Legal
Privacy Policy
Effective date: 27 September 2026
1. Who We Are
Featurely (“we”, “us”, “our”) operates the Featurely platform (the “Service”). For the purposes of the General Data Protection Regulation (“GDPR”) we are the data controller. Questions about this policy can be sent to support@featurely.no .
2. Data We Collect
We collect the following categories of personal data:
- Account data — name, email address, and authentication credentials when you create an account.
- Usage data — pages visited, features used, timestamps, and error reports generated by your applications.
- Device & technical data — IP address, browser type, operating system, and user-agent string.
- Analytics event data — anonymised or pseudonymous events sent by the Featurely SDK when you enable analytics.
- Payment data — billing name, email, and payment method metadata processed by our payment processor (Stripe). We never store full card numbers.
- Communications — emails you send us for support or privacy requests.
3. Legal Bases for Processing (GDPR Art. 6)
We process personal data under the following legal bases:
- Contract (Art. 6(1)(b)) — to create and manage your account, provide the Service, and process payments.
- Legitimate interests (Art. 6(1)(f)) — for security monitoring, fraud prevention, abuse detection, and improving the Service. We balance these interests against your rights.
- Consent (Art. 6(1)(a)) — for optional analytics cookies. You may withdraw consent at any time via the cookie banner.
- Legal obligation (Art. 6(1)(c)) — to comply with tax, accounting, or law enforcement requirements.
4. How We Use Your Data
- Provide, maintain, and improve the Service.
- Authenticate you and manage your session.
- Process payments and manage subscriptions.
- Send transactional emails (error alerts, account notifications).
- Detect and prevent fraud, abuse, and security incidents.
- Comply with legal obligations.
5. Data Sharing and Disclosure
We do not sell or share your personal data with advertisers. We share data only with the following categories of recipients:
- Cloud hosting & infrastructure — to host, store, and deliver the Service (e.g. Vercel, Neon).
- Payment processors — Stripe processes payment information under its own privacy policy.
- Email delivery — transactional emails are sent via Resend.
- Analytics providers — only if you consent to analytics cookies; no personally identifiable data is sent.
- Video hosting — if you accept optional cookies or press play on the marketing video, the player is loaded from YouTube (Google). YouTube processes that request under its own privacy policy. Until then, the page shows a still image hosted by us.
- Authorities — when required by law, court order, or to protect the rights and safety of others.
All processors are bound by data processing agreements and are required to handle data in accordance with GDPR.
6. Data Retention
We retain personal data for the following periods:
- Account data — kept while your account is active and deleted within 30 days of account closure.
- Authentication logs — 90 days.
- Analytics event data — 14 months.
- Error reports — until you delete them or close your account.
- Support emails — 24 months.
- Payment records — as required by applicable tax law (typically 5–7 years).
- Database backups — rolling 30-day window.
7. Cookies and Tracking
We use the following cookies:
| Name | Type | Purpose | Duration |
|---|---|---|---|
| featurely-active-theme | Functional | Stores your chosen UI theme to prevent a flash of unstyled content on page load. Set only when a theme preference is stored. | 365 days |
| featurely-cookie-consent | Essential | Records your cookie consent choice so the banner is not shown again. Accepting optional cookies also allows the homepage product video to load from YouTube. | 180 days |
| Firebase Auth cookies | Essential | Authentication session management. Set by Firebase/Google. | Session / 14 days |
Analytics cookies are only set if you click “Accept all cookies”. You can change your preferences at any time by clearing site data in your browser settings.
The homepage product video is a still image on our site (/hero/video-thumb-*.jpg) until you accept optional cookies or press play. Choosing “Essential cookies only” does not contact YouTube, Google, or DoubleClick. Pressing play, or accepting optional cookies, loads the player from YouTube’s privacy-enhanced domain (youtube-nocookie.com). YouTube may then set its own cookies, including VISITOR_INFO1_LIVE, and contact Google advertising domains. A press on play applies to that visit and does not by itself turn on analytics cookies. When the video loads because you already accepted optional cookies, it stays muted.
We do not place our own advertising pixels or marketing scripts. Blog and news articles cannot embed third-party players; their HTML is sanitized and discards iframe tags.
8. Children’s Data
Our Service is not directed to children under 13 (or under 16 in the EEA/UK where applicable). We do not knowingly collect personal data from children. If you believe a child has provided us with personal data, please contact support@featurely.no and we will delete it promptly.
9. Your Rights Under GDPR
If you are located in the EEA or UK, you have the following rights under GDPR. To exercise any of these, email support@featurely.no from the email address associated with your account. We may need to verify your identity before responding. We will respond within 30 days.
- Right of access (Art. 15) — Request a copy of the personal data we hold about you. Include “Access Request” in the subject line.
- Right to rectification (Art. 16) — Ask us to correct inaccurate or incomplete data.
- Right to erasure (Art. 17) — Request deletion of your personal data. Include “Erasure Request” in the subject line. We will delete or anonymise your data unless we are required to retain it for legal obligations.
- Right to restriction (Art. 18) — Ask us to pause processing while a dispute is resolved.
- Right to data portability (Art. 20) — Receive a copy of your personal data in a structured, commonly used, machine-readable format (e.g. JSON or CSV) and transmit it to another controller. Include “Data Portability Request” in the subject line.
- Right to object (Art. 21) — Object to processing based on legitimate interests.
- Right to withdraw consent — Where processing is based on consent (e.g. analytics cookies), you may withdraw at any time without affecting the lawfulness of prior processing.
- Right to lodge a complaint — You have the right to lodge a complaint with your local supervisory authority (e.g. Datatilsynet in Norway).
10. California Privacy Notice (CCPA/CPRA)
If you are a California resident, you have additional rights under the California Consumer Privacy Act (CCPA) and California Privacy Rights Act (CPRA).
Categories of personal information collected (last 12 months)
- Identifiers (name, email address, account ID)
- Internet or network activity (usage data, error logs)
- Commercial information (subscription and payment records)
- Inferences drawn from usage to improve the Service
Sources
Directly from you when you create an account or use the Service; automatically from your device and browser.
Business purposes
Providing and improving the Service, processing payments, fraud prevention, legal compliance.
Third parties disclosed to
Cloud infrastructure, payment processors (Stripe), and email delivery providers — see Section 5.
Sale or sharing of personal information
We do not sell or share personal information as defined under CCPA/CPRA.
Your California rights
- Right to know/access — request what personal information we have collected, used, and disclosed.
- Right to delete — request deletion of your personal information.
- Right to correct — request correction of inaccurate personal information.
- Right to opt-out of sale/sharing — not applicable as we do not sell or share PI.
- Right to limit use of sensitive PI — not applicable as we do not process sensitive PI for purposes beyond the Service.
- Right to non-discrimination — we will not discriminate against you for exercising these rights.
To submit a request, email support@featurely.no with “California Privacy Request” in the subject. We will verify your identity and respond within 45 days.
11. International Data Transfers
We are based in Norway (EEA). Some service providers (e.g. Vercel, Stripe) process data in the United States. Where data is transferred outside the EEA, we rely on Standard Contractual Clauses (SCCs) or the provider’s certification under an adequacy framework.
12. Security
We implement technical and organisational measures to protect your personal data, including TLS encryption in transit, access controls, and regular security reviews. No system is completely secure; if you discover a vulnerability, please contact support@featurely.no .
13. Changes to This Policy
We may update this policy from time to time. Material changes will be communicated via the Service or by email. The “Effective date” at the top of this page shows when it was last revised. Continued use of the Service after a change constitutes acceptance of the updated policy.
14. Contact
For any privacy-related questions or requests, contact us at support@featurely.no .