Data Processing

Effective Date: [Insert launch date]

This page provides an informational overview of how Wafeed processes data. It is not a formal Data Processing Agreement (DPA). Businesses that require a formal DPA should contact us.

1. What Data Wafeed Processes

Wafeed processes the following categories of data:

  • Business account data: name, email, business profile, branding settings.
  • Customer feedback submissions: star ratings, reason tags, optional comments, and source metadata.
  • Hashed IP addresses for spam protection (raw IPs are not stored).
  • Notification email addresses for sending low-rating alerts.
  • Session and authentication tokens for logged-in users.
  • Email delivery logs for audit and troubleshooting.

For a full description of data collected, see our Privacy Policy.

2. Data Roles

Business owners

When you use Wafeed to collect feedback from your customers, you act in a controller-like capacity in relation to that customer feedback data. You decide the purpose (collecting feedback about your service), and you are responsible for having an appropriate basis to collect that data from your customers.

Wafeed

In relation to customer feedback data collected through your links, Wafeed acts in a processor-like capacity — we store and display the data on your behalf in your dashboard. We do not use your customer feedback data for our own purposes beyond providing the Service.

For business account data (registration, settings, billing), we act as a controller and process that data to operate our platform.

3. Data Storage

All application data is stored in our primary database hosted via Supabase. Data is transmitted over HTTPS and encrypted at rest by the database provider.

Data centres are located in regions configured by Supabase and Vercel. The specific region may vary based on project configuration.

4. Subprocessors and Service Providers

We use the following service providers who may process data on our behalf:

Supabase

Database, authentication, and file storage. Processes account data and feedback submissions. Supabase is built on PostgreSQL with Row Level Security.

Vercel

Application hosting and serverless functions. Processes all web requests made to the Wafeed application.

SMTP / Email provider

Used for sending low-rating alert notifications. The specific provider depends on your configuration (default SMTP or custom SMTP on supported plans). Processes notification email addresses only.

Each provider maintains their own data protection commitments. We will update this list as subprocessors change.

5. Security Measures

We implement the following technical and organisational measures:

  • HTTPS: All data in transit is encrypted using TLS.
  • Authentication: Supabase Auth manages passwords as secure hashes. Plaintext passwords are never stored.
  • Row Level Security (RLS): Database policies ensure each business can only access their own data.
  • Role-based access control: Admin, user, and super-admin roles with separate permission levels.
  • Server-side secret handling: API keys and credentials are stored as environment variables and never exposed to the client.
  • IP hashing: Customer IPs are hashed with a secret salt for spam detection. Raw IPs are not stored.
  • Honeypot fields: Feedback forms include invisible honeypot fields to detect automated bot submissions.
  • Audit logging: Admin actions are recorded in an audit log.

See also our Security page.

6. Data Deletion Requests

If you wish to request deletion of your account and associated data, please contact us via the contact page. We will aim to process deletion requests within a reasonable timeframe, subject to any legal or operational constraints.

Note that some data (such as aggregated statistics or anonymised records) may be retained after account deletion.

7. Data Export

Business users on Team and Business plans can export their feedback submissions as a CSV file directly from the dashboard. This allows you to retain a copy of your data at any time.

If you require a data export but are on the Free or Starter plan, please contact us and we will assist where possible.

8. Formal Data Processing Agreement

Businesses that require a formal Data Processing Agreement (DPA) for compliance purposes — for example, under GDPR or similar regulations — should contact us. We do not have a standard DPA template available at this time, but we can discuss your requirements.

These pages are starter templates intended for informational purposes. They should be reviewed by a qualified legal professional before large-scale commercial launch.

View all legal pages →
Data Processing — Wafeed | Wafeed