Privacy Policy
Effective: August 29, 2026 · Last updated: August 29, 2026
Testimoni is operated by Neha Singh, doing business as Testimoni ("we", "us", "the Service"). This Privacy Policy explains what personal information we collect, why we collect it, how we use it, and the rights you have. By using testimoni.io and its subdomains, you agree to this policy.
Who this policy covers
Two groups of people interact with Testimoni:
- Workspace owners — anyone who signs up for a Testimoni account to collect testimonials.
- Testimonial submitters — customers of a workspace owner who fill out a collection form.
Different rules apply to each group. Both are covered below.
What we collect from workspace owners
- Account data: name, email address, password hash (via Supabase Auth), avatar URL if you sign in with Google, and the workspace name / slug you choose.
- Billing data: if you upgrade to Pro, our payment processor (Razorpay) collects your billing address, card details, and transaction history. We never see or store your card details on our servers — we only receive a token that identifies your subscription.
- Usage data: which pages of the dashboard you visit, when you approve or reject testimonials, and basic event timestamps. We use this to improve the product; it is never sold.
- Support conversations: emails or contact-form submissions you send to us at hello@testimoni.io.
What we collect from testimonial submitters
When a customer of a Testimoni workspace fills out a collection form, we collect and store:
- Their name (required).
- Their email address (optional).
- Their testimonial content, star rating, and any optional job title.
- Any images or videos they attach (Pro plans).
- The submission timestamp.
This data belongs to the workspace owner who runs that form — they are the data controller. Testimoni acts as a data processor on their behalf. If you submitted a testimonial and want it removed, contact the workspace directly first; contact us at hello@testimoni.io if the workspace does not respond.
How we use data
- To provide the Service (host your account, render widgets, deliver testimonials).
- To process payments and prevent fraud.
- To send transactional emails (verification links, receipts, security alerts).
- To improve product usability and diagnose bugs.
- To respond to your support requests.
We do not sell personal data, and we do not use it for advertising.
Third parties we share data with
Testimoni is built on top of these providers. By using Testimoni, you also agree to their privacy practices:
- Vercel — website hosting and CDN. vercel.com/legal/privacy-policy
- Supabase — authentication and Postgres database. supabase.com/privacy
- Razorpay — payment processing (INR and international cards). razorpay.com/privacy
- Google — optional sign-in method (Google OAuth). policies.google.com/privacy
- Resend — transactional email delivery (verification emails, receipts, security alerts). resend.com/legal/privacy-policy
- ImprovMX — inbound mail forwarding for our support address to the operators. improvmx.com/privacy
We share only the minimum data each provider needs to perform its role.
Data location and retention
Data is stored on Supabase and Vercel in the regions configured for this project. Contact hello@testimoni.io if you need the current region. We keep account data for as long as your account is active. If you delete your account, we delete your workspace and its testimonials within 30 days. Billing records may be retained for up to 7 years to comply with tax and financial regulations.
Cookies and local storage
We use essential cookies to keep you signed in and store your preferred pricing currency (USD/INR). We do not use tracking cookies for advertising. Any analytics we add later will be privacy-respecting and disclosed here.
Your rights
You can, at any time:
- Access the data we have about you (email us).
- Correct inaccurate data (via your dashboard or by emailing us).
- Delete your account and all associated workspace data.
- Export a copy of your testimonials as CSV or JSON (email support).
- Opt out of non-essential communications.
GDPR (EU / UK) and DPDP (India) rights are honoured on request.
Security
We use industry-standard security controls: HTTPS everywhere, hashed passwords (via Supabase Auth), server-side session tokens, HTTPS-only cookies, and encrypted database backups. No system is 100% secure, but we treat security failures seriously and will notify affected users within 72 hours of a confirmed breach.
Children
Testimoni is not intended for people under 16. We do not knowingly collect data from children. If you believe a child has submitted data through our forms, email hello@testimoni.io and we will remove it.
Changes to this policy
We may update this policy as the product changes. Material changes will be announced via email or an in-app banner at least 14 days before taking effect. The "Last updated" date at the top of this page always reflects the current version.
Contact
For privacy questions, data-access requests, or complaints, email hello@testimoni.io. We respond within 5 business days.
See also: Terms of Service.