Yeah, it would work.
Basically you'd just have a text file of comment on the server but NOT in the public_html folder - that way the server can still read the contents but no one can view the page of comments by itself.
To add to the page just append the comment to the end of the file, separating files by tabs (\t) or something, and putting each new entry on a separate line.
To extract the data just assign the contents of the text file to a variable and use explode (keyword) to get the person's name / email address and the comment for each new line.
Obviously if you want to let people edit their comments (i.e. if they make a mistake), etc. then doing it this way would be recommended even less!