All documents

Data processing terms

Version 5 · Effective September 17, 2026

Data processing terms

These terms apply whenever we handle personal data on your behalf — the details of your customers, their orders, and the people you employ. They sit alongside the Legal terms and the Privacy notice, and they exist to say plainly who is responsible for what, because "we take privacy seriously" is not a commitment anybody can hold us to.

The English text governs. This document may be shown in Spanish or another language as a courtesy. Where a translation differs from the English, the English controls, as Section 19.1 of the Legal terms sets out.

1. Which of us is responsible

For the personal data you put into the platform — your customers, their orders, your workers — you are the controller and we are the processor. You decide what to collect and why. We act on your instructions, and using the product is how you give them.

For the personal data we hold about you as our customer — your account, your billing, your support conversations — we are the controller, and the Privacy notice describes that separately.

If you connect a sales channel such as Shopify, the customer data that arrives from it is yours in exactly the same way. We process it to bring your orders into the platform, help you fulfil them, and send fulfilment and tracking back. Nothing more.

In the words the statutes use. We are a "service provider" under the California Consumer Privacy Act, and a "processor" under the equivalent laws of Virginia, Colorado, Connecticut, Utah, Texas and the other states that use that term. We do not sell personal data and we do not share it for cross-context behavioural advertising. We do not retain, use or disclose it for any purpose other than performing the service for you, and we do not combine it with personal data obtained from anywhere else, except where those laws expressly permit a service provider to. We certify that we understand those restrictions and will comply with them — which is language those statutes require in a contract, and which we would rather state here than have you ask for an addendum.

2. What we do with it, and what we never do

We process personal data only to provide the product to you, to keep it secure, and to meet legal obligations. Specifically, we do not:

  • sell personal data, or share it for anyone else's advertising;
  • use your customers' personal data to train machine-learning models;
  • use it to market our own products to your customers;
  • access it to build a competing service, or to profile the people in it.

Where the product uses an AI feature, the data sent to that provider is limited to what the feature needs and is not used by them to train models.

3. Sub-processors

We use these providers to run the service. Each is bound by terms at least as protective as these, and each is used for one purpose:

ProviderPurpose
NeonDatabase hosting (AES-256 at rest, TLS 1.2/1.3 in transit, encrypted backups)
VercelApplication hosting and file storage
ResendTransactional and campaign email
TwilioSMS and WhatsApp conversations, where you enable them
Meta (WhatsApp)WhatsApp conversations, where you enable them and a customer chooses WhatsApp
Stripe, SquarePayment processing, where you enable it
SentryError monitoring
CloudflareBot protection on public forms
OpenAIAI assistance features, where your workspace enables them
QuickBooksAccounting sync, where you enable it
ShopifyMarketplace sync, where you enable it

Meta is the exception to the paragraph above the table. It receives WhatsApp conversations under its own terms with you, as the business that connected WhatsApp, rather than on our instructions or under terms we set.

This list and the one in Section 4 of the Privacy notice describe the same providers. Where they ever differ, the Privacy notice is the one to read: Section 7 of the Legal terms commits us to the providers named there and no others without notice.

We will tell you before adding a sub-processor that handles personal data, with enough notice for you to object.

4. Security

The measures we actually operate, rather than a list of aspirations:

  • Encryption in transit (TLS 1.2/1.3) and at rest (AES-256), including backups.
  • Integration credentials encrypted separately, with their own key, so a database copy alone does not yield access to your connected accounts.
  • Passwords hashed with argon2id, a twelve-character minimum, and multi-factor authentication — required for workspace owners.
  • Role-based access inside each workspace, with an append-only audit log of significant actions.
  • An access log recording who read personal data — which surface, when, and how many records at a time, so a bulk export is visible next to ordinary use. Kept for 400 days, then deleted.
  • Every query scoped to one workspace, checked by an automated audit that fails the build if a path can reach another workspace's data.
  • Test and production data held in separate database branches, never the same one.

Section 7 of the Privacy notice sets out the retention periods, and Section 9 there describes these safeguards in the form we publish them. We keep a fuller internal data protection policy covering data loss prevention and incident response, and we will share it with you under Section 9 of this document.

5. Telling you about a breach

If personal data you control is exposed, we will tell you without undue delay, and in any case within 72 hours of becoming aware. We will tell you what happened, what data was involved, what we have done, and what we recommend you do — including whatever you need in order to notify a regulator or the people affected. We will not wait until we have a complete picture before telling you there is one.

Two things that commitment is not. It is not an admission: telling you about an incident, and telling you early, is not an acknowledgment of fault or liability by us or by anyone else, and we would rather say so here than have that fear slow a notification down. And it does not cover events that are not incidents — failed logins, port scans, pings, and the ordinary background noise every internet-facing system absorbs are not reportable and are not counted.

6. Your people's rights

If one of your customers or workers asks to see, correct, export or delete their data, that request is yours to answer, and the product gives you the tools to do it. Where you need us, we will help, without charge, within the time the law gives you to respond.

Where a connected sales channel sends us a deletion or data request on a customer's behalf — as Shopify does — we act on it and record that we did.

7. Deletion and return

You can export your data at any time while your account is active. When your account ends, we delete it on the schedule in the Privacy notice, except where the law requires us to keep something — billing records, for instance — or where a legal hold applies.

Uninstalling a connected sales channel deletes the credentials for it immediately and the data associated with that connection on the schedule that channel requires.

8. Where data is held

Data is processed in the United States. If we transfer personal data out of a region that restricts it, we do so under a lawful transfer mechanism, and we will tell you which.

9. Audit

If you need evidence of our compliance for your own obligations, ask. We will provide what we have — our security documentation, our retention schedule, our sub-processor list, and any third-party reports we hold — and answer reasonable questions about it. We would rather answer them than have you assume.

Four limits, so this stays a commitment we can actually keep rather than an open door:

  1. Once in any twelve-month period, unless a confirmed incident affecting your data gives cause for another.
  2. Remotely, through documents and written answers. There is no on-site inspection and no access to our production systems: a third party inside production is itself a risk to every other customer's data, which is the thing an audit is supposed to be protecting.
  3. Under confidentiality, at your own cost, and without disturbing the running of the service. Where an audit finds a material failure on our side, we bear its cost and the cost of fixing what it found.
  4. Nothing we provide will contain another customer's data, and nothing we provide is a certification: we hold no third-party security certification of our own, though our sub-processors do. We would rather say so in the same breath as offering the evidence than let the offer imply an audit that has not happened.

10. Your side of this

You instruct us by using the product, and those instructions have to stay inside what the product documents itself as doing. Where you give us one that falls outside it, we may decline, and we will tell you why rather than quietly not doing it.

You confirm that you have a lawful basis for the personal data you put into the platform, that you have given the people in it whatever notice their jurisdiction requires, and that you hold the consent that data needed — including messaging consent and workforce monitoring consent. Section 7 of the Legal terms sets out that division in full, and Section 14 of that document is the indemnity that follows from it.

11. Sub-processors, and the limit on liability

We remain responsible to you for a sub-processor's performance of these terms as if it were our own performance. That responsibility, and every other claim under this document, is subject to the limitation of liability in Section 13 of the Legal terms, which governs this document exactly as it governs that one.

There is one liability cap across every agreement between us, not one per document. This document does not create a second one, and nothing in it should be read as raising the first.

Where this document and the Legal terms conflict about how we handle personal data on your behalf, this one wins. On everything else — liability, indemnity, termination and disputes — the Legal terms win.