Privacy Policy
Last updated: August 11, 2026
1. Introduction
Welcome to Vorbra ("the Service," "the Platform," "we," "us," or "our"), accessible at vorbra.com. This Privacy Policy explains how we collect, use, disclose, retain, and protect the personal information of all individuals who interact with our Service, including but not limited to business users who create accounts ("Account Holders"), individuals who submit testimonials or reviews through the platform ("Reviewers"), and visitors to our website ("Visitors").
Vorbra is a software-as-a-service platform that enables businesses to collect, manage, and display customer testimonials and reviews on their websites through embeddable widgets. This Privacy Policy applies to all information collected through our website, our application programming interfaces (APIs), our embeddable widget scripts, and any related services, sales, marketing, or events (collectively, the "Service").
We are committed to protecting your privacy and handling your personal information in an open and transparent manner. We comply with applicable data protection laws including, but not limited to, the General Data Protection Regulation (GDPR), the California Consumer Privacy Act (CCPA) as amended by the California Privacy Rights Act (CPRA), the UK Data Protection Act 2018, the Canadian Personal Information Protection and Electronic Documents Act (PIPEDA), and other applicable privacy and data protection legislation worldwide.
By accessing or using the Service, you acknowledge that you have read, understood, and agree to the collection and use of information in accordance with this Privacy Policy. If you do not agree with this Privacy Policy, please do not access or use the Service. This Privacy Policy should be read in conjunction with our Terms of Service, which govern your use of the platform.
If you have any questions or concerns about this Privacy Policy or our data practices, please contact us using the information provided in Section 15 of this document.
2. Information We Collect
We collect several types of information from and about users of our Service. The categories of information we collect depend on how you interact with us and the Service, and we have organized them below for clarity.
2.1 Information You Provide Directly
When you register for an account, submit a testimonial, or otherwise interact with our Service, you may provide us with the following types of personal information:
- Account Registration Information: When you create an account as a business user, we collect your email address and password. Passwords are securely hashed and are never stored in plain text.
- Profile Information: Any additional profile information you choose to provide, such as your name, company name, business website URL, and profile picture.
- Space Configuration Data: Information you provide when creating testimonial collection spaces, including space names, descriptions, custom slugs, widget theme preferences, and branding settings.
- Testimonial Submission Data: When reviewers submit testimonials through our platform, we collect the reviewer's name, email address, title or role, star ratings, written review content, and any audio or video recordings they choose to submit.
- Audio and Video Recordings: Our Service allows reviewers to submit audio and video testimonials. These recordings are stored on our servers and may contain the reviewer's voice, likeness, and any information they choose to share in their recording.
- Payment Information: When you subscribe to a paid plan, payment information such as credit card numbers, billing addresses, and related financial data is collected and processed by our third-party payment processor, Stripe. We do not directly store your full credit card number or payment card details on our servers.
- Communications: When you contact us for support, send us feedback, or otherwise communicate with us, we collect the content of those communications along with your name and email address.
2.2 Information Collected Automatically
When you access or use our Service, we automatically collect certain information about your device, browsing activity, and usage patterns. This information is collected through cookies, log files, and similar tracking technologies:
- Device Information: We collect information about the device you use to access the Service, including hardware model, operating system and version, browser type and version, screen resolution, device identifiers, and language preferences.
- Log Data: Our servers automatically record information ("log data") created by your use of the Service. Log data may include your Internet Protocol (IP) address, browser type, the referring/exit pages, operating system, date and time stamps, clickstream data, and other statistics.
- Usage Information: We collect information about how you interact with the Service, including the pages or features you access, the time spent on pages, the links you click, the actions you take (such as creating spaces, approving testimonials, or configuring widgets), and other usage statistics.
- Location Information: We may infer your approximate geographic location based on your IP address. We do not collect precise geolocation data unless you explicitly grant permission through your device settings.
2.3 Information Collected Through Our Embeddable Widget
When an Account Holder embeds our testimonial widget on their website using our embed script (embed.js), the widget may collect certain information from visitors to that website:
- Widget Interaction Data: We may collect data about how end-users interact with the embedded widget, such as whether the widget was displayed, testimonials viewed, and interaction events.
- Technical Data: The widget may collect the referring URL (the page on which the widget is embedded), browser type, and device type for the purpose of rendering the widget correctly and collecting analytics.
- No Cross-Site Tracking: Our embed widget does not use third-party tracking cookies and does not track users across websites. The widget makes API calls to our servers only to fetch approved testimonial data for display purposes.
2.4 Information from Third Parties
We may receive information about you from third-party sources, which we may combine with other information we have about you:
- Authentication Providers: If we offer social login options in the future (such as Google or GitHub authentication), we may receive your name, email address, and profile picture from those providers, subject to your privacy settings with those services.
- Payment Processors: Our payment processor, Stripe, may share transaction-related information with us, such as payment confirmation, subscription status, and billing address, but not your full payment card details.
- Analytics Providers: We may receive aggregated or de-identified analytics data from third-party analytics services that help us understand how our Service is used.
- Publicly Available Information: We may collect publicly available information about businesses that use our Service to improve our records and provide better support.
2.5 Sensitive Information
We do not intentionally collect sensitive personal information such as racial or ethnic origin, political opinions, religious or philosophical beliefs, trade union membership, genetic data, biometric data for uniquely identifying a natural person, health data, or data concerning a person's sex life or sexual orientation. If you include such information in a testimonial submission, it is provided at your own discretion. We strongly discourage the submission of sensitive personal information through testimonials.
3. How We Use Your Information
We use the information we collect for various purposes related to operating, maintaining, and improving the Service. The specific legal basis for processing your information depends on the type of information and the context in which we collect it.
3.1 To Provide and Maintain the Service
- Create and manage your user account
- Process and store testimonials submitted through the platform
- Display approved testimonials through embedded widgets on third-party websites
- Provide our API for retrieving testimonial data
- Process payments and manage subscriptions
- Deliver the features and functionality you request
- Generate unique public URLs for testimonial collection pages
3.2 To Communicate With You
- Send you service-related notices, including email verification, password resets, security alerts, and account notifications
- Respond to your requests, comments, and questions and provide customer support
- Send you technical notices, updates, and administrative messages
- Notify you of changes to our Terms of Service, Privacy Policy, or other legal documents
- Send you marketing communications (where permitted by law and with your consent where required), which you may opt out of at any time
3.3 To Improve and Develop the Service
- Analyze usage trends and user behavior to improve the Service's functionality, user interface, and user experience
- Conduct research and development to enhance our products and services
- Test new features and functionalities before releasing them to all users
- Debug and fix technical issues, bugs, and errors
- Monitor and analyze the effectiveness of our Service and marketing campaigns
3.4 To Protect and Secure the Service
- Detect, investigate, and prevent fraudulent transactions, abuse, and other illegal activities
- Protect the rights, property, and safety of Vorbra, our users, and the public
- Enforce our Terms of Service and other agreements
- Monitor for and prevent spam, fake testimonials, and platform abuse
- Maintain the security and integrity of our infrastructure, systems, and data
3.5 Legal Bases for Processing (GDPR)
If you are located in the European Economic Area (EEA), United Kingdom, or Switzerland, we process your personal data based on the following legal grounds:
- Contract Performance: Processing necessary to perform our contract with you (e.g., providing the Service, managing your account, processing payments).
- Legitimate Interests: Processing necessary for our legitimate interests, such as improving the Service, preventing fraud, and ensuring security, provided these interests are not overridden by your rights and freedoms.
- Consent: Processing based on your explicit consent, such as when you opt in to receive marketing emails or submit a testimonial.
- Legal Obligation: Processing necessary to comply with applicable laws and regulations, such as tax reporting requirements or responding to lawful government requests.
4. How We Share Your Information
We do not sell your personal information to third parties. We may share your information in the following circumstances and with the following categories of recipients:
4.1 Service Providers and Sub-Processors
We share information with third-party service providers who process data on our behalf to help us operate, maintain, and improve the Service. These providers are contractually obligated to use your information only as directed by us and in accordance with this Privacy Policy. Our current service providers include:
- Supabase (Database and Authentication): We use Supabase as our database and authentication provider. Your account information, testimonial data, and other application data are stored in Supabase's PostgreSQL databases. Supabase implements Row Level Security (RLS) to ensure data isolation between users. Supabase's infrastructure is hosted on Amazon Web Services (AWS). For more information, refer to Supabase's Privacy Policy.
- Stripe (Payment Processing): We use Stripe to process payments for our subscription plans. When you make a payment, your payment information is collected and processed directly by Stripe in accordance with PCI DSS (Payment Card Industry Data Security Standard) requirements. We receive only limited transaction information from Stripe (such as the last four digits of your card, transaction status, and billing address). For more information, refer to Stripe's Privacy Policy.
- Vercel (Hosting and Content Delivery): Our website and application are hosted on Vercel's infrastructure. Vercel may process server logs and request metadata as part of delivering our Service. For more information, refer to Vercel's Privacy Policy.
4.2 Display of Testimonials
The core function of our Service involves the public display of approved testimonials. When an Account Holder approves a testimonial, the following information from that testimonial may be publicly displayed through our embeddable widget or API:
- The reviewer's name (as provided during submission)
- The reviewer's title or role (if provided)
- The star rating
- The written review content
- Audio or video recordings (if provided)
Reviewer email addresses are never publicly displayed through our widgets or API. Email addresses are only visible to the Account Holder who manages the space in which the testimonial was submitted.
4.3 Account Holders and Testimonial Data
When a reviewer submits a testimonial to a space managed by an Account Holder, the Account Holder can view the full testimonial submission including the reviewer's name, email address, title, rating, review content, and any audio or video recordings. Account Holders are responsible for their own use of reviewer data in compliance with applicable privacy laws.
4.4 Legal Requirements and Law Enforcement
We may disclose your information if we believe in good faith that such disclosure is necessary to:
- Comply with applicable law, regulation, legal process, or governmental request, including but not limited to subpoenas, court orders, or other compulsory legal demands
- Enforce our Terms of Service or other agreements, including investigation of potential violations
- Detect, prevent, or otherwise address fraud, security, or technical issues
- Protect against harm to the rights, property, or safety of Vorbra, our users, or the public, as required or permitted by law
- Respond to an emergency involving danger of death or serious physical injury to any person
Where legally permitted, we will attempt to notify you before disclosing your information in response to legal process, unless doing so would be prohibited by law or would jeopardize an investigation.
4.5 Business Transfers
If Vorbra is involved in a merger, acquisition, reorganization, bankruptcy, dissolution, sale of all or a portion of its assets, or similar transaction, your personal information may be transferred as part of that transaction. We will notify you (for example, via email and/or a prominent notice on our website) of any such change in ownership or control of your personal information, and any choices you may have regarding your personal information. In such event, the acquiring entity will be subject to the terms of this Privacy Policy with respect to your personal information.
4.6 With Your Consent
We may share your information with third parties when you give us explicit consent to do so. For example, if you authorize a third-party application to access your Vorbra account or data, we will share information in accordance with your authorization.
4.7 Aggregated and De-Identified Data
We may share aggregated or de-identified data that can no longer reasonably be used to identify you. Such data is not considered personal information under applicable law. For example, we may share aggregate statistics about the total number of testimonials collected through our platform or general usage trends.
5. Data Retention
We retain your personal information for as long as necessary to fulfill the purposes for which we collected it, including to satisfy any legal, accounting, or reporting requirements. The specific retention period depends on the type of data and the context of our relationship with you.
5.1 Account Data
We retain your account information for as long as your account is active or as needed to provide you with the Service. If you request deletion of your account, we will delete or anonymize your personal information within 30 days, except where we are required to retain certain information for legal or legitimate business purposes (such as tax reporting, fraud prevention, or dispute resolution). Certain information may persist in encrypted backups for up to 90 days after deletion before being permanently removed.
5.2 Testimonial Data
Testimonials submitted through the platform are retained for as long as the associated space exists and the Account Holder maintains an active account. If a testimonial is rejected by the Account Holder, the testimonial data is retained but not publicly displayed. Account Holders may delete individual testimonials at any time. When a space or account is deleted, all associated testimonials (including approved, pending, and rejected testimonials, as well as any audio or video recordings) are permanently deleted within 30 days.
5.3 Usage and Log Data
Server logs and usage data are retained for a maximum of 12 months for security monitoring, debugging, and analytics purposes, after which they are automatically purged or anonymized.
5.4 Payment Records
Transaction records and billing information may be retained for up to 7 years as required by applicable tax and financial regulations, even after account deletion.
5.5 Communication Records
Records of support requests, emails, and other communications are retained for up to 3 years after the last communication, or longer if required for ongoing disputes or legal proceedings.
6. Data Security
We take the security of your personal information seriously and implement appropriate technical and organizational measures to protect it against unauthorized access, alteration, disclosure, or destruction. However, no method of transmission over the Internet or method of electronic storage is 100% secure, and we cannot guarantee its absolute security.
6.1 Technical Safeguards
Our security measures include, but are not limited to:
- Encryption in Transit: All data transmitted between your browser and our servers is encrypted using TLS (Transport Layer Security) 1.2 or higher. Our website is served exclusively over HTTPS.
- Encryption at Rest: Data stored in our databases is encrypted at rest using AES-256 encryption through our database provider, Supabase.
- Password Security: User passwords are hashed using industry-standard bcrypt hashing algorithms and are never stored in plain text. We do not have access to your plain-text password.
- Row Level Security (RLS): Our database implements PostgreSQL Row Level Security policies to ensure that users can only access their own data. This provides an additional layer of data isolation at the database level.
- Secure Authentication: We use Supabase Auth for secure session management, including HTTP-only cookies and CSRF protection.
- CORS Protection: Our API endpoints implement Cross-Origin Resource Sharing (CORS) policies to prevent unauthorized cross-origin requests.
- Input Validation and Sanitization: All user inputs are validated and sanitized to prevent common web vulnerabilities such as SQL injection and cross-site scripting (XSS).
6.2 Organizational Safeguards
- Access to personal information is restricted to authorized personnel on a need-to-know basis
- We regularly review and update our security practices and procedures
- We conduct periodic assessments of our data processing activities and security measures
- Our third-party service providers are required to maintain appropriate security measures and are bound by data processing agreements
6.3 Incident Response
In the event of a data breach that poses a risk to your rights and freedoms, we will notify affected users and relevant supervisory authorities within 72 hours of becoming aware of the breach, as required by applicable law. Our notification will include a description of the breach, the types of data affected, the likely consequences, and the measures taken or proposed to address the breach.
6.4 Your Responsibility
You are responsible for maintaining the confidentiality of your account credentials and for restricting access to your account. You should use a strong, unique password and enable any additional security features we offer. You should notify us immediately of any unauthorized access to or use of your account.
7. Your Rights and Choices
Depending on your location and applicable laws, you may have certain rights regarding your personal information. We are committed to honoring these rights and providing you with the tools and processes to exercise them.
7.1 Rights Under the GDPR (EEA, UK, and Switzerland)
If you are located in the European Economic Area, the United Kingdom, or Switzerland, you have the following rights under the General Data Protection Regulation (GDPR) and equivalent local laws:
- Right of Access (Article 15): You have the right to request a copy of the personal data we hold about you. We will provide this information in a commonly used, machine-readable format within 30 days of your request.
- Right to Rectification (Article 16): You have the right to request that we correct any inaccurate or incomplete personal data we hold about you.
- Right to Erasure / Right to be Forgotten (Article 17): You have the right to request the deletion of your personal data in certain circumstances, such as when the data is no longer necessary for the purpose it was collected, when you withdraw your consent, or when the data has been unlawfully processed.
- Right to Restriction of Processing (Article 18): You have the right to request that we restrict the processing of your personal data in certain circumstances, such as when you contest the accuracy of the data or when the processing is unlawful but you oppose deletion.
- Right to Data Portability (Article 20): You have the right to receive your personal data in a structured, commonly used, and machine-readable format and to transmit that data to another controller without hindrance.
- Right to Object (Article 21): You have the right to object to the processing of your personal data based on our legitimate interests. We will cease processing unless we demonstrate compelling legitimate grounds that override your interests, rights, and freedoms.
- Right Not to be Subject to Automated Decision-Making (Article 22): You have the right not to be subject to a decision based solely on automated processing, including profiling, which produces legal effects or similarly significant effects concerning you. Vorbra does not currently engage in automated decision-making of this nature.
- Right to Withdraw Consent: Where we rely on your consent to process your personal data, you have the right to withdraw that consent at any time. Withdrawal of consent does not affect the lawfulness of processing carried out before the withdrawal.
- Right to Lodge a Complaint: You have the right to lodge a complaint with a supervisory authority in the EU member state of your habitual residence, place of work, or place of the alleged infringement if you believe that our processing of your personal data violates the GDPR.
7.2 Rights Under the CCPA/CPRA (California Residents)
If you are a California resident, you have the following rights under the California Consumer Privacy Act (CCPA) as amended by the California Privacy Rights Act (CPRA):
- Right to Know: You have the right to request information about the categories and specific pieces of personal information we have collected about you, the categories of sources from which we collected the information, the business or commercial purposes for which we collected or sold the information, and the categories of third parties with whom we shared the information.
- Right to Delete: You have the right to request the deletion of your personal information, subject to certain exceptions provided by law.
- Right to Correct: You have the right to request that we correct inaccurate personal information that we maintain about you.
- Right to Opt-Out of Sale or Sharing: You have the right to opt out of the "sale" or "sharing" of your personal information, as those terms are defined under the CCPA/CPRA. Vorbra does not sell personal information, and we do not share personal information for cross-context behavioral advertising purposes.
- Right to Limit Use of Sensitive Personal Information: You have the right to limit the use and disclosure of your sensitive personal information. Vorbra does not use sensitive personal information for purposes beyond what is necessary to provide the Service.
- Right to Non-Discrimination: You have the right not to receive discriminatory treatment for exercising your privacy rights. We will not deny you the Service, charge you different prices, provide a different level of quality, or retaliate against you for exercising any of your CCPA/CPRA rights.
Categories of Personal Information Collected (preceding 12 months):
| Category | Examples | Collected |
|---|---|---|
| Identifiers | Name, email address, IP address | Yes |
| Commercial Information | Subscription plan, payment history | Yes |
| Audio/Visual Data | Audio and video testimonial recordings | Yes |
| Internet/Network Activity | Browser type, pages visited, usage data | Yes |
To exercise any of the rights described above, please contact us using the information in Section 15. We will verify your identity before processing your request. We may ask you to provide additional information to help us verify your identity and fulfill your request. We will respond to verifiable consumer requests within 45 days. If we need more time (up to an additional 45 days), we will notify you in writing of the reason and extension period.
California residents may designate an authorized agent to make requests on their behalf. If you use an authorized agent, we may require proof of the agent's written authorization and verify your identity directly.
7.3 Rights Under Other Privacy Laws
If you are a resident of other jurisdictions with comprehensive privacy laws (including but not limited to Virginia, Colorado, Connecticut, Utah, Brazil, Canada, Australia, or other applicable jurisdictions), you may have similar rights to those described above, including rights to access, correct, delete, and port your personal data, as well as the right to opt out of certain processing activities. Please contact us to exercise any rights available to you under your applicable local privacy laws.
7.4 Opt-Out of Marketing Communications
You may opt out of receiving marketing or promotional emails from us by clicking the "unsubscribe" link at the bottom of any marketing email you receive, or by contacting us directly. Please note that even if you opt out of marketing emails, we may still send you transactional or service-related communications, such as account notifications, security alerts, and updates to our Terms of Service or Privacy Policy.
7.5 Account Deletion
You may request deletion of your account at any time by contacting us. Upon account deletion, we will delete or anonymize your personal information in accordance with the retention periods described in Section 5. Please note that deletion of your account will also result in the permanent deletion of all spaces, testimonials (including approved, pending, and rejected testimonials), and associated data, including audio and video recordings.
8. International Data Transfers
Vorbra operates globally, and your personal information may be transferred to, stored, and processed in countries other than the country in which you reside. These countries may have data protection laws that differ from those of your country of residence.
Our primary infrastructure providers, including Supabase (hosted on Amazon Web Services), Stripe, and Vercel, may store and process data in the United States and other countries. When we transfer personal data from the European Economic Area, United Kingdom, or Switzerland to countries that have not been deemed to provide an adequate level of data protection, we implement appropriate safeguards to ensure that your personal information remains protected in accordance with this Privacy Policy and applicable law.
8.1 Transfer Mechanisms
We rely on the following transfer mechanisms to lawfully transfer personal data internationally:
- Standard Contractual Clauses (SCCs): We enter into the European Commission-approved Standard Contractual Clauses with our service providers to ensure adequate protection for personal data transferred outside the EEA.
- UK International Data Transfer Agreement (IDTA): For transfers from the United Kingdom, we rely on the UK IDTA or the UK Addendum to the EU SCCs, as applicable.
- Data Processing Agreements: We maintain data processing agreements with all service providers who process personal data on our behalf, ensuring they are contractually obligated to protect your information.
- Adequacy Decisions: Where available, we may rely on adequacy decisions by the European Commission or other relevant authorities recognizing that a country provides an adequate level of data protection.
8.2 Supplementary Measures
In addition to the transfer mechanisms described above, we implement supplementary technical and organizational measures, such as encryption of data in transit and at rest, access controls, and regular security assessments, to ensure that your personal data is adequately protected regardless of where it is processed.
9. Children's Privacy
Vorbra is not directed to children under the age of 16 (or under the age of 13 in jurisdictions where 13 is the applicable age of consent for data processing, such as the United States under COPPA). We do not knowingly collect, use, or disclose personal information from children under these ages.
Account registration requires users to be at least 18 years of age, or to have the consent and supervision of a parent or legal guardian who agrees to be bound by our Terms of Service and this Privacy Policy.
The testimonial submission forms are publicly accessible and do not require age verification. We rely on Account Holders to implement appropriate measures if their products or services are directed at children. Account Holders should not use Vorbra to collect testimonials from individuals under the age of 16 (or 13 where applicable) without verifiable parental consent.
If we become aware that we have inadvertently collected personal information from a child under the applicable age threshold without appropriate consent, we will take immediate steps to delete such information from our records. If you believe that we may have collected information from a child under the applicable age, please contact us immediately using the information provided in Section 15.
10. Cookies and Tracking Technologies
We use cookies and similar tracking technologies to provide, maintain, and improve the Service. This section explains what these technologies are, how we use them, and what choices you have.
10.1 What Are Cookies
Cookies are small text files that are placed on your device (computer, tablet, or mobile phone) when you visit a website. Cookies are widely used to make websites work, to make them work more efficiently, and to provide reporting information to website owners. Cookies set by the website owner are called "first-party cookies." Cookies set by parties other than the website owner are called "third-party cookies."
10.2 How We Use Cookies
We use the following types of cookies:
- Strictly Necessary Cookies: These cookies are essential for the Service to function and cannot be switched off in our systems. They are usually only set in response to actions made by you which amount to a request for services, such as setting your privacy preferences, logging in, or filling in forms. These include authentication session cookies managed by Supabase Auth, which are required to keep you logged in and maintain your session security. Without these cookies, the Service cannot function properly.
- Functional Cookies: These cookies enable the Service to provide enhanced functionality and personalization. They may be set by us or by third-party providers whose services we have added to our pages. If you do not allow these cookies, some or all of these features may not function properly. Examples include cookies that remember your widget theme preferences or dashboard display settings.
- Analytics Cookies: These cookies allow us to count visits and traffic sources so we can measure and improve the performance of the Service. They help us understand which pages are the most and least popular and how visitors navigate the site. All information these cookies collect is aggregated and therefore anonymous. If you do not allow these cookies, we will not know when you have visited our site.
10.3 Session Cookies vs. Persistent Cookies
Session cookies are temporary cookies that expire when you close your browser. Persistent cookies remain on your device for a set period of time specified in the cookie or until you delete them. Our authentication cookies are persistent cookies that expire after the session duration configured in our authentication provider (typically 7 days of inactivity).
10.4 Local Storage
In addition to cookies, we may use browser local storage and session storage for similar purposes, such as storing authentication tokens and user preferences. These technologies function similarly to cookies but are stored differently in your browser.
10.5 Cookies in Our Embeddable Widget
Our embeddable widget script (embed.js) does not set any cookies on the websites where it is embedded. The widget makes API requests to our servers to fetch testimonial data but does not use cookies or similar tracking technologies to track visitors on third-party websites. The widget does not perform cross-site tracking.
10.6 Managing Cookies
Most web browsers allow you to manage your cookie preferences through their settings. You can set your browser to refuse cookies, delete cookies, or alert you when cookies are being sent. Please note that if you disable or refuse cookies, some parts of the Service may become inaccessible or may not function properly. The methods for managing cookies vary by browser, and you should consult your browser's help documentation for instructions.
You can typically find cookie management options in the "Settings," "Preferences," or "Privacy" sections of your browser. Links to cookie management instructions for common browsers:
10.7 Do Not Track Signals
Some browsers transmit "Do Not Track" (DNT) signals to websites. Because there is no common understanding of how to interpret DNT signals, we do not currently respond to DNT signals. We will continue to monitor developments around DNT browser technology and the implementation of standards.
11. Third-Party Links and Services
The Service may contain links to third-party websites, services, or applications that are not operated by us. These links may appear in testimonials, in Account Holder websites where our widget is embedded, or in our own website content.
We have no control over, and assume no responsibility for, the content, privacy policies, or practices of any third-party websites or services. We strongly advise you to review the privacy policy and terms of service of every website or service you visit or interact with.
Our embeddable widget is designed to be placed on third-party websites operated by our Account Holders. When you interact with our widget on a third-party website, you are subject to both this Privacy Policy (with respect to data processed by Vorbra through the widget) and the privacy policy of the website on which the widget is embedded. We are not responsible for the data practices of websites that embed our widget beyond the data that flows through our widget and API.
We do not endorse, warrant, or guarantee the products or services offered through any third-party websites or services linked to or integrated with our Service.
12. Testimonial Data and Public Display
The fundamental purpose of Vorbra is to collect and display customer testimonials. This section provides additional detail about how testimonial data is handled.
12.1 Submission of Testimonials
When a reviewer submits a testimonial through one of our public collection forms (accessible at URLs in the format vorbra.com/r/[slug]), they voluntarily provide their personal information including name, email address, title, star rating, and review content, along with optional audio or video recordings. By submitting a testimonial, reviewers acknowledge that their testimonial (excluding email address) may be publicly displayed if approved by the Account Holder.
12.2 Approval Process
All testimonials are submitted with a "pending" status. Account Holders review pending testimonials and may approve, reject, or leave them pending. Only approved testimonials are publicly displayed. Rejected and pending testimonials are stored in the Account Holder's dashboard but are not accessible through the public API or widget.
12.3 Public Display of Approved Testimonials
Approved testimonials may be displayed publicly through:
- The Vorbra embeddable widget on the Account Holder's website
- The Vorbra API (which returns JSON data of approved testimonials for a given space)
- Any other integration or display method the Account Holder may implement using our API
Once a testimonial is approved and displayed through our widget or API, it may be cached by browsers, search engines, content delivery networks, or other intermediary systems. While we can remove the testimonial from our own systems and API, we cannot guarantee removal from all third-party caches and systems.
12.4 Reviewer Rights Regarding Testimonials
If you have submitted a testimonial and wish to have it modified or removed, you may contact us at the email address provided in Section 15 or contact the Account Holder directly. We will make reasonable efforts to accommodate your request. Account Holders can delete testimonials from their dashboard at any time. Upon deletion, the testimonial will be permanently removed from our systems and will no longer be served through our API or widgets.
12.5 Audio and Video Testimonial Data
Audio and video testimonial recordings may contain personally identifiable information such as the reviewer's voice, likeness, and any personal information they choose to share in their recording. Reviewers should be aware that once an audio or video testimonial is approved by an Account Holder, it may be publicly accessible. We recommend that reviewers do not include sensitive personal information (such as financial details, health information, or government-issued identification numbers) in their testimonial recordings.
13. Data Processor vs. Data Controller Roles
Under data protection laws such as the GDPR, different parties may have different roles and responsibilities with respect to personal data. This section clarifies the roles of Vorbra and our Account Holders.
13.1 Vorbra as Data Controller
Vorbra acts as the data controller with respect to the following categories of personal data:
- Account Holder Data: Personal information provided by Account Holders when registering for and using the Service (e.g., email address, password, profile information).
- Website Visitor Data: Information collected from visitors to vorbra.com, including log data, cookies, and usage information.
- Payment Data: Billing and payment-related information processed in connection with subscriptions.
As data controller, Vorbra determines the purposes and means of processing this data and is directly responsible for complying with applicable data protection laws, including responding to data subject requests.
13.2 Vorbra as Data Processor
Vorbra acts as a data processor with respect to testimonial data submitted by reviewers on behalf of Account Holders. In this capacity:
- The Account Holder is the data controller who determines the purposes for collecting testimonials (e.g., to display social proof on their website).
- Vorbra processes testimonial data on behalf of the Account Holder in accordance with the Account Holder's instructions (e.g., storing, displaying, and serving approved testimonials).
- Account Holders are responsible for ensuring that they have a valid legal basis for collecting and processing reviewer data through Vorbra, including obtaining any necessary consents.
- Account Holders are responsible for responding to data subject requests from reviewers regarding their testimonial data, though Vorbra will assist as required.
13.3 Data Processing Agreement
Account Holders who process personal data of individuals in the European Economic Area, United Kingdom, or other jurisdictions that require data processing agreements may request a Data Processing Agreement (DPA) from Vorbra. The DPA sets out the terms under which Vorbra processes personal data on behalf of the Account Holder, including the subject matter and duration of processing, the nature and purpose of processing, the types of personal data processed, and the categories of data subjects.
13.4 Account Holder Responsibilities
Account Holders who use Vorbra to collect testimonials from their customers are responsible for:
- Ensuring they have a lawful basis for collecting and processing reviewer data
- Providing appropriate privacy notices to reviewers informing them how their data will be used
- Obtaining any necessary consents from reviewers, particularly for the public display of testimonials and for the processing of audio or video recordings
- Responding to data subject requests from reviewers in a timely manner
- Complying with all applicable data protection laws in their jurisdiction and the jurisdictions of their reviewers
- Not using Vorbra to collect testimonials from children under the applicable age without verifiable parental consent
14. Changes to This Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in our data practices, legal requirements, or our Service. When we make changes to this Privacy Policy, we will update the "Last updated" date at the top of this page.
For material changes that significantly affect how we collect, use, or share your personal information, we will provide additional notice, such as:
- Sending an email notification to registered Account Holders at the email address associated with their account
- Displaying a prominent notice on our website or within the Service dashboard
- Requiring you to acknowledge the updated Privacy Policy before continuing to use the Service
We will provide at least 30 days' notice before material changes take effect, giving you the opportunity to review the updated Privacy Policy and, if you disagree with the changes, to stop using the Service and request deletion of your data.
We encourage you to review this Privacy Policy periodically to stay informed about how we protect your information. Your continued use of the Service after the effective date of any updated Privacy Policy constitutes your acceptance of the updated terms.
Prior versions of this Privacy Policy will be archived and made available upon request.
15. Contact Information
If you have any questions, concerns, or requests regarding this Privacy Policy, our data practices, or your personal information, please contact us through any of the following methods:
- Email: privacy@vorbra.com
- General Inquiries: support@vorbra.com
- Website: vorbra.com
When contacting us about a privacy-related matter, please include sufficient information for us to identify you and respond to your request, including your full name, email address associated with your Vorbra account (if applicable), a description of your request, and any relevant details that will help us process your request promptly.
15.1 Data Protection Officer
For inquiries specifically related to data protection compliance, GDPR, or data subject rights, you may contact our data protection team at: privacy@vorbra.com. We will endeavor to respond to all legitimate inquiries within 30 days. If it will take longer to resolve your request, we will notify you of the expected timeline.
15.2 Supervisory Authority
If you are located in the European Economic Area or the United Kingdom and believe that our processing of your personal data violates applicable data protection laws, you have the right to lodge a complaint with your local supervisory authority. A list of EEA supervisory authorities is available at: https://edpb.europa.eu/about-edpb/about-edpb/members_en. For the United Kingdom, the relevant supervisory authority is the Information Commissioner's Office (ICO) at ico.org.uk.
We would, however, appreciate the chance to address your concerns before you approach a supervisory authority, so please contact us first.
This Privacy Policy is effective as of August 11, 2026 and will remain in effect except with respect to any changes in its provisions in the future, which will be in effect immediately after being posted on this page. By using the Service, you signify your acceptance of this Privacy Policy. If you do not agree to this Privacy Policy, please do not use the Service.
See also: Terms of Service