Security and privacy, built in
Your customers trust you with their questions, contact details and orders. Here's how Chatloom protects that trust, and the tools it gives you to meet privacy laws like GDPR and the UAE's PDPL.
How we protect data
Safeguards at every layer
Encrypted everywhere
HTTPS for all traffic, an encrypted private network to the database, and encryption at rest. Keys for connected apps are encrypted a second time by Chatloom.
Never used to train AI
Your content and your customers' chats are used only to run your chatbot. We don't sell data, use it for advertising, or train AI models on it.
Access you control
Each business's data lives in its own workspace. Owners, admins and members get different rights, and only owners and admins can connect apps or use privacy tools.
Every view logged
Opening a chat, viewing leads or exporting data is recorded in an access log that owners and admins can read and download, kept for a year.
Backed up nightly
Automatic nightly backups kept for four weeks, plus an extra backup before every database change.
Least privilege
Connections ask only for what they need. Shopify access, for example, is read-only and limited to orders.
Privacy tools
Answer privacy requests in minutes
When a customer asks what you hold about them, or to be forgotten, everything you need is on one page in Chatloom.
- Choose how long chats are kept: 30 days to a year, or until you delete them
- Find everything held about a visitor by their email, in seconds
- Download a visitor's data, or delete all of it, for access and erasure requests
- A privacy notice under the chat, with a link to your own policy
- Ready-made wording for your website's privacy policy
- Shopify order details deleted automatically after 90 days
Agreements
Clear terms for your data
Every customer gets our Data Processing Agreement as part of the Terms: we process your customers' data only on your instructions, keep it secure, and help you meet your obligations.
Service providers we use
| Provider | Purpose |
|---|---|
| Railway CorporationUnited States | Hosting, database and backupsAlways |
| Anthropic, PBCUnited States | AI model that writes chat replies, summaries and labelsAlways |
| Resend, Inc.United States | Sending Chatloom's emails (password reset, invites, alerts, weekly reports)Always |
| Stripe, Inc.United States | Payments and billing for paid plansPaid plans |
| Slack Technologies, LLCUnited States | Alerts posted to the business's Slack channelOnly if the business connects Slack |
| Shopify Inc.Canada / United States | Looking up a customer's order in the chatOnly if the business connects Shopify |
| Cal.com, Inc. / Calendly LLCUnited States | Booking calls from the chatOnly if the business adds booking links |
| Browser push services (Apple, Google, Mozilla)United States | Delivering notifications to team members' devicesOnly for people who turn on notifications |
Incident response
If something goes wrong
We keep a written incident response policy. In short:
- 01
Detect and report
Anyone who suspects a problem, staff, customers or researchers, reports it to [email protected]. Reports are acknowledged within one business day.
- 02
Assess and contain
We confirm what's affected and stop it: revoking access, replacing keys, disconnecting integrations or taking a feature offline.
- 03
Notify
If customers' personal data is affected, we tell affected customers without undue delay and within 72 hours, with what happened and what we're doing.
- 04
Recover and learn
We restore from backups where needed, record every incident, review its cause and improve our safeguards. The policy is reviewed every year.
Found a security problem?
Email the details and how to reproduce it. Please don't access other people's data or disrupt the service while testing. We'll respond quickly and keep you informed.
Your website, answering customers tonight.
Set up your chatbot in minutes. Start free, no card needed.