Legal

Privacy Policy

This policy explains what PageApprove collects, why we collect it, and how it supports client feedback, device verification, approval records, and product operations.

Effective date: June 25, 2026

1. Overview

This Privacy Policy explains how PageApprove collects, uses, stores, and shares information when you use our website, dashboard, feedback widget, review links, and related services.

PageApprove is designed for freelancers and small agencies that need structured website feedback, device verification, and approval records. Because device verification is a core feature, some technical device and browser information is collected when reviewers open review links.

PageApprove is operated from South Africa and is intended for global use. This policy is written to support transparency requirements under privacy laws including the GDPR, UK GDPR, South Africa's Protection of Personal Information Act (POPIA), and similar privacy laws, but your rights may vary depending on where you live and how you use the service.

2. Our Role

For account, billing, website, security, support, and product operations information, PageApprove generally acts as an independent controller or responsible party.

For project content, client reviewer information, comments, approvals, and device-verification data processed on behalf of a project owner, PageApprove generally acts as a processor, operator, service provider, or operator under applicable privacy law. The project owner is generally the controller or responsible party for that project data.

If you are a project owner, you are responsible for giving your clients and reviewers appropriate privacy notices and for making sure your use of PageApprove has a lawful basis under the privacy laws that apply to you.

3. Information We Collect

Account information: name, email address, workspace details, authentication data, and settings you provide when creating or managing an account.

Project and review information: project names, client details, staging URLs, review page URLs, comments, replies, statuses, reviewer names or email addresses, approval actions, and timestamps.

Device verification information: user agent, browser name and version, operating system, device category, viewport size, screen size, device pixel ratio, touch support, orientation, and related technical details.

Usage and operational information: log data, basic analytics, error information, IP address where needed for security or abuse prevention, security events, and information needed to maintain, debug, and protect the service.

Payment information: purchase status, plan, billing contact details, transaction identifiers, and payment processor records. Full card details are handled by payment processors and are not stored directly by PageApprove.

4. How We Use Information

We use information to provide the PageApprove service, create projects, display review links, capture feedback, verify device coverage, record approvals, maintain audit trails, support users, prevent abuse, improve reliability, and communicate important service information.

We may also use aggregated or de-identified information to understand product usage, improve features, and make business decisions. We do not sell your personal information.

5. Legal Bases for Processing

Where GDPR, UK GDPR, POPIA, or similar laws require a lawful basis, we rely on one or more of the following: performance of a contract, legitimate interests, consent, compliance with legal obligations, and protection of rights, safety, and security.

Performance of a contract covers account creation, authentication, dashboard access, project setup, review links, comments, approvals, support, billing, and service communications.

Legitimate interests cover product security, abuse prevention, service improvement, basic analytics, debugging, audit trails, device verification, and helping project owners understand client review context, provided those interests are not overridden by applicable privacy rights.

Consent may apply to optional marketing communications, certain cookies or analytics where required, and situations where a reviewer or user chooses to submit information. Where processing is based on consent, you may withdraw consent at any time without affecting earlier lawful processing.

Legal obligations cover tax, accounting, compliance, dispute, fraud-prevention, and regulatory obligations.

6. Client Reviewers

Client reviewers usually do not need a PageApprove account. When a reviewer opens a review link, PageApprove may collect their name, email address if provided, comments, approval actions, device and browser information, viewport details, review URL, and timestamps.

Project owners are responsible for ensuring their clients and reviewers understand that PageApprove records basic technical details for device verification, feedback context, and troubleshooting.

If you are a reviewer and want to exercise privacy rights over information submitted through a project review, contact the project owner first where possible. You may also contact PageApprove at help@pageapprove.com, and we may need to coordinate with the project owner to respond.

7. Cookies and Local Storage

PageApprove may use cookies, local storage, session storage, or similar browser technologies to keep users signed in, remember reviewer identity, preserve session state, secure review links, and improve the review experience.

We may use essential cookies or storage for authentication, security, session management, reviewer identity, and review-link functionality. We may use analytics or performance technologies to understand product usage and improve reliability, where permitted by law or consented to where required.

You can control cookies through your browser settings, but disabling them may affect authentication, dashboard access, or review-link functionality. If a separate cookie banner or cookie settings tool is provided, use that tool to manage non-essential cookies.

8. Service Providers

We use trusted third-party providers to operate PageApprove. These may include hosting, database, authentication, email delivery, payment processing, logging, analytics, and security providers.

Examples may include Supabase for authentication and database services, Resend for email delivery, and payment processors such as Lemon Squeezy or the payment provider shown at checkout for billing. Payment information is handled by the payment provider and is not stored directly by PageApprove unless explicitly stated.

Service providers are authorized to process information only as needed to provide services to PageApprove or as otherwise permitted by their agreements and applicable law.

9. Sharing Information

We share information when needed to provide the service, process payments, send email, troubleshoot issues, comply with law, enforce our terms, protect rights and safety, or complete a business transfer such as a merger or acquisition.

Project owners can see review information submitted by reviewers on their projects. Reviewers may also see comments or feedback context where the review workflow displays shared project discussion.

We do not sell personal information. We also do not share personal information for cross-context behavioral advertising unless we provide any notices or opt-out rights required by applicable law.

10. International Transfers

PageApprove is operated from South Africa and may use service providers in South Africa, the United States, the European Economic Area, the United Kingdom, or other countries. Your information may therefore be transferred to and processed in countries that may have different data protection laws from your country.

Where required, we use appropriate transfer mechanisms or safeguards, such as contracts with service providers, data processing terms, standard contractual clauses, adequacy decisions, or other legally recognized transfer mechanisms.

11. Data Retention

We retain information for as long as needed to provide PageApprove, maintain approval records, comply with legal and billing obligations, resolve disputes, prevent abuse, and support security.

Retention periods depend on the type of information, the account status, legal requirements, customer instructions, operational needs, and whether the information is part of an approval record or audit trail. Approval records and related device verification data may be retained for as long as the project owner keeps the project active or as needed to preserve the sign-off history.

You may request deletion of account or project information by contacting us. Some information may remain in backups, audit logs, billing records, security records, or legal records for a limited period where retention is necessary.

12. Security

We use reasonable technical and organizational measures to protect information. No online service can guarantee perfect security, and you are responsible for protecting your account credentials and sharing review links carefully.

If you believe your account or a review link has been compromised, contact us promptly at help@pageapprove.com.

If we become aware of a personal data breach that requires notice under applicable law, we will notify affected users, customers, regulators, or project owners as required by law and our role in the processing.

13. Your Privacy Rights

Depending on your location and the laws that apply, you may have rights to access, correct, update, delete, or export personal information; request restriction of processing; object to processing; withdraw consent; opt out of certain marketing or sharing; and lodge a complaint with a data protection authority or regulator.

For GDPR and UK GDPR users, these rights may include the right of access, rectification, erasure, restriction, portability, objection, consent withdrawal, and complaint to a supervisory authority. For POPIA users, these rights may include access, correction, deletion, objection to processing, and complaint to the Information Regulator.

To exercise rights, email help@pageapprove.com. We may need to verify your identity and, where information is controlled by a project owner, coordinate with that project owner. Some rights may be limited by law, security, audit trails, legal claims, or the rights of others.

14. Automated Decision-Making

PageApprove does not use personal information to make decisions based solely on automated processing that produce legal or similarly significant effects about users or reviewers.

Device classification and device verification are automated technical features used to label review sessions as mobile, tablet, desktop, or unknown and to help project owners understand review coverage. These features support workflow context and do not determine legal rights by themselves.

15. Your Choices

You may update account information in the dashboard where available. You may contact us to request access, correction, export, or deletion of personal information, subject to identity verification and legal or operational limits.

You may opt out of non-essential marketing emails, but we may still send transactional or service-related messages.

16. Children

PageApprove is intended for business use and is not directed to children. You must not knowingly submit personal information about children unless you have the authority and lawful basis required by applicable law.

If you believe a child has provided personal information to PageApprove without appropriate authorization, contact help@pageapprove.com.

17. Contact and Complaints

Questions, privacy requests, refund-related privacy questions, or complaints about this Privacy Policy can be sent to help@pageapprove.com.

If you are in South Africa, you may have the right to complain to the Information Regulator. If you are in the European Economic Area or the United Kingdom, you may have the right to complain to your local data protection authority or the UK Information Commissioner's Office, as applicable.

We may update this policy from time to time. The version posted on this page is the current version.