Feder Privacy Policy

Effective date:

1. Who this is for

Feder serves customers in the United States only at launch. This policy describes what we collect, why, and what we do with it.

Feder is a business product for marketing agencies. It is not intended for anyone under 18, and we do not knowingly collect data from children.

2. What we collect

Account information. When you sign up, we collect your name, work email, agency name, and login details. If you invite staff or client viewers, we collect their names and emails too.

Google OAuth connection. Feder connects to your GA4 data through Google OAuth (read-only). We store the OAuth tokens needed to keep that connection working. Tokens are stored encrypted and are used only to check your GA4 properties on your behalf.

GA4 metadata. We collect metadata about the GA4 properties you connect: property identifiers, check results, and configuration facts needed to detect tracking failures (for example, whether expected data is arriving). We do not pull or store your clients' end-user analytics event data beyond what is needed to determine tracking health.

Alert and incident history. When Feder detects a tracking issue, we store the incident record: what was detected, when, and which alerts were sent. This is the core of the service.

Billing information. Payments are processed by Stripe. We do not see or store your full credit card number. We store plan, billing status, and transaction records needed to run your subscription.

Support communications. If you email support@getfeder.com, we keep the correspondence so we can help you and improve the service.

Launch notify list. If you leave your email on getfeder.com to be told when Feder opens for sign-ups, we store it in our Resend email list for that one purpose. You can ask us to remove it at any time by emailing support@getfeder.com.

3. How we use it

We use your data to:

  • Provide monitoring, detection, and alerts.
  • Manage your account, plan, and billing.
  • Send service emails (alerts, billing notices, security notices).
  • Respond to support requests.
  • Improve reliability and fix bugs.

We do not use your data for advertising, and we do not sell your personal information.

4. Cookies

We use first-party cookies only. We do not use third-party advertising trackers. Cookie categories:

  • Strictly necessary: login sessions, security, load balancing. The site and app cannot work without these.
  • First-party analytics: if we measure usage of our own site, we use first-party analytics only (pages visited, not cross-site tracking). No advertising identifiers.
  • Preferences: remembers choices like display settings.

We do not set third-party advertising or cross-site tracking cookies.

5. Who we share data with (subprocessors)

We share data only as needed to run the service:

  • Stripe - payment processing and subscription billing.
  • Google - OAuth authentication and GA4 data access (read-only, at your direction).
  • Resend - email delivery for alert and service emails.
  • Hosting - application and database hosting: Vercel and Neon.

We do not sell personal information to anyone. We do not share data with advertisers or data brokers.

We may disclose data if required by law (for example, a valid court order), and we will notify you unless legally prohibited.

6. Data retention

  • When you cancel, your workspace data is deleted within 90 days of cancellation.
  • Backups containing your data age out on the same 90-day schedule. We do not keep separate long-lived copies.
  • Billing records needed for tax and accounting may be kept longer as required by law.

7. Your privacy requests

You can request access to, correction of, or deletion of your personal data by emailing support@getfeder.com. Although we currently serve US customers only, we honor these requests in the spirit of the California Consumer Privacy Act (CCPA/CPRA) for our California customers: we will confirm what we hold, correct inaccuracies, and delete on request, subject to the legal record-keeping noted above.

We will respond within a reasonable time and never discriminate against you for making a request.

8. Security

We protect your data with measures including:

  • Encryption of sensitive credentials (such as OAuth tokens) at rest.
  • Encrypted connections (TLS) for data in transit.
  • Strict separation between customer workspaces, so one agency cannot see another's data.
  • Least-privilege internal access: only the systems and people that need access have it.

No system is perfectly secure, but we treat your clients' tracking data as the trust-sensitive asset it is.

9. Changes to this policy

If we change this policy materially, we will notify your account email at least 30 days before the change takes effect.

10. Contact

Privacy questions or requests: support@getfeder.com