Feedback4.dev Privacy Notice
Effective and last updated: August 10, 2026 · Version 2026081002
1. Who is responsible and how this notice applies
Feedback4.dev is the trade name used by Feedback4.dev ("Feedback4.dev", "we", "us"). The provider's business address and agreed place of performance is Santiago de Querétaro, Querétaro, Mexico. Privacy requests and legal notices may be sent to contact@feedback4.dev.
This notice applies to feedback4.dev, its account area, public feedback pages, browser widget, API, MCP server, webhooks and related support. Feedback4.dev acts as controller or responsible party for account, authentication, billing, security, support and its own business records. For feedback content, reviewer details and other data a workspace customer chooses to collect, Feedback4.dev generally acts as processor or service provider on that customer's documented instructions. In that situation, the workspace customer remains responsible for its own notice, legal basis and responses to the people whose data it submits.
The applicable order form or invoice will repeat the contracting provider's legal identity and business address and should be kept together with this notice.
2. Personal information we process
- Account and membership data: name, email address, password hash, email-verification status, workspace, role, invitations, language and notification preferences.
- Reviewer-access data: authorized email address, six-digit verification-code records, verification attempts, session-token hashes, expiration, revocation and last-use timestamps. The one-time code is consumed when verified; the resulting browser session expires no later than 24 hours after issuance.
- Feedback and project content: project and domain settings, ticket title and description, comments, status, priority, approvals, assignee, page URL, selected-element or DOM context, viewport, browser context, screenshots, images, PDFs and other attachments submitted by authorized users.
- Technical and security data: IP address, user agent, device/browser information, timestamps, request and audit logs, rate-limit events, idempotency keys, security events and diagnostic information.
- Integration data: API-key and agent-credential identifiers and hashes, credential scopes and expiry, MCP activity, webhook URLs, event types, delivery status and logs. Secrets are encrypted or hashed where the feature requires it; the plaintext of a newly issued credential may be displayed only once.
- Billing data: workspace subscription status, PayPal subscription and plan identifiers, payer identifier, subscriber email, billing dates and cancellation status. Payment-card or bank details are entered with and processed by PayPal; Feedback4.dev does not receive or store the complete card number.
- Communications: support requests, account and security email delivery records, and messages you send to us.
Please do not submit government identifiers, payment-card data, health information, biometric data, precise location, information about children, or other sensitive or regulated data in feedback tickets or integrations unless Feedback4.dev has expressly agreed in writing to process it and you have every required authorization.
3. Sources of information
We receive information directly from account holders, workspace owners and members, authorized reviewers, the widget and browser used to submit feedback, PayPal, and integrations or agents configured by the workspace. A customer may also provide information about its personnel, clients or reviewers. Customers must only provide data they are authorized to process.
4. Why we use information
- Create and administer accounts, workspaces, projects, roles and reviewer access.
- Verify email addresses, issue single-use codes, maintain sessions and recover accounts.
- Receive, reproduce, organize, route, discuss, approve and track feedback.
- Deliver API, MCP, webhook and agent workflows selected by the workspace.
- Process subscriptions, invoices, renewals, cancellations and service entitlements.
- Send transactional, security, service and support communications.
- Prevent abuse, investigate incidents, enforce limits and terms, protect users and maintain service integrity.
- Debug, maintain and improve reliability using aggregated or de-identified information where practical.
- Comply with law, lawful process, accounting, tax, dispute and recordkeeping duties.
Depending on the jurisdiction and context, processing is based on performance of a contract or requested pre-contract steps, consent, compliance with law, protection of vital or security interests, and legitimate interests that do not override applicable rights. Optional marketing requires a separate lawful basis and unsubscribe mechanism. We do not use feedback content to train a general-purpose artificial-intelligence model unless a customer expressly agrees to a separate written arrangement.
5. Cookies and browser storage
We use essential session cookies and storage needed for sign-in, security, language and requested product functions. Reviewer access may be kept in sessionStorage for the current browser tab or browsing context and remains subject to the server-side maximum expiration. The widget may store only the access state needed to avoid requesting a new code for every ticket during that session.
If analytics is enabled by Feedback4.dev, we offer a separate choice before loading Google Tag Manager (GTM). Until you select “Allow analytics,” this feature does not request GTM or execute an analytics tag. If you allow it, GTM runs only inside a restricted, opaque-origin browser frame. Feedback4.dev provides that frame with a fixed analytics event and an allowlisted public route label; it does not provide the query string, referrer, page title, parent-page content, account data, feedback, tokens or other session information. The frame cannot access the parent document, Feedback4.dev cookies or storage, authenticated APIs, forms, popups or top-level navigation. Custom HTML and non-Google tags are blocked by the frame policy.
Google analytics tags that run in that frame may still process the public route label, timestamps, browser/device characteristics and network information such as the IP address and user agent needed to transmit the request. Google acts under its applicable data-processing terms and may process information in the United States or other countries where it operates. We configure advertising storage and personalization as denied and do not use this feature for advertising tags.
Your choice is stored locally in your browser so we can remember it. You may reject analytics without losing essential product functions, reopen the persistent “Privacy” control at any time, and revoke consent. Revocation is stored before the page reloads so GTM is no longer loaded on the next page execution; it does not affect processing already completed before withdrawal. We use analytics to understand product usage, reliability and conversion in aggregated reports, not for cross-context behavioral advertising, data brokerage or sale of personal information. Blocking essential storage may still prevent sign-in, reviewer verification or other requested functions.
6. When information is disclosed
We disclose only what is reasonably necessary to:
- Workspace owners, administrators, members, reviewers and agents according to their roles and project permissions.
- Infrastructure, hosting, database, object-storage, malware-scanning, email-delivery, observability, support and security providers acting under contract.
- Google, only after analytics consent and only for the restricted measurement purposes described in Section 5.
- PayPal for subscription and payment processing.
- Webhook destinations, APIs, MCP clients and artificial-intelligence agents deliberately configured by the workspace. The customer controls those destinations and must assess their privacy and security terms.
- Professional advisers, insurers, auditors, a successor in a corporate transaction, or authorities when legally required or necessary to protect rights and safety.
We do not sell personal information. We do not share personal information for cross-context behavioral advertising and do not process it for targeted advertising. We do not disclose personal information for money to data brokers.
7. International processing and transfers
The service is operated from Mexico and information may be accessed or processed in Mexico, the United States, Canada or another country where a customer-selected integration or contracted provider operates. The laws and lawful-access rules in those places may differ from those where you live. We use contractual, organizational and technical measures intended to require an appropriate and comparable level of protection. A workspace customer is responsible for any additional assessment, notice, consent or transfer mechanism required for destinations it configures.
8. Retention and deletion
Attachments are retained for no more than 90 days and may be permanently deleted earlier with their ticket or workspace. Reviewer codes, expired reviewer sessions and rate-limit records are short-lived and are removed by scheduled maintenance. Tickets, comments, project settings and account records are retained while the relevant workspace or account remains active and for a reasonable period needed for export, recovery, security or dispute handling after termination. Billing, transaction, consent and contract evidence may be retained for the period required by tax, accounting, consumer and commercial law; electronic contract evidence may be retained for at least ten years where Mexican commercial law requires it. Security, audit and backup copies are deleted or anonymized on a rolling schedule unless a legal hold applies.
When Feedback4.dev acts as processor, retention is also governed by the customer's instructions, the service configuration and our data-processing agreement. Deletion requests remain subject to legal, fraud-prevention, security and evidentiary exceptions.
9. Security and incidents
We use administrative, technical and physical safeguards appropriate to the nature of the service, including tenant authorization checks, restricted reviewer access, scoped credentials, hashing or encryption of secrets where applicable, rate limiting, logging, backups and file controls. No Internet service can promise absolute security. Customers must protect credentials, limit permissions, review agent actions, configure only trusted destinations and notify us promptly of suspected compromise.
If a breach creates a legally reportable risk, we will notify affected parties and authorities as required by applicable law. Contact contact@feedback4.dev immediately to report a suspected security or privacy incident.
10. Your choices and general rights
Subject to identity verification and applicable exceptions, you may request access, correction, deletion, portability or a copy of information; object to or restrict certain processing; withdraw consent for future optional processing; opt out of sale, sharing, targeted advertising or qualifying profiling; and appeal a denied request where local law provides that right. We will not discriminate against you for exercising a privacy right.
Send a request to contact@feedback4.dev with the subject "Privacy request" and identify your account or the workspace and project involved. Do not send a password, one-time code or API secret. We may ask for information proportionate to verify identity and authority. An authorized agent may act where permitted if it supplies valid authorization. If Feedback4.dev processes the data only for a workspace customer, we may route the request to that customer and assist it.
We aim to answer verified requests within 45 days unless a shorter period applies. We may extend when legally permitted and will explain why. Requests are normally free, but manifestly unfounded or excessive requests may be handled as the law permits.
11. Mexico privacy rights
Under Mexico's Federal Law on the Protection of Personal Data Held by Private Parties (LFPDPPP), you may exercise rights of Access, Rectification, Cancellation and Objection (ARCO), revoke consent, and limit use or disclosure. A request should include your name, a way to communicate the response, documents reasonably proving identity or representation, a clear description of the data and right, and information that helps locate the records. We will communicate our determination within the legally applicable period, generally no more than 20 days, and, if granted, make it effective within the following 15 days, subject to lawful extensions and exceptions.
Primary purposes necessary for the service are described in Section 4. Optional marketing is a secondary purpose and may be refused or withdrawn without losing contracted core functions. Financial or sensitive data will be processed with the express consent required by law when an exception does not apply. National or international transfers are made only with the notice, consent, contract or statutory exception required by law.
You may contact the competent Mexican privacy authority, currently the Secretaría Anticorrupción y Buen Gobierno, when the LFPDPPP provides that remedy. Mandatory consumer rights before PROFECO are unaffected.
12. United States state disclosures
Residents of a state with a comprehensive privacy law may have rights to know or confirm processing, access specific information, correct, delete, obtain a portable copy, opt out of sale, sharing, targeted advertising or qualifying profiling, limit use of sensitive information, use an authorized agent, appeal and receive equal service. These rights and business thresholds differ by state; we will apply the law that covers the request.
For the preceding 12 months, the categories collected and purposes are those in Sections 2 and 4, sources are in Section 3, and recipient categories are in Section 6. We have not sold personal information or shared it for cross-context behavioral advertising. We do not knowingly sell or share information of people under 16. Because we do not conduct those activities, a "Do Not Sell or Share" link is not currently necessary for our practices. If that changes, we will provide the required link and honor applicable browser-based opt-out signals, including Global Privacy Control. You may still send any request to contact@feedback4.dev without creating an account or accepting these Terms.
13. Canada privacy rights
For commercial information covered by Canada's Personal Information Protection and Electronic Documents Act (PIPEDA), Feedback4.dev follows the principles of accountability, identified purposes, meaningful consent, limited collection, limited use/disclosure/retention, accuracy, safeguards, openness, access and challenging compliance. You may request access to and correction of your information, withdraw consent to optional uses, and challenge our compliance through the contact above. Cross-border processing does not remove our accountability for providers acting on our behalf.
If you are not satisfied after contacting us, you may complain to the Office of the Privacy Commissioner of Canada or the applicable provincial regulator. Additional provincial rights apply where required. Before Feedback4.dev actively offers a consumer adhesion contract in Quebec, the required French contract and related documents must be presented first; the current English and Spanish versions are not a substitute for that requirement.
14. Children
Feedback4.dev is a business service for people 18 or older and is not directed to children. Customers must not intentionally use the service to collect personal information from a child under 13 in the United States, a minor for whom parental consent is required in another jurisdiction, or a school/student context without our prior written agreement and all required notices, contracts and verifiable consents. If you believe a child submitted information improperly, contact us so it can be investigated and deleted where required.
15. Customer obligations and automated agents
A workspace customer determines which sites, reviewers, ticket fields, webhooks and agents it configures. It must provide an appropriate notice at or before collection, establish a lawful basis, honor data-subject requests, minimize data, avoid prohibited sensitive information and sign any required data-processing agreement. Automated agents may receive ticket content at the customer's direction; the customer must limit their credentials and destinations and provide meaningful human review where a change could affect a person, production system, legal right or material decision.
16. Changes and contact
We may update this notice when practices or law change. The page shows its effective date and version. We will provide additional notice before a material change when required and will seek consent if a new purpose requires it. Earlier versions and acceptance evidence may be retained for legal accountability.
Questions, rights requests, complaints and privacy or security notices: contact@feedback4.dev. Postal or formal notices: Feedback4.dev, Santiago de Querétaro, Querétaro, Mexico.