Privacy policy

Last updated 22 August 2026

Public consultation only works if people trust what happens to their answers. This page says what we collect, why we collect it, and who else can see it — in the same language we would use if you asked us on the phone.

1. Who this covers

CommunityFeedback (“we”, “us”) provides software that organisations use to run public consultations. Two very different groups of people appear in this policy, and the rules are not the same for each:

  • Organisers — people with an account who create campaigns. We are the controller of their account data and decide how it is used.
  • Respondents — members of the public who answer a survey, drop a pin or post an idea. The organisation running that campaign decides what to ask and what to do with the answers; we process that data on their behalf and under their instructions.

So if you answered a consultation and want your response removed, the organisation that ran it is the first place to ask. Tell us too and we will help make it happen.

2. If you have an account

We collect the minimum needed to run an account:

  • Your email address, and your name and avatar if you sign in with Google.
  • Your organisation's name, slug, brand colour and logo.
  • Which organisations you belong to and your role in each.
  • Billing state — plan, subscription status and renewal date.
  • Ordinary server logs, kept briefly for security and debugging.

Card details never reach us. Payments run through Stripe Checkout, and what comes back is a customer identifier and a subscription status.

3. If you answered a campaign

Answering a consultation does not create an account and never requires one. What gets stored when you take part:

  • Your answers to the survey questions the organisation wrote.
  • Map pins you place — the coordinates, the category you chose, your comment, and any photo you attached. If you used the address field instead of the map, the address is geocoded to a point and the point is what we store.
  • Ideas, comments and votes you post on an idea board.
  • An email address or phone number, only if you chose to give one to hear about the campaign.
  • A random identifier stored in a cookie named cf_fp, so the campaign can tell one participant from another without knowing who you are.
  • A hashed version of your IP address — a one-way fingerprint with a secret salt, used for rate limiting and to block abuse. We do not store the raw address alongside your response, and the hash cannot be reversed back into an address.

The organisation running the campaign can see the responses, including any contact details you volunteered, and can export them. Whether your comment appears publicly on the campaign page is a setting they control and one the page tells you about before you post.

4. Cookies and similar technology

There are three, and none of them are for advertising:

  • cf_fp — the random participant identifier described above. It is what stops one person voting on the same idea ten times, and it holds no personal information.
  • An authentication cookie for account holders, set by Supabase Auth. It only exists once you log in.
  • cf-theme in local storage — whether you chose light or dark. Not sent to a server.

There are no advertising cookies, no third-party analytics scripts and no tracking pixels on this site or on the campaign pages we host. That is also why you have not had to dismiss a consent banner to read this.

5. Why we process any of it

  • To run the service you or an organiser asked us to run — storing responses, drawing maps, producing charts, sending the invites an organiser triggers.
  • To keep it working and safe: rate limiting, spam prevention, moderation, debugging and backups.
  • To bill paid accounts and comply with tax and accounting obligations.
  • To answer you when you contact us.

Where the law requires a legal basis, ours is contract for account and service data, legitimate interests for security and abuse prevention, consent where you opted in to hear from a campaign, and legal obligation for financial records.

6. What we never do

  • We do not sell personal data, and we do not share it for cross-context behavioural advertising.
  • We do not use responses, comments or map pins to train machine-learning models.
  • We do not build advertising profiles or pass data to ad networks.
  • We do not email an organisation's respondents on our own behalf. Only the organisation running the campaign can send to its list, from inside that campaign.

7. Who else touches the data

We use a small number of specialist providers. Each one processes data only to deliver the function next to its name:

  • Supabase — the database, authentication and file storage. Effectively all application data lives here.
  • Vercel — application hosting and content delivery. Sees request metadata such as IP addresses in transit.
  • Stripe — payments and subscription management for paid accounts. Handles card data directly; we never receive it.
  • Resend — transactional and invite email. Receives the recipient address and the message.
  • Twilio — SMS invites and opt-out handling on plans that use them. Receives the recipient number and the message.
  • Map tiles and geocoding — background map imagery is served from our tile provider, and addresses typed into the accessible address field are sent to a geocoding service (the US Census Geocoder, with OpenStreetMap Nominatim as a fallback) to convert them into coordinates.

We will update this list before adding anyone to it. If you need a formal subprocessor notification arrangement, email us and we will set one up.

8. Ownership, retention and deletion

Campaign data belongs to the organisation that collected it. We hold it to provide the service and for no other purpose. Organisers can export everything at any time, on any plan including the free one, as CSV and GeoJSON.

  • Delete a campaign and its responses, pins, ideas and votes are deleted with it.
  • Close an account and we delete organisation data within 30 days, except where we must keep financial records for tax purposes.
  • Backups roll off on their own schedule, which can take up to a further 30 days.
  • Hidden or moderated content is not deleted automatically — it stays in the organisation's export with its status, so a moderation decision leaves a trail.

9. Your rights and how to use them

Depending on where you live you may have rights to access, correct, delete, port or object to the processing of your personal data, and to withdraw consent you previously gave.

  • Account holders: email hello@communityfeedback.ai and we will handle it directly.
  • Respondents: contact the organisation that ran the campaign — they decide what happens to their consultation data. Copy us in and we will make sure the request can actually be actioned.
  • Campaign emails and texts: every email carries an unsubscribe link and every text accepts STOP. Both take effect immediately and across the whole organisation, not just that message.

We answer rights requests within 30 days, and we will not charge you for the first one.

10. Security

  • Traffic is encrypted in transit; data is encrypted at rest by our database provider.
  • Tenant separation is enforced in the database itself with row-level security, not only in application code, so one organisation cannot read another's campaign data even if the application has a bug.
  • Public write paths — survey submissions, pins, ideas, votes, sign-ups — are rate limited by hashed IP and participant identifier, with a honeypot field and optional captcha.
  • IP addresses used for abuse control are stored only as salted hashes.
  • Access to production data is limited to the people who operate the service.

No system is perfectly secure. If you find a vulnerability, email us before disclosing it publicly and we will work with you.

11. Children

The service is not directed at children, and accounts are for adults. Consultations sometimes legitimately ask young people questions — a school catchment review, a youth services plan — and where that happens the organisation running the campaign is responsible for the consent and safeguarding arrangements around it. If you believe a child’s personal data has reached us in a way it should not have, tell us and we will remove it.

12. Where data is stored

Our infrastructure runs in the United States. If you are outside the US, using the service involves transferring your data there. Where a transfer mechanism is legally required, we rely on standard contractual clauses with our providers. If your consultation has a data-residency requirement, say so before you sign up — we would rather tell you honestly that we cannot meet it than find out later.

13. Changes to this policy

When this policy changes materially we will update the date at the top and email account holders before the change takes effect. Older versions are available on request.

14. Contact

Privacy questions, rights requests and complaints all go to the same place: hello@communityfeedback.ai. A person answers, usually within a working day.

If you are unhappy with our response and you are in a jurisdiction with a data protection authority, you have the right to complain to it.