Privacy policy
What personal data Hushdesk collects, why, how long we keep it, and the choices you have.
Last updated 6 October 2026
This page is a carefully written template that has not yet been reviewed by a lawyer. It will be finalised before Hushdesk opens to the public.
This policy explains how Hushdesk (“we”, “us”) handles personal data when you visit our website, create an account, or use the Hushdesk product. It also explains how we handle the data of your customers that you store in Hushdesk.
Two roles
- For our own customers and website visitors, we decide why and how personal data is used. We are the controller.
- For the conversations, customers and orders you store in Hushdesk, you decide. You are the controller and we process that data on your behalf as your processor, under our Data processing agreement.
What we collect
When you visit the website
- Pages viewed, approximate location from your IP address, browser and device type. Analytics run only if you accept them in the cookie banner.
- What you type into our chat widget or contact form.
When you create and use an account
- Your name, work email, password (stored only as a one-way hash), and optional profile photo.
- Sign-in records: devices, approximate location, and times, so you can see and end your sessions.
- Two-step sign-in secrets and passkey public keys, stored encrypted or as public keys only.
- Billing details, handled by our payment providers (Stripe, or Shopify for app installs). We never see full card numbers.
What you store in Hushdesk (as our customer)
- Conversations, messages, attachments, customer profiles and order data from connected stores.
Why we use it
- To provide the service you signed up for (contract).
- To keep accounts secure, prevent abuse and fix problems (legitimate interest).
- To send service emails such as sign-in links and invoices (contract).
- To send product news, only if you opt in (consent).
- To meet legal obligations such as tax records (legal obligation).
We do not sell personal data, and we do not use your customers’ conversations to train AI models.
AI features
When you use AI features, the relevant ticket text and order data are sent to the AI provider configured for your workspace to produce a reply. Providers we use are listed on the Sub-processors page and are contractually barred from training on this data.
How long we keep it
- Account data: while your account is open, then deleted within 30 days of closing it.
- Workspace data: until you delete it, or 30 days after your workspace is closed.
- Sign-in records: 90 days.
- Billing records: as long as tax law requires.
Your rights
Depending on where you live, you can ask to access, correct, export or delete your personal data, and object to or restrict some uses. Most of this you can do yourself in your account. For anything else, email privacy@hushdesk.tech. You can also complain to your local data protection authority.
Transfers
Our hosting provider and the countries our providers work from are listed on the Sub-processors page. Where data moves to a country without an adequacy decision, we rely on standard contractual clauses.
Changes
We will post changes here and, for significant ones, tell account owners by email before they take effect.
Contact
Hushdesk · privacy@hushdesk.tech