1. Who this policy applies to
- Customers — businesses and individuals who register for a ChatSaaS account and configure bots, widgets, and team access.
- End users — visitors who interact with the chat widget embedded on a customer's website. In those cases, our customer is typically the data controller for end-user data, and ChatSaaS acts as a processor providing the platform.
2. Information we collect
Account and profile data
When you sign up or sign in, we may collect your name, email address, authentication credentials (passwords are stored using industry-standard hashing), and optional Google account information when you use Google sign-in (via Firebase Authentication).
Business and configuration data
We store data you provide to operate the Service, including website URLs, bot knowledge base content, widget appearance settings, team member invitations, API keys, webhook endpoints, and billing plan selections.
Chat, lead, and support data
Messages exchanged through the widget, conversation metadata, lead information captured in chat flows, agent replies, and related support records are stored to deliver inbox, analytics, and automation features.
Technical and usage data
We automatically collect information such as IP address, browser type, device identifiers, session cookies, API usage, and error logs. Authentication uses secure cookies (for example, session tokens with SameSite protections).
Payment data
Subscription payments are processed by third-party providers (such as Stripe or PayU). We do not store full payment card numbers on our servers. We may receive billing status, transaction references, and limited payment metadata from those providers.
3. How we use information
- Provide, maintain, and improve the Service
- Authenticate users and enforce role-based access controls
- Generate AI-assisted chat responses using configured knowledge and LLM providers
- Capture and manage leads on behalf of our customers
- Process subscriptions, invoices, and usage limits
- Send service-related communications and security alerts
- Detect abuse, fraud, and violations of our Terms of Service
- Comply with legal obligations
4. AI and automated processing
ChatSaaS uses artificial intelligence to suggest or generate responses in chat conversations. Message content and relevant knowledge-base context may be transmitted to configured large-language-model (LLM) providers to produce replies. AI output may be inaccurate; customers remain responsible for reviewing critical communications.
5. How we protect your data
We implement technical and organizational measures designed to protect personal data, including:
- Encryption in transit — data transmitted between your browser, our APIs, and embedded widgets is protected using HTTPS/TLS.
- Encryption at rest for sensitive secrets — selected credentials (such as API keys and encrypted provider configuration) are protected using AES-based encryption before storage.
- Access controls — multi-tenant isolation, JWT-based authentication, and role-based permissions limit access to tenant data.
- Webhook security — webhook deliveries can be verified using signing secrets you configure.
- Infrastructure security — we host the Service on secured cloud infrastructure with restricted administrative access.
No method of transmission or storage is 100% secure. We cannot guarantee absolute security, but we work to maintain safeguards appropriate to the nature of the data we process.
6. Data sharing and subprocessors
We may share information with:
- Infrastructure providers — hosting, databases (e.g. MongoDB), and caching (e.g. Redis)
- Authentication providers — Google Firebase for optional Google sign-in
- AI / LLM providers — as configured in your account for bot responses
- Payment processors — Stripe, PayU, or other gateways enabled for your region
- Professional advisers and authorities — when required by law or to protect rights and safety
We do not sell personal data.
7. Data retention
We retain account and service data for as long as your subscription is active or as needed to provide the Service. Chat and lead records are retained according to your plan and configuration. After account termination, we may retain certain data for a limited period for backups, billing, dispute resolution, and legal compliance, after which it is deleted or anonymized where feasible.
8. Your rights
Depending on your location, you may have rights to access, correct, delete, restrict, or export personal data, and to object to certain processing. Account holders can manage much of their data in the tenant panel. To exercise rights or request deletion, contact us at privacy@chatsaas.com.
9. International transfers
Your information may be processed in countries other than your own. Where required, we implement appropriate safeguards for cross-border data transfers.
10. Children
The Service is not directed to children under 16 (or the minimum age required in your jurisdiction). We do not knowingly collect personal data from children.
11. Changes to this policy
We may update this Privacy Policy from time to time. We will post the revised version on this page and update the "Last updated" date. Material changes may be notified via email or in-product notice.
12. Contact us
Questions about this Privacy Policy or our data practices: privacy@chatsaas.com
General support: support@chatsaas.com
See also our Terms and Conditions.