Data processing agreement
This is the Article 28(3) agreement between you, as controller of the bug reports your visitors submit, and us, as your processor. It is part of the terms of service, it applies from the moment you create an account, and nobody has to request it.
Last updated: July 27, 2026
Status of this document
This agreement (the “DPA”) is incorporated into the terms of service and takes effect when you create an account. No signature is required to make it binding. Where it conflicts with the terms of service or the privacy policy about our processing of personal data on your behalf, this document wins. If your procurement process needs a countersigned PDF of this same text, email support@supportshot.com and we will sign it; we will not negotiate a different one, because a fleet of bespoke DPAs is a set of promises no engineering team can keep track of.
It survives termination of your account for as long as we hold any personal data you were the controller of, which after a workspace erasure means the backup window in clause 11 and nothing else.
1. The parties
Processor: 2662415 Ontario Inc., a corporation incorporated in Ontario, Canada under corporation number 2662415, registered office 408 Dundas Street South, Unit 101, Cambridge, Ontario N1R 8H7, Canada, trading as SupportShot(“we”, “us”).
Controller: the person or company that holds the SupportShot account (“you”). You are the controller of every bug report submitted through a widget you installed: it is your website, your visitors, and your decision to collect them.
For your own account data — your name, email, workspace, subscription — we are the controller and this DPA does not apply; the privacy policy governs that instead. This document is about ticket data only.
Point of contact. Every notice, request and instruction under this agreement — documented instructions under clause 4, subprocessor objections under clause 7, data subject requests under clause 9, breach notifications under clause 10, and audit requests under clause 12 — is given by emailing support@supportshot.com, and reaches a person at the processor named above. We have no other office and no other intake address, so there is no route you could take that is faster than that one.
2. Subject matter, duration, nature and purpose
- Subject matter. Our provision of the SupportShot bug report service: an embeddable widget that collects a report your visitor writes, a hosted dashboard that stores it, and email notifications to the recipients you configure.
- Duration. From account creation until the account is closed, plus the backup window in clause 11.
- Nature of the processing. Collection at the moment your visitor presses send; transmission to us; storage in a database and, for screenshots, on server disk; display to you in the dashboard; transmission by email to your recipients; and deletion when you ask. No profiling, no automated decision-making, no enrichment against any other dataset, and no training of machine-learning models.
- Purpose. To provide the service to you, and nothing else.
3. Categories of data subjects and personal data
Data subjects: visitors to your website who submit a bug report, and any person visible in a screenshot one of them attaches or named in the message they type.
Categories of personal data, which is the full list of what the widget sends:
- The free-text message the visitor wrote, which can contain anything they choose to put in it.
- Their email address, either typed by them or supplied by your page through
SupportShot.identify(), and the id and name you pass alongside it. - The screenshot, if the visitor attaches one, in both the annotated and the original form. A screenshot is a picture of their screen and may contain any personal data that was on it.
- Technical and diagnostic data: the full page URL and title, the browser family and major version, the operating system family, viewport size, device pixel ratio, timezone, locale, widget version, the last 200 console entries, and the last 50 failed network requests.
- The IP address a submission arrived from, held only as the key of a rate-limit counter, never joined to a ticket, and deleted within hours.
Special-category data under Art. 9, and criminal-offence data under Art. 10, are not a category we ask for and not one the service is designed for — but a screenshot and a free-text message can carry anything that was on the visitor’s screen. Clause 4 is where that lands: deciding which of your pages carry the widget is your instruction to give, and the terms of service asks you to be careful about pages that display health data, payment card data or government identifiers.
Two things reach us that a reader may assume do not. The page URL is recorded in full, including its query string and fragment, and console output is recorded exactly as your code printed it. If your application puts a token or an identifier in either, it is in the ticket. The privacy policy sets this out at “Where a secret still could reach us”.
4. Processing on your documented instructions
We process ticket data only on your documented instructions, including for transfers, unless we are required to do otherwise by law that applies to us — and in that case we will tell you before processing, unless that law forbids it on important grounds of public interest.
Your documented instructions are, in full:
- This DPA and the terms of service.
- The settings you choose in your dashboard: which projects exist, whether each widget is enabled, the allowed-origins list, the notification recipients, and the widget’s appearance and prompt.
- Which of your pages carry the embed tag. That is the instruction with the most weight in it and the only one we cannot see you give.
- Any deletion you perform or request, and any additional instruction we agree in writing.
We will tell you if, in our opinion, an instruction infringes the GDPR, the UK GDPR, or another applicable data protection law. We do not use ticket data for our own purposes, do not sell it, do not share it for advertising, and do not use it to train models.
5. Confidentiality
Everyone we authorise to process ticket data is bound by an obligation of confidentiality that survives the end of their engagement, and access is limited to the people who need it to run the service — in practice, to fix a fault or answer a support request you raised. Access to production is not a routine part of anybody’s day.
6. Security (Art. 32)
The measures we take are published in full, and in specifics, on the security page, which is incorporated into this clause. In summary: TLS on every connection; Argon2 password hashing; per-project origin checks and two layers of rate limiting on the ingest API; screenshots served only through authenticated dashboard routes or unguessable signed links that expire on their own 180 days after they are signed and die with the ticket in any case; no per-request access logs kept anywhere; and dedicated servers under our own control rather than shared hosting.
What we do not do, because you are entitled to assess us on it: there is no encryption at rest. The database, the screenshot files and the backups are stored unencrypted on disks in Beauharnois, Quebec, Canada. If your risk assessment requires encryption at rest for the data you would send us, this service does not meet it, and we would rather say so here than let you find out during an audit.
We may change these measures as the service develops, provided the level of security is not reduced. A material reduction would be notified the same way a subprocessor change is.
7. Subprocessors
You give us general authorisation to engage subprocessors. The ones engaged today are listed, with what each processes and where, in the subprocessor table. The one that holds all ticket data at rest is OVH Hosting Inc. (OVHcloud) in Beauharnois, Quebec, Canada.
- Notice. We will email account owners at least 30 days before a new or replacement subprocessor begins processing ticket data, naming it and saying what it will do.
- Objection. You may object on reasonable data-protection grounds within those 30 days by emailing support@supportshot.com. We will work with you to find an alternative; if there is none, you may terminate the affected subscription and we will refund the unused portion of what you have paid.
- Flow-down and liability. Each subprocessor is engaged under a written contract imposing data protection obligations no less protective than these, and we remain fully liable to you for its performance.
- Emergencies. If we must change a subprocessor immediately to keep the service running or secure, we will tell you as soon as we can afterwards; your objection right and the refund still apply.
8. International transfers
Ticket data at rest stays in Beauharnois, Quebec, Canada. Transfers out of Canada happen for two purposes and no others: email delivery through Resend and billing through Stripe, both in the United States, and both under those providers’ standard contractual clauses. Cloudflare, Inc. provides authoritative DNS for supportshot.com and is not in the path of your requests: connections are made to our servers in Beauharnois, Quebec, Canada directly, so no connection metadata is transferred to an edge network. DNS queries are resolved by Cloudflare, Inc.’s worldwide infrastructure, which is a lookup of our domain name rather than a transfer of your data or your visitors’. Where the EU or UK standard contractual clauses apply to a transfer from us, they are incorporated into this DPA by reference, with us as data exporter, the module for processor-to-processor transfers, and the governing law and forum of clause 13 below where the clauses allow a choice.
9. Assisting you with data subject rights
Most of this you can do yourself, immediately, which is faster than any assistance obligation:
- Access and portability — every ticket, with its diagnostics and screenshots, is visible in your dashboard.
- Erasure — delete a ticket from your inbox, a project with everything under it from that project’s settings, or the whole workspace from Org settings. Each is immediate and irreversible, and none of them is a request we queue.
- Rectification and restriction — a bug report is a record of what a visitor said, so the mechanism is deletion rather than editing. Email support@supportshot.com if you need something else and we will do what we can.
Where you cannot do it yourself, we will assist by appropriate technical and organisational measures, insofar as possible, taking into account the nature of the processing. If one of your visitors contacts us directly about their own report, we do not act on it as though we were the controller: we locate the report and pass the request to you, and tell them we have done so, except where the law requires us to act directly.
We will also assist you, taking into account the nature of processing and the information available to us, with your obligations under Articles 32 to 36 — security, breach notification and communication, data protection impact assessments, and prior consultation.
10. Personal data breaches
We will notify you without undue delay after becoming aware of a personal data breach affecting ticket data you control, and in any event in time for you to meet your own 72-hour deadline to your supervisory authority. The notification will describe the nature of the breach, the categories and approximate number of data subjects and records concerned, the likely consequences, the measures taken or proposed, and a contact point — and where we do not have all of that yet, we will send what we have rather than wait, and follow up.
We will not notify your data subjects on your behalf without your instruction, except where the law requires it of us directly.
11. Return and deletion
At any time, you delete ticket data yourself. On termination, you choose: export what you want from the dashboard, then delete the workspace, or ask us at support@supportshot.com to erase it for you and we will do so within 30 days. There is no separate return process because you have continuous access to the data throughout — and no dormant copy is kept “in case”.
Erasing a workspace deletes, in one transaction, the projects, every ticket and both copies of every screenshot filed under them, the recipient lists, the counters, the workspace, and the accounts of everyone in it who has no other workspace. That transaction runs while you wait and either commits whole or changes nothing.
The subscription is cancelled after those rows are gone, not before. The same transaction records what is owed — the Stripe subscription and customer identifiers, and nothing else about you — and we call Stripe immediately afterwards, normally within the same second. That record is itself deleted within 14 days of the cancellation settling, so the pointer does not outlive the reason it existed. If Stripe refuses or cannot be reached at that moment the cancellation stays queued and is retried automatically until it succeeds. The order is deliberate: an outage at Stripe cannot stand between you and the destruction of your data, and it cannot lose the cancellation either. What it can do is delay it, so the honest bound is this — a subscription that resists cancellation is caught at the latest by its own next renewal event, which means at worst one further billing period may be charged after the workspace is gone. Any charge raised after the erasure is refundable on request at support@supportshot.com, and you will need that address because there is no account left to raise it from.
A cancellation that fails permanently — a subscription Stripe will not act on for us at all — stops being retried and becomes a person’s job here. It is not lost, and it is not silent: the queued record is what we work from.
The two exceptions, stated rather than buried. A backup taken before an erasure still contains what it contained when it was taken; no backup is kept for more than 14 days, backups are never opened to answer a request, and if one is ever restored we re-run every erasure that happened after it was taken. And Stripe holds invoices and tax records under its own legal retention obligations, which we cannot and may not delete.
12. Audits and information
We will make available to you all information necessary to demonstrate compliance with Art. 28 and allow for and contribute to audits, including inspections, conducted by you or an auditor you mandate. In practice:
- First, read what is already published. The privacy policy, the security page and this document are written to be diffed against the product rather than to reassure, and they name what the service does not do as precisely as what it does. Most security questionnaires are answerable from them.
- Then ask. Email support@supportshot.com with what is missing and a person answers it, within 30 days, at no charge. We hold no SOC 2 or ISO 27001 certification and do not claim one.
- On-site or hands-on inspection is available to controllers who need it, on 30 days’ notice, no more than once in any 12 months unless a breach or a supervisory authority requires otherwise, during business hours, scoped so it cannot expose another customer’s data, and subject to confidentiality. You bear your own costs; we bear ours, unless the inspection finds no material non-compliance and a second one is requested in the same year.
13. Governing law and liability
This DPA is governed by the law of the Province of Ontario, Canada, and the courts of Ontario have exclusive jurisdiction, on the same terms and with the same consumer carve-out as section 17 of the terms of service — except where a standard contractual clause incorporated under clause 8 requires the law and forum of an EU member state or the United Kingdom, in which case that requirement prevails for that transfer.
Each party’s liability under this DPA is subject to the limitation of liability in section 14 of the terms of service, except where that limitation is not permitted by applicable data protection law.
14. Changes
We may update this DPA. If a change materially affects your rights or our obligations we will email account owners at least 14 days before it takes effect, and the date at the top always reflects the current version.
15. Contact
Anything about this agreement: support@supportshot.com, or in writing to 2662415 Ontario Inc., 408 Dundas Street South, Unit 101, Cambridge, Ontario N1R 8H7, Canada.
Records for your Article 30 register
Processor: 2662415 Ontario Inc., 408 Dundas Street South, Unit 101, Cambridge, Ontario N1R 8H7, Canada. Categories of processing: collection, storage, display and email transmission of website bug reports and their diagnostics. Third-country transfers: United States, for email delivery and billing, under standard contractual clauses. Technical and organisational measures: the security page, including the absence of encryption at rest.