing โ necessary to process payments and meet legal obligations.
- Account consent โ recorded at signup (GDPR Art. 6(1)(a)); you can withdraw by deleting your account.
- Legal compliance โ retaining data where required by applicable law.
4. Who we share data with
- Stripe โ payment processing (subscriptions, invoices). Stripe receives your email and subscription identifiers; card details go to Stripe directly, never to us.
- Resend โ transactional email delivery (digests and status notifications). Resend processes the recipient address and message content only, under a data processing agreement.
- Hosting providers โ the infrastructure that stores and serves the Service (database and application hosting), under data processing agreements.
- We do not sell personal data, and we do not use it for advertising.
5. Retention
Account data is retained while your account is active. When you delete your account or workspaces, associated data is deleted from our systems (backups may retain copies for up to 30 days). Security logs are retained for a limited period proportionate to abuse prevention. Unsubscribed email addresses are kept only to honor the opt-out. Where law requires longer retention (for example, billing records for tax purposes), we keep only what is required.
6. Your rights
Depending on your jurisdiction (including GDPR and CCPA/CPRA), you may have the right to access, correct, export, or delete your personal data, to object to or restrict processing, and to withdraw consent. You can export your posts (CSV, Pro plan) and delete your account from the dashboard at any time. Notification recipients can unsubscribe with one click from any email. To exercise other rights, email contact@featurewall.site โ we respond within 30 days. You also have the right to lodge a complaint with your local data protection supervisory authority.
7. Security
Passwords are hashed with scrypt (OWASP work factor). Sessions use signed HttpOnly cookies and are revocable server-side. Unsubscribe links are HMAC-signed and cannot be forged. All traffic is served over HTTPS. We apply industry-standard safeguards (encryption in transit, hashing at rest for credentials, strict access controls) to protect your data; no method of transmission or storage is 100% secure, and we cannot guarantee absolute security.
8. International transfers and changes
Data is stored on servers in the regions of our hosting providers, which may be outside your country. We use providers that offer appropriate safeguards (e.g., EU Standard Contractual Clauses where applicable). We may update this policy; material changes will be announced on the Service and, where required, re-consent will be requested. Questions: contact@featurewall.site.