Privacy Policy
Last updated: October 8, 2026
This policy explains what personal data intoCHAT ("we", "us") processes, why, who helps us process it, how long we keep it, how we protect it, and the choices you have. It covers our website, the intoCHAT dashboard, the AI agents our customers build with intoCHAT, and the integrations they connect, including Shopify and WooCommerce.
1. Who this policy covers, and our role
We act in two roles.
- As the controller, for the data of people who use our website or have an intoCHAT account: account holders, their team members, and people who contact us.
- As a processor, for the data that flows through the AI agents our customers ("businesses") build: their website visitors' conversations, the contact details visitors give, and order data from a connected store. The business decides what its agent does and is the controller of that data; we process it only on its behalf and on its instructions.
If you chatted with an agent on a business's website, that business is responsible for your data. Contact it first; we help it answer your request.
2. Data we process
Account and team data:
- Name, email address and company, and your password, stored only as a one-way hash.
- If you sign in with Google: your name, email address and profile picture from Google.
- Two-factor authentication: the authenticator secret, stored encrypted, and recovery codes, stored only as hashes.
- Team membership: who belongs to which account and with which role.
- Billing: handled by Stripe. We store your plan and Stripe's customer and subscription identifiers, never card numbers.
Content a business adds to its agents: website pages we read for it, files, text and Q&A, and Notion pages it connects.
Data from conversations with an agent, processed on the business's behalf:
- Messages and the agent's replies, and files a visitor attaches when the business allows it.
- The visitor's approximate country, derived from the IP address by our hosting provider; the IP address itself is not stored with the conversation. The page the chat started on, without its query string.
- Ratings, and, when the business turns them on, topic and sentiment labels, spam checks and summaries of ended conversations.
- Details the visitor chooses to give: contact details, form answers, meeting bookings, and return or exchange requests.
- When the business uses identity verification: the user ID, name, email and other details its own website passes for a signed-in visitor.
- Messages written by the business's team in a live chat.
Order data from a store the business connects (Shopify or WooCommerce):
- To answer a visitor's question about an order, the agent reads that order's number, date, status, items, shipment tracking and total. It does not store them.
- Each lookup is recorded in an access log with its time, the order number and the outcome, without the email or the order's contents. The log is kept for 90 days.
- The order's email address is read only to check that the visitor gave the same email (or is the signed-in customer). It is never shown to the AI or stored for a lookup.
- We do not request customers' names, phone numbers, addresses or payment details from Shopify, and we never show them to the AI.
- If the business turns on returns, a return or exchange request stores the order number, email, items and reason the visitor gave, so the business can handle it.
Technical data:
- IP addresses, used briefly to prevent abuse (rate limits) and kept in our hosting providers' logs for their retention period.
- On our website and dashboard (not in the chat widget), Vercel Analytics measures how pages are used without cookies, and Google Analytics does so with cookies only if you accept them in the cookie banner.
3. How we use data
We use personal data only to:
- Provide intoCHAT: run agents, answer visitors for the business, and show the business its conversations, leads and statistics.
- Verify that a visitor owns an order before the agent shares its status, and pass return requests to the business.
- Send the emails, webhooks and Slack messages the business turns on, and service messages to account holders.
- Keep intoCHAT secure: authentication, rate limits, spam protection and preventing misuse.
- Bill subscriptions, provide support, and improve intoCHAT using aggregate usage statistics.
We do not sell personal data, use it for advertising, or use it for automated decisions with legal or similarly significant effects. We do not train AI models on our customers' or their visitors' data: agents answer by looking up the business's own knowledge at the moment a question is asked.
4. How the AI is used
To write a reply, the visitor's message, recent conversation history and the relevant parts of the business's knowledge are sent to OpenAI. OpenAI is also used to index knowledge, and, where the business turns them on, for topic and sentiment labels, spam checks, conversation summaries, reply drafts for its team, and web search. Under OpenAI's API terms, data sent through its API is not used to train its models by default, and OpenAI may keep it for up to 30 days to detect abuse.
5. Service providers
We use these providers to run intoCHAT. Each processes data only to provide its service to us:
- Vercel: hosting, file storage and website analytics.
- Supabase: database.
- Redis Cloud (Redis Ltd., EU): short-lived data for rate limits.
- OpenAI: AI replies and the other AI features above.
- Firecrawl: reading the website pages a business adds.
- Resend: emails.
- Stripe: payments.
- Google: sign-in with Google, and Google Analytics on our website.
When a business connects them, we also exchange data with Shopify, WooCommerce, Notion, Cal.com, Calendly, Slack, Zendesk, Freshdesk and HubSpot, and send webhooks to addresses the business chooses.
6. How long we keep data
- Account data: for as long as the account exists. Deleting your account deletes its agents, conversations, leads and other content.
- Conversations, leads, form answers, bookings and return requests: until the business deletes them, the agent or its account. Where the business allows it, visitors can delete their own chat.
- Attached files: deleted with their conversation; files uploaded but never sent are removed after 24 hours.
- Order data from a store: not stored. A lookup reads it, answers, and keeps nothing. Each lookup's access-log entry (time, order number, outcome) is deleted after 90 days.
- Shopify: uninstalling the intoCHAT app deletes the store's connection and its return requests. When Shopify forwards a customer's or a store's deletion request, we delete that customer's return requests, or all data for that store.
- Backups and logs: kept by our database and hosting providers for their limited retention periods, then overwritten.
7. How we protect data
- Encryption in transit (HTTPS) everywhere, and encryption at rest for the database and its backups.
- Credentials for connected services (store keys and tokens, Notion, calendars, identity verification secrets, two-factor secrets) are additionally encrypted by intoCHAT with AES-256-GCM. Passwords and recovery codes are stored only as hashes.
- Two-factor sign-in for accounts, roles for team members, and rate limits on sign-in and on order lookups.
- Separate development and production environments and data.
- Access to production systems is limited to the people who need it, using two-factor authentication.
- Only the minimum data is requested from connected stores, and order data is not stored.
If a security incident affects personal data, we investigate and contain it, and inform affected businesses without undue delay, and within the time limits the law sets, so they can inform their customers. No system is completely secure, but we work to keep risks low.
8. Your rights
Depending on where you live, you can ask to access, correct, delete or export your personal data, or object to or restrict how we use it. Account holders can update their details and delete their account in Settings. For anything else, email privacy@intochat.ai. If you chatted with a business's agent, contact that business: it controls that data, and we help it respond. You may also complain to your data protection authority.
9. International transfers
Our database, which holds the data intoCHAT stores, is hosted in Switzerland. Some of our providers process data in the United States and other countries; where the law requires it, these transfers rely on the providers' standard contractual clauses or other approved safeguards.
10. Cookies and browser storage
The dashboard uses cookies to keep you signed in and remember which account you are working in. The chat widget stores an ID in the visitor's browser to continue the conversation, and, when the business turns them on, a list of earlier chats and whether the launcher is shown. Our website and dashboard set Google Analytics cookies only after you accept them in the cookie banner, and you can change your choice with Cookie settings. See our Cookie Policy for details.
11. Children
intoCHAT is not directed at children under 16, and we do not knowingly collect their personal data.
12. Businesses and data processing agreements
Businesses that need a data processing agreement for the data their agents process can request one at privacy@intochat.ai. Businesses are responsible for telling their visitors and customers how their agent uses their data, for example in their own privacy policy.
13. Changes
When we change this policy, we update the date at the top. If a change is significant, we also tell account holders by email before it takes effect.
14. Contact us
Questions about this policy or your data: privacy@intochat.ai.