Legal
Privacy policy
Last updated 8 September 2026
This is the legal document. For a plain-language account of who can see what and why, read who can see what — it describes the same system without the formalities.
1Who is responsible for your data
facets.team is operated by GasBuggy Media LLC.
There are two distinct relationships here, and which one applies to you changes your rights:
If you created an account — a team lead, facilitator, or leader — we handle your account data as the party that decides why and how it is used.
If you were invited to answer a survey, the organization that invited you decided to collect that feedback and chose who to include. We process it on their instructions. Requests about ratings you gave or received are usually best directed to whoever invited you, but you can contact us either way and we will help.
If you are that organization, the terms on which we process this data for you are set out in the data processing agreement. It is offered as standard, it needs no signature, and it is already in force from the moment an account is created.
2What we collect
Account data. Email address, and the organization and team names you enter. There is no password — sign-in is by emailed link.
Roster data. The names and email addresses you enter for the people you invite.
Survey responses. Ratings of colleagues, ratings of the team, nominations, self-assessments, and any free-text comments. The self-assessment includes questions about how being on the team is going for you, including whether your workload is sustainable and whether you expect to still be on the team in a year; these are reported only as part of a team aggregate.
Manager records. Where a customer uses the manager tools, a manager records information about people who report to them: name and optional email address, role and scope, what they are accountable for, strengths and development areas, goals and targets, quarterly progress and a performance band, notes from one-to-one meetings, follow-up actions, and written quarterly or annual assessments. This is a performance record, it is written by their employer, and it is the most sensitive category of personal data in the service.
Colleague input on an assessment. Where a manager requests it, the name and email address of each colleague asked, and their written answers — held with their name attached. Whether someone declined is recorded; no reason is collected, and a declined request’s draft text is discarded.
Ideas on a board. Where a manager runs an idea board for their team, the name and email address of everyone they add to it, and what those people post: ideas, comments, votes and reactions. Whether a name is attached to an idea or a comment follows the board’s names setting, which is fixed before anybody posts; on the setting that hides names from everyone, who posted what is held where neither the manager nor an administrator can read it. Who voted and who reacted is never shown to anyone, the manager included — only the counts are. What people post is deleted within 90 days of the organization leaving the service, on the same clock as the answers in clause 6; what stays is the manager’s own record that the board happened: its title, the question it asked, and its counts.
Generated results. Computed scores and the written reports produced from them.
Operational records. An audit log of report accesses and significant actions, and standard server logs.
Requests from the public site. If you ask for the instrument specification or the research brief, the name, organization and email address you give, which of the two you asked for, and whether you left ticked the boxes asking for occasional notes from us or for a follow-up conversation. Notes are sent only after you open the emailed link, which confirms the address; every note carries an unsubscribe link that works in one click. A follow-up request is one conversation, initiated by us, and nothing more.
We do not use advertising or analytics trackers, and there is no third-party tracking on this site.
3Why we use it
To run the assessment and produce results; to send invitations, reminders, and notifications that results are ready; to authenticate account holders; to keep the service secure and diagnose faults; and to comply with legal obligations.
We also compute aggregated, de-identified statistics across many teams to improve the instrument, and intend in future to publish research from them. Nothing published this way will identify a person, team, or organization. A workspace owner can opt out of this use by emailing privacy@facets.team — clause 6 of the terms says what to include and what happens next.
We do not sell personal data, use ratings or comments to train machine-learning models, or use your data to advertise to you.
4Who can see what
The access rules are enforced in the database, not by policy, and they differ between the two halves of the service.
Feedback surveys. Individual ratings and comments are not readable by any signed-in account, including the team lead’s. Leads see participation counts and released team reports. Individuals see their own note. A facilitator sees additional quality and routing information, and only where the team has named that person by email address — no other account can read an individual note or the facilitator’s view, whatever role they hold in the organization. Nothing on this side is reported below three responses.
Manager records. Readable by the manager who created them. An owner or admin of the manager’s workspace can open a record to read it; each open is logged with their name and the date, and the log is shown to the manager. Nobody can change a manager’s record but the manager, and when a manager leaves, their records are reassigned to another manager or archived, never deleted. There is no minimum number of respondents here: a single colleague’s answer is used, and is presented to the manager as one person’s view rather than as a pattern. This half is not anonymous and does not claim to be.
The two are not joined. One table references across — the record of a summary the person the feedback is about chose to share with their manager — and no access rule reads through it into the review, its raters or its responses. Attaching that summary to their record is a manual act.
A limit we want to state plainly: on a three-person team each person has exactly two peers, so someone who knows their own rating can infer the other. The product withholds per-dimension peer scores at that size for this reason, and raters are told so before they answer. We do not promise anonymity that the arithmetic cannot deliver.
The floors, as numbers, and who can move them. A team result needs at least three raters before anything is shown, and at least five before individual items are broken out. A leadership 360 works the same way. An engagement cycle reports nothing about a group smaller than five, and the organization can raise that figure but cannot lower it. These are not settings your employer configured and they are not a description of our current defaults — they are limits built into the product, and an owner, an admin, a manager and we ourselves are all equally unable to switch them off. We are stating them here, in the binding document, because a promise that lives only in a help page is one that can be quietly revised.
When we would break confidentiality, and it is a short list. We would rather tell you now than have you discover it later. There are two situations where we may look at, or disclose, something a rater wrote believing it would not be traced back: where there is a credible indication that someone is at risk of serious harm, and where a court order, subpoena or equivalent legal demand compels us. Nothing else qualifies — not a manager’s curiosity, not an internal investigation, not a customer asking, however senior. Where the law allows it we will tell the person affected before we act. If it does not, we will tell them afterwards.
Your employers do not see each other. If you are rated in more than one organization — a consultant, a contractor, someone who changed jobs — nothing you did in one is visible in the other, and no report joins them.
5Service providers
We share data with the following, and only as needed to run the service:
Supabase — database, authentication and file storage (United States).
Vercel — application hosting (United States).
Cloudflare — bot protection on the sign-in form. Receives the IP address and the browser and TLS characteristics of anyone who opens that page, and nothing else. It never sees survey answers, and it is not used on any page where someone answers questions. Cloudflare runs the check on our instructions and, separately and on its own account, uses those signals to improve its bot detection.
Resend — transactional email delivery. Receives recipient addresses and message contents, including invitation links.
Anthropic — where enabled, generates the narrative sections of a report or a draft assessment, and follow-up questions to raters. For a team pack it receives team-level aggregates only, and never anyone’s written answers. For a leadership brief it receives aggregated evidence — never individual ratings — together with raters’ written comments with the writer’s identity removed, and never the confidential note to a facilitator. For a follow-up question it receives one rater’s own ratings and comments and nothing from anyone else. For a manager’s draft assessment it receives that person’s record with colleague names already removed, and never an email address — the data structure sent has no field for one. Anthropic’s commercial terms state that it may not train models on customer content from the services. Nothing written in Facets trains a model.
GIPHY, Inc. — the GIF picker on an idea board, and only on a board whose manager has switched GIFs on. It receives the words someone types into the picker, and nothing else: not their name, not their email address, not any account or board identifier, and nothing that would let it tell one person’s searches from another’s. Searches are restricted to GIPHY’s own G rating. The images themselves are fetched by us and served from our servers, so the browser of anyone reading a board never contacts GIPHY, never loads anything from it, and is never seen by it. A GIF on a board is a link we hold, never an upload: when the words on an idea are deleted or expire, the link goes with them.
Stripe — payments, once billing begins. Stripe acts as merchant of record for the purchase: it takes the card details, which we never see or store, and it calculates, collects and remits any tax due. Because it decides on its own account what that requires, it is a separate controller of the payment rather than a provider acting on our instructions, and your receipt comes from it rather than from us.
Google — measurement on the public pages of this site: how many people arrive, which pages they read, and where they came from. It receives the page address and the usual browser and network details, and it is not present on the app or on any page where somebody answers a question. We buy advertising on Google; we do not show advertising here, and we do not build audiences from visitors.
Where this runs. The database and the application are both in the United States — Supabase in AWS us-east-1, Vercel in its US regions. A dedicated instance can be created in another region, and the region is fixed when it is created. Email, payment processing, bot protection and the model provider are reached as services rather than hosted by us, and each keeps its own regions. Each of these providers uses sub-processors of its own; the list above is the set of companies we hand data to, and each of them publishes its own.
When this list changes. These are the only parties we share data with, and this page is the current list. If we add one, we will update this page and email every workspace owner at least thirty days before the new provider begins handling any data. Within those thirty days you may object on reasonable data-protection grounds by writing to privacy@facets.team. We will make a good-faith effort to offer you a way to keep using Facets without that provider; if we cannot, you may end the affected part of your subscription without penalty, and we will refund what you have paid for time you have not used. If a provider has to be replaced at short notice to keep the service secure or running, we will tell you as soon as we reasonably can rather than thirty days ahead.
5AIf the business changes hands
We may one day be acquired, merged into another company, or sold with our assets. If that happens the data described here goes with the business, because a company cannot be bought without the thing it operates.
That is not the same event as selling your data. Section 10 says we have never sold anyone’s personal information and never will, and that stays true: a change of ownership is a different thing, and the state privacy laws that define the word “sale” treat it as a different thing too.
What we commit to is this. We will tell you. The version of this notice in force at the time keeps applying to everything already collected, and a successor that wants to use it differently has to say so in advance rather than change the rules behind you. That last part is not only our preference — a material change applied backwards is prohibited under the same laws.
6How long we keep it
Survey responses and results are kept while the account that owns them exists.
Raw answers are deleted within 90 days of the team or organization leaving the service. This is the commitment already made to every participant on the consent screen before they answer, and it is repeated here so the two cannot drift apart.
Manager records are kept while the account that owns them exists, and are deleted with it. A manager can export any person’s record and any assessment at any time.
A request from the public site is kept so that the link keeps working and so we know what was sent to whom; unsubscribing keeps the address on file as unsubscribed so it is not written to again. Ask at the address below to have it deleted outright.
Deletion requests are honored for teams, reviews, or whole accounts, including the underlying ratings.
Deleted data survives in infrastructure backups for up to seven days. Our database provider takes automatic daily backups on a rolling seven-day window, so a backup taken before a deletion holds those rows until it ages out — ninety-seven days end to end for a departing team, against the ninety-day promise for the answers themselves.
Audit-log entries do survive. An entry recording that something existed is not deleted when the thing itself is, because a log that could be erased by the same action it exists to record would not be a log. Those entries hold what happened and when, not the ratings or the comments.
An account nobody uses does not keep data forever. After twenty-four months with no activity we email the account holder at the address on the account, and if nothing happens we close the workspace and delete it on the ordinary ninety-day path. This exists because the promise above starts running when a team leaves the service, and an account nobody ever closes never leaves — without this paragraph, answers given in one year would still be here in the next decade, which is not something anybody agreed to.
7Your rights
Depending on where you live you may have rights to access, correct, delete, or port your personal data, and to object to or restrict certain processing.
One honest complication, and what we actually do about it. A right of access may reach ratings and comments about the person making the request. Those were given by colleagues who were told their individual answers would not be shown. A promise we made to a rater cannot switch off a right the law gives you, so the question is not whether we answer but how much we can answer while keeping it. Here is where we have drawn that line, in advance, so that neither of you finds out during a dispute.
Your results, freely. The scores, themes and reports the product shows. You do not need a request for these: an owner or admin can export everything at workspace level at any time, and a manager can export any person’s record from that person’s own page.
The substance of what was written about you, in paraphrase. That is the only form written answers exist in for reporting. Nobody is shown them verbatim, and that includes you and includes your employer.
Individual ratings tied to the person who gave them: no. Who said what: never. Article 15(4) says a right to a copy must not adversely affect the rights and freedoms of others, and a rater’s answer is also the rater’s own personal data, given on an assurance we published before they answered. That is the balance the law asks us to strike and this is where we have struck it. The same law is clear that the balance cannot become a refusal to tell you anything, which is why the two tiers above are deliberately generous rather than grudging.
We will not ask your colleagues to consent to disclosure. It is the textbook mechanism and it is the wrong one here. Asking a rater whether you may see what they wrote tells them they have been identified as a rater and puts them under exactly the pressure the design exists to remove — and if they decline and we told you that somebody declined, that would be information about them too. So we do not ask, and no answer of ours should be read as implying that we did.
What no rule can fix. On a small team, content identifies the writer whatever we do with the wording — one person has the Tuesday one-to-ones. Where paraphrase would still point at somebody, you get a description of the theme rather than the text, and we will tell you that is what we have done rather than let you think you received everything.
Where the law requires more, the law wins. This is our default, not a rule we would defend against a regulator, a court, or a specific legal duty in your jurisdiction. Where one of those requires more, we disclose more, and we tell you we have.
This is a property of the product, not a decision we make about you. Your employer is the controller and answers your request; we hold the data on their instructions. What they cannot do is get past the same architecture you cannot. Individual peer ratings have no read access for any signed-in account, and the reporting floors cannot be lowered by your employer, by a manager, or by anyone with an account. That constraint was bought along with the product, and it is the reason your colleagues answered candidly in the first place.
There is one exception and you should hear it from us rather than infer it. We can set a lower floor on a single engagement cycle, at the organization’s written request — for a pilot of forty people where a floor of five reports nothing at all. It is per cycle, never a default, and the cycle’s own page says so in plain sight to everyone who can read the results, so it cannot be done quietly. If it was done on a cycle you answered, you were able to see that before you answered.
Correcting and deleting are different problems. An opinion cannot be made accurate by correcting it. If you think a rating or a comment about you is wrong, what can be corrected is the record — that the view was expressed, by whom in aggregate, and when — and you may have a statement of your own recorded alongside it. Erasing individual answers about you is a different matter again: they are part of an aggregate that other people’s results depend on, so removing them changes what your colleagues were told. Ask us and we will tell you which of these we can do in your case and why, rather than answering with a form.
Which of us to ask. If a manager recorded information about you, or a colleague was asked for input about you, their employer decided to collect it and we hold it on their instructions — so that request is usually best made to them. Ask us either way and we will help, and we will tell you which of us can act on it.
No decisions are made about you by a machine. Every score in the product is arithmetic that a person could do by hand — no model decides a number, a threshold, or whether a result is shown to anyone. Where a model writes, it writes narrative from figures already computed. So there is no automated decision-making with legal or similarly significant effects within the meaning of Article 22.
Profiling is a broader word, and we do not claim to be outside it. The definition covers automated processing used to evaluate personal aspects of somebody, and the first example it gives is performance at work. Computing a score about how a person works, from ratings other people gave, is that. What Article 22 restricts is a decision taken solely on that basis with a legal or similarly significant effect, and there is none here — but saying “no profiling” would have been a word we had not earned.
What we cannot promise is what your employer does next. They may take a report into a promotion, a pay review or a performance conversation, and that decision is theirs and is made by people. If you want to know how it was used, they are the ones who can tell you — and the reporting floors in section 4 exist precisely because a number built from too few people should not be carrying that weight.
If we get it wrong. In the EU, the EEA, the UK and Switzerland you may complain to your national data protection authority, and you do not have to come to us first. In the US, see section 10 for the appeal we offer and for your state attorney general. We would rather you told us — but the right does not depend on that.
To exercise a right, contact us using the details in section 12.
8Security
Data is encrypted in transit and at rest by our infrastructure providers. Access links are random tokens of which only a one-way hash is stored, so an existing link cannot be looked up or read back by anyone, including us. Administrative access to production is limited to a small number of named operator accounts, controlled by an allowlist in our deployment configuration together with a roster we can revoke at any time, and each of those accounts must additionally pass a one-time code from an authenticator app before the operator console will open. Report accesses are logged.
If something goes wrong. No system is perfectly secure. If personal data is breached in a way that presents a real risk of harm to the people it is about, we will tell the affected organization without undue delay and in any case within seventy-two hours of becoming aware — first with whatever we know at the time, which may be very little, and then in writing with the full account once we have it. We will not wait until the picture is complete to make the first call. Where the law requires us to notify individuals or a regulator directly, we will.
For a product built on people answering candidly, a breach is not only a data loss — it is an unmasking. We treat it that way.
9Cookies
Every cookie below is listed by name. Three of them are needed for the site to work at all and are set whatever you choose; the rest are not, and are only set if you say so.
Nothing in the analytics or advertising column ever runs on a page where somebody answers a question. The measurement tag loads on the public pages of this site and nowhere else — not in the app, and not on any survey, rating or feedback link. Those pages carry a token in the address, and a measurement tag reports the address it was loaded on. Rather than stripping that out, we do not put the tag there.
| Name | Set by | What it does | Kept for |
|---|---|---|---|
sb-…-auth-token | Us | Keeps you signed in. Required — without it there is no session. | 30 days |
facets_ol_… | Us | Lets you pick up a 360 you joined through an open link without starting again. Set only if you use such a link. | 14 days |
facets_access | Us | Remembers that you asked for the item bank or the research summary, so the link keeps working. | 30 days |
facets_consent | Us | Your answer to the cookie question, so we do not ask again. Set only once you have answered. | 12 months |
| Turnstile | Cloudflare | The bot check on the sign-in form, which runs inside Cloudflare’s own frame and stores what it needs there rather than here. | The sign-in attempt |
_ga, _ga_… | Analytics. Tells one browser from another so a return visit is not counted as a new person. Not set unless you accept. | Google’s default, which we do not change |
How we ask. If you are in the EU, the EEA, the UK or Switzerland, nothing beyond the first four rows is set until you say yes, and declining is one click in the same place as accepting. Elsewhere the measurement cookies are set by default and you can turn them off at any time — see the next section.
Global Privacy Control. If your browser sends a Global Privacy Control signal we treat it as a refusal, on every page, automatically. It overrides an earlier acceptance, because a signal you turned on later is you changing your mind.
We do not use session recording, heat mapping, or any tool that replays what you did on a page.
10US state privacy rights
California, Colorado, Connecticut, Texas, Virginia and a growing list of other states give their residents rights over personal information. Where those laws apply to us, the rights below are yours. Ask by writing to privacy@facets.team — you do not need an account, and an authorised agent may ask on your behalf.
We have never sold anyone’s personal information, and we never will. Not survey answers, not ratings, not email addresses, not anything. That is a promise about how we run this company, and it holds for as long as we run it — if the business itself is ever sold, section 5A says what happens and what you are told.
We do not share it either. Those laws use that word for using what you did on one site to decide what you are shown on another. We buy advertising on Google to bring people here, and we measure which of those ads worked — but we do not build audiences from visitors, we do not add anyone to a remarketing list, and no advertising is shown on this site. Every page we send to Google carries an instruction not to use it for personalised advertising, so this is enforced in the code rather than left to a setting.
The categories we hold are: identifiers (name, work email, the organization you belong to); professional or employment information (role, team, manager, start and end dates); the content you write in the product (ratings, comments, goals, notes); commercial information for customers who pay us (plan, invoices — card numbers go to Stripe and never reach us); and internet activity limited to what is described in the cookie table above. We ask for none of the categories those laws call sensitive — no government identifiers, no financial account numbers, no health data, no precise location, no biometrics — and if you put them in a comment box we would rather you did not.
Your rights are to know what we hold, to get a copy, to correct it, to have it deleted, to opt out of sharing, and to be treated no differently for asking. We will not degrade the service, change the price, or refuse to deal with you because you exercised any of them.
If we say no, you can appeal. Colorado, Connecticut and Virginia require it and we offer it to everyone: reply to our refusal and a different person will look at it again, and tell you the outcome and the reasoning within a reasonable time. If you are still unhappy you can complain to your state attorney general, and we will tell you how.
Note which of us to ask. For anything you did as a customer of ours, ask us. For survey answers, ratings and rosters, your employer decides — see section 1 — and we will pass your request to them and tell you we have done it.
11People under 18
The service is for workplace teams and is not directed at anyone under 18. Account holders confirm they are 18 or over when they accept the terms, and we do not knowingly collect data about anyone younger.
We cannot verify it, so we are telling you how it actually works. Rosters and survey invitations are uploaded by the employer, as names, work email addresses and reporting lines — none of which say anything about age. Sixteen- and seventeen-year-olds hold real jobs in retail, hospitality and food service, so “nobody under 18 is in here” is a fact only the employer is in a position to know. Clause 4 of the terms therefore makes it their obligation not to include anyone under 18, rather than leaving it as something we quietly assume.
If someone under 18 was included anyway, tell us at privacy@facets.team and we will delete what we hold about them and confirm that we have. You do not need an account to use that address.
12Contact
facets.team is operated by GasBuggy Media LLC, gasbuggymedia.com.
For anything in this policy — access, correction, deletion, portability, or an objection — write to privacy@facets.team. You do not need an account to use that address, and you do not need to explain why you are asking.
If you were invited to answer a survey or asked for input about a colleague and would rather not go through whoever invited you, that address reaches us directly. We will tell you which of us can act on the request.
Formal legal notices go to legal@facets.team; general questions to support@facets.team.
Where to write to us. GasBuggy Media LLC, 1209 Mountain Road Pl NE, Ste N, Albuquerque, NM 87110-7825, United States.
EU and UK representative. No participant in the EU or the UK has used the service to date, so no representative has been appointed under Article 27 of the GDPR or its UK equivalent. Before we take one, we will appoint a representative and name them here. If you are about to run a cycle that includes people in either place, tell us first — that is the event that triggers this, and we would rather hear it from you than find out afterwards.
13Changes
If we make material changes we will notify account holders by email and update the date at the top of this page.
Participants are not account holders, so two things stand in place of an email to them. The date at the top of this page always names the version you are reading. And if you answered a survey and want to see the version that was in force on the day you answered, ask at the address in section 12 and we will send you that version within thirty days.
A change does not reach backwards. Answers already given stay under the version of this notice that was in force when they were given. If we ever want a change to apply to data we already hold, we will ask rather than assume — which is the same rule we set ourselves for the research opt-out in the terms.