Terms of service

These terms govern your use of SupportShot. They are written to be read: plain sentences, no defined-term maze. By creating an account or installing the widget you agree to them.

Last updated: July 28, 2026

1. Who this is between

This agreement is between 2662415 Ontario Inc., a corporation incorporated in Ontario, Canada under corporation number 2662415, whose registered office is at 408 Dundas Street South, Unit 101, Cambridge, Ontario N1R 8H7, Canada (“SupportShot”, “we”, “us”), and the person or company that opens an account (“you”). SupportShot is that company’s product and trading name; the company named here is the party you are contracting with, the party these terms bind, and the party section 17 sends to the courts of Ontario. If you accept these terms for a company, you confirm you are allowed to bind it. Reach us any time at support@supportshot.com.

2. What the service is

SupportShot provides an embeddable widget that lets visitors to your website submit bug reports with an optional annotated screenshot and automatically collected browser diagnostics, plus a hosted dashboard that stores those reports and emails them to the recipients you configure. Reports are stored in your account (the system of record) and delivered by email as a notification.

3. Your account

  • You must give an accurate email address and verify it before enabling a widget.
  • You are responsible for what happens under your account. Keep your credentials safe and tell us at support@supportshot.com if you think they have been compromised. Today a workspace has exactly one account in it, so there is nobody else whose actions this could cover; if we add a way to put more than one person in a workspace, we will say what that changes before it takes effect.
  • You must be at least 16 years old, or the age of digital consent where you live, whichever is higher.
  • One person or company per account, and one workspace per account. Do not share a single login between separate businesses. You cannot add anybody to your workspace today, and there is no invite form to try: every account is given a workspace of its own when it is created and cannot join a second, so there is nobody the feature could work for, and Org settings says “Adding people is not available yet” rather than offering a control that could only fail. It comes back when workspace switching ships. Notification recipients need no account at all, which is how teams route reports to more than one person in the meantime.

4. Your responsibilities to your visitors

You decide to put the widget on your site, so the reports it collects are yours to answer for. You agree that:

  • You will disclose in your own privacy policy that you use SupportShot to collect bug reports, and what that captures — the docs list it precisely so you can copy it.
  • The widget does part of that at the point of collection, and it does not do the rest. Every panel a visitor opens carries a line naming what sending a report attaches — recent console messages, failed network requests, the page address and their browser details — and links to the part of our privacy policy written for the person filing the report. That happens on every install with nothing to configure, so your visitor is not learning about us for the first time from us. It is still not your privacy policy: it does not say what you do with a report once you have it, what your lawful basis is, or how long you keep it. The obligation in the bullet above stays yours.
  • You have a lawful basis for collecting the personal data that reaches us through reports, including anything visible in a screenshot.
  • You will be careful about enabling the widget on pages that display other people’s personal data, health data, payment card data, or government identifiers. Screenshots capture what is on screen.
  • You will keep your project’s allowed origins accurate so reports only come from sites you control.
  • You will respond to your visitors’ privacy requests about their own reports. We will help where we can.
  • Every address you add as a notification recipient is one you are entitled to email — a colleague, a shared inbox, a client who asked for the reports. Not a list you bought, and not somebody who has told you to stop. If a recipient asks to come off, take them off; if they ask us instead, we will remove them and tell you we have.

5. Acceptable use

Do not use SupportShot to:

  • Collect data covertly — hiding the widget or triggering reports without the visitor’s action.
  • Capture screenshots of sites you do not operate or have permission to instrument.
  • Store or transmit malware, illegal content, or content that infringes someone else’s rights.
  • Send email through our notifications to people who did not ask to receive your bug reports.
  • Attack the service: probing for vulnerabilities without permission, circumventing rate limits or plan limits, scraping other tenants’ data, or overwhelming the ingest API deliberately.

Found a security flaw? Report it to support@supportshot.com, or follow the disclosure policy (also published at /.well-known/security.txt). We will not pursue you for a good-faith report that does not access other customers’ data.

6. Plans, limits, and what happens when you exceed them

Plans and their limits are listed on the pricing page: Free (1 project, 50 tickets a month), Pro at $29 a month (10 projects, 1,000 tickets a month), and Business at $99 a month (unlimited projects, 10,000 tickets a month). Ticket limits are counted per account per calendar month in UTC and reset on the first of the month.

Project limits are enforced when you create a project. Ticket limits are not enforced by rejection: reports beyond your monthly allowance are still accepted, stored, and emailed, flagged over limit in your inbox, and the account owner receives an upgrade notice no more than once a day. We do not throw away your visitors’ bug reports over a quota. If an account stays materially over its limit for more than two consecutive months, we may ask you to upgrade and, with at least 14 days’ written notice, move the account to the plan that matches its usage.

Submissions are rate limited two ways, both abuse controls rather than billing limits. Ten per minute per project, which is what stops a stuck script flooding your inbox. And sixty per minute per source IP address, applied to the ingest API before we know which project a report is for, which bounds how much parsing an anonymous caller can make our servers do. A visitor filing a report, retrying it, or opening a second tab is nowhere near either. Reports refused by a rate limit are not stored and are not counted against your plan.

7. Billing

  • Paid plans are billed monthly in advance through Stripe. Prices are in US dollars and exclude tax. Sales tax, VAT or GST/HST is calculated at checkout from the billing address you give and added to the listed price, on the first charge and on every renewal; the total shown before you confirm is what we charge. If you are registered for GST/HST or VAT you can enter your number at checkout and it appears on the invoice.
  • Our GST/HST registration number is 727243511RT0001. It identifies 2662415 Ontario Inc. to the Canada Revenue Agency and it is what your accountant needs in order to claim an input tax credit for the tax we charge you. It appears on the invoice Stripe issues for every charge.
  • Upgrades take effect immediately, prorated by Stripe. Cancellations take effect at the end of the period you have paid for. Plan downgrades take effect when Stripe applies them — if you use the billing portal to switch plans, the change and its proration are handled by Stripe. In either case there is no partial refund of the remaining period beyond the refund policy below.
  • Refunds: email support@supportshot.com within 30 days of a charge and we refund it in full, no reason required.
  • If a payment fails, Stripe retries it on the schedule configured for our account and emails you about it — those messages come from Stripe, not from us. While it is retrying, your plan is unchanged and nothing is restricted. If Stripe stops trying and the subscription ends up unpaid or canceled, the account moves to the Free plan at that point: your data stays, but Free limits apply. There is no fixed number of days on our side.
  • We may change prices with at least 30 days’ notice by email. Existing subscriptions keep the old price until the notice period ends, and you can cancel before then.
  • You can cancel yourself from the billing page at any time.

8. Your data stays yours

Tickets, screenshots, diagnostics, and account content belong to you. You grant us the limited license needed to run the service: to store, process, display, and email that content to the recipients you configure, and to make backups. That is the whole license. We do not use your content to train machine-learning models, and we do not use it to market to your visitors. How we handle it is set out in the privacy policy, which forms part of these terms.

Where the reports you collect contain personal data, you are the controller and we are your processor, and Article 28(3) of the GDPR (and its UK equivalent) requires that relationship to be in writing. It is: our data processing agreement forms part of these terms and applies automatically from the moment you create an account. You do not need to request it or sign anything, and it prevails over these terms wherever the two conflict about our processing of that data. If your procurement process needs a countersigned copy, email support@supportshot.com and we will sign the same document.

9. Availability and support

We aim to keep SupportShot available around the clock, but we do not offer a contractual uptime guarantee on any current plan, and we may take the service down for maintenance. We do not operate a status page or a maintenance notification list, so assume an interruption can happen without notice. The widget is designed to fail quietly: if SupportShot is unreachable, the widget does nothing, your site is unaffected, and nothing about your pages breaks while we are down.

Support is by email at support@supportshot.com. Pro customers get a one-business-day response target and Business customers are answered first; those are targets we work to, not contractual commitments.

10. Suspension, termination, and deletion

  • You can close your account at any time, and you do it yourself: the owner of a workspace deletes it from Org settings in the dashboard, confirming by typing the workspace name. That one action erases the projects, every ticket and both copies of every screenshot filed under them, the recipient lists, the workspace, and the account of every member who has no other workspace. The erasure runs while you wait and finishes before the page comes back — it is not a request we process later, and there is no 30-day window on it. If you cannot reach the account, email support@supportshot.com from the address you signed up with and we will do the same by hand within 30 days.
  • Your subscription is cancelled after that erasure, not before it. The transaction that destroys the workspace also records the cancellation we then owe Stripe, and we place it immediately afterwards — in the ordinary case within the same second, and you are not billed again. That is deliberate: with the old ordering a bad minute at Stripe could stand between you and the deletion of your own data, and could lose the cancellation with it. What the new ordering can do is delay the cancellation, and we would rather give you the bound than the reassurance. A cancellation that does not go through at once is retried on a schedule, and a subscription that resists it is caught at the latest by its own next renewal, so at worst one further billing period may be charged after the workspace is gone. Any such charge is refundable on request at support@supportshot.com.
  • One honest qualification on that. Erasure is immediate and complete in the live systems, but the licence in section 8 lets us keep backups, and a backup taken before you pressed the button still contains what it contained when it was taken. Those copies are not readable by the service, are never restored to answer a support request, and are not kept beyond a fixed limit; if we ever restore one, we re-run the erasure for everything erased since it was taken. The privacy policy says how long that leaves them.
  • We may suspend or terminate an account that breaches these terms, particularly section 5. Except where the breach is serious or unlawful, we will contact you first and give you a chance to fix it.
  • We may discontinue the service with at least 60 days’ notice. In that case we refund any prepaid, unused fees and give you the notice period to export your data. You do not have to ask us for it: each project’s settings page in the dashboard has an Export tickets section that downloads every report that project has received, as JSON or as CSV. That export is per project rather than one file for the whole workspace, and it covers reports rather than your account, workspace, project-settings or recipient-list records. If you want any of the rest, email support@supportshot.com during the notice period and we will get it to you before the service goes away.
  • Sections 8, 11, 13, 14, 15, 17, and 18 survive termination, as does the data processing agreement for as long as we hold any personal data you were the controller of.

11. Our intellectual property

SupportShot, its widget, its dashboard, and its name and branding are ours. While your subscription is active you have a non-exclusive, non-transferable license to embed and use the widget on websites you operate. You may not copy, reverse-engineer, resell, or white-label the service without our written agreement. The one thing you do not need our agreement for is the attribution: the widget shows a small “Powered by SupportShot” line at the foot of its panel, it is on by default, and there is a switch for it in each project’s appearance settings. Turning it off is your decision and costs you nothing. Feedback you send us we may use freely, with no obligation to you.

12. Third-party services

We use Stripe for payments, Resend for email delivery, Cloudflare, Inc. as the authoritative DNS for supportshot.com (DNS only — it does not sit in the path of your requests, which reach our servers directly), and OVH Hosting Inc. (OVHcloud) for the dedicated servers in Beauharnois, Quebec, Canada that run the application, the database and screenshot storage. Each is named, with what it processes, in the subprocessor table, and the notice and objection rights that apply when that list changes are in the data processing agreement. Their availability and terms are outside our control, and we are not liable for their failures beyond using reasonable care in choosing and configuring them.

13. Disclaimers

SupportShot is provided “as is”. We do not warrant that it will be uninterrupted, error-free, or that every screenshot will render perfectly — browsers and pages vary, and capture can fail. We do not warrant that the diagnostics attached to a report are complete, and you should not rely on them as the sole record of an incident. To the extent the law allows, we disclaim implied warranties of merchantability, fitness for a particular purpose, and non-infringement.

14. Limitation of liability

Neither party is liable for indirect, incidental, special, or consequential damages, or for lost profits, revenue, or goodwill. Our total liability arising out of or relating to the service in any 12-month period is limited to the greater of the amount you paid us in the 12 months before the claim, or US$100. Nothing here limits liability for fraud, willful misconduct, death or personal injury caused by negligence, or anything else that cannot be limited by law.

15. Indemnity

You will defend and indemnify us against third-party claims arising from your use of the service in breach of these terms or of the law — for example, a claim by one of your visitors that you collected their data unlawfully. We will tell you promptly about any such claim and let you control the defense, and we will not settle it without your consent.

16. Changes to these terms

We may update these terms. If a change materially affects your rights we will email account owners at least 14 days before it takes effect; continuing to use SupportShot after that means you accept the new terms. If you do not, cancel before the change takes effect and we will refund any prepaid, unused fees. The date at the top always reflects the current version.

17. Governing law and disputes

The party bound by this section is 2662415 Ontario Inc., identified in section 1.

These terms are governed by the laws of the Province of Ontario, Canada, and the federal laws of Canada that apply there, without regard to conflict-of-laws rules. The courts of Ontario have exclusive jurisdiction, except that either party may seek injunctive relief anywhere it is needed. If you are a consumer, this does not remove mandatory protections or courts available to you where you live. Before filing anything, email support@supportshot.com — most disputes are a misunderstanding that a reply can fix.

18. The rest

  • These terms and the privacy policy are the entire agreement between us about the service, and replace anything said earlier.
  • If a clause is unenforceable, the rest stays in force and that clause is narrowed to what is enforceable.
  • Not enforcing a right once does not waive it.
  • You may not assign this agreement without our consent; we may assign it as part of a merger or sale of the business, with notice to you.
  • Neither party is liable for delays caused by events genuinely beyond its control.

19. Contact

Questions about these terms, or anything else: support@supportshot.com.

Notices in writing go to 2662415 Ontario Inc., 408 Dundas Street South, Unit 101, Cambridge, Ontario N1R 8H7, Canada. A notice we send you goes by email to the address on the account of every owner of your workspace — today that is the one account the workspace has — which is why section 3 asks you to keep that address accurate and verified. Where a clause above gives a notice period, we send no later than that period before the change takes effect. A workspace with no owner at all has no address we can send to, and we cannot reach it: if you ever change who owns your workspace, make sure somebody still does.