Legal

Privacy Policy

What we collect, why we collect it, who it goes to, and how long we keep it — including the difference between your account data and the customer conversations inside your workspace.

Last updated

Template — have a lawyer review it. This text describes how CraftiConnect actually handles data and what the service does, so it is a realistic starting point. It is not legal advice, and the bracketed placeholders must be completed for your company and jurisdiction before you publish it.

1.Who this covers

CraftiConnect is a shared inbox for customer messaging, operated by [Company legal name]. This policy explains what we do with personal data — both the data of people who use CraftiConnect, and the data of the customers they talk to.

The distinction matters, because our role is different in each case.

2.Two different roles

For workspace content we are a processor. The conversations, contacts, orders and files inside a workspace belong to the organisation that runs it. That organisation decides why the data is collected and what happens to it; we act on its instructions, which in practice are the actions its team takes in the product. If you are a customer who messaged a business using CraftiConnect, that business — not us — is who to ask about your data, and we will point you to them.

For account and billing data we are a controller. Names, emails, phone numbers, sign-in records, plan and payment details, and how the product is used are ours to decide about, and this policy governs them directly.

3.What we collect

Account data — full name, email address, username, phone number, password (stored only as a hash), avatar, language and timezone, workspace name and role.

Sign-in and security data — timestamps, IP address, browser and device description for each session; one-time codes sent to your email; two-factor settings; audit records of security-relevant actions such as role changes, exports and deletions. We keep these to show you your own active sessions and to investigate abuse.

Workspace content — messages sent and received over connected channels and their attachments, contact records, tags, internal notes, assignments, templates, campaigns, orders and reports. Attachments are stored as files in object storage.

Presence and activity — when members are online or away, and reply-time measurements. These power staffing and performance views inside the workspace and are visible to that workspace's admins.

Billing data — plan, invoices, and the billing contact. Card details go directly to our payment processor; we never receive or store full card numbers.

Technical data — logs and error reports needed to keep the service running and to diagnose faults.

We do not use cookies for advertising, and we do not sell personal data to anyone.

4.Where it comes from

  • Directly from you, when you sign up, invite a teammate or write a message.
  • From a connected messaging network, when it delivers an inbound message — typically the sender's phone number or platform ID, their display name, and any profile picture the network shares.
  • From an identity provider, if you sign in with Google, Microsoft or Facebook — your name, email address and profile picture, and nothing else. We do not post anything to those accounts.
  • From a connected integration you authorise, such as a store or calendar, limited to what that integration is for.

5.Why we use it, and on what basis

Providing the serviceAccount, workspace content, technicalPerformance of a contract
Keeping accounts secureSign-in, security, auditLegitimate interests — preventing unauthorised access
Support and service noticesAccount, technicalPerformance of a contract
Billing and tax recordsBilling, accountContract and legal obligation
Improving and troubleshooting the productAggregated usage, error logsLegitimate interests — a service that works
Product marketing emailsName and emailConsent, withdrawable in one click

Where we rely on legitimate interests, we have weighed them against your rights and use the least data that achieves the purpose.

6.Automated features and AI

Some features process message text automatically — for example suggested replies, summaries or routing. Where such a feature uses a third-party model provider, message text is sent to that provider only to produce the result and is not used to train their models.

We do not use your workspace content to train models for ourselves or anyone else. No feature makes a decision with a legal or similarly significant effect on a person without a human involved.

7.Who we share it with

We share personal data only with service providers who help us run CraftiConnect, under contracts that bind them to use it for nothing else. The categories are:

Messaging networksThe messages you send and receive, and sender identifiersMeta (WhatsApp, Instagram, Messenger), Telegram, LINE, Viber
Cloud hostingAll service data, encrypted at rest[Hosting provider, region]
Object storageAttachments and exports[Storage provider]
Email deliveryAddress and message body of service emails[Email provider]
PaymentsBilling contact and payment method[Payment processor]
Error monitoringTechnical logs, which may include identifiers[Monitoring provider]
Identity providersOnly what you choose to sign in withGoogle, Microsoft, Facebook

A current list of sub-processors is available at [link]. Customers on a data processing agreement are notified before we add one.

We may also disclose data where the law requires it — and where we are allowed to tell you about such a request, we will. If the business is ever sold or merged, data moves with it and you will be told beforehand.

8.International transfers

We host in [region]. Some providers above operate elsewhere, so data may be transferred outside your country. Where that happens we rely on adequacy decisions or on Standard Contractual Clauses with additional safeguards. Ask us at [privacy@yourdomain.com] for the mechanism that applies to a given provider.

9.How long we keep it

Workspace contentAs long as the workspace existsDeleted with the workspace
Account dataWhile your account is activeDeleted or anonymised
Sign-in and audit records[12] monthsDeleted
Billing and tax records[7] years, as tax law requiresDeleted
Backups[30] days on a rolling cycleOverwritten

Deleting a workspace is permanent. When the owner deletes it, everyone is signed out, channels stop receiving, and content is removed from the database and from object storage. Backups then age out on the cycle above. We cannot restore a deleted workspace, so export anything you need first.

10.How we protect it

  • Tenant isolation is enforced in the database. Every workspace-owned table has a row-level security policy tied to the workspace of the current request, so a query cannot reach another workspace's rows even if application code is wrong.
  • Encryption in transit (TLS) and at rest; channel credentials stored encrypted.
  • Passwords stored only as salted hashes, never in a readable form.
  • Workspace-level security controls — session lifetime, idle timeout, maximum concurrent sessions, required two-factor authentication, minimum password length and IP allowlists — configurable by admins under Settings → Security.
  • Access to production limited to staff who need it, and logged.

If a breach affects your data, we will notify the workspace owner without undue delay and within the deadlines the law sets, with what we know and what we are doing about it.

11.Your rights

Depending on where you live, you may have the right to access your data, correct it, have it deleted, restrict or object to how it is used, receive a portable copy, and withdraw consent at any time. Exercising them will not get you worse service.

Much of this is self-service in the product:

  • Profile — see and correct your own details, and sign out sessions on other devices.
  • Settings → Data — export conversations, contacts and orders as CSV.
  • Contacts — delete or block an individual customer record.
  • Settings → General — the owner can delete the entire workspace.

For anything else, write to [privacy@yourdomain.com]. We respond within 30 days. If we hold your data only as a processor for a business you messaged, we will forward your request to that business and tell you we have done so.

You can also complain to your data protection authority — in the UK, the ICO; in the EU, the authority where you live.

12.Cookies and local storage

We use the minimum needed to run the product:

  • a session cookie that keeps you signed in and lets your workspace subdomain recognise you;
  • local storage for interface preferences — theme, sidebar state, drafts and the conversation you had open — which stays in your browser;
  • a small number of security cookies that protect against cross-site request forgery.

No advertising or cross-site tracking cookies are set, by us or by anyone else.

13.Children

CraftiConnect is a business tool and is not directed at children under 16. We do not knowingly collect their data as account holders; if you believe a child has created an account, tell us and we will remove it.

14.Changes and contact

We will update this policy as the product changes. The date at the top always reflects the current version, and for material changes we notify workspace owners by email at least [30] days before they take effect.

Contact: [privacy@yourdomain.com] · [Company legal name, registered address] · Data protection officer / EU representative: [if appointed].

See also our Terms of Service.