Privacy Policy

Customer Voice

Last updated: 13.04.2026

This Privacy Policy explains how Maxim Lutsan (“we”, “us”, or “our”) collects, uses, and processes personal data when you use the Customer Voice application, website, and related services (the “Service”).

If you have any questions, contact:
support@customer-voice.app

This Privacy Policy is provided for transparency. Where we rely on your consent for specific processing activities, we will ask for it separately when required by law.

1. Who We Are

Controller
Maxim Lutsan
Germany
Email: support@customer-voice.app

For purposes of the EU General Data Protection Regulation (GDPR), we act as:

  • Processor for workspace and customer data processed through the Service
  • Controller for limited operational and technical data needed to run, secure, and improve the Service

2. How the Service Works

Customer Voice is a public feedback portal that integrates with monday.com and allows teams to collect, manage, and organize product feedback.

The Service operates in connection with your monday.com workspace and processes data only as necessary to provide its functionality. Feedback submissions and any uploaded files are transmitted to and stored in your monday.com account; we do not store separate copies of that feedback content on our own systems.

3. Data We Process

A. Workspace / Customer Data (processed on your behalf)

When you use the Service, we may process:

  • feedback submissions
  • board and item data
  • names, emails, or other personal data included in submissions
  • content and files you upload
  • related metadata

This data belongs to you or your users.

We process this data only to provide and operate the Service according to your instructions. We do not store this feedback content on our own infrastructure; it is stored in your monday.com account.

B. Operational Data (collected by us)

We may collect limited technical and operational data such as:

  • workspace or account identifiers
  • user IDs
  • app lifecycle events received from monday.com (for example, installation, authorization, and subscription lifecycle events)
  • feature usage information
  • website and product analytics events (for example, page views and interaction events, including authentication flow events)
  • timestamps
  • log files and error reports
  • IP addresses
  • device or browser information
  • support communications

This helps us:

  • operate and maintain the Service
  • monitor reliability and performance
  • prevent abuse or unauthorized access
  • troubleshoot issues
  • improve features
  • understand usage of public pages and documentation
  • provide customer support and setup assistance

C. Authentication Data (processed by us)

To support passwordless sign-in for public portal users, we process:

  • name and email address entered in the sign-in form
  • magic-link authentication tokens and related metadata (for example, timestamp and return path)
  • session state in a secure authentication cookie

We use this data only to authenticate users and let them submit ideas, votes, and comments, we do not store this data.

4. Legal Basis for Processing (GDPR)

Where GDPR applies, we rely on:

  • Contract – to provide the Service
  • Legitimate interests – security, reliability, product improvement, and measurement of Service usage
  • Consent – where required by law

5. How We Use Data

We use personal data only to:

  • provide and operate the Service
  • host and display feedback content
  • authenticate users through passwordless magic links
  • provision plan-based features and manage access to Free and Pro plan functionality
  • maintain security and prevent fraud or abuse
  • provide support and setup assistance
  • analyze and improve performance
  • measure website and public-page usage through privacy-focused analytics
  • generate aggregated and anonymized statistics

We do not sell personal data.

6. Data Sharing and Subprocessors

We do not sell or rent personal data.

We share data only with trusted third-party service providers (“subprocessors”) that help us operate, secure, and maintain the Service. Where required under GDPR Article 28, we use appropriate contractual and organizational safeguards to ensure subprocessors process data only on our behalf and under confidentiality and data protection obligations.

These may include:

  • cloud hosting and infrastructure providers
  • security and content delivery providers
  • logging and monitoring tools
  • website analytics providers
  • email and support systems

In particular, we use Cloudflare, Inc. to provide hosting, content delivery (CDN), DNS resolution, and security services.

We use SMTP2GO to deliver transactional authentication emails (magic links). This involves processing recipient email addresses and message delivery metadata.

We also use Umami Cloud (cloud.umami.is) to measure usage of public web pages and product interactions (including authentication flow events). Umami receives limited technical data (such as page URLs, referrer information, browser/device metadata, and IP address information) to provide aggregated analytics and performance insights for our Service.

Feedback submissions and files are stored in your monday.com account. When you choose to connect the Service with monday.com, we transmit feedback content to monday.com for storage and management inside your workspace. monday.com processes that data according to its own terms and privacy policy and, depending on your setup, may act as an independent controller or a processor for your organization.

We also receive app lifecycle events from monday.com, including subscription lifecycle events, to provision features, manage Free and Pro plan access, and keep account settings in sync with your monday.com subscription status.

We may also disclose information if required by law or to protect our legal rights.

7. Data Storage and Security

Operational data required to run the Service (such as encrypted OAuth credentials and non-personal app settings) is stored on our infrastructure, which uses Cloudflare services for hosting and security.

We use reasonable technical and organizational measures to protect data, including:

  • encrypted connections (HTTPS/TLS)
  • access controls and authentication
  • limited internal access
  • logging and monitoring
  • infrastructure security and traffic protection via Cloudflare

We also follow a data-minimization approach and store only the minimum information required to operate the app. Specifically, we store:

  • an encrypted OAuth access token (used to authenticate requests to monday.com);
  • a monday user identifier linked to OAuth ownership for each board; and
  • app settings that do not contain personal information.

For public portal end-user authentication, we use a secure, HttpOnly cookie stored on the end user's device. The cookie payload is encrypted and signed, and currently contains session identity data (name and email) and expiry metadata required to keep the user signed in.

We do not maintain a separate server-side user profile database for public portal sign-in identities.

However, no system can be guaranteed to be 100% secure.

8. Data Retention

We retain data only as long as necessary to:

  • provide the Service
  • comply with legal obligations
  • resolve disputes
  • enforce agreements

Workspace feedback content is stored in your monday.com account. We do not retain separate copies of that content on our systems.

Magic-link tokens are short-lived and expire automatically (currently 15 minutes).

Authentication session cookies can persist for up to 90 days unless the user signs out or clears cookies.

Upon uninstalling the app and/or removing your account, we delete encrypted OAuth credentials and related app settings without undue delay, except where retention is required by law.

Operational logs (including error logs) are retained for up to 7 days for security and troubleshooting and are then deleted or anonymized.

Website analytics data processed via Umami Cloud is retained for the retention period configured in our Umami account and is then deleted or automatically overwritten according to that configuration.

9. Your Rights (GDPR/EEA/UK)

If you are located in the EU/EEA/UK, you may have the right to:

  • access your data
  • correct inaccurate data
  • delete data
  • restrict processing
  • object to processing
  • receive your data in portable form
  • withdraw consent at any time

To exercise your rights, contact: support@customer-voice.app

If we process data on behalf of a monday.com customer or workspace, please contact your workspace administrator first.

You also have the right to lodge a complaint with your local data protection authority.

10. Your Responsibilities

You are responsible for:

  • ensuring you have permission to upload or process personal data
  • complying with applicable privacy laws
  • informing your end users about your data practices
  • obtaining any required consents

11. Third-Party Services

The Service integrates with monday.com and may rely on other third-party infrastructure and analytics providers (including Cloudflare and Umami Cloud).

Your use of third-party platforms is governed by their respective terms and privacy policies. We are not responsible for their practices.

12. Children

The Service is not intended for children under 16, and we do not knowingly collect personal data from children.

13. International Transfers

Data may be processed in countries outside your own.

Where required, we use appropriate safeguards, such as contractual protections or legally recognized transfer mechanisms.

14. Changes to This Policy

We may update this Privacy Policy from time to time.

The updated version will be posted with a revised “Last updated” date. Continued use of the Service after changes means you accept the updated policy.

15. Contact

If you have questions or privacy requests:

support@customer-voice.app