Privacy Policy

Your privacy and data protection are our top priorities

Last updated: August 25, 2025

1. Company Information

Track Feedbacks is operated by:

Company: Tappect LLC

Address: 18 Kestrel Dr, Mechanicsburg, PA 17050, United States

Email: trackfeedbacks@gmail.com

Website: tappect.com

This Privacy Policy describes how Tappect LLC ("we," "us," or "our") collects, uses, and protects your information when you use Track Feedbacks, our Shopify application for collecting and analyzing customer feedback.

2. Data We Collect

2.1 Information You Provide Directly

  • Account Information: Email address, name, company name when you create an account
  • Feedback Data: Survey responses, feedback forms, and customer insights you collect through our platform
  • Communication Data: Messages you send to our support team
  • Payment Information: Billing details processed through secure third-party payment processors

2.2 Shopify Integration Data

When you install our Shopify app, we may access:

  • Store information (store name, domain, plan type)
  • Customer tags and segments (for survey targeting and personalization)
  • Order data to trigger feedback requests
  • Product information to personalize feedback surveys
  • Discount and gift card data (for survey incentive creation)

2.3 Automatically Collected Information

  • Usage Analytics: How you interact with our platform (via Google Analytics)
  • Technical Data: IP address, browser type, device information
  • Log Data: Server logs, error reports, performance metrics
  • Cookies: See our Cookie Policy section below

3. How We Use Your Data

Data Minimization Principle:

We only collect and process the minimum personal data required to provide our app functionality and services.

We use your information to:

  • Provide Services: Enable feedback collection, survey creation, and analytics
  • Account Management: Create and maintain your account, process payments
  • Customer Support: Respond to your inquiries and provide technical assistance
  • Platform Improvement: Analyze usage patterns to enhance our services
  • Communication: Send service updates, feature announcements, and educational content
  • Security: Protect against fraud, abuse, and unauthorized access
  • Legal Compliance: Meet regulatory requirements and legal obligations

4. Data Sharing & Third Parties

We do NOT sell your personal data.

We only share data with trusted service providers as described below.

4.1 Service Providers We Use

Analytics

Google Analytics: Website and app usage analytics

Data: Usage patterns, page views, user interactions

Hosting & Infrastructure

Cloud Providers: AWS, Vercel for hosting and storage

Data: All application data with encryption

Communication

Email Services: Transactional and marketing emails

Data: Email addresses, communication preferences

Payment Processing

Shopify Billing API: Subscription and payment processing

Data: Billing information (encrypted)

4.2 When We Share Data

  • Legal Requirements: When required by law, regulation, or court order
  • Business Transfers: In case of merger, acquisition, or asset sale
  • Protection: To protect our rights, users, or prevent illegal activity
  • Consent: When you explicitly consent to sharing

5. Shopify Customer Data Protection

Shopify App Compliance:

We adhere to Shopify's Protected Customer Data requirements and maintain Level 1 compliance standards for customer tags and basic data access.

5.1 Customer Data We Access

Through the Shopify API, we may access:

  • Customer tags and identifiers (for survey targeting and personalization)
  • Order information (to trigger post-purchase surveys)
  • Product data (to personalize feedback questions)
  • Store and location data (for context-specific surveys)

5.2 Customer Data Rights

  • Consent Respect: We honor customer opt-out requests for feedback collection
  • Data Minimization: We only process data necessary for feedback functionality
  • Transparency: Merchants can view all data we access through our dashboard
  • Deletion Rights: Customers can request deletion of their feedback data

5.3 Merchant Responsibilities

As a merchant using Track Feedbacks, you are responsible for:

  • Obtaining proper consent from customers for feedback collection
  • Informing customers about data sharing with Track Feedbacks
  • Honoring customer requests to opt out of feedback surveys
  • Maintaining compliance with applicable privacy laws
  • Displaying data usage notices in your app interface where customer data is accessed
  • Providing links to this privacy policy and terms of service to customers upon request

5.4 In-App Transparency

Data Usage Notices:

Our app displays clear notices about data usage wherever customer information is accessed, including:

  • Customer tags usage for survey targeting
  • Order data access for timing feedback requests
  • Product data usage for survey personalization
  • Links to full privacy policy and contact information

6. Cookies & Tracking Technologies

6.1 Types of Cookies We Use

Essential Cookies (Required)

Necessary for basic website functionality, user authentication, and security.

Analytics Cookies (Optional)

Help us understand how you use our platform to improve user experience.

Provider: Google Analytics

Functional Cookies (Optional)

Remember your preferences and settings for a better experience.

6.2 Managing Cookies

You can control cookies through:

  • Browser Settings: Most browsers allow you to block or delete cookies
  • Opt-Out Tools: Use Google Analytics opt-out browser add-on
  • Cookie Preferences: Manage preferences through our cookie banner

7. Data Security & Protection

Security Commitment:

We implement industry-standard security measures to protect your data.

7.1 Technical Safeguards

  • Encryption: All data is encrypted in transit (TLS/SSL) and at rest
  • Access Controls: Limited staff access with strong authentication requirements
  • Infrastructure Security: Hosted on secure cloud platforms with regular security updates
  • Data Backups: Encrypted backups with secure storage
  • Monitoring: Continuous monitoring for security incidents

7.2 Organizational Safeguards

  • Staff Training: Regular privacy and security training for team members
  • Access Logs: Comprehensive logging of data access and modifications
  • Incident Response: Established procedures for security incident response
  • Third-Party Agreements: Data processing agreements with all service providers

7.3 Data Breach Notification

In the unlikely event of a data breach, we will:

  • Notify affected users within 72 hours
  • Report to relevant authorities as required by law
  • Provide detailed information about the incident and remediation steps
  • Implement additional security measures to prevent future incidents

8. Your Privacy Rights

Know Your Rights:

You have comprehensive rights regarding your personal data under GDPR, CCPA, and other privacy laws.

8.1 Universal Rights

Access Right

Request a copy of all personal data we have about you

Rectification Right

Correct inaccurate or incomplete personal information

Deletion Right

Request deletion of your personal data ("right to be forgotten")

Portability Right

Receive your data in a machine-readable format

8.2 GDPR Rights (EU Residents)

  • Processing Restriction: Limit how we process your data
  • Objection Right: Object to processing based on legitimate interests
  • Automated Decision-Making: Opt out of automated profiling
  • Supervisory Authority: File complaints with your local data protection authority

8.3 CCPA Rights (California Residents)

  • Right to Know: Know what personal information is collected and how it's used
  • Right to Delete: Request deletion of personal information
  • Right to Opt-Out: Opt out of sale of personal information (we don't sell data)
  • Non-Discrimination: Equal service regardless of privacy choices

8.4 Exercising Your Rights

To exercise your privacy rights:

  1. Email us at trackfeedbacks@gmail.com
  2. Include "Privacy Request" in the subject line
  3. Specify which right you want to exercise
  4. Provide sufficient information to verify your identity
  5. We'll respond within 30 days (or as required by applicable law)

9. Data Retention & Deletion

9.1 Retention Periods

Account Data

Retained while your account is active and for 90 days after account deletion

Feedback Data

Retained as long as merchants need it for business purposes (merchant-controlled deletion)

Analytics Data

Aggregated analytics data retained for up to 26 months (Google Analytics standard)

Legal Data

Some data may be retained longer for legal compliance (tax records: 7 years)

9.2 Automated Deletion

  • Inactive accounts are automatically deleted after 2 years of inactivity
  • Temporary data (logs, caches) is deleted within 30 days
  • Backup data is securely deleted according to our retention schedule

10. International Data Transfers

Your data may be transferred to and stored in countries outside your residence, including the United States. We ensure appropriate safeguards through:

  • Standard Contractual Clauses: EU-approved data transfer mechanisms
  • Adequacy Decisions: Transfers to countries with adequate protection levels
  • Encryption: All data transfers are encrypted

11. Children's Privacy

Age Restriction:

Track Feedbacks is not intended for children under 13. We do not knowingly collect personal information from children.

If you believe we have collected information from a child under 13, please contact us immediately and we will take steps to delete such information.

12. Changes to This Privacy Policy

We may update this Privacy Policy periodically to reflect changes in our practices or legal requirements. We will:

  • Post the updated policy on this page
  • Update the "Last updated" date
  • Notify users of material changes via email
  • Provide 30 days notice for significant changes

13. Contact Information

Get in Touch

If you have questions, concerns, or requests regarding this Privacy Policy or your personal data, please contact us:

Email

trackfeedbacks@gmail.com

Privacy inquiries welcome

Address

Tappect LLC

18 Kestrel Dr

Mechanicsburg, PA 17050

United States

Website

tappect.com

Company website

Response Times

  • General inquiries: Within 2 business days
  • Privacy requests: Within 30 days
  • Security incidents: Within 24 hours

Questions About Your Privacy?

We're here to help you understand how we protect your data and respect your privacy rights.