Skip to main content

Privacy Policy

Last updated: March 2026

1. Introduction

Voiseback ("we", "our", or "us") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our voice feedback collection service ("Service").

This policy applies to three categories of users:

  • Account Holders: Businesses and individuals who create a Voiseback account to collect and manage voice feedback.
  • End Users: People who submit feedback through the Voiseback widget embedded on an account holder's website or through the dedicated feedback page hosted on Voiseback.
  • Demo Visitors: Visitors who try the Voiseback demo on our website without creating an account.

Different types of data are collected from each category. Please read this policy carefully to understand how your information is handled based on your interaction with Voiseback.

2. Data Controller & Processor Roles

Voiseback as Data Controller: We act as the data controller for personal data collected from account holders (account registration, billing, and usage data) and demo visitors (demo submissions and contact information).

Voiseback as Data Processor: For feedback data submitted by end users through the embeddable widget or feedback page, Voiseback acts as a data processor. The account holder who deploys the widget on their website is the data controller for that end-user feedback data.

Account holders who deploy the Voiseback widget on their websites are responsible for maintaining their own privacy policies that adequately disclose the collection and processing of end-user feedback data, including voice recordings and AI analysis.

3. Information We Collect

Account Information

  • Email address and name when you create an account
  • Profile information from third-party sign-in (name, email, profile picture) if you choose to use an OAuth provider
  • Payment and billing information processed through our payment processor — we do not store complete credit card numbers on our servers
  • Account preferences and project settings

Feedback Data

  • Voice recordings (audio files) submitted through the widget
  • Text feedback submitted through the widget
  • AI-generated transcriptions of voice recordings
  • AI-generated analysis including sentiment classification, category labels, and summaries
  • Email address (optional, when an end user voluntarily provides it for follow-up communication)
  • Page URL where feedback was submitted, browser type, operating system, input type, and timestamp

Testimonial Data

  • Name, company name, and job role/title — voluntarily provided by end users who agree to testimonial use
  • Consent to public display of their feedback as a testimonial
  • This information is only collected when an end user explicitly opts in to providing a testimonial

Technical Data

  • Browser type and version
  • Operating system
  • Page URL where feedback was submitted
  • IP address (temporarily processed in memory for rate limiting and security purposes — not stored in our database)
  • Device information

Demo Lead Data

  • First name, email address, and company name
  • Demo feedback transcript and AI analysis (sentiment, category, summary)
  • Exit survey responses (transcript, summary, sentiment, category)
  • Demo lead data is automatically deleted 30 days after submission

4. Cookies and Local Storage

Authentication Cookies

We use authentication session cookies that are essential for maintaining your login session. These cookies are required for the Service to function and cannot be disabled while using the dashboard.

OAuth Cookies

When you sign in using a third-party OAuth provider, temporary state and redirect cookies are set during the authentication flow. These cookies are automatically deleted after the authentication process is complete.

Widget Local Storage

The embeddable widget may use browser localStorage to manage widget state on end-user devices. No tracking cookies are used by the widget.

We do not use analytics cookies or third-party tracking cookies.

5. How We Use Your Information

  • Provide, operate, and maintain the Service
  • Transcribe voice recordings using AI
  • Analyze feedback and generate insights using AI
  • Identify potential testimonial candidates from positive feedback
  • Process payments and manage subscriptions through our payment processor
  • Send transactional emails including account verification, password resets, and subscription notifications
  • Enforce plan usage limits
  • Detect and prevent fraud, abuse, and security threats
  • Comply with legal obligations

6. Automated Decision-Making & AI Processing

We use artificial intelligence to automatically process feedback submitted through the widget. This processing includes:

  • Transcription of voice recordings to text
  • Sentiment analysis and categorization
  • Summary generation
  • Identification of potential testimonial candidates

These AI features are assistive in nature — they help account holders organize and understand feedback more efficiently. No decisions with legal or similarly significant effects are made solely by automated means. Account holders can manually override all AI-generated classifications and labels.

AI processing is subject to your plan's usage limits. When limits are reached, feedback continues to be saved but without AI-generated analysis.

AI processing is performed via a third-party AI service provider's API. In accordance with their data usage policy, data sent through their API is not used to train their models.

7. Third-Party Services

We rely on trusted third-party service providers to operate Voiseback, including providers for cloud infrastructure and data storage, AI-powered transcription and analysis, payment processing, transactional email delivery, authentication, and hosting. These providers only receive the data necessary to perform their specific function on our behalf.

Our AI provider does not use data submitted through their API to train their models. We do not store complete credit card information on our servers — all payment data is handled directly by our payment processor. For optional third-party sign-in, we only receive your name, email address, and profile picture from the authentication provider.

You may contact us at contact@voiseback.com to request the identity and privacy policy of any specific third-party provider we use.

8. Webhooks & Customer-Configured Data Sharing

Account holders may configure webhook endpoints to receive real-time feedback data. When a webhook is configured, feedback data — including transcripts, AI analysis results, and metadata — is sent to the account holder's specified URL.

Voiseback is not responsible for how account holders handle data received via webhooks. Webhook payloads are signed for integrity verification. Account holders are responsible for securing their webhook endpoints and ensuring compliance with applicable data protection laws.

9. Data Retention

  • Account data: Retained while your account is active; permanently deleted upon account deletion.
  • Feedback data: Retained until deleted by the account holder or until the account is deleted.
  • Audio files: Stored securely; deleted when the associated feedback is deleted or the account is closed.
  • AI analysis: Retained alongside the associated feedback data and deleted together with it.
  • Demo lead data: Automatically deleted 30 days after submission.
  • Payment records: Retained as required for tax, accounting, and legal compliance purposes.
  • Testimonial data: Retained while the testimonial is approved and publicly displayed; removed if consent is withdrawn or the testimonial is declined.

10. Account Deletion & Data Removal

You can delete your account from Account Settings or by contacting us at contact@voiseback.com.

When you request account deletion, the following process is carried out:

  • Active subscriptions are cancelled
  • All audio files are permanently deleted from storage
  • All projects and associated data (prompts, feedback replies, testimonials) are permanently deleted
  • Team invitations are removed
  • Your authentication account is permanently deleted

Account deletion is permanent and irreversible. We recommend exporting any data you wish to keep before requesting deletion. Some data may be retained where required by law (for example, payment records for tax purposes). Deletion is typically completed within 30 days.

11. International Data Transfers

Your data may be processed in countries other than your own through our third-party service providers.

For transfers of personal data from the European Economic Area (EEA) or the United Kingdom (UK) to countries that have not received an adequacy decision, we rely on Standard Contractual Clauses (SCCs) or other applicable legal mechanisms.

By using the Service, you acknowledge that your data may be transferred to and processed in countries other than your own, which may have different data protection laws.

12. Your Rights (GDPR)

If you are located in the European Economic Area (EEA) or the United Kingdom (UK), you have the following rights under the General Data Protection Regulation (GDPR):

  • Right of access: Request a copy of your personal data
  • Right to rectification: Request correction of inaccurate personal data
  • Right to erasure: Request deletion of your personal data ("right to be forgotten")
  • Right to restrict processing: Request that we limit how we use your data
  • Right to data portability: Request your data in a structured, commonly used format
  • Right to object: Object to processing of your personal data
  • Right to withdraw consent: Withdraw your consent at any time where processing is based on consent

We process personal data under the following legal bases:

  • Contract: Processing necessary to provide the Service to you
  • Consent: Where you have given explicit consent for specific processing
  • Legitimate interests: For security, fraud prevention, and service improvement

To exercise any of these rights, please email us at contact@voiseback.com. We will respond to your request within 30 days. You also have the right to lodge a complaint with your local Data Protection Authority.

13. CCPA Compliance (California Residents)

If you are a California resident, you have additional rights under the California Consumer Privacy Act (CCPA):

  • Right to know: What personal information we collect, use, and disclose
  • Right to delete: Request deletion of your personal information
  • Right to opt-out of sale or sharing: We do not sell or share personal information for cross-context behavioral advertising
  • Right to non-discrimination: We will not discriminate against you for exercising your CCPA rights

Categories of personal information we collect include:

  • Identifiers: Name, email address, IP address
  • Commercial information: Subscription and payment data
  • Internet activity: Browser type, operating system, page URLs
  • Audio data: Voice recordings submitted as feedback
  • Professional information: Company name and job role/title (in testimonials)

To exercise your CCPA rights, please email us at contact@voiseback.com.

14. Data Security

We implement appropriate technical and organizational measures to protect your data, including:

  • Encryption in transit (HTTPS/TLS) for all data transmitted to and from our servers
  • Encryption at rest for stored data
  • Database-level access controls ensuring strict data isolation between accounts
  • Secure authentication with session management
  • Rate limiting and input validation on API endpoints
  • Domain validation for widget embedding
  • Regular security reviews and updates
  • Access controls limiting who can access production systems

In the event of a personal data breach that is likely to result in a risk to your rights, we will notify affected users and relevant supervisory authorities as required by applicable law, including within 72 hours where required by GDPR.

15. Children's Privacy

Creating a Voiseback account requires you to be at least 18 years of age. The feedback collection widget and feedback pages are not intended for use by children under 13 years of age (or under 16 in the European Economic Area). We do not knowingly collect personal information from children under these ages. If you are a parent or guardian and believe your child has submitted personal data through a Voiseback feedback widget, please contact us immediately at contact@voiseback.com and we will promptly delete it. Account holders who deploy the widget are responsible for ensuring their own age-gating practices comply with applicable laws.

16. Changes to This Policy

We may update this Privacy Policy from time to time. Material changes will be communicated via email (for account holders) or by posting an updated version on this page with a new "Last updated" date. Continued use of the Service after changes are posted constitutes acceptance of the updated policy.

17. Contact Us

If you have questions about this Privacy Policy, wish to exercise your data rights, or have a complaint about our data practices, please contact us at:

Email: contact@voiseback.com

We aim to respond to all inquiries within 30 days.