Data Processing
Effective Date: 8 July 2026
Last updated: 8 July 2026
This page is currently available in English only — an Arabic translation of our legal documents is in progress.
هذه الصفحة متاحة حاليًا باللغة الإنجليزية فقط، والنسخة العربية من مستنداتنا القانونية قيد الإعداد.
This page provides an informational overview of how Wafeed processes data. It is not a formal Data Processing Agreement (DPA). Businesses that require a formal DPA should contact us.
1. What Data Wafeed Processes
Wafeed processes the following categories of data:
- Business account data: name, email, business profile, branding settings.
- Team member / staff account data: name, email, and role, for users granted access to a business.
- Customer feedback submissions: star ratings, reason tags, optional comments, and source metadata (including which touchpoint — link, QR code, or NFC tag — was used).
- Customer contact details submitted for low-rating follow-ups or support cases, where enabled by the business.
- Custom domain and custom SMTP configuration, on supported plans.
- Hashed IP addresses for spam protection (raw IPs are not stored).
- Notification email addresses for sending low-rating alerts.
- Session and authentication tokens for logged-in users, including third-party sign-in identifiers where that method is used.
- Email delivery logs for audit and troubleshooting.
- Billing and plan request details submitted for manual activation (no online payment data is currently collected).
For a full description of data collected, see our Privacy Policy.
2. Data Roles
Business owners
When you use Wafeed to collect feedback from your customers, you act in a controller-like capacity in relation to that customer feedback data. You decide the purpose (collecting feedback about your service), and you are responsible for having an appropriate basis to collect that data from your customers.
Wafeed
In relation to customer feedback data collected through your links, Wafeed acts in a processor-like capacity — we store and display the data on your behalf in your dashboard. We do not use your customer feedback data for our own purposes beyond providing the Service.
For business account data (registration, settings, billing), we act as a controller and process that data to operate our platform.
3. Data Storage
All application data is stored in our primary database hosted via Supabase. Data is transmitted over HTTPS and encrypted at rest by the database provider.
Data centres are located in regions configured by Supabase and Vercel. The specific region may vary based on project configuration.
4. Subprocessors and Service Providers
We use the following service providers who may process data on our behalf:
Supabase
Database, authentication, and file storage. Processes account data and feedback submissions. Supabase is built on PostgreSQL with Row Level Security.
Vercel
Application hosting and serverless functions. Processes all web requests made to the Wafeed application.
SMTP / Email provider
Used for sending low-rating alert notifications. The specific provider depends on your configuration (default SMTP or custom SMTP on supported plans). Processes notification email addresses only.
Each provider maintains their own data protection commitments. We will update this list as subprocessors change.
5. Security Measures
We implement the following technical and organisational measures:
- HTTPS: All data in transit is encrypted using TLS.
- Authentication: Supabase Auth manages passwords as secure hashes. Plaintext passwords are never stored.
- Row Level Security (RLS): Database policies ensure each business can only access their own data.
- Role-based access control: Admin, user, and super-admin roles with separate permission levels.
- Server-side secret handling: API keys and credentials are stored as environment variables and never exposed to the client.
- IP hashing: Customer IPs are hashed with a secret salt for spam detection. Raw IPs are not stored.
- Honeypot fields: Feedback forms include invisible honeypot fields to detect automated bot submissions.
- Audit logging: Admin actions are recorded in an audit log.
See also our Security page.
6. Data Deletion Requests
If you wish to request deletion of your account and associated data, please contact us via the contact page. We will aim to process deletion requests within a reasonable timeframe, subject to any legal or operational constraints.
Note that some data (such as aggregated statistics or anonymised records) may be retained after account deletion.
7. Data Export
Business users whose plan includes CSV export can download feedback submissions from the dashboard and keep a copy of that file.
If your plan does not include CSV export, contact us to discuss the available options.
8. Formal Data Processing Agreement
Businesses that require a formal Data Processing Agreement (DPA) for compliance purposes — for example, under GDPR or similar regulations — should contact us. We do not have a standard DPA template available at this time, but we can discuss your requirements.
These pages are starter templates intended for informational purposes. They should be reviewed by a qualified legal professional before large-scale commercial launch.
View all legal pages →