Skip to main content

Privacy Policy

Effective Date: 8 July 2026

Last updated: 11 July 2026

This page is currently available in English only — an Arabic translation of our legal documents is in progress.
هذه الصفحة متاحة حاليًا باللغة الإنجليزية فقط، والنسخة العربية من مستنداتنا القانونية قيد الإعداد.

1. Introduction

This Privacy Policy explains how Wafeed (“we”, “our”, or “us”) collects, uses, and protects information when you use our customer feedback platform.

We aim to handle personal data responsibly and to support reasonable data access or deletion requests. This policy covers two groups: (a) registered business users who use the Wafeed dashboard, and (b) customers who submit feedback through a business's feedback link.

2. Who We Are

Wafeed is an independent SaaS platform. For questions about this policy or your data, please contact us via the contact page.

3. Information We Collect

Account information

When you register, we collect your name, email address, and password (stored as a secure hash). We do not store plaintext passwords.

Business profile information

Information you provide when setting up your business profile: business name, logo, brand colours, Google Review Link, feedback touchpoint links (including QR code and NFC-based links), and other settings you configure. On supported plans this may also include a custom domain and custom SMTP (email sending) configuration for your business.

Feedback submissions

Data submitted by your customers through feedback links, including star rating, selected reasons, and optional text comments. See Section 4 for more detail.

Team member / staff accounts

If you invite team members to help manage your business (for example as a manager, staff member, or another role), we collect their name, email address, and role. Team members can access only the businesses and data they have been granted access to.

Customer contact details (cases and follow-ups)

Where a business enables contact collection, a customer who leaves a low rating or opens a support case may optionally provide their name, phone number, and/or email address so the business can follow up. This information is only visible to the business that received it and to team members with permission to view contact details.

Notification settings

Email addresses you add for receiving low-rating notifications. These are used solely for sending alerts per your configuration.

Billing and subscription information

When you buy, renew, change, or cancel a subscription, billing information may be processed by Paddle. Wafeed does not directly store complete card information. We may store the minimum billing metadata needed to operate your account, such as Paddle customer ID, subscription ID, transaction ID, selected plan, subscription status, billing period, price ID, and payment outcome. If you submit a manual plan or add-on request, we also collect the contact details and notes you provide so our team can follow up. See our Terms of Service for more on billing terms.

Usage and technical data

Standard server-side metadata such as request timestamps and error logs, used for security, debugging, and performance monitoring.

Email delivery data

When we send notification emails, we may log delivery status (sent, failed) for audit and troubleshooting purposes.

For more detail on reports/export, subprocessors, and technical security measures, see our Data Processing page.

4. Customer Feedback Submissions

When a customer submits feedback through a feedback link, we collect:

  • Star rating (1–5).
  • Selected reason tags (optional).
  • Free-text comment (optional).
  • Source type (e.g. WhatsApp link, QR code) — as configured by the business.
  • A hashed IP address for spam detection — the raw IP is not stored in readable form.
  • Browser user-agent string, used for basic spam detection.
  • Whether the customer clicked the Google review link (recorded as a boolean flag).

Customers are not required to provide their name or contact information. The form does not ask for personally identifiable contact details unless a future release adds such an optional field.

Feedback submissions are displayed in the relevant business's dashboard and are not shared with other businesses.

5. How We Use Information

  • To provide and operate the Wafeed service.
  • To display feedback submissions in your business dashboard.
  • To send low-rating alert emails per your notification configuration.
  • To prevent spam and abuse through IP hashing and honeypot detection.
  • To improve the product and diagnose technical issues.
  • To perform support and admin operations when required.

We do not use your data for advertising or sell it to third parties.

7. Sharing Information

We do not sell personal data. We may share data with:

Infrastructure and service providers

Database and hosting providers (currently Supabase and Vercel) who process data on our behalf to provide the Service. These providers maintain their own data protection commitments.

Email providers

If you configure email notifications, we use SMTP infrastructure to deliver alerts. Your notification email addresses are shared with the SMTP provider for delivery.

Billing provider

Paddle may process identity, contact, transaction, tax, billing, device, and fraud-prevention data as needed for checkout, invoicing, subscription management, tax compliance, payment security, refunds, and disputes. Paddle's own privacy terms may also apply to payment processing.

Legal requirements

We may disclose data if required by law, court order, or a regulatory authority, or where necessary to protect the rights, property, or safety of Wafeed, our users, or the public.

8. Third-Party Review Platforms

If a customer chooses to click the Google review link after submitting feedback, they leave Wafeed Feedback and are directed to an external Google URL. From that point, Google's own privacy policy and terms of service apply. We do not control or have access to data submitted on third-party review platforms.

9. Third-Party Sign-In Providers (مزودو تسجيل الدخول الخارجي)

Wafeed may allow users to sign in or register using third-party providers such as Google, LinkedIn, Microsoft (if supported later), or other OAuth providers. This section describes how that works when you use third-party sign-in — it does not mean every provider listed here is available today; check the login page for currently supported options.

  • When you sign in with a third-party provider, we may receive your name, email address, profile image, and a provider account ID from that provider.
  • We use this information solely to create or log in to your Wafeed account.
  • We do not receive your password for Google, LinkedIn, or any other provider — authentication is handled directly between you and that provider.
  • You can disconnect or manage Wafeed's access from your provider account settings where the provider supports this.

Your use of a third-party sign-in provider is also subject to that provider's own privacy policy and terms of service, which we do not control.

10. Data Retention

We retain account data for as long as your account is active. Feedback submissions are retained to provide historical reporting in your dashboard. If you request account deletion, we will aim to remove your account and associated data, subject to any legal or technical constraints.

11. Data Security

We implement reasonable technical and organisational measures to protect your data, including HTTPS encryption in transit, authentication and role-based access controls, server-side secret handling, and database-level Row Level Security (RLS). See our Security page for more details.

No system is 100% secure. In the event of a significant data breach affecting your account, we will notify affected users as required.

12. International Processing

Our infrastructure and billing providers (including Supabase, Vercel, and Paddle) may process data in data centres located in various countries. By using Wafeed, you acknowledge that your data may be transferred to and processed in countries other than your own. We select providers that maintain appropriate security standards.

13. Your Rights

We aim to support reasonable requests to:

  • Access the personal data we hold about you.
  • Correct inaccurate data.
  • Request deletion of your account and associated data.
  • Raise a concern about how your data is handled.

Please contact us via the contact page. Specific rights may vary depending on the laws applicable in your jurisdiction.

14. Business Customer Responsibilities

Businesses that use Wafeed to collect customer feedback are responsible for:

  • Ensuring they have a lawful basis to collect feedback from their customers.
  • Not collecting sensitive personal data through feedback forms unnecessarily.
  • Informing customers, where required by law, that their feedback is being collected.
  • Responding to any data requests from customers relating to feedback they have submitted.

15. Children's Privacy

Wafeed is not directed at children under the age of 13. We do not knowingly collect personal data from children. If you believe we have collected data from a child in error, please contact us so we can take appropriate action.

16. Cookies and Analytics

Wafeed uses essential cookies for authentication and session management, and a preference cookie to remember which business you last selected if you manage more than one business (the business switcher). These are necessary for the Service to function and cannot be disabled without affecting your ability to log in or use the dashboard normally.

We also use analytics tools — Vercel Analytics and Microsoft Clarity — to understand traffic and usage patterns on our marketing pages and a small number of non-sensitive dashboard pages, and to improve the product. Microsoft Clarity provides behavioural analytics, heatmaps, and session-replay recordings; we do not send names, email addresses, or phone numbers to Clarity, and it is never active on public feedback/ticket pages, the admin panel, or dashboard pages that display customer feedback content or contact details. See our Cookie Policy for more detail, including which pages are excluded.

17. Changes to This Policy

We may update this Privacy Policy from time to time. When we do, we will update the effective date at the top of this page. Where changes are material, we will aim to notify registered users. Continued use of the Service after changes are posted indicates your acceptance of the updated policy.

18. Contact

For privacy-related questions or requests, please contact us via the contact page.

These pages are starter templates intended for informational purposes. They should be reviewed by a qualified legal professional before large-scale commercial launch.

View all legal pages →
Privacy Policy — Wafeed | Wafeed