Legal
Privacy Policy
This Policy explains what information ChatResponder collects, how we use it, and the choices available to you and your contacts.
Last updated: July 25, 2026
1. Who this covers
This Privacy Policy applies to the ChatResponder website, dashboard, APIs, MCP gateway, webhooks, and embeddable widget (the "Service"). It covers:
- Customers and workspace users — people who create or join a ChatResponder workspace.
- End users / contacts — people who message a customer through Instagram, Messenger, SMS, web chat, or other connected channels.
- Website visitors — people who browse our marketing pages.
Customers are typically the "controller" of messaging and contact data they process through the Service; we act as a "processor" / service provider for that Customer Data. For account and Service operation data, we act as a controller.
2. Information we collect
Account and workspace information. Name, email address, authentication identifiers, organization/workspace membership, and profile details provided through our auth provider (Clerk).
Customer Data you upload or sync. Contacts, tags, custom fields, conversation transcripts, media, flow graphs, broadcasts, sequences, channel configuration, API keys (hashed), audit logs, and approval requests.
Channel connection data. Page IDs, Instagram account IDs, phone numbers, display names, and encrypted access tokens needed to send and receive messages. Webhook payloads from Meta, Twilio, and similar providers.
Widget visitor data. Anonymous visitor session identifiers, messages sent through the embeddable widget, and optional domain allowlist settings configured by the customer.
Usage and technical data. Log data, device/browser information, IP address, approximate location derived from IP, timestamps, error reports, and product analytics needed to operate and secure the Service.
Cookies and similar technologies. Described in our Cookie Policy.
3. How we use information
- Provide, operate, maintain, and improve the Service
- Authenticate users and enforce workspace tenancy and permissions
- Route, store, and deliver messages across connected channels
- Run automations, broadcasts, sequences, and background jobs
- Enforce plan limits, prevent abuse, and secure accounts and APIs
- Provide support and respond to requests
- Comply with law and enforce our Terms and Acceptable Use Policy
- Send Service-related notices (security, product, or administrative)
We do not sell personal information.
4. Legal bases (EEA/UK where applicable)
Where GDPR/UK GDPR applies, we rely on:
- Contract — to provide the Service you request
- Legitimate interests — to secure, improve, and administer the Service in ways that do not override your rights
- Consent — where required (for example certain cookies or optional communications)
- Legal obligation — when we must retain or disclose information
For Customer Data about end users, customers are responsible for establishing a valid legal basis (including messaging consent) before using the Service to contact them.
6. Retention
We retain account and Customer Data for as long as the workspace remains active and as needed to provide the Service. After deletion or account closure, we delete or de-identify data within a reasonable period, except where we must retain it for legal, security, dispute, or backup purposes. API idempotency records and similar operational data may be retained for short TTLs.
7. Security
We use administrative, technical, and organizational measures designed to protect personal information, including encryption of channel access tokens at rest, tenancy checks on dashboard and API access, hashed API keys, and transport encryption (HTTPS). No method of transmission or storage is fully secure; you are responsible for safeguarding credentials and reviewing member access.
8. International transfers
We and our providers may process data in the United States and other countries. Where required, we use appropriate transfer mechanisms (such as standard contractual clauses) for transfers from the EEA/UK/Switzerland.
9. Your rights and choices
Depending on where you live, you may have rights to access, correct, delete, export, or restrict processing of personal information, or to object to certain processing and to withdraw consent. Workspace users can update profile details through account settings or our auth provider. To exercise rights related to Customer Data about end users, contact the customer who operates the workspace first; we will assist customers with verified requests.
California residents may have additional rights under the CCPA/CPRA, including the right to know, delete, and correct personal information, and to opt out of “sale” or “sharing” as those terms are defined by law. We do not sell personal information and do not share it for cross-context behavioral advertising.
To submit a privacy request, email info@rallanmedia.com, or use Data deletion for Meta Login deletion status. We may need to verify your identity before responding.
10. Children
The Service is not directed to children under 16 (or under 13 where that is the applicable standard), and we do not knowingly collect personal information from children. If you believe a child has provided us personal information, contact us and we will take appropriate steps to delete it.
11. Changes
We may update this Policy from time to time. The "Last updated" date will change when we post revisions. Material changes may also be communicated through the Service or by email where appropriate.
12. Contact
Privacy questions or requests: info@rallanmedia.com
Related documents: Terms of Service, Acceptable Use Policy, Cookie Policy.