HeyRetro legal
Privacy Policy
This policy explains how HeyRetro handles personal data for accounts, teams, retrospective boards, guest participation, billing, integrations, transactional email, and support.
1. Who we are
HeyRetro is a web application for running real-time retrospective boards, surveys, voting, timers, team workspaces, action items, and related collaboration workflows.
This Privacy Policy explains how HeyRetro collects, uses, shares, and protects personal data when you visit heyretro.io, create an account, join a board, use a team workspace, pay for a subscription, contact support, or use an integration.
For privacy questions or requests, contact [email protected]. If a paid plan, written order, or account notice identifies a specific legal operator for HeyRetro, that operator is responsible for the account covered by that notice.
2. Information we collect
Account and authentication information
- Name, email address, password authentication data, email verification status, profile image or avatar details, account settings, and current team or organization membership.
- Security settings such as two-factor authentication status and recovery data needed to protect your account.
- Google OAuth, enterprise SSO, or other authentication identifiers if you choose to sign in through an external identity provider.
Team, organization, and invitation information
- Team names, organization names, member roles, organization domains, pending invitations, invited email addresses, and the user who sent an invitation.
- Enterprise SSO connection status, setup events, provider identifiers, and organization onboarding information when an organization enables SSO.
- Microsoft Teams tenant, user, tab, roster, or channel context when you install or use HeyRetro inside Microsoft Teams.
Retro board and collaboration content
- Board names, templates, groups, columns, cards, comments or card text, reactions, upvotes, votes, survey options, action items, timers, phase changes, finished status, and board settings.
- Guest participant names, guest tokens, and board participation records when a guest joins a shared board link.
- Anonymous survey settings and displayed results. Anonymous modes limit what is shown to participants, but technical records may still be processed to operate voting, prevent duplicate votes, and maintain the board.
Billing and subscription information
- Plan selection, trial status, subscription status, Stripe customer and subscription identifiers, payment method metadata such as card brand and last four digits when provided by Stripe, and billing events.
- HeyRetro does not store full credit card numbers. Payment processing is handled by Stripe.
Technical, device, and usage information
- IP address, user agent, session identifiers, CSRF tokens, browser and device information, request logs, security events, error reports, performance information, and approximate usage activity.
- Cookies and similar technologies needed for login sessions, security, user preferences, fraud prevention, and service operation. HeyRetro does not use advertising cookies by default.
Communications
- Messages you send to support, feedback, account requests, abuse reports, and related communications.
- Transactional email delivery metadata for account verification, password reset, team invitations, security notices, billing notices, and service-related notifications.
3. How we use information
- Provide, operate, maintain, and improve HeyRetro.
- Create and secure accounts, verify email addresses, authenticate users, support two-factor authentication, and enable SSO.
- Create teams, organizations, retro boards, guest sessions, invitations, surveys, votes, timers, and action items.
- Send transactional email such as verification messages, password reset links, team invitations, security notices, billing notices, and product-critical account notifications.
- Process subscriptions, trials, upgrades, downgrades, cancellations, invoices, fraud checks, and payment events through Stripe.
- Provide support, respond to requests, investigate errors, prevent abuse, enforce the Terms of Service, and protect users and the service.
- Comply with legal, tax, accounting, security, and regulatory obligations.
4. Legal bases where GDPR or similar laws apply
Where privacy laws require a legal basis for processing, we rely on the following bases depending on the context:
- Contract: to provide HeyRetro, manage accounts, operate boards, process subscriptions, and deliver requested services.
- Legitimate interests: to secure the service, prevent abuse, troubleshoot issues, improve the product, manage transactional email delivery, and communicate about service-related matters.
- Consent: where we ask for optional permissions, optional integrations, or future marketing communications.
- Legal obligation: to keep records required for tax, accounting, compliance, fraud prevention, and legal requests.
5. How we share information
We do not sell personal data. We share information only when needed to operate HeyRetro, comply with law, or protect the service.
- Hosting, infrastructure, CDN, security, and deployment providers that help run heyretro.io.
- Email providers, including Amazon SES, for transactional email delivery and provider-level bounce, complaint, and suppression handling.
- Stripe for checkout, billing, subscription management, invoices, tax-related payment records, and payment method processing.
- Authentication and integration providers such as Google, Microsoft Teams, and enterprise SSO providers when you choose to connect or use those integrations.
- Monitoring, logging, and error-reporting providers that help detect outages, exceptions, and abuse.
- Professional advisors, authorities, or other parties where required by law, legal process, security investigation, or to protect rights, users, and the service.
- A successor organization if HeyRetro is involved in a merger, acquisition, financing, reorganization, or sale of assets, subject to appropriate confidentiality and continuity protections.
6. Email practices
HeyRetro uses email for transactional and service-related purposes. Examples include account verification, password reset, team invitations, security notices, billing notices, and important account or product notifications.
HeyRetro does not use imported, purchased, rented, or scraped recipient lists. Team invitations should only be sent to people the sender has a legitimate reason to invite to a workspace or board.
Our email infrastructure may use bounce, complaint, and suppression information to protect deliverability and avoid sending further mail to addresses that reject or complain about messages.
7. Cookies and local storage
- Session cookies keep you signed in and help protect requests against cross-site request forgery.
- Preference storage may remember settings such as appearance mode.
- Security and infrastructure providers may set cookies or process request metadata to detect abuse and protect the service.
- Payment, authentication, and integration providers may use their own cookies or storage when you interact with their hosted flows.
8. Data retention
We keep personal data for as long as needed to provide HeyRetro, maintain security, resolve disputes, enforce agreements, comply with legal obligations, and support legitimate business needs.
- Account, team, organization, board, and collaboration data is generally retained while the account, team, organization, or board remains active or until it is deleted.
- Billing and transaction records may be retained for tax, accounting, fraud prevention, and compliance purposes after an account is closed.
- Logs, session records, error reports, and security records are retained for limited operational periods unless they are needed to investigate abuse, security incidents, or legal issues.
- Support communications may be retained to resolve current and future requests, document decisions, and improve support quality.
9. Security
We use technical and organizational safeguards designed to protect personal data, including TLS for data in transit, access controls, account security features, authentication controls, and infrastructure protections.
No online service can guarantee absolute security. You are responsible for maintaining the confidentiality of your account credentials, using strong passwords, enabling two-factor authentication where appropriate, and limiting board links and invitations to intended recipients.
10. Your choices and rights
Depending on where you live, you may have rights to access, correct, delete, export, restrict, or object to certain processing of your personal data. You may also have the right to withdraw consent where processing is based on consent and to lodge a complaint with a data protection authority.
You can update some account information in the product. For other privacy requests, contact [email protected]. We may need to verify your identity or authority before fulfilling a request.
11. International processing
HeyRetro and its providers may process information in countries other than your own. When required, we rely on appropriate safeguards for international transfers, such as contractual protections or provider compliance mechanisms.
12. Children
HeyRetro is not directed to children under 16. Do not use HeyRetro if you are under 16, and do not submit personal data about children unless you have the authority and legal basis to do so.
13. Changes to this policy
We may update this Privacy Policy as HeyRetro changes or as legal, operational, or security requirements evolve. If changes are material, we will take reasonable steps to notify users through the service, by email, or by another appropriate method.
14. Contact
For privacy questions, data requests, security concerns, or abuse reports, contact [email protected].