Skip to content

Security and privacy, built in

Your customers trust you with their questions, contact details and orders. Here's how Chatloom protects that trust, and the tools it gives you to meet privacy laws like GDPR and the UAE's PDPL.

How we protect data

Safeguards at every layer

Encrypted everywhere

HTTPS for all traffic, an encrypted private network to the database, and encryption at rest. Keys for connected apps are encrypted a second time by Chatloom.

Never used to train AI

Your content and your customers' chats are used only to run your chatbot. We don't sell data, use it for advertising, or train AI models on it.

Access you control

Each business's data lives in its own workspace. Owners, admins and members get different rights, and only owners and admins can connect apps or use privacy tools.

Every view logged

Opening a chat, viewing leads or exporting data is recorded in an access log that owners and admins can read and download, kept for a year.

Backed up nightly

Automatic nightly backups kept for four weeks, plus an extra backup before every database change.

Least privilege

Connections ask only for what they need. Shopify access, for example, is read-only and limited to orders.

Privacy tools

Answer privacy requests in minutes

When a customer asks what you hold about them, or to be forgotten, everything you need is on one page in Chatloom.

  • Choose how long chats are kept: 30 days to a year, or until you delete them
  • Find everything held about a visitor by their email, in seconds
  • Download a visitor's data, or delete all of it, for access and erasure requests
  • A privacy notice under the chat, with a link to your own policy
  • Ready-made wording for your website's privacy policy
  • Shopify order details deleted automatically after 90 days

Agreements

Clear terms for your data

Every customer gets our Data Processing Agreement as part of the Terms: we process your customers' data only on your instructions, keep it secure, and help you meet your obligations.

Service providers we use

ProviderPurpose
Railway CorporationUnited StatesHosting, database and backupsAlways
Anthropic, PBCUnited StatesAI model that writes chat replies, summaries and labelsAlways
Resend, Inc.United StatesSending Chatloom's emails (password reset, invites, alerts, weekly reports)Always
Stripe, Inc.United StatesPayments and billing for paid plansPaid plans
Slack Technologies, LLCUnited StatesAlerts posted to the business's Slack channelOnly if the business connects Slack
Shopify Inc.Canada / United StatesLooking up a customer's order in the chatOnly if the business connects Shopify
Cal.com, Inc. / Calendly LLCUnited StatesBooking calls from the chatOnly if the business adds booking links
Browser push services (Apple, Google, Mozilla)United StatesDelivering notifications to team members' devicesOnly for people who turn on notifications

Incident response

If something goes wrong

We keep a written incident response policy. In short:

  1. 01

    Detect and report

    Anyone who suspects a problem, staff, customers or researchers, reports it to [email protected]. Reports are acknowledged within one business day.

  2. 02

    Assess and contain

    We confirm what's affected and stop it: revoking access, replacing keys, disconnecting integrations or taking a feature offline.

  3. 03

    Notify

    If customers' personal data is affected, we tell affected customers without undue delay and within 72 hours, with what happened and what we're doing.

  4. 04

    Recover and learn

    We restore from backups where needed, record every incident, review its cause and improve our safeguards. The policy is reviewed every year.

Found a security problem?

Email the details and how to reproduce it. Please don't access other people's data or disrupt the service while testing. We'll respond quickly and keep you informed.

[email protected]

Your website, answering customers tonight.

Set up your chatbot in minutes. Start free, no card needed.