Privacy policy

This policy explains what personal data FeedbackHub handles, why, and what rights people have over it. It covers three groups: visitors to this website, businesses that use the platform, and the customers of those businesses who submit feedback.

Last updated September 2026

1. Who we are

FeedbackHub is a customer feedback platform operated by The Apps Galore ("we", "us", "our"). Where you use the platform to collect feedback from your own customers, you are the data controller for that feedback and we act as a data processor on your behalf. Where you visit this website or contact us about the product, we are the controller.

For any privacy question, or to exercise any of the rights described below, contact us through the contact page.

2. Website visitors

When you browse this website, we handle only what is necessary to serve the pages and keep the service secure. That includes standard server log information such as the request made, the time, the response status and technical details of the browser and network used.

If you submit the quote or contact form, we store the name, email address, company, phone number, platform and message you provide, along with the IP address the submission came from. The IP address is recorded to limit repeated automated submissions.

We use that information to reply to your enquiry and to keep a record of the conversation. It is not sold, and it is not added to a marketing list without your agreement.

3. Businesses using the platform

When you hold an account, we process the information needed to operate it: the names, email addresses and roles of the people you give access to, your company details, your billing information, your sending domain configuration and the records of what the platform did on your behalf.

We also keep operational logs, such as which messages were dispatched and what status they reached, which integrations received events, and when configuration was changed. These exist so that both you and we can diagnose problems and so that delivery can be evidenced.

Payment card details are handled by our payment processor and are not stored on our systems. We hold the resulting invoice and payment records.

4. Feedback submitted by end customers

Where a business uses FeedbackHub to collect feedback, the personal data involved belongs to that relationship. We process it on their instructions, and the business decides what is asked and what is retained.

Depending on how the form is configured and how the request was sent, a response may include an email address, a phone number, a name, an order reference, the answers given, any free-text comment, and technical details such as the channel used, the time of submission and the browser and network the response came from.

Feedback submitted through a printed QR code is anonymous unless the form asks for contact details and the customer chooses to provide them.

If you have given feedback to a business and want it corrected or removed, the fastest route is to contact that business directly, since they control the data. You may also contact us and we will pass the request on and assist as processor.

5. Why we process personal data

  • To provide the service, including building forms, sending requests, receiving responses and producing reports.
  • To deliver messages by email, SMS and WhatsApp, which requires sharing the recipient's address or number with the relevant provider.
  • To analyse feedback, including sentiment scoring and theme grouping applied to free-text comments.
  • To honour opt-outs, which requires keeping a suppression record so that a contact who has opted out is not messaged again.
  • To bill and account for use of the platform.
  • To keep the service secure, prevent abuse and diagnose faults.
  • To respond to enquiries received through this website.

The lawful bases we rely on are the performance of a contract, our legitimate interests in operating and securing the service, compliance with legal obligations, and consent where consent is the appropriate basis.

6. Sub-processors and third parties

Operating the platform requires a small number of service providers. These currently include hosting and infrastructure providers, email delivery infrastructure, SMS and WhatsApp messaging providers, a payment processor for card payments, and an AI provider used to analyse free-text comments for sentiment and themes.

Where you connect your own SMTP server, outgoing email is sent through your infrastructure rather than ours.

We do not sell personal data, and we do not share it for advertising purposes.

7. AI analysis of comments

Free-text comments may be sent to a language model in order to produce a sentiment score, a sentiment label and one or more themes. Only the comment text needed for that analysis is sent. Customer contact lists are not sent for analysis.

If you prefer that this analysis is not applied to your account, tell us and it can be disabled. The rest of the platform functions without it, with the exception of workflow rules that trigger on detected sentiment.

8. Retention

Feedback responses are retained for as long as the business that collected them keeps an account, unless they delete them sooner. Businesses can delete individual responses at any time, and that ability can be restricted to specific users within their team.

Suppression records are retained for as long as they are needed, which is generally indefinitely, because the purpose of a suppression record is to make sure a contact who opted out is never messaged again. Deleting a suppression entry would defeat its purpose.

Enquiry records from this website are kept for as long as they are useful to the conversation and then removed. Billing records are retained for the period required by law.

9. Security

Access to production systems is restricted to the people who need it. Data is transmitted over encrypted connections, credentials for connected services are stored so that they are not exposed in the interface, and install keys can be rotated by account holders, which revokes anything paired with the previous key.

No system is immune from risk. If a breach occurs that affects personal data, we will notify affected account holders and relevant authorities as required.

10. International transfers

Some of the providers involved in delivering messages, hosting infrastructure or analysing text may process data outside the country where your business operates. Where that happens, we rely on the safeguards those providers have in place for international transfers.

11. Your rights

Depending on where you are, you may have the right to request access to the personal data held about you, to have inaccurate data corrected, to have data deleted, to restrict or object to certain processing, and to receive a copy of data in a portable format. You may also have the right to complain to a data protection authority.

If you are an end customer who gave feedback to a business, direct these requests to that business in the first instance, since they control the data. If you hold an account with us, contact us directly.

12. Cookies

This public website uses only what is necessary to serve pages. The application itself uses a session cookie to keep you logged in and a security token to protect form submissions against cross-site request forgery. These are required for the service to function and cannot be disabled while using it.

13. Changes to this policy

We may update this policy as the platform changes. The date at the top of the page indicates when it was last revised. Material changes affecting account holders will be communicated directly rather than only posted here.

14. Contact

Questions about this policy, or requests relating to personal data, can be raised through the contact page. We will respond within the timescales required by applicable law.