Privacy Policy
Effective date: 8 August 2026
This policy explains how Podratic Ltd ("we", "us") handles personal data when you use Pogo. Podratic Ltd is registered in England and Wales, company number 17221834. Registered office: 71-75 Shelton Street, Covent Garden, London, WC2H 9JQ, United Kingdom. Privacy questions: support@podratic.com.
1. Our role: controller and processor
For your account and security data (your registration details, sign-in records, devices, and billing state) we are the data controller. For content inside an organization (stories, votes, retro items, survey responses, and member profiles within that workspace) the organization that owns the workspace is the controller and we act as its processor: we handle that content on the organization's instructions, and requests about it (for example deleting a survey response) may need to go to your organization's administrators.
2. Data we collect, and where it comes from
Directly from you:
- Account data - name, email address, password (stored only as a salted hash), and avatar.
- Organization data - organizations, teams, memberships, roles, and invitations.
- Content you create - planning poker rooms, stories and votes, retrospective boards and items, DX surveys and survey responses. Survey responses are shared with your organization as shown in the product when you submit them.
- Support communications - messages you send us, including bug reports and feedback.
Automatically, when you use the service:
- Security and usage data - sign-in events, trusted devices, IP address, and email delivery logs, used to secure accounts (for example our email sign-in codes for unrecognized devices) and to operate the service.
From third parties:
- Google sign-in - if you sign up or sign in with Google, Google sends us your name, email address, and avatar to create or match your account.
- Billing data - your organization's plan and subscription state, and payment confirmations from Stripe, our payment processor. Card details are collected and held by Stripe, not by us.
3. Why we use it (lawful bases)
- To provide the service (performance of a contract) - accounts, collaboration features, billing, and support.
- To keep the service secure (legitimate interests) - sign-in protection, abuse and fraud prevention, rate limiting, and audit records.
- To meet legal obligations - accounting and tax records relating to payments, and responding to valid legal requests.
- To send service communications - emails needed to operate your account (verification, sign-in codes, billing notices). We do not send marketing email without your consent.
We do not use your personal data for automated decision-making that has legal or similarly significant effects, and we do not sell personal data.
4. Who we share it with
Every company that can reach personal data is named on the Subprocessors page, with what it does and where it processes data.
- Processors who help us run the service, under data processing agreements: Stripe (payment processing), Akamai Cloud, formerly Linode (application and database hosting), Resend (transactional email delivery), Google Workspace (our own email, so anything you send to our support address), and Cloudflare (confirming the sign-up bot check, which sends them your IP address).
- Services that load in your browser, which receive your IP address from your browser directly: Cloudflare Turnstile (the bot check on the sign-up form) and Giphy (the GIF picker on a retrospective board, and any GIF already on a board you view).
- Google - if you choose to sign in with Google.
- Your organization - content and profile information you contribute to a workspace is visible to that workspace as shown in the product.
- Legal reasons - we may disclose data where required by law or a valid legal request, or where necessary to protect the rights, safety, or property of our users or the public.
- Business transfers - if we are involved in a merger, acquisition, or sale of assets, your data may transfer with the business; this policy would continue to apply to it and we would notify you of any change of controller.
Where a processor is outside the UK, transfers are protected by UK-approved safeguards such as the UK Addendum to the EU Standard Contractual Clauses or a UK adequacy decision. Those safeguards cover what we send a processor; they do not reach what your own browser sends a service directly, which is governed by that service's own privacy policy, linked beside its name.
5. Security
We protect personal data with industry-standard measures: all traffic is encrypted in transit (TLS), passwords are stored only as salted hashes, sign-ins from unrecognized devices are challenged with email codes, and access to production systems is restricted and audited. No internet service can guarantee absolute security, but we work to protect your data and will notify you and the regulator of any breach where the law requires it.
6. How long we keep it
Account and content data are kept while your account exists. When you delete your account (available in your account settings) we delete or anonymize your personal data, except records we must keep for legal reasons (such as payment records, kept for 6 years) and short-lived backups that expire on their normal schedule. To prevent free-trial abuse we also retain a pseudonymized record (a cryptographic hash of your email address, not the address itself) of whether your account has used its free trial; this is kept after account deletion on the basis of our legitimate interest in preventing fraud, and its existence is disclosed in your data export. If an email to you ever permanently bounced or you marked one as spam, we likewise keep a hash of that address on our do-not-send list after deletion, so we do not resume mailing an address that rejected us. Content you contributed to an organization's workspace may be retained by that organization as the controller of its workspace.
7. Your rights
Under UK GDPR (and, for users in the EEA, the EU GDPR) you can ask for access to, correction of, deletion of, or a portable copy of your personal data, and you can object to or ask us to restrict certain processing. The product includes self-serve tools for the most common requests: you can export a copy of your data and delete your account from your account settings. For anything else, email support@podratic.com and we will respond within one month. You also have the right to complain to the Information Commissioner's Office (ico.org.uk) or your local supervisory authority.
8. Children
The service is not directed at children and you must be at least 16 years old to use it. We do not knowingly collect personal data from anyone under 16; if we learn that we have, we will delete it.
9. Cookies and advertising measurement
Inside the product we use only strictly necessary cookies and similar storage. On our public pages we also advertise through Google Ads, and if you accept the banner shown on your first visit, Google's tag measures whether an ad led to a sign-up. We do not load that tag until you accept, so declining means your browser never contacts Google at all. You can change your answer at any time from the footer. The Cookie Policy sets out exactly what is stored, what happens if you decline, and how to withdraw.
10. Changes
We will post any changes to this policy here and, for material changes, tell you by email or in the product.