Data Management
Aipera Technology · Last updated August 20, 2026
This page describes, in practical terms, how data flows through PraiseSnap, where it is stored, how long it is kept, and how to export or delete it. It supplements our Privacy Policy and serves as our standing data-processing commitment to Customers. Organizations requiring a signed Data Processing Agreement (DPA) can request one at info@aipera.com.
1. Roles
- You (the Customer) are the data controller for testimonial content collected through your forms: you decide what to ask, what to approve, and what to display.
- PraiseSnap is your data processor for that content: we store, process, and display it only on your instructions (given through the product), and we do not use your Submitters' personal data for our own marketing.
- For your own account data (email, billing, settings), PraiseSnap is the controller.
2. What we store, exactly
| Data | Examples | Where |
|---|---|---|
| Account data | Email, hashed auth, workspace settings | Supabase (Postgres, US East) |
| Testimonial content | Name, role, company, rating, quote, link, consent record, timestamps | Supabase (Postgres, US East) |
| Uploaded images | Submitter avatars, workspace logos | Supabase Storage (US East) |
| Billing records | Stripe customer ID, subscription status, plan | Stripe (we never store card numbers) |
| Email events | Transactional sends (password resets, notifications) | Resend |
| Server logs | IP, user agent, URL, status — transient, security-only | Application server (Hostinger VPS) |
What we deliberately do not collect: the embeddable widget sets no cookies and does not track or profile visitors who view widgets on your website. Viewer requests appear only in short-lived server logs.
3. Isolation between customers
Every customer's data is isolated at the database layer using row-level security (RLS): queries run under the requesting user's identity, and the database itself refuses cross-account access. This isolation is covered by automated integration tests that run before every release.
4. Retention schedule
| Data | Retained |
|---|---|
| Account & testimonial data | Life of the account; deleted or anonymized within 30 days of account deletion |
| Individual testimonials | Until you delete them |
| Transient server logs | ≤ 30 days, rolling |
| Billing records | 7 years where required by tax/accounting law (held at Stripe/our records) |
| Backups | Roll off automatically on the backup cycle after deletion (typically ≤ 30 days) |
5. Export (data portability)
You can export your testimonials from the dashboard (CSV) at any time, including author fields, ratings, quotes, tags, status, and timestamps. For a complete account export (including images), email info@aipera.com and we will provide a machine-readable archive within 30 days.
6. Deletion
- Individual testimonials: delete from the moderation dashboard; deletion is immediate in the application and propagates to widgets within minutes as caches expire.
- A Submitter's request: if a person who submitted a testimonial asks you to remove it, deleting it in your dashboard fulfills that; if they contact us directly, we will notify you and assist, or act ourselves where the law requires.
- Whole account: request deletion by email from your account address. We delete or irreversibly anonymize personal data within 30 days, excepting legally required records, then confirm.
7. Subprocessors
We keep our subprocessor list short and stable: Supabase (database, auth, storage), Stripe (payments), Resend (transactional email), Hostinger (application hosting). We will update this page before adding a subprocessor that handles personal data; Customers with a signed DPA will be notified and may object on reasonable data-protection grounds.
8. Security measures (summary)
- HTTPS/TLS for all traffic, including widget delivery
- Database row-level security with automated cross-account access tests
- Secrets kept in environment configuration, never in the codebase; scoped keys; routine rotation
- Server-side validation on every write; rate limiting and spam protection on public submission endpoints
- Least-privilege operational access; audited deploy pipeline
- Encrypted-at-rest storage via our infrastructure providers
9. Incidents
If we become aware of a personal-data breach affecting your data, we will notify you without undue delay (and within 72 hours where GDPR applies), describe what happened and what we are doing, and cooperate with your own notification obligations.
10. Questions & requests
All data requests — access, export, deletion, DPA signature, subprocessor questions — go to info@aipera.com. We respond within 30 days, usually much faster.
Aipera Technology, 30 N Gould St, Ste N, Sheridan, WY 82801, USA
Questions about any of this: info@aipera.com