Privacy Policy
Last updated: September 5, 2026
1. Who we are
mood.cards is a service of Squared Lemon. When we say "we", "us", or "our" in this policy, we mean Squared Lemon, the operator of the mood.cards service.
2. Two roles we play
We act in two distinct capacities under the GDPR:
- Data controller, for the personal data of our account holders (you, the customer who signs up and manages projects).
- Data processor, for any personal data that your end-users submit through feedback cards embedded on your site. You remain the controller of that data; we process it on your behalf to provide the service.
3. What data we collect
Account data (controller)
When you create an account we collect:
- Name
- Email address
- Password (hashed, never stored in plain text)
We use this data solely to operate your account, authenticate you, and communicate service-related information.
To look into a problem, we can open your dashboard ourselves and see your projects, your cards, and the feedback in them. That access is read only: nothing can be changed or deleted while we are in there. Every time it happens we record who looked, which team they looked at, and when.
Feedback submission data (processor)
When an end-user interacts with a mood.cards widget on your site, we may receive:
- The feedback response (rating, text, or emoji selection)
- Any context data you attach via the API (e.g. user IDs, order numbers)
- Page URL and trigger key
- Timestamp
- Whether a card was shown, expanded, or dismissed, so you can see how many people answered. These records carry a random value that is generated fresh on every page load, is never stored on the visitor's device, and cannot link one page view to another
- Persistent cards, the ones that sit in the corner of the page as a small pill, send none of these records on page load. Nothing is sent until you open the card yourself, or until the site's own code opens it for you. If you ignore the pill, we receive nothing at all
- A random session ID (see section 10) that links a rating to a comment added just after it. It is only created when someone submits feedback
We do not add tracking cookies, fingerprint end-users, or collect data beyond what your integration explicitly sends.
To detect abuse of the widget API we keep a short-lived count of requests per visitor. The visitor's IP address is hashed with a secret key before that count is stored, and the address itself is never written to our database or our logs. The hash expires after one minute.
Website analytics
We use Fathom Analytics (referral link) on our marketing site, our docs and the dashboard. It sets no cookies, so this site has no cookie banner. Section 9 lists what we send to Fathom and what its script picks up on its own.
Fathom describes its own service as collecting no personal data, not tracking individual visitors, and complying with GDPR, ePrivacy, PECR and CCPA. That is their account of their handling, not something we can vouch for on their behalf.
4. How we use data
We use the data we collect to:
- Provide, maintain, and improve the mood.cards service
- Authenticate your account and manage your projects
- Process and store feedback submissions on your behalf
- Send service-related communications (e.g. security notices)
- Look into problems with your account, which can mean opening your dashboard read only, as described in section 3
We do not sell, rent, or share personal data with third parties for marketing purposes.
5. Where data is stored
All data is stored on servers located in the European Union. Data does not leave the EU unless you explicitly export it.
6. Data retention
- Account data is retained for as long as your account is active. You can delete your account yourself, from the dashboard, at any time. Deletion is immediate and permanent: your account, any devices still signed in, and any team where you are the only member are removed straight away, along with every project, card and feedback submission in them. Teams you share with other people are not deleted. You are removed from them and the remaining members keep the data. Nothing is archived and nothing can be restored.
- Feedback submissions are retained for as long as the associated project exists. You can delete an entire project from the dashboard at any time, which removes its feedback with it. To remove a single submission, contact us at the address below.
7. Your rights (GDPR)
If you are located in the EU/EEA, you have the right to:
- Access your personal data
- Rectify inaccurate data
- Erase your data ("right to be forgotten")
- Restrict processing of your data
- Port your data to another service
- Object to processing of your data
Erasure you can do yourself. Deleting your account from the dashboard removes your personal data immediately, as described in section 6. To exercise any of the other rights, contact us at the email address listed below.
For end-users of our customers' sites
If you submitted feedback through a mood.cards widget on someone else's website, that website's operator is the data controller. Please contact them directly to exercise your rights. They may then instruct us to delete or export your data on their behalf.
8. Security
We take reasonable technical and organizational measures to protect data, including:
- Encrypted connections (TLS) for all data in transit
- Encrypted storage for sensitive data at rest
- Hashed passwords using industry-standard algorithms
- Origin validation for widget API requests
9. Third-party services
We use the following third-party services:
| Service | Purpose | Data shared |
|---|---|---|
| Fathom Analytics | Website analytics | Page address, referring site, campaign tags on the link you arrived through. No cookies. See below |
| Bunny Fonts | Web font delivery (Quicksand) | IP address, browser headers (no logging, GDPR-compliant by design) |
What Fathom receives from a dashboard page
Dashboard addresses contain the IDs of your projects and cards. We do not send those. The address we report is the template of the page rather than the page itself, so a card page is sent as /dashboard/projects/:project/cards/:card and the two IDs never leave our servers.
We do not send the query string either, but Fathom's script reads it for itself and picks up a fixed list of campaign tags, utm_source and the like. Those are for links into our marketing pages. None of the filters you set on a dashboard page carry one of those names, and we test for that, so your filters stay here.
Your IP address and browser headers reach Fathom as part of the request, as they do with any third-party service. Fathom states that it uses them to generate an anonymous hash and does not store them.
The widget on a customer's website loads no analytics at all. Fathom is not present there in any form.
10. Cookies and local storage
The mood.cards service uses essential cookies only: a session cookie for logged-in users and a CSRF token. We do not use tracking cookies, advertising cookies, or any third-party cookies. Because of this, we do not display a cookie consent banner.
The mood.cards widget embedded on a customer's site stores small amounts of data on the visitor's device, for functional purposes only. These values are pseudonymous. They are never used to identify anyone, never shared with third parties, and never used to track a visitor from one site to another. Browser storage is scoped to the site you are on, so a value written on one customer's site cannot be read on any other:
| Key | Storage | Purpose |
|---|---|---|
mc_aid |
sessionStorage | Anonymous per-session ID. Written only when you submit feedback, and used to link a comment to the rating you just gave. Cleared when the tab closes. |
mc_seen_<cardId> |
localStorage | Suppresses a card the visitor has already answered, closed, or left unanswered, when the card's visibility is set to "once" or "cooldown". Stores either "1" or a timestamp. |
mc_session_<cardId> |
sessionStorage | Suppresses a card for the rest of the visitor's session, when the card's visibility is set to "session". |
mc_config_<apiKey> |
localStorage | Caches the customer's card configuration to avoid refetching on every page load. Discarded after 30 days. |
These keys fall under the "strictly necessary" exemption in Article 5(3) of the ePrivacy Directive, because each one exists to deliver the feedback service to you, the visitor. The suppression keys are written when a card is answered, when it is closed, or when it fades away unanswered, and their only purpose is to stop the same question being asked again. The session ID is written only when you submit feedback. It lasts until you close the tab, and exists to link your rating to a comment you add straight after it. If you see a card and never answer it, no session ID is created.
None of these keys are meant to outlive the service they support. The widget discards its cached configuration after 30 days, and clears the suppression keys for any card the customer has removed.
The optional proof widget, the embeddable badge that shows a card's average rating on a customer's marketing pages, sets no cookies and writes no data to the visitor's device. It displays aggregate numbers only (an average and a rating count), never individual comments or any personal data. Because it stores nothing and identifies no one, it also requires no cookie banner.
11. Affiliate links
When we link to a recommended third-party service we sometimes use a referral link that earns us a small commission if you sign up. We only recommend services we use ourselves and the commission never affects which tools we choose. Referral links are clearly marked as such inline.
12. Changes to this policy
We may update this policy from time to time. We will notify account holders of material changes via email. The "last updated" date at the top reflects the most recent revision.
13. Contact
For privacy-related questions or to exercise your rights, contact us at: