Who we are
The controller for the data described here is Erdi Izgi, an individual entrepreneur in the Czech Republic, not yet entered in the Trade Register. For anything about your data, write to [email protected]. We don't have a data protection officer; we are not required to.
Our two roles
- Controller for the people who use Upvotekit itself: account holders, workspace members, visitors to upvotekit.com, and anyone who writes to us. This policy covers them.
- Processor for our customers' users: the people who vote, post and comment on a customer's board, or whom a customer identifies to us. The customer decides what happens with that data, and their privacy policy applies. We handle it only on their instructions, under our Data Processing Agreement. If you are one of those users, please contact the company whose board you used. We will help them answer you.
What we collect
Your account
- Name, email address, whether the address is verified, and a hash of your password (never the password itself).
- If you sign in with Google: the account identifier and tokens they give us, and your profile picture if they send one.
- Your workspaces, your role in each, and invitations you send or receive.
Sign-in sessions
For each signed-in session: its IP address, browser user agent, and when it started and was last used. You can see and end your sessions on the account page. We also record the time of your last sign-in, to apply the inactivity rule below.
Billing
Paddle handles payment. We never see or store card numbers. From Paddle we receive your customer and subscription identifiers, transaction references, the status of your subscription, and refunds or chargebacks. If you cancel or ask for a refund, you can tell us why; that answer is optional.
What you create
Projects, boards, feedback, comments, roadmap and changelog entries, settings, and files you attach. Images are re-encoded when uploaded, which removes their metadata, including location. Actions in a workspace are written to its audit log (who did what, when).
Emails we send
For each email: the recipient address, what kind of email it was, when it was sent, and whether it was delivered, bounced or marked as spam. We don't keep the content once the email has been sent. Addresses that hard-bounced or complained are kept on a suppression list so we don't email them again.
Visits to upvotekit.com
- Only if you accept analytics cookies, Google Analytics 4 receives the page you viewed (without anything after the
?), the previous page on our site, and a few events: sign-up, sign-in, starting checkout and completing a purchase. We send no names, email addresses or account ids, and advertising features are off. If you reject, Google is never contacted. Analytics never runs on customer boards or embeds. - Our servers see your IP address with every request. We use it briefly to limit abuse (rate limiting) and keep it only as part of a sign-in session and in short-lived server logs.
Error reports
When something breaks, our servers and your browser send an error report to our own error tracker (GlitchTip, which we host ourselves, so no one else receives it). A report holds the error, where in our code it happened, the kind of page (for example "a feedback page", never its address or anything after the ?) and the app version. Email addresses, stored values and anything you typed are removed before it is sent. Reports are kept for 90 days.
Support
What you write to us, and our replies.
Launch waitlist
If you join the launch waitlist: your email address, where on the site you signed up, and when you confirmed. We use it to send you one email when Upvotekit opens, nothing else. We store the address as soon as you send the form, and a confirmation email goes to it. If you never confirm, we delete it after 7 days. Every email has a link to leave the list, which deletes the address.
Free trial
When a free trial starts we keep a one-way hash of the email address and the date, without the address or your account. It lets us recognise the same address, including variants such as dots or a "+" tag in Gmail addresses, so each person gets one trial.
After an account is deleted
If a deleted account had a subscription, used the money-back guarantee, or was blocked after a chargeback, we keep a one-way hash of its email address with those facts and their dates. The hash can't be turned back into the address. It lets us recognise the same address if it signs up again, so a trial or refund isn't used twice and a block can't be avoided.
Data of our customers' users
On a customer's behalf we process:
- a random visitor identifier stored in a cookie, created when someone first votes, posts or comments;
- an email address and name, if the visitor gives them or the customer sends them;
- what the customer sends through an embed token or the API: a user id, name, email, company, revenue figures and other attributes they choose;
- posts, comments, votes and follows, and emails about them (status changes, releases, replies), each with an unsubscribe link;
- a check by Cloudflare Turnstile before a visitor posts, comments or leaves their email on a board with spam protection on (the default), or joins the waitlist. Cloudflare sees the visitor's IP address and browser signals while it checks; we receive only whether it passed;
- error reports from board pages, with the same removals as above: no content, addresses or page addresses.
Customers can export, anonymize and delete this data. We delete it when they do, or when their workspace is deleted. Email addresses in our email log follow the rules below.
Why we use it, and on what legal basis
- To provide the service you signed up for: your account, workspaces, sign-in, billing status and service emails. Basis: our contract with you (GDPR Art. 6(1)(b)).
- To keep the service secure and fair: sessions, rate limits, spam protection on boards, error reports, audit logs, the suppression list, the hashed record of free trials, and the hashed record of deleted accounts. Basis: our legitimate interest in preventing abuse and fraud (Art. 6(1)(f)).
- To answer you when you contact us. Basis: legitimate interest, or the contract when it's about your account.
- To email you when Upvotekit opens, if you joined the launch waitlist. Basis: your consent (GDPR Art. 6(1)(a)), withdrawn by leaving the list.
- To measure our website with Google Analytics. Basis: your consent (Art. 6(1)(a)), which you can withdraw any time under "Cookie settings" in the footer.
- To meet legal duties, such as tax and accounting records or requests from authorities. Basis: legal obligation (Art. 6(1)(c)).
We don't sell personal data, don't use it for advertising, and don't make automated decisions about you that have legal or similar effects.
Who we share it with
Only with service providers we need to run Upvotekit, listed with their purpose and location on the Subprocessors page: hosting, encrypted backups, email delivery, spam protection on boards, analytics (with consent), and sign-in with Google if you use it. Paddle is our merchant of record: it is the seller of your subscription and processes your payment and billing details as a controller under its own privacy policy. We may also disclose data when the law requires it.
Transfers outside the EU
Some providers are based in, or process data in, the United States or the United Kingdom. Transfers to the UK rely on the EU adequacy decision. Transfers to the US rely on the EU–US Data Privacy Framework where the provider is certified, and otherwise on the European Commission's standard contractual clauses. Ask us for a copy of the relevant safeguards.
How long we keep it
| Data | Kept |
|---|---|
| Your account | Until you delete it. A deletion takes effect 30 days after you ask; signing in before then cancels it. An account with no workspace and no subscription is deleted after 180 days without a sign-in, after two warning emails. Accounts that pay or belong to a workspace are never deleted for inactivity. |
| Workspaces and their content | Until you delete them. When the subscription that pays for them ends, they stay read-only for 30 days so you can export, then they are deleted with their files and audit log. |
| Items in a workspace's trash | Until you empty the trash or the workspace is deleted. |
| Sign-in sessions (with IP and user agent) | Until you sign out or the session expires, 7 days after it was last used. |
| Email log | Addresses are removed after 365 days, or earlier when the account is deleted or a customer anonymizes the user. Email content is not kept after sending. |
| Email suppression list (hard bounces, spam complaints) | Indefinitely, only the address, the reason and the date, so we never email that address again. |
| Waitlist | Unconfirmed addresses after 7 days; confirmed ones 30 days after the launch email, and never longer than 12 months; at once when you leave the list or create an account. |
| Hashed record of a free trial | 3 years after the trial started. |
| Hashed record of a deleted account | 3 years after the deletion. |
| Billing references and invoices | As long as tax and accounting law requires, currently up to 10 years. |
| Google Analytics data | As set in Google Analytics, at most 14 months. |
| Backups | Deleted data can remain in backups for up to 3 weeks until they rotate out. |
After an account is deleted, some records keep only its internal id and nothing that names you, for example platform audit entries and optional cancellation reasons.
Your rights
Under the GDPR you can ask us to:
- give you a copy of your data (you can also export workspaces yourself);
- correct it (most of it you can edit on the account page);
- delete it, or restrict how we use it;
- send it to you or another provider in a machine-readable format;
- stop using it where we rely on legitimate interests, unless we have compelling reasons;
- withdraw your consent to analytics, at any time, under "Cookie settings".
Write to [email protected]. We answer within one month. You can also complain to a data protection authority: in the Czech Republic that is the Úřad pro ochranu osobních údajů (uoou.gov.cz), or the authority where you live or work.
Security
Connections are encrypted (HTTPS). Passwords are stored as hashes, and secrets such as integration tokens are encrypted. Access to production data is limited to the people who run Upvotekit, and staff actions in our admin console are logged. If a breach puts your data at risk, we tell you and the authority as the law requires.
Other points
- Upvotekit is not meant for children. You must be at least 18 to create an account.
- Cookies are explained in the Cookie Policy.
- We update this policy when what we do changes. For important changes we email account holders before they apply. The date at the top shows the current version.