Privacy policy

SupportShot collects bug reports on behalf of the websites that install it. This policy explains exactly what data we hold, why we hold it, who else touches it, and how to get rid of it.

Last updated: July 26, 2026

The short version

  • We store what a bug report needs: the message, the screenshot the visitor chose to attach, browser diagnostics, and the page the report came from.
  • We never capture request or response bodies, headers, cookies, keystrokes, or form input, and we do not record sessions.
  • We do not sell data, we do not share it for advertising, and we run no third-party analytics or advertising trackers on supportshot.com.
  • You can delete any ticket at any time, and closing your account erases everything from our systems within 30 days.
  • Questions or requests go to support@supportshot.com and a person answers them.

Who we are, and who controls what

SupportShot (“SupportShot”, “we”) operates supportshot.com and the embeddable report widget served from it. Contact: support@supportshot.com.

There are two relationships to keep straight. For your account data — your name, email, organization, subscription — we are the data controller. For the bug reports your visitors submit, you are the controller and we are your processor: it is your website, your visitors, and your decision to collect them. We process that data to provide the service and on your instructions, which in practice means the settings you choose in your dashboard.

What we collect

Account data

Your email address and a hashed password (or your Google account email and name if you sign in with Google), your organization and project names, the recipient email addresses you configure, your allowed origins and widget appearance settings, and your subscription status. We keep this for as long as your account exists.

Ticket contents

Everything a visitor sends when they submit a report: the message they typed, the email address they gave or that your site supplied through identify() (with any id and name you pass), and the screenshot if they attached one — both the annotated version and the original. A screenshot is an image of what was on their screen, so it may contain personal data. The visitor decides whether to attach one and can send the report without it.

Diagnostics

Attached automatically to each ticket: the last 200 browser console entries (each truncated to 1 kB) including JavaScript errors and unhandled promise rejections with stack traces; the last 50 failed network requests as method, URL (truncated to 256 characters), status, duration, and timestamp; and the page URL and title, browser, operating system, viewport size, device pixel ratio, timezone, locale, and widget version.

What the widget never collects

  • Request or response bodies and headers — so authorization tokens and API payloads never reach us.
  • Successful network requests. Only failures are recorded.
  • Keystrokes, form field values, clipboard contents, cookies, localStorage, or sessionStorage.
  • Session recordings, mouse trails, or any continuous background capture.

Nothing reaches us until a visitor presses send. To be precise about what happens before that: on page load the widget makes one request to us for the project’s settings (its colour, its position, whether it is switched on), and that request carries the public project key and nothing about the visitor. From then on the console entries and failed requests listed above accumulate in two small buffers inside the page, in memory, and are discarded when the visitor navigates away. They are transmitted only as part of a report the visitor wrote and sent. The screenshot is taken at the moment they ask for one and never before.

The widget sets no cookies and stores nothing on your visitors’ devices.

Site and service logs

Our servers keep standard request logs for supportshot.com and the ingest API — IP address, timestamp, requested URL, user agent, response status. We use them to run the service, investigate abuse, and enforce rate limits. They are retained for 30 days and then deleted.

Payment data

Card details go directly to Stripe and never touch our servers. We store the Stripe customer and subscription identifiers, your plan, and your billing history as Stripe reports it.

How we use it

  • To store your tickets and show them to you in your dashboard.
  • To email each report to the recipients you configured.
  • To send transactional email: address verification, password resets, and, when you exceed your plan’s ticket limit, an upgrade notice (at most once a day).
  • To count tickets against your plan, enforce rate limits, and bill your subscription.
  • To keep the service working and secure — debugging failures, investigating abuse, and restoring service after a fault.

We do not sell personal data, we do not share it with advertisers, and we do not use your tickets or screenshots to train machine-learning models. Staff access production data only when needed to fix a fault or answer a support request you raised.

If you are in the EEA or UK: we process account data to perform our contract with you and, for security and product improvement, on the basis of our legitimate interests. Ticket data is processed on your instructions as controller. We will sign a data processing agreement on request — email support@supportshot.com.

Who else processes the data

We keep the list short on purpose. These are our subprocessors:

SubprocessorPurposeData involved
StripeSubscription billing and payment processingName, email, billing address, card details (entered directly with Stripe)
ResendDelivery of ticket notifications and transactional emailRecipient email addresses, email contents including the ticket message and a link to its screenshot
CloudflareDNS and edge proxying for supportshot.comConnection metadata: IP address, user agent, requested URL
Our hosting provider (named on request)Dedicated servers in Canada running the application, database, and screenshot storageAll service data at rest
GoogleOptional sign-in with Google, only if you choose itYour Google account email and name

We will also disclose data if the law requires it — a valid court order, for example — and we will tell you unless we are legally barred from doing so. If SupportShot is ever sold or merged, your data moves with the service and you will be told before it does.

Where the data lives

Tickets, screenshots, and the database sit on dedicated servers we manage in Canada; screenshots are stored on the server’s own disk, not in a third-party object store. Email delivery (Resend) and billing (Stripe) involve transfers to the United States, made under those providers’ standard contractual clauses.

How long we keep it

  • Tickets and screenshots — until you delete them, or until your account is closed. We do not expire them on a timer. Deleting a ticket removes its screenshots from storage and invalidates the image links in already-sent emails.
  • Account data — for the life of the account.
  • Closing your account — email support@supportshot.com from the address you signed up with; deletion propagates through our systems within 30 days, apart from invoices and tax records we are legally required to keep.
  • Server logs — 30 days.
  • Notification emails already delivered to your recipients are in their mailboxes and outside our control.

Security

All traffic runs over HTTPS. Passwords are hashed with Argon2 and are never recoverable, by us or anyone else. Screenshots are served through authenticated routes in the dashboard, and through unguessable signed links in email that stop working when the ticket is deleted. Every submission is checked against your project’s allowed origins and rate limited. No system is perfect; if we ever suffer a breach affecting your data we will tell you promptly and tell you what we know.

Your rights and choices

  • See it — every ticket is visible in your dashboard, and you can ask us for a copy of your account data.
  • Correct it — account and project details are editable in your settings.
  • Delete it — delete individual tickets from the dashboard, or email support@supportshot.com to close your account and remove everything.
  • Object or restrict — email support@supportshot.com and tell us what you want stopped.
  • Complain — if you are in the EEA or UK you may complain to your local data protection authority. We would rather hear from you first.

We answer requests within 30 days and do not charge for them.

If you filed a report on someone else’s website

The website that showed you the SupportShot widget decides what happens to your report; ask them first, since they hold the account. You can also email support@supportshot.com with the ticket reference from the confirmation message (for example SS-4F2A9C) or the email address and website you used, and we will locate the report and pass your request to the account owner, or act on it directly where the law requires us to.

Cookies

supportshot.com sets a small number of strictly necessary cookies, for keeping you logged in and for CSRF protection. There are no advertising cookies, no third-party analytics, and no tracking pixels on this site. The widget on your site sets no cookies at all.

Children

SupportShot is a tool for website operators and is not directed at children under 16. We do not knowingly hold account data about children. If a child’s personal data reaches us inside a bug report, tell us and we will delete it.

Changes to this policy

When we change this policy we update the date at the top. If a change materially affects how we handle your data we will email account owners at least 14 days before it takes effect. The terms of service cover the rest of the relationship.

Contact

Privacy questions, data requests, and DPA requests: support@supportshot.com.