Legal
Privacy policy
What we collect, why, how long we keep it, and what happens to the data of visitors on sites that use Miniwall.
Last updated: October 7, 2026
1.Who this covers
This policy explains how Miniwall handles personal data in two situations: when you visit miniwall.app or use your Miniwall account (the dashboard and editor at app.miniwall.app), and when a website that uses the Miniwall SDK shows a screen to its own visitors.
Miniwall is run by a small independent team in Vietnam. Questions about this policy go to hello@miniwall.app.
2.What we collect from account holders
- Account. Your email address and a password, handled by our authentication provider. We never see your password in readable form.
- What you build. Projects, screens and their versions, placements, A/B tests, schedules, targeting rules, allowed websites, team members and their roles, and preview links.
- Images. Files you upload to use in screens, kept in file storage. Uploaded images are served from a public address so that the screens on your site can load them.
- API keys. Public keys are meant to be placed in your website. Secret keys are stored only as a hash, so we cannot show them to you again.
- Invitations. When you invite a teammate we store their email address and the role offered, keep the invitation link only as a hash, and send the invitation by email.
- Messages to us. Anything you send to hello@miniwall.app or post in our public issue tracker.
On this marketing site we measure page visits and clicks on our own buttons with Vercel Web Analytics. It counts visits and events without using cookies and does not build a profile of you across other sites.
3.How we use it
- To provide the service: sign you in, save your work, deliver your published screens to your site and show you analytics.
- To send emails that the service needs, such as team invitations and account emails like password resets.
- To count views against your plan and apply plan limits.
- To keep the service secure, fix problems and answer your questions.
We do not sell personal data, and we do not use your customers' data for advertising.
4.Visitors of sites that use the SDK
When your site shows a Miniwall screen, the SDK loads your published screen from our servers and reports what happened to it. For each event it sends:
- the kind of event (a screen was shown, closed, a package was tapped, a purchase was reported, a choice was answered);
- which screen, version and placement it belongs to, and the A/B variant if a test is running;
- the ID of the package or button involved, and for question screens the ID of the option chosen (text a visitor types is never sent);
- the time of the event;
- a visitor ID: a random identifier the SDK creates and keeps in the visitor's browser storage (localStorage) so that we can count unique visitors. It is not linked to a name, email address or account.
The SDK does not set cookies. It also keeps small items in browser storage on the visitor's device: how often a screen was shown (for frequency limits), the last screen shown, and a cached copy of the screen so it loads quickly.
Targeting attributes stay in the browser. If your site gives the SDK attributes about a visitor (for example a plan or a country) so it can choose an audience, they are matched in the browser and are not sent to us. They are not part of any event we store.
As with any request on the internet, the visitor's IP address and browser details reach our servers and our hosting provider while a request is handled. We do not store them with events. Your site can turn event reporting off in the SDK settings.
Roles. For this visitor data, the customer who installed the SDK decides why and how it is used and is the controller. Miniwall acts on the customer's behalf to store and show it in analytics. Customers are responsible for telling their visitors about the SDK and for any consent their local law requires before running it. If a visitor contacts us about data from a customer's site, we may pass the request to that customer.
5.Service providers
We use these providers to run Miniwall. Each handles personal data only to provide its part of the service.
- Vercel: hosting of this site, the dashboard and the API, and web analytics for this site.
- Supabase: database, sign-in and file storage.
- Resend: sending transactional email, such as team invitations.
- Cloudflare: DNS for our domain and email forwarding for addresses such as hello@miniwall.app.
We may add or replace providers as the service grows; this page will be updated when that happens.
6.How long we keep data
- Account and project data is kept while your account is open. When you ask us to delete your account, we delete your account and the projects, screens, keys and events that belong to it.
- SDK events are kept for at most 95 days and then deleted automatically. The dashboard shows analytics for up to the last 90 days.
- Emails you send us are kept as long as needed to deal with your request.
Backups held by our providers can keep copies for a short time after deletion. Items you remove yourself in the dashboard, such as a screen or an image, are removed from the live service.
7.Security
Traffic to Miniwall is encrypted in transit. Access to a project is limited to its members according to their role. Secret API keys and invitation links are stored only as hashes. No system is perfectly secure, so we cannot guarantee absolute security, but we limit what we collect and keep, and we fix problems when we learn of them.
8.Where data is processed
Our providers run infrastructure in several countries, and the team that runs Miniwall works from Vietnam. Your data may therefore be processed outside the country where you live. By using Miniwall you accept that. We do not claim that data stays in any one region.
9.Your choices and rights
Depending on where you live, you may have the right to access the personal data we hold about you, correct it, delete it, object to some uses, or receive a copy. To make a request, email hello@miniwall.app from the address on your account. We may need to confirm it is you, and we will reply within a reasonable time.
You can change your project content in the dashboard at any time. If you only want your account and its data deleted, email us and say so.
10.Children
Miniwall is a service for businesses and is not directed at children. We do not knowingly collect personal data from anyone under 16. If you believe a child has given us personal data, email hello@miniwall.app and we will delete it.
11.Changes to this policy
We may update this policy. The date at the top shows when it last changed. For significant changes we will also tell account holders by email or in the dashboard before they apply.
12.Contact
Questions, requests and complaints about privacy: hello@miniwall.app. You can also read our terms and learn about Miniwall.