Privacy Policy

Last updated: September 2026

This policy explains what CoApprove collects and how we use it.

Controller vs processor. For feedback collected through a connected Site, the company that operates that Site is the data controller; CoApprove acts as a data processor on their behalf. End users should direct data requests to the company whose Site they used.

What we collect

How we use it

Solely to provide the service — to display feedback, let teams triage it, and operate and secure the platform. We do not sell personal data and do not use it for third-party advertising.

Cookies

Signed-in users receive a single, HttpOnly session cookie so the site knows who they are. We do not use third-party advertising or cross-site tracking cookies.

Sharing

We share data only as needed to run the service (e.g. with infrastructure providers acting on our behalf) and with the company operating the Site the data came from. We may disclose data where required by law.

Security

Signing secrets and API keys are held server-side and never exposed to the browser; session cookies are HttpOnly; traffic is served over TLS. No system is perfectly secure, but we take reasonable measures to protect data.

Retention

We keep data while the account is active or as needed to provide the service, and delete or anonymize it on request from the responsible company, subject to legal requirements.

Your rights

Depending on your jurisdiction, you may have rights to access, correct, or delete your data. End users should contact the company whose Site they used; account administrators can contact us.

Changes

We may update this policy; the date above reflects the latest version.

Contact

hello@coapprove.com.