Privacy Policy

Last updated: December 2024

1. Introduction

PraiseThat ("we," "our," or "us") operates the PraiseThat platform (the "Service"). This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our Service.

By using PraiseThat, you agree to the collection and use of information in accordance with this policy. If you do not agree with this policy, please do not use our Service.

2. Information We Collect

2.1 Account Information

When you create an account, we collect:

  • Email address (required for authentication)
  • Name (optional)
  • Company/workspace name
  • Password (stored securely using industry-standard hashing)

2.2 Testimonial Data

When testimonials are submitted through our platform, we collect:

  • Submitter name, role, and company (as provided, may be optional)
  • Testimonial text content
  • Photos (if uploaded)
  • Star ratings (if provided)
  • Consent preferences (public, anonymous, or private)
  • Submission timestamp

2.3 Payment Information

Payment processing is handled by Stripe, Inc. We do not store credit card numbers, CVVs, or other sensitive payment details on our servers. Stripe's Privacy Policy governs the collection and use of payment data. We receive only:

  • Last four digits of your card (for display purposes)
  • Card brand (Visa, Mastercard, etc.)
  • Billing address (if provided)
  • Subscription status and billing history

2.4 Usage Data

We automatically collect certain information when you use our Service:

  • IP address (anonymized for analytics)
  • Browser type and version
  • Device type
  • Pages visited and features used
  • Time spent on pages
  • Referring website

3. How We Use Your Information

We use the information we collect to:

  • Provide, maintain, and improve our Service
  • Process and display testimonial submissions
  • Authenticate users and secure accounts
  • Process payments and manage subscriptions
  • Send transactional emails (submission notifications, account updates, billing receipts)
  • Respond to support requests and inquiries
  • Analyze usage patterns to improve user experience
  • Detect and prevent fraud or abuse
  • Comply with legal obligations

4. How We Share Your Information

4.1 Service Providers

We share data with trusted third-party service providers who assist in operating our Service:

  • Supabase: Database hosting, authentication, and file storage
  • Vercel: Application hosting and content delivery
  • Stripe: Payment processing and subscription management
  • Resend: Transactional email delivery

These providers are bound by contractual obligations to protect your data and use it only for the purposes we specify.

4.2 Public Testimonials

Testimonials marked as "public" by the submitter and approved by the workspace owner will be displayed on public testimonial walls and may be embedded on third-party websites. Only information the submitter chose to share (name, company, testimonial text, photo, rating) will be publicly visible.

4.3 Legal Requirements

We may disclose your information if required to do so by law or in response to valid requests by public authorities (e.g., court order, government agency).

4.4 Business Transfers

In the event of a merger, acquisition, or sale of assets, your information may be transferred. We will provide notice before your data is transferred and becomes subject to a different privacy policy.

5. Data Retention

We retain your data for as long as your account is active or as needed to provide our Service. Upon account deletion:

  • Your account data will be deleted within 30 days
  • Testimonial data associated with your workspace will be deleted
  • Backup copies may persist for up to 90 days
  • We may retain anonymized, aggregated data for analytics

6. Your Rights

You have the right to:

  • Access: Request a copy of the personal data we hold about you
  • Correction: Request correction of inaccurate data
  • Deletion: Request deletion of your personal data
  • Export: Request your data in a portable format
  • Withdraw Consent: Withdraw consent for testimonial publication at any time
  • Object: Object to processing of your data in certain circumstances

To exercise these rights, contact us at contact@praisethat.com. We will respond to your request within 30 days.

7. Data Security

We implement industry-standard security measures to protect your data:

  • All data transmitted between your browser and our servers is encrypted using TLS 1.3
  • Passwords are hashed using bcrypt with appropriate cost factors
  • Database access is restricted and audited
  • Regular security reviews and updates
  • Secure, SOC 2 compliant hosting infrastructure

While we strive to protect your data, no method of transmission over the Internet is 100% secure. We cannot guarantee absolute security.

8. International Data Transfers

Your data may be transferred to and processed in countries other than your own. Our service providers may be located in the United States and other countries. We ensure appropriate safeguards are in place for international transfers.

9. Children's Privacy

Our Service is not intended for users under 13 years of age (or 16 in certain jurisdictions). We do not knowingly collect personal data from children. If you believe a child has provided us with personal data, please contact us immediately.

10. Cookies and Tracking

We use essential cookies to:

  • Maintain your login session
  • Remember your preferences
  • Ensure security of the Service

We may use analytics cookies to understand how our Service is used. You can control cookies through your browser settings.

11. Third-Party Links

Our Service may contain links to third-party websites. We are not responsible for the privacy practices of these external sites. We encourage you to read their privacy policies.

12. Changes to This Policy

We may update this Privacy Policy periodically. We will notify you of significant changes by:

  • Posting the new policy on this page with an updated "Last updated" date
  • Sending an email notification for material changes

Continued use of our Service after changes constitutes acceptance of the updated policy.

13. Contact Us

For privacy-related questions, concerns, or to exercise your rights, contact us at: