Privacy Policy
At SureFeedback, we respect your privacy and are committed to protecting your personal information. This Privacy Policy explains how we collect, use, store, process, and safeguard information when you use SureFeedback Cloud, our hosted website feedback and collaboration platform, and when you visit our website at surefeedback.com.
This policy also explains how SureFeedback Cloud interacts with our WordPress plugins, including the Cloud plugin and the self-hosted client plugin.
Who We Are
SureFeedback Cloud is a Software-as-a-Service (SaaS) platform operated by Brainstorm Force US LLC, which is the controller responsible for the personal data described in this policy, except where we state that we act as a processor on a customer’s behalf.
Contact Information
Support: [email protected]
Privacy: [email protected]
SureFeedback Cloud App: https://app.surefeedback.com
You can find more information about us, including our full address, on our company website.
Scope of This Privacy Policy
This Privacy Policy applies only to SureFeedback Cloud, including:
- The SureFeedback Cloud web application
- APIs and backend services supporting SureFeedback Cloud
- Feedback widgets served from SureFeedback Cloud
- Integrations used to connect SureFeedback Cloud with customer websites
- Our public website at surefeedback.com, including its marketing pages, forms and tracking technologies
Related Plugins (Referenced Only)
- SureFeedback Cloud Plugin (WordPress Connector):
https://wordpress.org/plugins/surefeedback-cloud/ - SureFeedback Client Site (Self-Hosted Plugin):
https://wordpress.org/plugins/projecthuddle-child-site/
These plugins are referenced for clarity. This policy governs SureFeedback Cloud (SaaS) and the surefeedback.com website. Data held only on a customer’s own WordPress server by the self-hosted plugin is governed by that customer’s own privacy policy unless it is connected to Cloud services.
Our role in relation to your data
We act in two distinct roles, and which one applies determines who you should contact about your data.
We are a controller: for the personal data we collect for our own purposes: your account, your billing records, your support requests, our marketing communications, and the analytics and advertising technologies on our own website.
We are a processor: for the feedback data our customers collect using our service. When you leave a comment, annotation or screenshot on a website that uses SureFeedback, the operator of that website decides what is collected, why it is collected and how long it is kept. We process that data on their instructions. If you want to access, correct or delete feedback you submitted on someone else’s website, please contact that website’s operator. If you contact us instead, we will pass your request to them and tell you that we have done so.
Where we get your data from
We collect personal data:
- Directly from you – when you create an account, contact support, complete a form on our website, subscribe to updates, or submit feedback through a widget.
- Automatically from your device and browser – when you use our website or the Cloud application.
- From our customers – where they use our service to collect feedback from their own website visitors.
- From our payment and licensing providers – in connection with purchases, subscriptions and licence checks.
- From our analytics and advertising providers – in aggregated or pseudonymised form, and only where you have consented to those technologies.
Information We Collect
A. Information Collected from SureFeedback Cloud Customers
When you create or use a SureFeedback Cloud account, we may collect:
- Full name and email address
- Account login credentials (stored using one-way encryption; we cannot read your password)
- Subscription details and billing status
- Workspace, project, and team configurations
- Team member email addresses
- Support tickets and communications
- Cloud usage and feature interaction data
Payment Information
Payments are processed by Stripe or PayPal.
- SureFeedback Cloud does not store credit card numbers
- We retain only limited billing metadata, such as plan, status and invoices
- Card details are entered directly with the payment provider, not with us
B. Information collected from website visitors who submit feedback
When visitors submit feedback through SureFeedback Cloud widgets, we may collect:
- IP address (anonymized where legally required)
- Country-level location (derived from IP)
- Browser type, device type, and operating system
- Page URLs where feedback is submitted
- Comments, replies, annotations, and screenshots
- Element position and interaction context
- Timestamp and session metadata
We do not intentionally collect visitor names, email addresses or account credentials through the feedback widget.
C. Automatically Collected Technical Data
SureFeedback Cloud and our website automatically collect limited technical data such as:
- Browser and platform information
- Referring URLs
- Performance metrics and error logs
- Feature usage and interaction events
This data is used for security, reliability, analytics, and product improvement.
Which information is required
Some information is necessary for us to provide the service. An email address and a password are required to create an account, and billing details are required to take payment for a paid plan. Without these we cannot open or maintain your account.
Other information – such as a profile picture, job title, company name or the optional fields in a contact form – is genuinely optional. Leaving it out does not affect your access to any feature.
Information you enter into our forms
When you complete a form on our website – a support request, a contact form, a newsletter signup, a demo request – we receive what you enter, along with technical details such as your IP address and the page you submitted it from.
We do not capture passwords or payment card security codes through website forms. Payment details are entered directly with our payment provider. Form submissions are stored in our support and email systems, which are listed under service providers below.
Sensitive and special-category data
We do not seek or intentionally collect special-category data such as information about your health, racial or ethnic origin, religious or political beliefs, trade union membership, genetic or biometric data, or sexual orientation. Please do not include such information in feedback comments, screenshots or support requests.
The only data we treat as sensitive is your account login credentials, which we use solely to authenticate you and protect your account.
Visual Feedback & Screenshot Data
SureFeedback Cloud enables visual feedback features, including:
- Page screenshots captured for context
- Annotations and comments linked to page elements
- Comment threads, replies, and resolution status
Screenshot Handling
- Screenshots are generated client-side or during feedback submission
- Only relevant page content is captured
- Screenshots are encrypted and access-controlled
- Retention follows project and account settings
Please be aware that a screenshot of a web page may incidentally capture personal data that is displayed on that page. If you are a customer using SureFeedback to review pages that display third-party personal data, you are the controller of that data and should take this into account in your own privacy notice and retention settings.
WordPress Plugins & Cloud Interaction
SureFeedback Cloud Plugin
The SureFeedback Cloud plugin allows WordPress sites to connect to the SureFeedback Cloud SaaS.
- Acts as a connector to SureFeedback Cloud
- Sends site identifiers and authentication tokens
- Does not independently store Cloud feedback data
All Cloud-related data is governed by this Privacy Policy.
SureFeedback Client Site (Self-Hosted Plugin)
Plugin URL: https://wordpress.org/plugins/projecthuddle-child-site/
- This plugin is self-hosted
- Data is stored on the customer’s WordPress server
- SureFeedback Cloud only receives data if the customer explicitly connects it
Self-hosted data is governed by the customer’s own privacy policy unless it is connected to Cloud services.
Why we process your data, and our legal basis
Where the EU GDPR or UK GDPR applies, we rely on the following legal bases.
| Purpose | Legal basis |
| Creating and operating your account, delivering the service, enabling collaborative feedback, authenticating users and managing access, providing customer support | Performance of a contract – Art. 6(1)(b) |
| Processing subscriptions, billing, invoicing, and keeping tax and accounting records | Legal obligation – Art. 6(1)(c), and performance of a contract – Art. 6(1)(b) |
| Securing the service, preventing fraud and abuse, spam and bot protection, monitoring system performance and reliability, diagnosing faults | Legitimate interests – Art. 6(1)(f) |
| Product improvement using aggregated usage data | Legitimate interests – Art. 6(1)(f) |
| Website analytics, session replay and heatmaps, advertising and retargeting, non-essential cookies | Consent – Art. 6(1)(a) |
| Marketing emails and newsletters | Consent – Art. 6(1)(a), or legitimate interests where permitted for existing customers, with an opt-out in every message |
| Processing feedback data on behalf of a customer | We act as a processor; the customer determines the legal basis |
| Responding to lawful requests from courts, regulators and law enforcement | Legal obligation – Art. 6(1)(c) |
Using data for a new purpose
If we intend to use your personal data for a purpose that is materially different from the purposes described in this policy, we will tell you beforehand, explain the legal basis we intend to rely on, and obtain your consent where the law requires it.
Cookies and similar technologies
We and our providers use cookies, pixels, local storage and similar technologies on our website. We group them into four categories:
- Strictly necessary – required for the site to work, including session management, security, abuse prevention, and completing a purchase or licence check you have asked for. These are always active and cannot be switched off.
- Functional – remember your preferences and enable features such as on-site messaging.
- Analytics – help us understand how the site is used, including page views, navigation paths, session replay and heatmaps.
- Advertising – measure the performance of our campaigns and allow our advertising partners to show you relevant ads on other services.
The table below lists the technologies currently in use on surefeedback.com, who provides them, why we use them and how long they persist. We review this table whenever a technology is added to or removed from the site.
| Technology / Cookie | Provider | Category | Purpose | Duration |
| Google Analytics 4 – _ga | Analytics | Distinguishes visitors so we can count unique users and measure how the site is used | 2 years | |
| Google Analytics 4 – _ga_<container-id> (multiple live containers) | Analytics | Maintains GA4 session state per property. Several GA4 containers are active on the site | 2 years | |
| Google Analytics 4 – _gid | Analytics | Distinguishes visitors within a short window | Not stated – see note below | |
| Google Tag Manager | Analytics (tag delivery layer) | Loads and manages the tags listed in this table. GTM itself sets no cookie; it controls which of the technologies below load and when | No cookie set | |
| Google reCAPTCHA-_GRECAPTCHA | Strictly necessary (spam and abuse prevention) | Distinguishes humans from bots on our forms and login pages, to prevent spam and automated abuse | 6 months | |
| Google Fonts | Not gated by the consent banner – see note below | Loads the typefaces used on our site. Requesting a font transmits your IP address and browser details to Google | No cookie set | |
| Meta Pixel – _fbp (Pixel ID 928044814774965) | Meta Platforms | Advertising | Identifies your browser so we can measure our advertising and show ads to people who have visited our site | 90 days |
| Meta Pixel – fr | Meta Platforms | Advertising | Delivers, measures and improves the relevance of advertising | 90 days |
| Microsoft Clarity – _clck | Microsoft | Analytics (session replay) | Retains a Clarity user ID so repeat visits are attributed to the same recording profile | 1 year |
| Microsoft Clarity – _clsk | Microsoft | Analytics (session replay) | Links the page views in a single session into one recording | 1 day |
| Microsoft Clarity — CLID / MUID | Microsoft | Analytics (session replay) | Identifies the browser to the Clarity service across sessions and Microsoft properties | 1 year |
| Stripe – __stripe_mid | Stripe | Strictly necessary (fraud prevention) | Fraud prevention and payment-form security. Set wherever the Stripe library loads, including marketing pages | 1 year |
| Stripe – __stripe_sid | Stripe | Strictly necessary (fraud prevention) | Session-level fraud prevention for payment forms | 30 minutes |
| Freemius – cookies and storage set from checkout.freemius.com | Freemius | Essential / strictly necessary (checkout and licensing) | Purchase, licensing and plugin distribution | Not stated – see note below |
| ConvertBox | ConvertBox | Functional | On-site messages, offers and signup forms; remembers which messages you have already seen or dismissed | Not stated – see note below |
| Cloudflare – cf_clearance | Cloudflare | Strictly necessary (security) | Records that your browser has passed a security or bot challenge, so you are not challenged repeatedly | Not stated – see note below |
| Cloudflare – __cf_bm | Cloudflare | Strictly necessary (security) | Bot management; distinguishes automated traffic from human visitors | 30 minutes |
| session_cookie (first party) | SureFeedback (Brainstorm Force US LLC) | Strictly necessary | Server-side session management for the website. Set by our web application before any consent choice, because the site cannot maintain a session without it | Not stated – see note below |
| surecookie_session_id (first party) | SureFeedback (Brainstorm Force US LLC) | Strictly necessary | Identifies your consent session so your cookie choice can be recorded and applied | Not stated – see note below |
| surecookie_user_consent (first party) | SureFeedback (Brainstorm Force US LLC) | Strictly necessary | Stores the cookie categories you accepted or declined, so we honour your choice and do not ask again on every page | 365 days |
About durations:
The durations shown are the lifetimes documented by the provider that sets the cookie. Where the table says “Not stated”, we have not yet independently verified the lifetime and we would rather leave it blank than publish a figure we cannot stand behind. We are confirming these and will add them to this table as they are established. You can always inspect the current expiry of any cookie on this site through your browser’s developer tools or cookie settings.
About Google Fonts:
Our typefaces are requested through a stylesheet link in our pages, so this request is made when the page loads and is not controlled by the consent banner. Making the request transmits your IP address and browser details to Google. We are working to serve these fonts from our own servers so that the request no longer leaves your browser.
Several Google Analytics 4 and Google Tag Manager containers are currently active on the site.
Analytics and session analysis
With your consent, we use Google Analytics 4, delivered through Google Tag Manager, to measure how visitors find and use our website — page views, navigation paths, traffic sources and conversion events.
We also use Microsoft Clarity, which records session replays of your visit and produces heatmaps of clicks and scrolling. Clarity captures your interactions with our pages, including mouse movement, clicks, scrolling, the pages you view and the content displayed to you, and it may capture text you type into non-sensitive form fields. We do not use session replay to build advertising profiles, and we do not use it to monitor identified individuals.
Google Analytics 4, Google Tag Manager and Microsoft Clarity do not load until you accept analytics cookies, and you can withdraw that consent at any time using the Cookie Preferences control in our website footer.
Advertising and retargeting
With your consent, we use advertising technologies that let us measure our campaigns and reach people who have previously visited our website. These currently include the Meta Pixel (Pixel ID `928044814774965`), provided by Meta Platforms, and Google advertising tags.
These technologies set identifiers in your browser and send Meta or Google a record of your visit, including the pages you viewed and the actions you took. That record may be matched to an account you hold with those providers. Advertising identifiers set through our site are retained for up to 90 days.
The Meta Pixel and Google advertising tags do not load until you accept advertising cookies. You can decline or withdraw that consent at any time through the Cookie Preferences control in our footer. You can also control ad personalisation directly in your Meta and Google account settings.
Because these technologies transmit online identifiers and browsing activity to advertising partners, we treat this activity as “sharing for cross-context behavioral advertising” under California law. See Your California privacy rights below.
How we obtain and honour your consent
When you first visit our website, we show a consent banner.
- Google Analytics 4, Google Tag Manager, Microsoft Clarity, the Meta Pixel and ConvertBox are blocked by default. None of them loads until you make a choice and accept the category it belongs to.
- We use Consent Mode, configured so that Google tags are held in a denied state for all regions before you consent.
- If you decline, we do not load those technologies. Declining is honoured, and none of those tags fires.
- We record your choice so that you are not asked again on every page.
You can change or withdraw your choices at any time using the Cookie Preferences link in our website footer. Withdrawing consent is as straightforward as giving it. Withdrawal applies going forward; it does not undo processing that already took place while your consent was active.
Strictly necessary technologies remain active regardless of your choice, because the site cannot function securely without them. These are listed in the cookie table above, with the reason each one is necessary.
Some technologies are loaded through our page templates rather than through the consent banner. Google Fonts, described in the note under the cookie table above, is one of them.
Your cookie choice applies to surefeedback.com. Other Brainstorm Force websites run their own consent controls, so a choice you make here does not carry across to them.
Global Privacy Control
Some browsers and browser extensions can send a Global Privacy Control (GPC) signal, which is a legally recognised opt-out of the sale or sharing of personal information in California, Colorado and several other US states.
Our website detects the GPC signal at the origin. When we receive it, we treat it as a request to opt out of advertising cookies and of sharing for cross-context behavioral advertising, and we apply it to that browser automatically – you do not need to interact with the banner for the opt-out to take effect.
Because the signal is stored in your browser, you may need to set it again on other browsers or devices, or if you clear your browsing data.
Do Not Track
There is no agreed industry standard for how websites should interpret the browser “Do Not Track” signal, so we do not respond to it.
We instead give you direct control in two ways that are standardised and that we do honour: our consent banner and the Cookie Preferences link in our footer, and the Global Privacy Control signal described above.
Service providers and sub-processors
We use carefully selected third parties to deliver our service. Each is bound by a written agreement that limits them to processing personal data on our instructions and requires appropriate security measures.
| Function | Provider | Role |
| Hosting and infrastructure | Hetzner (application and database hosting), AWS (storage) | Service provider – not shared for advertising |
| Network security and content delivery | Cloudflare – protects the site from attack and abuse and sets its own security cookies, including a clearance cookie that records that your browser has passed a security check | Service provider – not shared for advertising |
| Payment processing | Stripe, PayPal | Service provider – not shared for advertising |
| Purchase, licensing and plugin distribution | Freemius | Service provider (essential) – not shared for advertising |
| Analytics | Google (Google Analytics 4, Google Tag Manager) | Service provider – loads only after you consent to analytics |
| Session replay and heatmaps | Microsoft (Clarity) | Service provider – loads only after you consent to analytics |
| Advertising | Meta Platforms, Google | Shared for cross-context behavioral advertising – loads only after you consent to advertising |
| Website functionality | Google reCAPTCHA (form spam and abuse protection), Google Fonts (web typography), ConvertBox (on-site messages and signup forms) | Service provider – not shared for advertising |
| Email delivery | AWS SES | Service provider – not shared for advertising |
| Customer support | HelpScout | Service provider – not shared for advertising |
All providers are contractually bound to protect data and to use it only for the purposes we define.
Where we act as a processor for a customer, we will notify that customer of material changes to this list before a new sub-processor begins processing their data.
Where your data is processed
We are a global team and our providers operate in several countries. Your personal data may be processed in:
- The United States, where our contracting entity Brainstorm Force US LLC is established;
- India, where much of our engineering, product and support work is carried out;
- The European Union, where our infrastructure provider operates data centres;
- And in other countries where our providers operate infrastructure or support functions.
Where we transfer personal data out of the European Economic Area, the United Kingdom or Switzerland, we rely on one or more of the following safeguards: - An adequacy decision by the European Commission or the relevant authority;
- The European Commission’s Standard Contractual Clauses, together with the UK International Data Transfer Addendum where applicable;
- Or another lawful transfer mechanism permitted by the applicable law.
We do not claim certification under the EU-U.S. Data Privacy Framework, the UK Extension or the Swiss-U.S. Data Privacy Framework. Our transfers out of the EEA, the UK and Switzerland rely on Standard Contractual Clauses and adequacy decisions.
We also assess, for each transfer, whether additional technical and organisational measures are needed, such as encryption in transit and at rest and access controls limited to named personnel.
You can request further information about the safeguards applying to a specific transfer by writing to [email protected].
How long we keep data
We keep personal data only as long as needed for the purposes described above. In general: account data is deleted within 90 days of account closure; support correspondence is kept for up to 3 years; server and security logs for up to 12 months; advertising identifiers for up to 90 days; and records of cookie consent for 365 days. Backups are held on a rolling 30–90 day cycle. Billing and tax records are retained for as long as applicable tax and accounting law requires. Where we process feedback data on behalf of a customer, that customer sets the retention period
Data security
We use industry-standard security measures, including:
- TLS/SSL encryption for data in transit
- Encrypted storage for sensitive data
- One-way encryption of account passwords
- Role-based access controls
- Limited internal access on a need-to-know basis
- Regular security reviews
While no system is completely secure, we take reasonable steps to protect all Cloud data.
Security incidents and breach notification
If a personal data breach occurs, we notify the relevant supervisory authority within 72 hours where required, and inform affected individuals and customers without undue delay where the breach poses a high risk to their rights.
Your Privacy Rights
Depending on where you live, you may have the right to:
- Access the personal data we hold about you, and be told how and why we process it
- Correct inaccurate or incomplete data
- Delete your data (“right to be forgotten”)
- Restrict our processing while a dispute about accuracy or lawfulness is resolved
- Object to processing based on our legitimate interests, and to direct marketing at any time
- Data portability – receive your data in a structured, commonly used, machine-readable format, and have it transmitted to another provider where technically feasible
- Withdraw consent at any time, where our processing is based on consent
- Opt out of marketing communications, using the unsubscribe link in any message or by writing to us
- Not be subject to solely automated decision-making that has a legal or similarly significant effect on you. We do not carry out such decision-making
- Lodge a complaint with your local data protection authority
Exercising these rights is free and will not affect your service.
We respond within one month under the GDPR and UK GDPR, and within 45 days under California law. We may extend where a request is complex — by up to two further months under the GDPR, or once by 45 days under California law — and we will tell you if that applies.
Your California privacy rights (CCPA/CPRA)
If you are a California resident, the California Consumer Privacy Act as amended by the California Privacy Rights Act gives you the right to:
- Know what categories of personal information we collect, the sources, the purposes, and the categories of third parties we disclose it to
- Access a copy of the specific pieces of personal information we hold about you
- Correct inaccurate personal information
- Delete your personal information, subject to legal exceptions
- Opt out of the sale or sharing of your personal information
- Limit the use and disclosure of sensitive personal information
- Non-discrimination – we will not deny you service, charge you a different price or give you a lower quality of service for exercising any of these rights
- You may exercise these rights yourself or through an authorised agent.
We do not sell personal information. However, when advertising cookies are active, online identifiers and browsing activity are transmitted to our advertising partners – currently Meta Platforms and Google – which constitutes “sharing” for cross-context behavioral advertising under the CPRA. You can opt out at any time via the Cookie Preferences link in our footer, or by enabling Global Privacy Control in your browser, which we detect and honour automatically.
Categories of personal information and disclosure
| Category (Cal. Civ. Code § 1798.140) | Do we collect it? | Disclosed for a business purpose to | Shared for advertising? |
| Identifiers (name, email, IP address, account ID, cookie IDs) | Yes | Hosting, security, payment, email, support and analytics providers | Yes — cookie and device identifiers, to Meta and Google, when advertising cookies are active |
| Commercial information (subscription, purchase and billing history) | Yes | Payment, licensing, accounting and support providers | No |
| Internet or network activity (pages viewed, referring URLs, clicks, scrolling, session replay) | Yes | Analytics and session-replay providers | Yes — where advertising cookies are active |
| Geolocation data (country level, derived from IP) | Yes | Hosting, security and analytics providers | Yes — where advertising cookies are active |
| Sensitive personal information (account login credentials) | Yes | No third party; used only to authenticate you | No |
| Professional or employment information (job title, company, where you provide it) | Yes, optional | Support and email providers | No |
| Biometric information, precise geolocation, government identifiers, health information, racial or ethnic origin, religious beliefs, union membership, contents of private communications | No | – | – |
The only sensitive personal information we process is your account login credentials, used solely to authenticate you. We do not use or disclose it for any purpose that would give rise to the right to limit its use.
Your Rights Under India’s DPDP Act, 2023
If you are in India, you have the right to access a summary of your personal data and its processing; to correction, completion, updating, and erasure; to grievance redressal; to nominate another person to exercise your rights on death or incapacity; and to withdraw consent. Contact our Grievance Officer, Pratik Chaskar, Chief Technology Officer, at [email protected]. We acknowledge grievances within 72 hours and aim to resolve them within 30 days, and in all cases within 90 days. If unresolved, you may escalate to the Data Protection Board of India.
Children’s Privacy
The services are intended for business use and are not directed to children. We do not knowingly collect personal data from a child below the age at which consent is required in their jurisdiction (for example, 16 in much of the EU, 13 under U.S. COPPA). Where consent-based processing involves a minor below the applicable age, we require verifiable parental consent. We do not sell or share the personal information of consumers under 16. If we learn we have collected a minor’s data without the required consent, we delete it promptly; contact [email protected].
Changes to this policy
We update this policy when our practices change.
- The Last updated date at the end always reflects the current version.
- We will give notice of material changes as the law requires – by email or an in-product notice where appropriate.
- Our cookie inventory is reviewed and updated whenever a technology is added to or removed from our website, so that table may change more often than the rest of this policy.
- Continued use of SureFeedback Cloud after a change takes effect indicates acceptance of the updated policy, except where the law requires us to obtain your consent afresh.
Contact Us
For questions, concerns, or privacy requests:
Email: [email protected]
Support: [email protected]
India grievance redressal: [email protected]
Mailing Address:
Brainstorm Force US LLC
2093 Philadelphia Pike #3090
Claymont, Delaware 19703, United States
Last updated: August 21, 2026