Feedback JourneyFeedback Journey

Privacy Policy

This page explains, in plain language, how Feedback Journey handles personal data. We would rather be specific than vague, so this page names the tools we use and the situations where data leaves our own systems.

Who is responsible for the data?

Feedback Journey is run by Feedbach As, registration number 933393585, Norway. If you have questions about privacy, access, deletion, or anything else related to personal data, send an email to hey@feedbackjourney.com.

Whose data do we handle?

1. People visiting this website

When you use feedbackjourney.com or the app on go.feedbackjourney.com, we handle the normal website or app traffic data needed to run those services. If you contact us, we also handle whatever you write in the contact form.

2. Users of the Feedback Journey app

In the app we handle account and profile data such as name, email address, title/role, profile image, organization membership, and subscription/billing metadata.

3. Respondents invited to surveys

We handle respondent email addresses, invitation status, preferred language, responses, timestamps, written comments, and optional recommendation data. If a respondent chooses to add their name and title together with a recommendation, that can also be stored.

4. Billing contacts

When someone pays for a subscription, billing and subscription data is handled through Stripe and linked back to the relevant user or organization.

5. People who are being given feedback

Feedback Journey is used to collect feedback about a specific person — usually the account holder, or someone a user runs a survey on behalf of. The scores, comments and reflections gathered are personal data about that person. Results stay private to the user and the people they share with inside their organization, unless the person (or the account owner) chooses to publish a summary as a public Journey Card (see below).

What data do we use, and why?

  • Account and organization data: to create accounts, control access, show profiles, and let organizations manage members.
  • Survey and respondent data: to send invitations, collect responses, show results, and support improvement work inside the product.
  • Billing data: to create and manage subscriptions, handle renewals and cancellations, and keep payment state in sync.
  • Website contact data: to reply when you ask for support, a demo, or other help.
  • Website traffic data:to see which pages get read and how people — and AI assistants — find us, using the cookieless setup described under “What about cookies and tracking?” below.
  • AI feature input: if a user chooses to use the AI coach or AI goal suggestions in the app, we send the relevant survey context to our AI provider to generate that result.
  • Onboarding and product emails:we send new users a small number of onboarding and product emails (for example after the first survey or first goal) to help them get started. You can opt out of these at any time — see “What is our legal basis?” below.

What is our legal basis?

Under the GDPR we rely on the following legal bases:

  • Performance of a contract (Art. 6(1)(b)): running accounts, organizations, surveys, responses, results, and subscriptions for our users and customers.
  • Legal obligation (Art. 6(1)(c)): keeping billing and accounting records for as long as tax and accounting law requires.
  • Legitimate interests (Art. 6(1)(f)): keeping the service secure, handling support and contact requests, measuring website traffic in the cookieless, non-profiling way described below, and sending onboarding and product emails to our users. You can object to the onboarding/product emails and unsubscribe at any time, either via the unsubscribe link in those emails or by emailing hey@feedbackjourney.com.

Which third parties receive personal data?

These are the main external services that currently receive personal data from Feedback Journey:

  • Cloudflare: hosting, delivery, and infrastructure services.
  • Auth0 by Okta: authentication and identity handling for app users.
  • MailerSend: delivery of survey invitation emails to respondents.
  • Stripe: checkout, billing, subscription management, invoices, and payment administration.
  • Google Gemini: optional AI-generated comments and improvement-goal suggestions inside the app.
  • Brevo: sending onboarding and product emails to users, and storing the contact details needed to do that.
  • Slack: operational notifications and contact-message handling.

What exactly does each of these get?

  • Cloudflare handles our hosting and network layer, so it processes the IP address and standard request metadata of everyone who uses the website or app, and stores application data and uploaded files as part of running the service.
  • Auth0 by Okta gets the data needed to sign users in, such as name, email address, and authentication/session information.
  • Stripe gets the data needed to run checkout and subscriptions, such as email address, Stripe customer/subscription/payment IDs, invoice data, and subscription status.
  • MailerSend gets respondent email addresses and the content needed to send invitation emails.
  • Slack gets limited operational data when we receive contact requests or internal service events, such as name, email address, message content, or organization name, depending on the event.
  • Brevogets a user’s email address and first name, and a record of a few product milestones (such as creating a first survey, receiving a first response, or creating a first goal), so we can send relevant onboarding and product emails. Brevo is based in the EU. You can unsubscribe from these emails at any time.
  • Google Gemini gets the survey context needed to generate optional AI features. That can include survey scores, comments, messages, recommendations, and related names/titles already stored in the service.

Do we transfer data outside Europe?

Yes. Several of the services listed above operate from the United States or may process data there. That means personal data can be transferred outside the EU/EEA. When that happens, we rely on the transfer mechanisms offered by the provider, such as standard contractual clauses and/or the EU-U.S. Data Privacy Framework where relevant.

Journey Cards (public proof points)

A user can choose to publish a Journey Card— a summary of their feedback results. When they do, the card becomes available to anyone who has its link: it can show the person’s name, title, profile image, and aggregated scores and statistics. The card link is a long, unguessable address rather than something protected by login, so treat it as public once shared.

A card does not show individual responses or respondent identities. It can optionally include an aggregated breakdown of the email domains that responded (for example how many came from a given company). This is off by default and only appears if the card owner turns it on. A user can take their own Journey Card down at any time from inside the app, which removes it from public view.

How long do we keep personal data?

We try to keep data for as long as it is needed to run the service properly, handle support, and meet legal obligations, and not longer than that. In practice, that means:

  • account, survey, and improvement data is kept while the service relationship is active and while the historical record is still needed;
  • billing data is kept as long as needed for accounting, tax, subscription administration, and dispute handling;
  • contact messages are kept only as long as needed to handle the request and any reasonable follow-up.

What about cookies and tracking?

Feedback Journey uses only necessary cookies or similar storage for things like language preferences and login/session handling in the app. We do not use marketing or ad cookies, and our website analytics do not use cookies or browser storage either — so there is still no cookie banner or consent choice to make. Where it makes sense technically, we may scope cookies to the parent domain so the same preference can be reused across feedbackjourney.com and go.feedbackjourney.com. The details are in the cookie policy.

How we count website visits

We do want to know which pages people find useful and how they got here, so we count page views with Trackking — analytics software we built ourselves and run on our own server. It is not a third-party analytics service: nothing is handed to an external analytics vendor, and nothing is ever sold or shared for advertising.

It works without cookies, without browser storage, and without any tracking script on the page — the counting happens on our server as the page is requested. What gets recorded is the page you opened, the site that linked you here (only the domain, for example google.com, never the full address), your browser’s user agent, and a handful of ordinary request headers that help us tell real visitors apart from bots and AI crawlers.

Your IP address is used only in the moment the request arrives. It is combined with a secret that changes every day and turned into a short visitor code, so we can count one person once per day — and then the address itself is thrown away and never stored. The daily secret is discarded too, which means those codes cannot be linked from one day to the next or turned back into an IP address. There is no cross-site tracking, no advertising profile, and nothing that identifies you personally. Detailed traffic records are deleted after 90 days.

What rights do people have?

Depending on the situation, you may have the right to ask for access, correction, deletion, restriction, objection, or a copy of your personal data. If you want help with that, email hey@feedbackjourney.com and explain what you need. If we need more information to find the right data, we will ask.

A few practical notes on deletion. To keep results honest, we do not remove individual responses one by one — that would let results be edited after the fact. Instead, a user’s feedback data (their surveys, responses, comments and goals) is removed when their account is deleted. Signed-in users can do this themselves from Settings → Data & privacy: deleting your account permanently removes your profile and all of that feedback data, cancels any active subscription, and removes your contact and login records. A published Journey Card can also be taken down at any time from inside the app.

You can also download a copy of your personal data yourself from Settings → Data & privacy as a JSON file (profile, surveys, the responses you received, Journey Cards, improvement goals and a billing summary). If you would rather we handle an access, export or deletion request for you, email hey@feedbackjourney.com. Some records — such as billing and accounting data — may need to be kept where the law requires it.

Do we make fully automated decisions about people?

No. The AI features in Feedback Journey are optional coaching tools. They suggest text and ideas, but they do not make legal, employment, credit, or similar significant decisions for people.

How will we tell you about changes?

If we make a meaningful change to how Feedback Journey handles personal data, we will update this page. If the change is important for customers or users, we will also communicate it more directly where that makes sense.