Polletra

Privacy Policy

Effective date: January 1, 2025 · Last updated: January 1, 2025

1. Introduction

Polletra ("we", "us", "our") operates the Polletra platform, accessible at polletra.com. This policy explains how we collect, use, disclose, and safeguard information when you use our service. By using Polletra, you agree to the collection and use of information as described here.

2. Definitions

  • Tenant — A business or individual with a Polletra account.

  • End User — A user of a Tenant's product who interacts with a Polletra-powered widget or API.

  • Personal Data — Any information that identifies or can identify a natural person.

  • Processing — Any operation performed on Personal Data.

3. Information We Collect

From Tenants (account holders):

  • Name, email, company name, billing information collected at registration.

  • Usage data: API call logs, dashboard activity, plan tier.

  • Support communications.

From End Users (via Tenant-deployed widgets/API):

  • User identifier (provided by the Tenant from their own system — typically a hashed user ID or email).

  • Feedback content: text, votes, comments, attached metadata.

  • IP address and browser user-agent for fraud prevention and rate limiting only.

  • We do not set third-party tracking cookies on End Users. We do not build advertising profiles.

4. How We Use Information

For Tenants: to provide and improve the service, process billing, send transactional emails, respond to support requests, and comply with legal obligations.

For End User data: solely to provide the feedback collection and management service on behalf of the Tenant. We do not use End User data for our own marketing, analytics, or profiling. Tenants are the data controller for their End Users' data; Polletra acts as a data processor.

5. Data Sharing and Disclosure

We do not sell Personal Data. We share data only with:

  • Service providers — hosting (Supabase/AWS), payment processing (Stripe), transactional email — under data processing agreements.

  • Tenants — End User data is accessible to the Tenant who deployed the widget.

  • Legal compliance — when required by law, court order, or to protect rights and safety.

6. Data Retention

Tenant account data is retained for the life of the account plus 30 days after deletion request. End User feedback data is retained as long as the Tenant's account is active. Tenants may delete their End User data at any time via the API or dashboard. Billing records are retained for 7 years per tax requirements.

7. Security

We implement industry-standard safeguards: TLS in transit, AES-256 at rest, row-level security in our database layer, scoped API keys with origin validation, and regular security reviews. No method of transmission over the internet is 100% secure. We will notify affected Tenants of any breach within 72 hours of discovery.

8. GDPR and CCPA

GDPR (EU/EEA users):

Legal basis for processing Tenant data is contract performance. Legal basis for processing End User data is the Tenant's legitimate interest or consent, as determined by the Tenant. Data subjects may request access, rectification, erasure, portability, or restriction by contacting privacy@polletra.com. Tenants acting as data controllers are responsible for obtaining appropriate consent from their End Users.

CCPA (California residents):

You have the right to know what personal information is collected, to delete it, and to opt out of sale (we do not sell personal information). To exercise rights, contact privacy@polletra.com.

9. Cookies

We use strictly necessary cookies for session authentication on the Polletra dashboard. We use no third-party advertising cookies. Tenants' End Users are not cookied by Polletra.

10. Children's Privacy

Polletra is not directed at children under 16. We do not knowingly collect personal data from children. If we discover we have, we will delete it promptly.

11. Changes to This Policy

We will post changes on this page with a new effective date. Material changes will be notified via email to Tenant account holders.

12. Contact

Polletra Inc. · privacy@polletra.com ·