Privacy
What we collect, and why
This page covers the comments portal, its API, and the widget that customers put on their own pages. It says what is stored, for how long, and which tags load on this portal and only after you agree.
Who is responsible
Vergence B.V.
Fornheselaan 254
3734 GE Den Dolder, the Netherlands
Chamber of Commerce (KvK) 96476133
Write to that address for any request about your data. You can also complain to the Dutch data protection authority, the Autoriteit Persoonsgegevens.
The service: accounts, sites and comments
- Owners sign in by email. We store the email address, the account it belongs to, sign-in sessions (14 days, with the IP address and browser they were created from) and the single-use sign-in links (15 minutes).
- Sites are stored with their name, origin, keys (as hashes), review links (as hashes), the time the widget was first seen on a page, and an audit trail of what the owner changed.
- Reviewers have no account. We store the display name they chose, the link they joined through, and their comments together with the text on the page the comment was pinned to.
- API tokens are stored as hashes with a name and the time they were last used.
Comments stay until the owner deletes them, clears the site, or sets the site to delete threads after a number of days. Deleting a site deletes everything under it.
Server logs
The API writes one log line per request: the route, the status, how long it took, the kind of caller (owner, agent, reviewer, widget), the account or site it acted on, and the caller's IP address. Errors are logged with their traceback. Log lines never carry an email address, a token, a key, a review code or the text of a comment.
Logs and traces are kept for 30 days in Microsoft Azure (Application Insights) in the Sweden Central region, the same region as the service and its database.
When a page of this portal, or the widget on a customer's page, hits an error it could not handle, the browser sends the page path, the error message and where in the code it happened to the API, which logs it the same way.
Cookies and tags on this portal
Needed to work, no consent asked:
comments_session, the sign-in cookie, 14 days, set by the API.- Your cookie choice, kept in this browser's local storage.
- On the demo page, the reviewer token and display name, kept in this browser's local storage for the demo site only.
Only if you accept: the portal loads Google Tag Manager, which then loads the tags we have switched on. Today those can be Google Analytics 4 (analytics), and the Meta Pixel, the LinkedIn Insight Tag and the TikTok Pixel (measuring our advertising). They set their own cookies and send page views and the steps you take on this portal, such as signing in or creating a site, to those companies. We never send them your email address, a key, a token or a review code. Until you accept, none of them load and nothing is sent.
You can change your mind at any time with Cookie settings in the footer of every page.
The widget on customers' sites
The widget runs on pages that belong to our customers. It stores the reviewer token and display name in that browser's local storage, keyed by the site, and sends comments to our API. It sets no cookies, loads no analytics and no advertising tags, and reports nothing about the visitor to anyone but the site owner through the comments they write.
Your rights
You can ask for a copy of your data, have it corrected or deleted, restrict or object to its use, and take it with you. Owners can export a whole site as JSON from the site page and delete the site themselves. For anything else, write to the address above.