1. Scope and roles
This Privacy Policy applies to the SuggestionBox.io website, owner dashboard, hosted public suggestion boxes, emails, and related services (together, the "Service"). It does not cover a customer's own website or any other third-party service.
A box owner is the person or organization that creates and manages a suggestion box. A participant is someone who visits a box or submits, votes on, follows, or comments on a suggestion.
For information collected through a customer's suggestion box, that customer generally decides why it wants the information and how it responds to suggestions. SuggestionBox.io processes that information to provide and secure the Service. We also make our own decisions about account administration, billing, fraud prevention, security, and legal compliance.
2. Information we collect
Owner and organization information
We collect an owner's email address, optional username, authentication data, and account activity. We also store organization details such as company name, website, logo, brand color, public subdomain, moderation settings, and suggestion box status. Passwords are stored as password hashes, not as readable plaintext.
Participant and suggestion information
When a participant interacts with a suggestion box, we may collect an email address, email-verification state, notification choices, suggestions, bug reports, feature requests, votes, comments, and image attachments. Participants do not create accounts. Owners may also add product ideas directly; those ideas identify the organization publicly as their source, not an owner's private account details. We store the status, moderation, and verification history needed to run and secure the Service.
Billing information
Paid subscriptions use Stripe Checkout and the Stripe Customer Portal. We send Stripe the owner's email address and identifiers needed to associate the purchase with the correct organization. We receive subscription identifiers, price, status, billing period, cancellation state, and payment-event information. SuggestionBox.io does not receive or store full payment-card numbers entered on Stripe-hosted pages.
Technical and support information
We may collect IP address, request time, requested page, browser or device information, error and security events, and related server-log data. IP addresses are used for rate limits and abuse prevention. The application's hourly rate-limit buckets store only a one-way, service-keyed hash of the client identity and are scheduled for deletion after 48 hours; infrastructure and anti-abuse providers may still process the address as described below. If you contact support, we collect your email address and the information you include in the conversation.
3. What is public and what stays private
Public suggestion boxes can display the owner's organization name, website, logo, and brand color. Approved suggestion titles, descriptions, types, statuses, vote totals, public comments, image attachments, owner-added YouTube companion videos, and official owner responses may also be public. Public content can be indexed, copied, or shared by other people.
Participants do not receive public usernames, profiles, or cross-box activity pages. Public comments use the neutral label Verified visitor. Participant email addresses are not displayed publicly. They are available to authorized owners only for activity inside that owner's private dashboard. Unapproved, hidden, or spam content remains available to authorized owners for moderation but is not shown on the public box.
Do not submit confidential information, account credentials, payment-card data, health information, government identifiers, or other sensitive personal information in a suggestion, comment, or attachment.
4. How we use information
We use information to:
- create and administer owner accounts and suggestion boxes;
- verify participant email addresses before publishing or counting protected interactions;
- publish, moderate, search, sort, count, and display suggestions, votes, comments, and statuses;
- send verification links, status updates, official responses, billing notices, security messages, and requested support;
- process subscriptions and reconcile Stripe webhook events;
- detect spam, enforce rate limits, troubleshoot errors, and protect the Service and its users;
- maintain backups, improve reliability, and understand product performance; and
- comply with law, enforce our Terms, and protect legal rights.
Where applicable law requires a legal basis, we rely on performance of a contract, legitimate interests in operating and securing the Service, consent where requested, and compliance with legal obligations.
5. How we share information
We share information only as needed for the following purposes:
- With the box owner. Authorized owners receive suggestion content, participant email addresses, vote and comment activity, and moderation details for their own box. They do not receive the participant's activity in other suggestion boxes.
- With service providers. Providers support server hosting, managed database and object storage, backups, transactional email, security, and support. Infrastructure providers include DigitalOcean for server hosting, managed PostgreSQL, object storage, and managed database backups; Amazon Web Services (AWS) for SES transactional email delivery; and Cloudflare Turnstile for automated-abuse prevention on anonymous public actions.
- With Stripe. Stripe processes subscription checkout, billing, payment methods, invoices, fraud signals, and the customer billing portal. Stripe handles that information under the Stripe Privacy Policy.
- For legal and safety reasons. We may disclose information when reasonably necessary to comply with law, respond to valid legal process, investigate abuse, prevent harm, or protect rights and security.
- In a business transaction. Information may transfer as part of a merger, financing, acquisition, reorganization, or sale of all or part of the Service, subject to applicable law.
We do not sell personal information, rent email lists, or share information for cross-context behavioral advertising.
6. Cookies and browser storage
The Service currently uses essential technologies rather than advertising or analytics cookies:
- host-only session and security cookies keep owners signed in on the host that created the session and protect forms from unauthorized requests;
- a signed, tenant-specific participant cookie can remember an email-verified participant for up to one year, so that person does not need to verify the same identity for every interaction;
- temporary browser session storage can preserve interface behavior, such as restoring focus after a suggestion search; and
- Stripe may use its own cookies or similar technologies on Stripe-hosted checkout and billing pages under Stripe's policies.
- Cloudflare Turnstile processes technical interaction and device signals needed to distinguish people from automated abuse when an anonymous public action is submitted. Cloudflare describes this processing in its Turnstile Privacy Addendum.
- An owner-created suggestion with a companion video loads an embedded YouTube player. Google and YouTube may process technical information under the Google Privacy Policy.
You can clear cookies through your browser. Clearing an owner session signs the owner out. Clearing the participant cookie means the participant may need to verify by email again.
7. Retention and deletion
We generally keep account, organization, suggestion, participant, and moderation data while it is needed to provide the Service. When a subscription becomes canceled or unpaid, the application assigns the workspace a 90-day recovery date. Data may remain after that date until deletion is completed.
Participant-interaction rate-limit buckets are scheduled for deletion after 48 hours. Message content can remain in the transactional email ledger for its separate operational-retention period even though a verification link expires much sooner.
Some information may remain longer in backups, security logs, billing and tax records, support records, or records needed to prevent fraud, resolve disputes, enforce agreements, or comply with law. Previously active public addresses may be protected during recovery and later reassigned only after ownership or rights review.
An owner or participant may request deletion by contacting us. We may need to verify the request, coordinate with the relevant box owner, and retain information where law or legitimate security needs permit. Removing public content does not guarantee removal of copies already indexed, cached, or shared by others.
8. Your choices and privacy rights
Depending on where you live, you may have rights to request access, correction, deletion, portability, restriction, or objection, or to appeal a privacy decision. We will respond as required by applicable law and may verify your identity before completing a request.
- Owners can update organization and account information through the Service and manage billing through the Stripe Customer Portal.
- Participants can use an unsubscribe link in a notification email to stop future updates for that suggestion.
- Participants can clear the remembered identity from a suggestion page or through browser settings.
- For content controlled by a box owner, contacting that owner directly may be the fastest way to request correction or removal.
To make a privacy request, email support@suggestionbox.io. We do not discriminate against anyone for exercising a privacy right.
9. Security and international processing
We use reasonable administrative, technical, and organizational measures designed to protect information, including access controls, signed time-limited verification links, tenant isolation, host-only cookies, encrypted transport in production, secure cookies, rate limits, and restricted owner dashboards. Knowing a participant's email address alone is not enough to publish or count a protected interaction; access to the valid verification link sent to that inbox is required. No internet service can guarantee absolute security.
The Service and its providers may process information in the United States and other countries where they operate. Those countries may have privacy laws different from the laws where you live. Where required, we use lawful transfer mechanisms available through our service providers or applicable law.
10. Children's privacy
The Service is not directed to children under 13, and we do not knowingly collect personal information from a child under 13. Box owners must not intentionally use the Service to solicit personal information from children under 13 without all notices, consent, and other protections required by law. Contact us if you believe a child has provided information improperly.
11. Changes to this policy
We may update this policy as the Service, providers, or law changes. We will post the revised policy with a new effective date and provide additional notice when required by law. Continued use after an update means the revised policy applies to later activity.
12. Contact
For privacy questions, requests, account deletion, billing privacy concerns, or suspected misuse, email support@suggestionbox.io.
SuggestionBox.io is the service name used throughout this policy. A box owner's own privacy notice may also apply to information collected through that owner's suggestion box.