Who we are

Storysnap, LLC (“Storysnap,” “we,” “us,” or “our”) is a US-based company headquartered in Boston, Massachusetts. We operate two brand websites and services: Testimonial Hero (testimonialhero.com), which produces customer and employee video testimonials, and Product Hype (producthype.com), which produces animated product and brand videos. This Privacy Policy applies to storysnap.com, testimonialhero.com, producthype.com, and any other website or service Storysnap operates that links to this Policy.

We've written this Policy to be straightforward. If something is unclear or you have a question, contact us at privacy@storysnap.com.

EU and UK Representative

Storysnap has appointed Prighter Group as our EU and UK Representative under Article 27 of the EU and UK GDPR. If you are in the European Union, European Economic Area, or United Kingdom and wish to exercise your privacy rights, you can contact Prighter at https://app.prighter.com/portal/11580231050.

Data Privacy Lead

Storysnap has designated an internal Data Privacy Lead as the point of contact for privacy questions and requests. You can reach our Data Privacy Lead at:

Storysnap, LLC

Attn: Data Privacy Lead

56 Broad St., STE 14099

Boston, MA 02109

privacy@storysnap.com

How we handle your data depends on your relationship with us

Different categories of people interact with Storysnap in different ways. The data we collect, how we use it, and how long we keep it varies by category. Below we describe each category. California residents and residents of other US states with privacy laws can find additional disclosures in the US State Privacy Rights section.

Website visitors

When you visit storysnap.com, testimonialhero.com, producthype.com, or other Storysnap-operated sites, our servers automatically log certain information: IP address, general location, browser type, operating system, pages viewed, referring URL, and similar usage data. We use cookies and similar tracking technologies — see our Cookies Policy for details.

Why: Legitimate interest in operating, securing, and improving our websites; consent for non-essential cookies.

How long: Per the retention periods in our Cookies Policy; typically tied to cookie expiry.

Business contacts and prospects

If you contact us through a form, engage with our marketing, or are identified as a relevant business contact through professional research (e.g., LinkedIn) or third-party data providers, we collect contact data: name, job title, employer, work address, work email, work phone, and basic information about your role or industry.

Why: Legitimate interest in business development; consent where required for marketing communications.

How long: While you remain a relevant business contact or until you ask us to remove you. Marketing and CRM data is reviewed periodically and removed when no longer relevant.

Clients and client account contacts

If your company engages Storysnap to produce video content, we collect the contact and account information needed to deliver the services: account manager contacts, billing contacts, project information, and similar.

Why: Performance of our contract with your company; legitimate interest in account management.

How long: For the duration of the client relationship and a reasonable period thereafter for legal, accounting, and business continuity purposes. Client project data and deliverables are kept indefinitely by default so clients can continue accessing them through the Storysnap portal, and are deleted on request within 30 days. See “How long we keep your information” below.

Individuals featured in customer testimonials

Storysnap clients sometimes introduce their own customers or employees to Storysnap for video testimonial production. If you are featured in a testimonial produced for one of our clients, the data we process about you — name, contact details, employer and role, video and audio recordings, and likeness — is processed on behalf of that client.

Storysnap is a data processor for this data; our client is the data controller. We process this data only on the client's documented instructions and under the terms of our Data Processing Agreement with them. If you want to exercise your privacy rights regarding a testimonial you participated in, please contact the client (the company that engaged Storysnap to produce the video). If you reach out to Storysnap, we will forward your request to the controlling client and assist them in fulfilling it. We do not unilaterally modify or delete testimonial content except where the client is unresponsive within a reasonable timeframe or the request indicates an imminent safety concern.

Why we process: On the client's lawful basis, typically consent obtained through the release form you signed at the time of recording.

How long: Until the controlling client instructs us to delete, subject to your right to withdraw consent at any time.

Storysnap team members and contractors

If you are employed or engaged by Storysnap as a contractor, the personal data we process about you is governed primarily by our internal HR policies and your individual agreement with us, not by this Privacy Policy. Contact our Data Privacy Lead with questions.

Special category data

Storysnap does not knowingly collect, process, or store special category personal data as defined under GDPR Article 9 (data revealing racial or ethnic origin, political opinions, religious beliefs, health data, biometric data for identification, etc.) in the normal course of business. If you believe special category data has been inadvertently included in content you have provided, contact us at privacy@storysnap.com.

When we share information with third parties

We do not sell personal data. We share personal data only as needed to operate our business, deliver our services, and meet our legal obligations.

Subprocessors

We use third-party service providers (“Subprocessors”) to host our infrastructure, deliver our services, and operate our business. Subprocessors that process personal data on our behalf do so under a written Data Processing Agreement that restricts their use of the data to providing services to Storysnap. Our current list of Subprocessors is published at our Trust Center at trust.storysnap.com.

Service providers, agents, and partners

We may share personal data with service providers and agents that perform functions on our behalf — for example, payment processors, communications platforms, or analytics providers. These parties are contractually restricted from using personal data for their own purposes.

Legal and compliance

We may disclose personal data when required by law, in response to lawful requests from public authorities, to enforce our agreements, or to protect the rights, property, or safety of Storysnap, our clients, our team, or others. Where lawfully permitted, we will notify the affected party before disclosure.

Aggregate and anonymized data

We may share aggregate, de-identified, or anonymized data with partners and service providers for analytical, marketing, or research purposes. Such data cannot reasonably be used to identify you.

Connections with third-party services

Our websites may connect with third-party services such as LinkedIn, X (formerly Twitter), and Facebook. If you choose to share information from our sites through these services, your interaction with the third-party service is governed by that service's privacy policy.

International data transfers

Storysnap is headquartered in the United States and processes personal data primarily in the United States. The US has not received an adequacy decision from the European Commission under GDPR Article 45.

For personal data transferred from the European Economic Area, the United Kingdom, or Switzerland to the United States, Storysnap relies on Standard Contractual Clauses (SCCs) approved by the European Commission (Implementing Decision 2021/914), the UK International Data Transfer Addendum (IDTA), and Swiss FADP modifications, as applicable. These safeguards apply both to Storysnap's own data flows and to the agreements we maintain with our Subprocessors.

For more information about a specific transfer mechanism, contact our Data Privacy Lead.

Your privacy rights

You have rights regarding the personal data we hold about you. The specific rights available depend on the laws that apply where you live.

Rights available under GDPR (EU and UK)

  • Right to be informed about how your data is processed (this Policy)
  • Right of access to the personal data we hold about you
  • Right to rectification of inaccurate personal data
  • Right to erasure (“right to be forgotten”), subject to exceptions
  • Right to restrict processing in certain circumstances
  • Right to data portability to receive your data in a structured, machine-readable format
  • Right to object to processing based on legitimate interests or for direct marketing
  • Rights related to automated decision-making, including profiling (Storysnap does not engage in fully automated decision-making with legal effects)
  • Right to lodge a complaint with your data protection supervisory authority

Residents of other countries (e.g., Canada under PIPEDA, Brazil under LGPD) have rights under those laws to substantially similar standards. California residents and residents of other US states with privacy laws can find additional disclosures in the US State Privacy Rights section below.

How to exercise your rights

To exercise any of these rights, submit a request through our data privacy request page at storysnap.com/data-request, email privacy@storysnap.com, or contact our EU and UK Representative Prighter if you are in the EU, EEA, or UK.

What to expect:

  • We will confirm receipt of your request promptly.
  • We may ask for information to verify your identity before acting on the request.
  • We will respond within 30 days of receiving a verified request. If your request is complex or numerous, we may extend the response period by up to two additional months and will notify you of the extension.
  • Access to your personal data is provided at no cost.
  • If we cannot fulfill your request, we will explain the reason.

Controller vs. Processor: how to direct your request

For requests regarding data Storysnap controls (e.g., your business contact data, your website visit data, your account data as a client), contact us directly.

For requests regarding Client Assets (video, audio, transcripts, or other content featuring you that was produced for one of our clients), Storysnap acts as a processor on the client's behalf. The client is the controller of that data. Storysnap cannot unilaterally delete or modify Client Assets. Direct your request to the client (the company that engaged Storysnap to produce the video). If you contact Storysnap, we will confirm receipt of your request and promptly forward it to the controlling client, and we will assist the client in fulfilling your request in accordance with our contractual obligations. Where the controlling client is unresponsive within a reasonable timeframe or the request indicates an imminent safety concern, Storysnap will determine appropriate next steps in consultation with applicable supervisory authorities or counsel.

US State Privacy Rights

This section provides additional disclosures for residents of California, Colorado, Connecticut, Texas, Utah, Virginia, and other US states with comprehensive privacy laws.

Your rights as a US state resident

Depending on your state, you may have the right to:

  • Know what personal information we have collected about you and the categories of sources, purposes, and third parties involved
  • Delete personal information we have collected from you, subject to exceptions
  • Correct inaccurate personal information
  • Receive a copy of your personal information in a portable format
  • Opt out of “sale” or “sharing” of your personal information for cross-context behavioral advertising
  • Limit the use of sensitive personal information
  • Not be discriminated against for exercising your privacy rights

Categories of personal information collected (CCPA)

Over the past 12 months, Storysnap has collected the following categories of personal information:

Category Examples Sources Purposes Disclosed to
Identifiers Name, email, IP address You; professional research; our clients Service delivery, marketing, security Subprocessors; service providers
Customer records Business contact info, billing info You; our clients Service delivery, billing Subprocessors; payment processors
Internet/network activity Browser type, pages viewed, cookies Automatic collection Site operation, analytics Subprocessors; analytics providers
Audio/visual data Video and audio recordings captured on behalf of our clients You (with consent via release form); our clients Service delivery to clients Our clients; Subprocessors
Professional information Job title, employer, role You; professional research Marketing, service delivery Subprocessors
Inferences Aggregate analytics derived from the above Derived Service improvement Subprocessors

We do not knowingly collect categories of sensitive personal information beyond what is voluntarily shared in a testimonial recording on behalf of our clients.

No sale or sharing

Storysnap does not sell personal information, and we do not “share” personal information for cross-context behavioral advertising as defined under the CCPA. We have certified this commitment to our business clients in our Data Processing Agreement.

How to exercise your US state rights

Submit a request through our data privacy request page at storysnap.com/data-request or contact privacy@storysnap.com. We will verify your identity using reasonable methods proportionate to the sensitivity of the data and the request, and we will respond within the timeframes required by applicable law (typically 45 days under CCPA, extendable by 45 additional days where necessary).

Authorized agents

You may use an authorized agent to submit a request on your behalf. We will verify the agent's authority and may require you to confirm the request directly.

Right to appeal (Virginia, Colorado, Connecticut, and others)

If we decline to act on your request, you may appeal our decision by contacting privacy@storysnap.com. We will respond to your appeal within the timeframes required by applicable law.

How long we keep your information

We keep personal data only as long as we need it for the purposes described in this Policy, or as required by law. Specific retention periods depend on the data category:

  • Website visit data: Per cookie expiry settings; see our Cookies Policy.
  • Business contact and prospect data: While you remain a relevant business contact or until you opt out or request deletion.
  • Client business and relationship data: For the duration of the client relationship and a reasonable period thereafter for legal, accounting, and business continuity needs.
  • Client project data and deliverables: Raw footage, working files, and final deliverables (including content featuring testimonial participants) are retained indefinitely by default so clients can continue accessing content through the Storysnap portal, and are deleted on the client's written request within 30 days. Testimonial participants retain the right to erasure regardless of this default retention.
  • Employee and contractor data: Per applicable employment law and our internal retention schedules, typically at least seven years following the end of the relationship.
  • Financial and tax records: Per applicable law, typically at least seven years.

Cookies and tracking technologies

We use cookies and similar tracking technologies on our websites. Our Cookies Policy describes the specific cookies used, their purposes, and how you can accept or reject them. To view it, see our Cookies Policy.

You can manage non-essential cookies through our cookie consent banner on our sites, or through your browser settings.

How we protect your information

Storysnap maintains technical and organizational measures designed to protect personal data against unauthorized access, loss, alteration, or disclosure. Our security program includes:

  • Encryption: Data transmitted over external networks is encrypted using TLS 1.2 or higher. Data at rest within our cloud infrastructure is encrypted using AES-256 or an equivalent strong protocol as implemented by our subservice organizations.
  • Access controls: Role-based access control (RBAC), least privilege, and multi-factor authentication (MFA) for systems handling personal data.
  • Endpoint security: Storysnap operates a bring-your-own-device (BYOD) model with continuous endpoint security monitoring through the Secureframe Agent installed on team members' devices.
  • Vendor management: Subprocessors handling personal data are reviewed and contracted under Data Processing Agreements, with annual reviews of their independent assurance reports for our critical vendors.
  • Compliance program: Storysnap is pursuing SOC 2 Type 2 certification, with the initial observation period commencing July 2026. Our policy framework and related control documentation are available via our Trust Center at trust.storysnap.com.
  • Incident response: We maintain a documented Security Incident Response Plan that includes breach notification commitments consistent with GDPR Articles 33 and 34 and applicable US state law.

No security program eliminates all risk. If we become aware of a personal data breach that is likely to affect your rights, we will notify you and any applicable supervisory authority in accordance with our legal obligations.

Children's data

Storysnap's services are directed at businesses and business professionals. We do not knowingly collect or solicit personal information from children under 16 (or under 13 in the United States under COPPA). If we become aware that we have inadvertently collected personal data from a child without verified parental consent, we will delete that data as soon as reasonably possible. If you believe we may have collected information from a child, contact us at privacy@storysnap.com.

Changes to this Privacy Policy

We may update this Privacy Policy from time to time as our services, applicable laws, or industry practices change. The “Last Updated” date at the top of this Policy reflects the date of the most recent change. For material changes, we will provide additional notice through our websites or by direct communication where appropriate.

Questions, concerns, or complaints

If you have questions or concerns about this Privacy Policy or Storysnap's privacy practices, or if you would like to exercise your rights, please contact us:

Storysnap, LLC

Attn: Data Privacy Lead

56 Broad St., STE 14099

Boston, MA 02109

privacy@storysnap.com

EU and UK residents may also contact our EU and UK Representative, Prighter, at https://app.prighter.com/portal/11580231050.

You also have the right to lodge a complaint with your data protection supervisory authority. In the EU and EEA, your competent supervisory authority is determined by your country of residence; if no authority is identified, the lead supervisory authority is the Irish Data Protection Commission. In the UK, the supervisory authority is the Information Commissioner's Office (ICO).