Privacy policy
SupportShot collects bug reports on behalf of the websites that install it. This policy explains exactly what data we hold, why we hold it, who else touches it, and how to get rid of it.
Last updated: July 26, 2026
The short version
- We store what a bug report needs: the message, the screenshot the visitor chose to attach, browser diagnostics, and the page the report came from.
- We never capture request or response bodies, headers, cookies, keystrokes, or form input, and we do not record sessions.
- We do not sell data, we do not share it for advertising, and we run no third-party analytics or advertising trackers on supportshot.com.
- You can delete any ticket at any time, and closing your account erases everything from our systems within 30 days.
- Questions or requests go to support@supportshot.com and a person answers them.
Who we are, and who controls what
SupportShot (“SupportShot”, “we”) operates supportshot.com and the embeddable report widget served from it. Contact: support@supportshot.com.
There are two relationships to keep straight. For your account data — your name, email, organization, subscription — we are the data controller. For the bug reports your visitors submit, you are the controller and we are your processor: it is your website, your visitors, and your decision to collect them. We process that data to provide the service and on your instructions, which in practice means the settings you choose in your dashboard.
What we collect
Account data
Your email address and a hashed password (or your Google account email and name if you sign in with Google), your organization and project names, the recipient email addresses you configure, your allowed origins and widget appearance settings, and your subscription status. We keep this for as long as your account exists.
Ticket contents
Everything a visitor sends when they submit a report: the message they typed, the email address they gave or that your site supplied through identify() (with any id and name you pass), and the screenshot if they attached one — both the annotated version and the original. A screenshot is an image of what was on their screen, so it may contain personal data. The visitor decides whether to attach one and can send the report without it.
Diagnostics
Attached automatically to each ticket: the last 200 browser console entries (each truncated to 1 kB) including JavaScript errors and unhandled promise rejections with stack traces; the last 50 failed network requests as method, URL (truncated to 256 characters), status, duration, and timestamp; and the page URL and title, browser, operating system, viewport size, device pixel ratio, timezone, locale, and widget version.
What the widget never collects
- Request or response bodies and headers — so authorization tokens and API payloads never reach us.
- Successful network requests. Only failures are recorded.
- Keystrokes, form field values, clipboard contents, cookies,
localStorage, orsessionStorage. - Session recordings, mouse trails, or any continuous background capture. Nothing is captured until a visitor presses send.
The widget sets no cookies and stores nothing on your visitors’ devices.
Site and service logs
Our servers keep standard request logs for supportshot.com and the ingest API — IP address, timestamp, requested URL, user agent, response status. We use them to run the service, investigate abuse, and enforce rate limits. They are retained for 30 days and then deleted.
Payment data
Card details go directly to Stripe and never touch our servers. We store the Stripe customer and subscription identifiers, your plan, and your billing history as Stripe reports it.
How we use it
- To store your tickets and show them to you in your dashboard.
- To email each report to the recipients you configured.
- To send transactional email: address verification, password resets, and, when you exceed your plan’s ticket limit, an upgrade notice (at most once a day).
- To count tickets against your plan, enforce rate limits, and bill your subscription.
- To keep the service working and secure — debugging failures, investigating abuse, and restoring service after a fault.
We do not sell personal data, we do not share it with advertisers, and we do not use your tickets or screenshots to train machine-learning models. Staff access production data only when needed to fix a fault or answer a support request you raised.
If you are in the EEA or UK: we process account data to perform our contract with you and, for security and product improvement, on the basis of our legitimate interests. Ticket data is processed on your instructions as controller. We will sign a data processing agreement on request — email support@supportshot.com.
Who else processes the data
We keep the list short on purpose. These are our subprocessors:
| Subprocessor | Purpose | Data involved |
|---|---|---|
| Stripe | Subscription billing and payment processing | Name, email, billing address, card details (entered directly with Stripe) |
| Resend | Delivery of ticket notifications and transactional email | Recipient email addresses, email contents including the ticket message and a link to its screenshot |
| Cloudflare | DNS and edge proxying for supportshot.com | Connection metadata: IP address, user agent, requested URL |
| Our hosting provider (named on request) | Dedicated servers in Canada running the application, database, and screenshot storage | All service data at rest |
| Optional sign-in with Google, only if you choose it | Your Google account email and name |
We will also disclose data if the law requires it — a valid court order, for example — and we will tell you unless we are legally barred from doing so. If SupportShot is ever sold or merged, your data moves with the service and you will be told before it does.
Where the data lives
Tickets, screenshots, and the database sit on dedicated servers we manage in Canada; screenshots are stored on the server’s own disk, not in a third-party object store. Email delivery (Resend) and billing (Stripe) involve transfers to the United States, made under those providers’ standard contractual clauses.
How long we keep it
- Tickets and screenshots — until you delete them, or until your account is closed. We do not expire them on a timer. Deleting a ticket removes its screenshots from storage and invalidates the image links in already-sent emails.
- Account data — for the life of the account.
- Closing your account — email support@supportshot.com from the address you signed up with; deletion propagates through our systems within 30 days, apart from invoices and tax records we are legally required to keep.
- Server logs — 30 days.
- Notification emails already delivered to your recipients are in their mailboxes and outside our control.
Security
All traffic runs over HTTPS. Passwords are hashed with Argon2 and are never recoverable, by us or anyone else. Screenshots are served through authenticated routes in the dashboard, and through unguessable signed links in email that stop working when the ticket is deleted. Every submission is checked against your project’s allowed origins and rate limited. No system is perfect; if we ever suffer a breach affecting your data we will tell you promptly and tell you what we know.
Your rights and choices
- See it — every ticket is visible in your dashboard, and you can ask us for a copy of your account data.
- Correct it — account and project details are editable in your settings.
- Delete it — delete individual tickets from the dashboard, or email support@supportshot.com to close your account and remove everything.
- Object or restrict — email support@supportshot.com and tell us what you want stopped.
- Complain — if you are in the EEA or UK you may complain to your local data protection authority. We would rather hear from you first.
We answer requests within 30 days and do not charge for them.
If you filed a report on someone else’s website
The website that showed you the SupportShot widget decides what happens to your report; ask them first, since they hold the account. You can also email support@supportshot.com with the ticket reference from the confirmation message (for example SS-4F2A9C) or the email address and website you used, and we will locate the report and pass your request to the account owner, or act on it directly where the law requires us to.
Cookies
supportshot.com sets a small number of strictly necessary cookies, for keeping you logged in and for CSRF protection. There are no advertising cookies, no third-party analytics, and no tracking pixels on this site. The widget on your site sets no cookies at all.
Children
SupportShot is a tool for website operators and is not directed at children under 16. We do not knowingly hold account data about children. If a child’s personal data reaches us inside a bug report, tell us and we will delete it.
Changes to this policy
When we change this policy we update the date at the top. If a change materially affects how we handle your data we will email account owners at least 14 days before it takes effect. The terms of service cover the rest of the relationship.
Contact
Privacy questions, data requests, and DPA requests: support@supportshot.com.