SnitchHQ

Privacy Policy

Last updated: July 17, 2026

SnitchHQ is a QR-code issue-reporting service for rooms, operated from the United States. This policy explains what we collect, why, and what your choices are — in plain language, because that's how we'd want it explained to us.

If you scan a QR code to report an issue

You don't need an account, and we collect as little as possible:

  • The report itself — which room, which issue button you tapped, and any note or photo you chose to add. Photos are automatically stripped of hidden metadata (like GPS location) before storage.
  • Your email, only if you opt into "notify me when it's fixed." It's used for that one notification and visible to the organization that owns the room.
  • A one-way hash of your IP address, used solely to rate-limit spam. We do not store your actual IP with reports, and the hash can't be reversed into it.

The scan page is 100% tracker-free: no cookies, no analytics, no third-party beacons of any kind. Reports belong to the organization whose room you reported — contact them for questions about a specific report.

If you have a SnitchHQ account (admins & teams)

  • Account data: your email address, role, and organization membership. Sign-in is passwordless (email links), so we never store a password.
  • Workspace content: rooms, groups, button sets, alert rules, branding (logo, colors), teammate invites, and the reports your rooms receive.
  • Session cookies to keep you signed in. No advertising or cross-site tracking cookies, ever.

How we use data

To run the product: deliver alerts (email, Slack, or Teams webhooks you configure), show dashboards and analytics to your team, and prevent abuse. We don't sell data, rent it, or use it for advertising. We look at customer content only when needed to support you or keep the service running.

Website & product analytics

On our marketing website and the signed-in dashboard, we use Vercel's privacy-friendly, cookielessanalytics and performance monitoring to count page views and measure page speed. It sets no cookies, builds no cross-site or advertising profiles, and doesn't identify you individually.

We deliberately do not load any of this on the public QR scan pages — the flow anonymous reporters use stays entirely tracker-free.

How we protect your data

  • Tenant isolation: each organization's data is separated at the database level with row-level security, enforced by the database itself — not just our application code — so one customer can never read or change another's rooms, reports, or team.
  • Role-based access: within a workspace, what each teammate can see and do is governed by their role (owner, admin, technician, viewer), enforced on the server and in the database.
  • Passwordless sign-in: we authenticate with one-time email links and never store passwords, so there's no password to leak or reuse.
  • Encryption & minimization: traffic is encrypted in transit (HTTPS); report photos are kept in private storage and stripped of location metadata; reporter IP addresses are only ever stored as irreversible one-way hashes.

Who processes data for us

SnitchHQ runs on a small set of infrastructure providers:

  • Vercel — application hosting and cookieless website analytics
  • Supabase — database, authentication, and file storage (hosted in the US)
  • Resend — transactional email delivery

If you connect Slack or Microsoft Teams alerts, report contents are sent to the webhook URLs your organization configures.

Retention & deletion

Your workspace data is kept while your account is active. Organization owners can delete rooms (which permanently deletes their reports) at any time, and can request full organization deletion — we remove all associated data, including photos. Reporters who left an email can ask the room's organization, or us, to remove it.

Your rights

You can request a copy, correction, or deletion of your personal data by emailing us. Depending on where you live (GDPR, CCPA, and similar laws), you may have additional rights — we honor reasonable requests regardless of geography.

Changes & contact

If this policy changes materially, we'll note it here with a new date. Questions or requests: [email protected].