How ProductBridge stores, processes and protects customer data, documented in full for the teams responsible for reviewing it.
Last updated 8 September 2026
Where we stand on compliance
We are a small team, and we have not completed a SOC 2 Type II audit yet. Rather than leave you to guess what that means, this page sets out exactly what we do have in place — most of which you can verify yourself — and we will answer any security questionnaire you send us.
Data stays in the EU
Database and files in Paris
No model training
Your data never trains an AI model
Encrypted end to end
TLS 1.2+ in transit, AES-256 at rest
Access is logged
Every administrative access is recorded
How we handle your data
The controls that are actually in place today, described specifically enough that you can check them.
No training on your data
Your data is never used to train AI models, ours or our providers’. AI requests go through the OpenAI API, which does not train on data submitted to it.
Data residency and hosting
ProductBridge runs on AWS. Your database and files sit in eu-west-3 (Paris) and vector search in eu-central-1 (Frankfurt). AI processing is the exception, and takes place outside the EU under Standard Contractual Clauses.
Encryption
All traffic uses TLS 1.2 or higher, and data at rest is encrypted with AES-256. Credentials for connected tools are encrypted again inside the application, so a database dump alone does not expose them.
Retention and deletion
We keep your data for as long as your account is open, with no automatic expiry. Ask us to delete anything and it is gone from live systems and backups within 30 days — including one customer’s records for a subject access request.
Backups and recovery
Daily automated backups, retained for seven days, with point-in-time recovery to the last five minutes. Restores are best-effort; we do not offer a contractual RTO or RPO yet.
Authentication
Sign in with email and password or a social provider. Passwords are hashed and sessions use signed, HTTP-only, Secure cookies. SAML and SSO are not self-serve today — contact us if you need them on the Business tier.
Subprocessors
Every third party that processes customer data on our behalf, taken from what actually runs in production — not from a template.
Amazon Web Services (RDS)
Primary application database
All customer, feedback and support data
eu-west-3 · Paris
Amazon Web Services (S3)
File and attachment storage
Uploads and attachments
eu-west-3 · Paris
Qdrant Cloud
Vector search and duplicate detection
Feedback text embeddings
eu-central-1 · Frankfurt
OpenAI
AI processing: extraction, summarisation, support agent
Feedback and conversation text
Voyage AI
Text embeddings for semantic search
Feedback text
Resend
Transactional and notification email
Email addresses and message content
Brevo
Marketing contact sync
Email addresses
European Union
Better Stack
Application logging and uptime monitoring
Application and access logs
European Union
Cloudflare
DNS, CDN and custom domains
Traffic metadata
Global edge network
Inngest
Background job orchestration
Job payloads
Europe
Before we add a new one
We give 30 days’ notice before a new subprocessor starts handling customer data. To get those notices by email, write to help@productbridge.io with “subprocessor notices” in the subject and we will add you to the list.
Tools you connect yourself
Connecting an integration sends data to that provider on your instruction. Intercom, Zendesk, Jira, Linear, ClickUp, GitHub, Salesforce and Discord only receive data once you connect them, and disconnecting stops it.
Incidents and disclosure
What we owe you if we get something wrong, and how to tell us when you find it first.
If something goes wrong
If customer data is breached, we tell you within 72 hours of becoming aware of it. Notice goes to the account owner of every affected organisation and to any security contact you have given us. It says what happened, which data was involved, what we have already done, and what we suggest you do.
Reporting a vulnerability
Send security reports to help@productbridge.io and we will acknowledge them within three business days. We will not pursue legal action against anyone doing good-faith research who reports privately, does not access or change other people’s data, does not degrade the service, and gives us reasonable time to fix the issue before publishing it.
Legal documents
Everything your legal team will ask for, in one place.
Privacy Policy
What personal data we collect, why, and the rights you have over it.
Terms and Conditions
The contract that governs your use of ProductBridge.
GDPR Policy
How we meet our obligations as a processor under the GDPR.
DPA and Cookie Policy
Our Data Processing Agreement and Cookie Policy are available on request while we finish the self-serve versions. Email us and we will send them.
Transfers of personal data out of the EEA rely on the European Commission’s Standard Contractual Clauses, which are named as the transfer mechanism in our Data Processing Agreement.
Questions security reviews always ask
Short answers, no hedging.
Do you train AI models on my data?
Where is my data stored?
Are you SOC 2 certified?
Can I sign a DPA?
How long do you keep my feedback data?
Can I delete a single customer’s records?
Who at ProductBridge can access my data?
What happens to my data if I cancel?
A security question this page does not answer?
Send it to us. We would rather answer something awkward than have you guess from a vague page.