PrivacyTerms

Privacy Policy

Last updated September 4, 2026

We collect as little as we can, we never sell it, and the data your users send through the SDK stays yours.

  1. 1.Who we are

    SuggestKit ("we", "us") is operated by Firat Tamur. SuggestKit is a feedback platform for software teams: you embed our widget or SDK in your product, your users submit and vote on feature requests, and we show you which requests carry the most revenue.

    This policy covers two groups of people. Customers are the teams who create an account and install the SDK. End users are the customers' own users who vote and comment through the widget. Most of this policy applies to both; section 4 is specific to end users.

  2. 2.What we collect

    We collect the following.

    • Account data: your name, email address, password hash or sign-in provider, and workspace details.
    • Billing data: plan, invoices and payment status. Card numbers are held by our payment processor, never by us.
    • Feedback content: the posts, votes, comments and statuses you or your users create.
    • Usage data: pages viewed, features used, and events such as a request being moved to Shipped. Collected through PostHog.
    • Technical data: IP address, browser, device type, and error reports collected through Sentry when something breaks.
    • Support data: anything you send us by email or through the contact form.
  3. 3.How we use it

    We use personal data to:

    We do not sell personal data and we do not use it for advertising.

    • Run the service: authenticate you, store feedback, and compute the revenue behind each request.
    • Send transactional email such as sign-in links, invoices and status updates on requests you voted for.
    • Understand how the product is used so we can improve it. Analytics is aggregated wherever possible.
    • Detect abuse, keep the service secure, and meet our legal obligations.
    • Send occasional product updates. Every marketing email has an unsubscribe link; account emails cannot be turned off while you have an account.
  4. 4.Data you send us about your users

    When a customer calls identify() in the SDK, they send us data about their own users. The customer is the controller of that data and we are their processor: we act only on the customer's instructions and only to provide the service. What the SDK typically sends:

    We keep end-user data for as long as the customer's project exists. Customers can delete individual users or a whole project from the dashboard, and the data is removed within 30 days. If you are an end user and want to access, correct or delete your data, contact the company whose product you used; we will assist them. If you cannot reach them, email us and we will help.

    Customers are responsible for having a lawful basis to share their users' data with SuggestKit and for describing this processing in their own privacy notice. Our Terms include the processing commitments we make to customers.

    • Email address and display name, so a vote can be attributed and the voter can be notified when a request ships.
    • Plan and monthly recurring revenue (MRR), used only to weight votes. This is optional and set by the customer.
    • Any custom properties the customer chooses to pass.
    • The posts, votes and comments the end user creates.
  5. 5.Subprocessors

    We share personal data only with the providers below, each bound by a data processing agreement, and with authorities where the law requires it. We will notify customers by email before adding a new subprocessor that handles end-user data.

    • Vercel: hosting and content delivery.
    • Neon: primary database.
    • Cloudflare R2: file and attachment storage.
    • Resend: transactional email.
    • Sentry: error reporting.
    • PostHog: product analytics.
    • A payment processor for subscriptions, named on your invoice.
  6. 6.Cookies and analytics

    The dashboard uses strictly necessary cookies for sign-in and preferences, plus a PostHog analytics cookie. The marketing site uses PostHog only. We do not use advertising cookies or cross-site tracking, and we honor the Global Privacy Control signal.

    The feedback widget sets no cookies of its own on your users' browsers; it identifies users through the data the customer passes to the SDK.

  7. 7.Retention and deletion

    Account and feedback data is kept while your account is active. When you delete your account or a project, we delete the associated data within 30 days, except for invoices and records we must keep for tax and accounting purposes, which are kept for the period the law requires. Backups roll off within 35 days.

    Error and analytics data is retained for 90 days and then deleted or aggregated.

  8. 8.Security

    All traffic is encrypted in transit with TLS, and data is encrypted at rest by our hosting providers. Access to production is limited to the people who operate the service, and API keys are hashed before storage so we cannot read them back. If we learn of a breach affecting your data we will notify you without undue delay, and within 72 hours where the GDPR applies.

  9. 9.International transfers

    Our providers store data in the United States and the European Union. Where data leaves the EU or UK we rely on the providers' Standard Contractual Clauses and Data Privacy Framework certifications.

  10. 10.Your rights

    Depending on where you live, including under the GDPR, UK GDPR, CCPA and KVKK, you have the right to:

    To exercise any of these, email support@suggestkit.app. We answer within 30 days and never charge for a reasonable request.

    • Access the personal data we hold about you and receive a copy.
    • Correct data that is wrong or incomplete.
    • Delete your data, subject to the retention exceptions above.
    • Export your feedback data in a machine-readable format.
    • Object to or restrict certain processing, and withdraw consent where processing is based on it.
    • Complain to your local data protection authority.
  11. 11.Children

    SuggestKit is a business tool and is not directed at children. We do not knowingly collect data from anyone under 16. If you believe a child has given us personal data, email us and we will delete it.

  12. 12.Changes to this policy

    We may update this policy as the product changes. For material changes we will email account holders at least 14 days before they take effect. The date at the top shows the current version.

Questions? Email support@suggestkit.app.