Legal
Sub-processors
Last updated:
When you connect Linear or Slack to your GRIPE workspace, some of the data we hold on your behalf travels to that third party. We use each of these tools as a sub-processor for one specific feature only — they are not involved in any other part of GRIPE. The records below list exactly which company processes that data, what we send, why, on what legal basis, and how long it stays there.
Scope: this page covers the Linear and Slack integrations. Sub-processors for the rest of GRIPE (Supabase, Vercel, OpenAI, Anthropic, Resend, Sentry) are listed in our privacy notice (§5). If any sub-processor or our use of it changes materially, we update this page at least 30 days before the change takes effect and email workspace admins.
Linear Orbit, Inc.
- Registered address
- 2261 Market Street, STE 10632, San Francisco, CA 94114, United States (registered mailing address; Linear is a Delaware corporation).
- Data residency
- Data residency is chosen by your workspace admin at Linear workspace creation (US default; EU available). GRIPE cannot enforce the region — if you require EU residency, configure it in your Linear workspace before connecting.
- Purpose
- Create and update a Linear issue from a GRIPE feedback item when an admin in your workspace clicks “Send to Linear”, so your engineers can triage and resolve the feedback inside the tool they already use.
- Data categories transferred
- The issue title — an AI-cleaned, one-line summary of the feedback.
- The issue description — auto-generated markdown that includes a verbatim quote of the feedback content (the typed message or the Whisper transcript of the voice recording), the channel and duration (e.g. “voice feedback, 18s”), the end-user reference your widget passed to GRIPE, the page URL where the feedback was captured, the browser name and version, and a back-link to the item in GRIPE.
- Labels — derived from GRIPE's AI-inferred topics (e.g. “search”, “onboarding”, “bug”). No personal data.
- Priority — derived from GRIPE's AI-inferred severity (blocking → Urgent, major → High, minor → Medium). No personal data.
- One Linear attachment, named “GRIPE”, that links back to the full feedback item in your GRIPE dashboard. Following the back-link from Linear into GRIPE requires a separate GRIPE login — Linear users without GRIPE access cannot open the audio, screenshot, or AI analysis.
We do not send the raw audio file, the screenshot, the raw IP address, or any GRIPE access token to Linear. Screenshots and audio recordings remain in GRIPE and are only accessible via the back-link above.
End-user reference: you decide what string to pass when calling our widget. We recommend an opaque identifier (e.g. your internal user ID) rather than a name or email, to apply GDPR data-minimisation. Whatever you pass appears verbatim in the Linear issue.
Incidental special-category content: because the transcript is a verbatim quote of what the end-user said, it may incidentally contain special-category content (health, political opinions, etc.) if the end-user mentions it. GRIPE has no purpose to process such content, but it can flow through to Linear if present in the feedback.
- Linear's onward sub-processors
- Linear engages its own sub-processors to operate its service (currently including Google Cloud, AWS, Anthropic, OpenAI, Sentry, Stripe). GRIPE remains contractually responsible for Linear's compliance with the obligations Linear flows down to those sub-processors (GDPR Art. 28(4)). The current Linear list is published at trust.linear.app/subprocessors.
Transfer mechanism
Linear — retention and deletion
Linear stores the issue for as long as your Linear workspace keeps it. When you delete a feedback item in GRIPE, GRIPE calls Linear's archive/delete API at the moment of deletion and the GRIPE-side audit row is deleted at the same time as the feedback. If the Linear call fails, GRIPE proceeds with the local deletion and queues a retry; persistent failures are logged for a daily sweep so orphan Linear issues can be cleaned up.
Linear's own DPA commits to deleting or returning customer data on request at contract termination, but Linear retains compliance audit records for up to three years after termination (DPA § 7.3), so some technical traces may survive on Linear's side after a deletion request. Full mechanics are described in Linear's privacy notice at linear.app/privacy.
Slack Technologies, LLC
A subsidiary of Salesforce, Inc.
- Registered address
- 500 Howard Street, San Francisco, CA 94105, United States.
- Data residency
- United States (with global edge locations operated by Slack's own sub-processors).
- Purpose
- Post each new feedback as a Slack message in the channel your workspace admin has chosen, so your team is notified in real time. Configured per workspace; can be disabled at any time from the GRIPE Integrations page.
- Data categories transferred
- The AI-refined feedback text (one-line summary + blockquote of the cleaned content).
- The severity tag (blocking / major / minor / none).
- The category and subcategory (e.g. “bug”, “onboarding”).
- Customer name and company, if your widget passes them alongside the feedback. We display whichever you sent — we recommend an opaque identifier or the company name rather than a personal email.
- Customer plan label, if your widget passes it.
- A deep-link back to the feedback item in your GRIPE dashboard. Following the link requires a separate GRIPE login — Slack users without GRIPE access cannot open the audio, screenshot, or AI analysis behind it.
We do not send the raw audio file, the screenshot, the raw transcript, the end-user identifier you passed to GRIPE, the IP hash, or any GRIPE access token to Slack.
Channel access: the GRIPE bot can post to any public Slack channel without invite (via the chat:write.public scope) and to private channels only after being invited. If your workspace admin chooses a sensitive channel, every subsequent feedback — potentially including end-user-supplied text — will land there.
- Slack's onward sub-processors
- Slack engages its own sub-processors to operate its service (currently including Amazon Web Services, Google Cloud, and others). GRIPE remains contractually responsible for Slack's compliance with the obligations it flows down to those sub-processors (GDPR Art. 28(4)). The current Slack list is published at slack.com/trust/compliance/sub-processors.
Transfer mechanism
Slack — retention and deletion
GRIPE keeps a small audit row per Slack push (channel id, message timestamp, status) for the lifetime of the feedback item; deleting the feedback in GRIPE deletes that audit row immediately via a database cascade.
On the Slack side, the message itself persists in your workspace according to your Slack message-retention policy. GRIPE does NOT call chat.delete when you delete a feedback currently: the message remains visible to Slack users with access to the channel until your workspace's retention policy removes it. A future enhancement will add a best-effort chat.delete on feedback deletion; until then, treat Slack messages as durable copies of the data they carry.
Disconnecting the integration in GRIPE (from the Integrations page) calls Slack's auth.revoke endpoint to invalidate our bot token workspace-side and marks our internal record as revoked. A workspace admin can also uninstall the GRIPE app from the Slack admin UI directly — in that case our next attempted push fails with a token_revoked error and the dashboard automatically surfaces a Reconnect banner.
Your rights
You keep all the rights GDPR gives you over the personal data we process on your behalf — access, rectification, erasure, restriction, portability and objection. You can exercise them at any time by deleting the feedback item directly in your GRIPE dashboard (which triggers the Linear archive/delete described above and removes the GRIPE-side Slack audit row), or by writing to us at privacy@usegripe.com. We respond within 30 days and pass the request on to Linear or Slack when their action is required.
For rectification specifically: we will edit or remove the affected fields in the Linear issue on your behalf where technically possible. For Slack messages, GRIPE does not call chat.delete at this time — until that enhancement ships, rectification on Slack's side requires either editing the message manually from the Slack admin UI or deleting the channel content per your workspace's retention policy. Where the transcript is the source of truth and editing would destroy its evidentiary value, we will either annotate it with a correction or delete and recreate the issue at your choice.
For data Linear or Slack processes as an independent controller (for example, their own service usage logs), please refer to their privacy notices at linear.app/privacy and slack.com/trust/privacy/privacy-policy.