1. Who we are
This Privacy Policy explains how Gatherly (“Gatherly,” “we,” “us,” or “our”) collects, uses, shares, and protects personal data when you use our websites, dashboard, APIs, and embeddable widget (together, the “Service”).
Contact: support@gatherly.sh
2. Roles and responsibilities
Gatherly customer accounts. When you create a Gatherly account, we act as a controller of your account, billing, and usage data.
End-user feedback on a customer’s site. Feedback, messages, identity claims, attachments, and related end-user content submitted through a customer’s embed are processed on behalf of that customer. The customer is the controller of that data and determines the purposes of processing. Gatherly is the processor. If you are an end user of a customer’s product, review that customer’s privacy policy as well, and contact them for requests about content they control. We will assist the customer where appropriate.
For a practical breakdown of where data lives and how to delete it, see Transparency.
Processing of that end-user data is also described in our Data Processing Agreement. If you need a signed copy, email support@gatherly.sh.
3. Data we collect
Depending on how you use Gatherly, we may collect:
- Account data — name, email address, password or OAuth identifiers (for example Google or GitHub), profile image, and account preferences. If you sign in with Google or GitHub, those providers share the identifiers you authorize (typically name, email, and avatar).
- Billing data — plan selection, Stripe customer and subscription identifiers, and payment status. Payment card details are handled by Stripe; we do not store full card numbers.
- Project and configuration data — project names, public/secret keys, embed appearance settings, team membership, and similar workspace settings.
- End-user and feedback data — messages, feedback type (for example bug, idea, feature request), attachments you or end users upload, metadata such as timestamps, page URL where relevant, and identity claims from a customer-signed identity JWT (for example user id, email, username, avatar URL, plan, or Stripe customer id when the customer chooses to include them).
- Technical and usage data — IP address, browser and device information, approximate location derived from IP, referrer, pages or events related to the Service, error logs, and performance metrics.
- Communications — emails and messages you send us (for example support requests), and transactional emails we send you (auth, billing, security notices).
4. How we use data
We use personal data to:
- Provide, operate, secure, and improve the Service
- Authenticate users and maintain sessions
- Process subscriptions and prevent fraud
- Deliver the embed widget and route feedback to the correct project
- Send transactional and service-related emails
- Respond to support requests and enforce our Terms
- Comply with law and protect our rights and users
- Analyze aggregated or de-identified usage to understand product performance (where permitted)
We do not sell personal data. We do not use customer end-user feedback content to train public AI models. We do not currently send marketing emails; if we do, we will provide a way to opt out.
5. Legal bases (EEA/UK)
Where GDPR/UK GDPR applies, we rely on:
- Contract — to provide the Service you request, including accounts, billing, and delivering the widget
- Legitimate interests — to secure, improve, and administer the Service, prevent abuse, and keep records, in ways that do not override your rights
- Consent — where required (for example optional marketing, if we offer it)
- Legal obligation — when we must retain or disclose data to comply with law (including Danish bookkeeping rules for billing records)
For end-user feedback we process as a processor, the customer’s legal basis is the relevant one. Customers must provide required notices and collect consents from their end users.
6. Service providers and processors
We use vendors who process data on our instructions to run Gatherly:
- Supabase — authentication, database, and file storage on servers in the EU (Ireland)
- Stripe — payments and subscription management
- Resend — transactional email delivery
- Vercel — application hosting and edge delivery
- Sentry — application error monitoring and diagnostics (when a DSN is configured)
- Google and GitHub — identity providers if you choose to sign in with them
These providers may process data in the European Union, the United States, or other countries. Your Gatherly database, files, and auth records in Supabase are stored in Ireland. We use contractual and organizational safeguards appropriate to any transfer, including standard contractual clauses where required.
8. Retention
We retain account and project data for as long as your account remains active and as needed to provide the Service. You can delete your account from the dashboard after deleting owned projects. Feedback and related end-user content are retained until the customer deletes them, deletes the project, or the account is closed, plus a limited period in operational backups.
Bug-report image attachments follow the retention period the customer sets on the project (30 days by default). Billing records may be kept for as long as Danish accounting law requires (typically five years). Security logs may be kept longer where needed for fraud prevention or dispute resolution. When data is no longer needed, we delete or anonymize it.
9. Security
We use industry-standard measures such as encrypted transport (HTTPS), access controls, and secret management for project keys. No method of transmission or storage is 100% secure. You are responsible for protecting your account credentials and project secret keys, and for configuring identity JWTs correctly on your product.
11. Your rights
Depending on your location, you may have rights to access, correct, delete, export, or restrict processing of your personal data, and to object to certain processing. Account holders can often update profile details and delete their account in the dashboard.
To exercise rights related to your Gatherly account, email support@gatherly.sh. End users should contact the Gatherly customer whose product they used; we will assist that customer where appropriate.
You may also lodge a complaint with your local data protection authority. If you are in Denmark, that is Datatilsynet.
12. Children’s privacy
The Service is not directed to children under 16, and we do not knowingly collect personal data from children. If you believe a child has provided us data, contact us and we will take appropriate steps.
13. International transfers
Gatherly is operated from Denmark. Your database, files, and auth records in Supabase are stored in Ireland (EU). Other providers may process data in the EU, the United States, and other countries where they operate. Where a transfer outside the EEA or UK requires a safeguard, we use appropriate transfer mechanisms (such as standard contractual clauses).
14. Changes
We may update this Privacy Policy from time to time. We will post the revised version on this page and update the effective date. Material changes may also be communicated by email or in-product notice where appropriate.
15. Contact
Privacy questions: support@gatherly.sh