Contents
- 1Who we are
- 2Data we collect
- 3How we use your data
- 4Payment data and Dodo Payments
- 5Third-party processors
- 6Data retention
- 7Your rights
- 8Children's data
- 9International data transfers
- 10Security
- 11Changes to this policy
- 12Your rights under the DPDP Act (India)
- 13Grievance Officer (India)
- 14Contact
1 · Who we are
1.1Reqio is operated by K S Poorvik, an individual trading as Reqio, based at #786, 1st stage, 2nd cross, Sangameshwara ext., Hassan, Karnataka, India. We can be reached at support@reqio.app.
1.2This Privacy Policy explains what data we collect when you use the Reqio dashboard or when your end users interact with a Reqio widget embedded on your site, how we use that data, and your rights.
2 · Data we collect
2.1Account data
When you sign up, we collect your name and email address. Sign-in is passwordless: we email you a one-time login code and store only a bcrypt-hashed, single-use copy of that code until it expires. We never store a password. If you sign in with Google or GitHub, we receive your name and email address from those providers.
2.2Project and feature data
The projects you create, the feature requests you manage, your widget configuration, the Context you write on requests, and team member records.
2.3End-user data (collected via the widget on your site)
When an end user interacts with the widget, we collect:
- Anonymous identifiers, randomly generated per browser.
- Email addresses, where the end user chooses to leave one to receive updates on their request, or where you enable the identity feature and pass one from your server. External user IDs, only where you enable the identity feature.
- Feature request text, votes, and comments.
- The page URL at the time of submission and optional context strings.
- Browser and device diagnostics (browser name and version, OS, viewport size, screen resolution, language, timezone, connection type, JS errors), collected only when a request is submitted.
- Screenshots, where the end user chooses to attach one to a report. A screenshot captures only the visible portion of the page (the viewport) at its current scroll position, never the whole page. Form fields the user typed into are masked before capture, and the end user previews the image and can redact it before attaching.
- Where the identity feature is enabled: additional user attributes you supply in the signed identity token, which can include display name, email address, and revenue attributes (monthly recurring revenue, plan name, or external identifiers). These attributes are stored alongside the submission and used to weight feedback by the revenue value of the requester.
2.4Inbound email replies
When an end user replies to a Reqio notification email, we receive and process the content and headers of that reply message. The reply is stored in the associated conversation thread and is subject to the same retention policy as widget submissions.
2.5Billing and payment data
We do not store your credit or debit card details. Payment data is collected and processed by Dodo Payments. We receive from Dodo Payments a record of your subscription status, plan, and billing period.
2.6Usage and log data
Server logs (including IP addresses), API request timestamps, and error traces. These are used for security and operations and are retained for a limited period, as described in the Data retention section.
2.7Cookies and session data
We use a small set of strictly necessary first-party cookies to keep you signed in to the dashboard and to protect the sign-in flow. The dashboard also stores interface preferences (such as your theme choice) in your browser's localStorage. The embeddable widget does not set cookies on the host site; it uses browser storage as described in our Cookie Policy.
3 · How we use your data
3.1To provide and operate the Service: authenticating you, storing your projects and requests, powering the widget on your site.
3.2To process payments: we pass your subscription intent to Dodo Payments and receive back subscription status.
3.3To communicate with you: transactional emails (one-time login codes, team invitations, billing receipts, and the notification emails you have enabled), and product updates where you have not opted out.
3.4To secure the Service: detecting abuse, rate limiting, and fraud prevention.
3.5To improve the Service: aggregate, anonymised analytics on feature usage. We do not sell your data or use it to train third-party AI models.
4 · Payment data and Dodo Payments
4.1All payment processing for Reqio subscriptions is handled by Dodo Payments, acting as the Merchant of Record and authorized reseller. When you subscribe to a paid plan, you are transacting with Dodo Payments, who collects your payment details, processes the charge, handles tax, and issues receipts.
4.2Reqio does not receive or store your card number, bank account details, or CVV. We receive only the subscription outcome (plan, status, next billing date) from Dodo Payments.
4.3Dodo Payments' own privacy policy governs how they handle your payment data. By subscribing, you agree to Dodo Payments' terms.
5 · Third-party processors
5.1We share data with the following sub-processors only to the extent necessary to operate the Service:
- Dodo Payments: payment processing and billing. Data shared: subscription intent, customer email for receipts.
- Vercel: hosting, serverless compute, and cookieless web analytics for the dashboard and marketing site. Data shared: all request data passing through the application.
- PostHog (EU region): product analytics for our own marketing site and dashboard, and only where you have accepted analytics. Data shared: pages viewed and product actions taken by you, our account holder, plus your Reqio account and project identifiers. Not loaded at all if you decline. Receives no data from the embeddable widget and no data about your end users.
- Neon: managed PostgreSQL database. Data shared: all structured application data (accounts, projects, features, widget submissions).
- Resend: transactional email delivery and inbound email receiving. Data shared: recipient email addresses and email content (login codes, invitations, notification emails, and end-user replies to notification emails).
- Upstash: rate limiting and abuse prevention. Data shared: short-lived request identifiers used to enforce rate limits.
- Cloudflare: email routing for inbound replies. Data shared: email metadata and content in transit.
5.2We do not sell data to any third party for marketing purposes.
5.3Services you connect yourself
Separately from the sub-processors above, you can connect third-party services to your own account: AI agents over the MCP server, API clients using your project API keys, project integrations you authorize with your own credentials (such as Slack, Jira, and Linear, which receive notifications containing end-user request titles and message excerpts), and the optional GitHub agent workflow, which sends end-user content (including request text, conversation threads, screenshots, and browser diagnostics) to the AI model provider whose API key you configured. Those providers act on your instructions, under your own accounts and your own agreements with them. They are not Reqio sub-processors, and their handling of that data is governed by your agreement with them, not by this policy. As the controller, you are responsible for disclosing this processing to your end users.
6 · Data retention
6.1Account data is retained while your account is active. If you delete your account, we remove your personal data within 30 days, except where retention is required by law.
6.2End-user data (widget submissions) is stored for as long as your account is active and the project exists. Deleting a project permanently removes its associated requests, comments, votes, conversation messages, screenshots, and notification records.
6.3Server logs are retained for up to 90 days.
6.4Billing records are retained longer where required for tax or legal compliance.
6.5One-time login codes expire minutes after they are issued and are stored only as bcrypt hashes, never in plaintext. All prior codes for an email address are deleted when a new code is requested.
6.6When data is deleted, it is removed from the live database at the time of deletion. Copies can persist for a limited additional period in the automatic continuous backups kept by our database host (Neon), until those backups expire on the host's rolling retention schedule, and in no case longer than 30 days after deletion. We do not run separate manual backups, we cannot selectively erase individual records from the host's backup history before it expires, and we do not use backup copies for any purpose other than restoring the Service after data loss or corruption. If we restore from a backup taken before a deletion, we will re-apply that deletion promptly after the restore.
7 · Your rights
7.1Depending on your location, you have the right to access, correct, or delete your personal data, and to restrict or object to its processing.
7.2To exercise any of these rights, email us at support@reqio.app. We will respond within 30 days.
7.3If you are in the European Economic Area or United Kingdom, you also have the right to lodge a complaint with your local data protection authority.
7.4Note: Reqio dashboard users control the data their end users submit via the widget. If an end user of your product wants to exercise their privacy rights, that request must be directed to you as the data controller for that relationship. We will assist you in honoring such requests.
8 · Children's data
The Service is not directed to children under 18, and we do not knowingly collect personal data from children under 18 without verifiable parental consent, as required under the Digital Personal Data Protection Act 2023 of India (DPDP Act). If you believe a child has provided us with personal data, contact us at support@reqio.app and we will address it promptly.
9 · International data transfers
9.1Reqio is operated from India. Our sub-processors (including Vercel, Neon, Resend, and Upstash) store and process data in the United States or other countries. By using the Service, you acknowledge that your data is transferred to and processed in countries whose data protection laws can differ from those in your country.
9.2We rely on our sub-processors' own compliance frameworks (including Standard Contractual Clauses where applicable) for cross-border transfers.
9.3Reqio has not appointed a representative in the EU or UK under Article 27 GDPR or its UK equivalent. If you are in the European Economic Area or the United Kingdom and have questions about your data or the transfer safeguards that apply, contact support@reqio.app.
10 · Security
10.1We implement industry-standard security measures: TLS in transit, AES-256-GCM encryption for sensitive stored secrets, passwordless login with one-time codes that are bcrypt-hashed at rest, single use, and expiring, and rate limiting with attempt lockout on authentication endpoints. We store no passwords.
10.2No method of transmission over the internet or electronic storage is 100% secure. We cannot guarantee absolute security, but we take reasonable steps to protect your data and will notify you of a breach as required by applicable law.
11 · Changes to this policy
11.1We reserve the right to update this Privacy Policy from time to time. Material changes will be communicated by email or by a notice in the dashboard. The "last updated" date at the top of this page always reflects the most recent revision.
11.2Continued use of the Service after a change takes effect constitutes acceptance of the revised policy.
12 · Your rights under the DPDP Act (India)
12.1If you are a Data Principal under the Digital Personal Data Protection Act 2023 of India (DPDP Act), the following applies to your personal data processed by Reqio.
12.2Purposes of processing
We collect and process your personal data to provide and operate the Service, process payments, communicate with you (transactional emails about your account, and product updates where you have not opted out), secure the Service against abuse, and improve the Service through aggregate analytics. The specific categories of data we process are described in the 'Data we collect' section above.
12.3Your rights
You have the right to:
- Obtain a summary of the personal data Reqio holds about you and information on its processing.
- Correct inaccurate or incomplete personal data.
- Erase your personal data where it is no longer necessary for the purpose it was collected, subject to legal retention obligations.
- Grievance redress as described below.
12.4How to exercise your rights
Email us at support@reqio.app. We will respond within 30 days. Where a request concerns end-user data submitted through the widget on your product, that request must be directed to the product owner (the Reqio customer) as the Data Fiduciary for that relationship.
12.5Complaint to the Data Protection Board
If you are not satisfied with our response, you can lodge a complaint with the Data Protection Board of India established under the DPDP Act.
13 · Grievance Officer (India)
13.1In compliance with the Digital Personal Data Protection Act 2023 of India (DPDP Act), Reqio has designated a Grievance Officer to address data protection concerns raised by Data Principals.
- Name: K S Poorvik
- Contact: support@reqio.app
13.2If you have a concern about how Reqio processes your personal data, you can contact the Grievance Officer by email. We will acknowledge your concern within 48 hours and aim to resolve it within 30 days.
13.3If you remain unsatisfied after raising a concern with the Grievance Officer, you can escalate to the Data Protection Board of India.
14 · Contact
Privacy questions or requests can be sent to support@reqio.app.
K S Poorvik, #786, 1st stage, 2nd cross, Sangameshwara ext., Hassan, Karnataka, India.