1.Who this covers
CraftiConnect is a shared inbox for customer messaging, operated by [Company legal name]. This policy explains what we do with personal data — both the data of people who use CraftiConnect, and the data of the customers they talk to.
The distinction matters, because our role is different in each case.
2.Two different roles
For workspace content we are a processor. The conversations, contacts, orders and files inside a workspace belong to the organisation that runs it. That organisation decides why the data is collected and what happens to it; we act on its instructions, which in practice are the actions its team takes in the product. If you are a customer who messaged a business using CraftiConnect, that business — not us — is who to ask about your data, and we will point you to them.
For account and billing data we are a controller. Names, emails, phone numbers, sign-in records, plan and payment details, and how the product is used are ours to decide about, and this policy governs them directly.
3.What we collect
Account data — full name, email address, username, phone number, password (stored only as a hash), avatar, language and timezone, workspace name and role.
Sign-in and security data — timestamps, IP address, browser and device description for each session; one-time codes sent to your email; two-factor settings; audit records of security-relevant actions such as role changes, exports and deletions. We keep these to show you your own active sessions and to investigate abuse.
Workspace content — messages sent and received over connected channels and their attachments, contact records, tags, internal notes, assignments, templates, campaigns, orders and reports. Attachments are stored as files in object storage.
Presence and activity — when members are online or away, and reply-time measurements. These power staffing and performance views inside the workspace and are visible to that workspace's admins.
Billing data — plan, invoices, and the billing contact. Card details go directly to our payment processor; we never receive or store full card numbers.
Technical data — logs and error reports needed to keep the service running and to diagnose faults.
We do not use cookies for advertising, and we do not sell personal data to anyone.
4.Where it comes from
- Directly from you, when you sign up, invite a teammate or write a message.
- From a connected messaging network, when it delivers an inbound message — typically the sender's phone number or platform ID, their display name, and any profile picture the network shares.
- From an identity provider, if you sign in with Google, Microsoft or Facebook — your name, email address and profile picture, and nothing else. We do not post anything to those accounts.
- From a connected integration you authorise, such as a store or calendar, limited to what that integration is for.
5.Why we use it, and on what basis
| Purpose | Data used | Legal basis (UK/EU GDPR) |
|---|---|---|
| Providing the service | Account, workspace content, technical | Performance of a contract |
| Keeping accounts secure | Sign-in, security, audit | Legitimate interests — preventing unauthorised access |
| Support and service notices | Account, technical | Performance of a contract |
| Billing and tax records | Billing, account | Contract and legal obligation |
| Improving and troubleshooting the product | Aggregated usage, error logs | Legitimate interests — a service that works |
| Product marketing emails | Name and email | Consent, withdrawable in one click |
Where we rely on legitimate interests, we have weighed them against your rights and use the least data that achieves the purpose.
6.Automated features and AI
Some features process message text automatically — for example suggested replies, summaries or routing. Where such a feature uses a third-party model provider, message text is sent to that provider only to produce the result and is not used to train their models.
We do not use your workspace content to train models for ourselves or anyone else. No feature makes a decision with a legal or similarly significant effect on a person without a human involved.
8.International transfers
We host in [region]. Some providers above operate elsewhere, so data may be transferred outside your country. Where that happens we rely on adequacy decisions or on Standard Contractual Clauses with additional safeguards. Ask us at [privacy@yourdomain.com] for the mechanism that applies to a given provider.
9.How long we keep it
| Data | Kept for | Then |
|---|---|---|
| Workspace content | As long as the workspace exists | Deleted with the workspace |
| Account data | While your account is active | Deleted or anonymised |
| Sign-in and audit records | [12] months | Deleted |
| Billing and tax records | [7] years, as tax law requires | Deleted |
| Backups | [30] days on a rolling cycle | Overwritten |
Deleting a workspace is permanent. When the owner deletes it, everyone is signed out, channels stop receiving, and content is removed from the database and from object storage. Backups then age out on the cycle above. We cannot restore a deleted workspace, so export anything you need first.
10.How we protect it
- Tenant isolation is enforced in the database. Every workspace-owned table has a row-level security policy tied to the workspace of the current request, so a query cannot reach another workspace's rows even if application code is wrong.
- Encryption in transit (TLS) and at rest; channel credentials stored encrypted.
- Passwords stored only as salted hashes, never in a readable form.
- Workspace-level security controls — session lifetime, idle timeout, maximum concurrent sessions, required two-factor authentication, minimum password length and IP allowlists — configurable by admins under Settings → Security.
- Access to production limited to staff who need it, and logged.
If a breach affects your data, we will notify the workspace owner without undue delay and within the deadlines the law sets, with what we know and what we are doing about it.
11.Your rights
Depending on where you live, you may have the right to access your data, correct it, have it deleted, restrict or object to how it is used, receive a portable copy, and withdraw consent at any time. Exercising them will not get you worse service.
Much of this is self-service in the product:
- Profile — see and correct your own details, and sign out sessions on other devices.
- Settings → Data — export conversations, contacts and orders as CSV.
- Contacts — delete or block an individual customer record.
- Settings → General — the owner can delete the entire workspace.
For anything else, write to [privacy@yourdomain.com]. We respond within 30 days. If we hold your data only as a processor for a business you messaged, we will forward your request to that business and tell you we have done so.
You can also complain to your data protection authority — in the UK, the ICO; in the EU, the authority where you live.
13.Children
CraftiConnect is a business tool and is not directed at children under 16. We do not knowingly collect their data as account holders; if you believe a child has created an account, tell us and we will remove it.
14.Changes and contact
We will update this policy as the product changes. The date at the top always reflects the current version, and for material changes we notify workspace owners by email at least [30] days before they take effect.
Contact: [privacy@yourdomain.com] · [Company legal name, registered address] · Data protection officer / EU representative: [if appointed].
See also our Terms of Service.

