Legal
Privacy Policy
Last updated 21 September 2026
This policy explains what personal data Squidfy (“we”, “us”) collects, why, and the choices you have. It covers visitors to our website, the people who sign in to the Service, and — as a processor — the end customers who message our customers’ WhatsApp numbers.
1. Two roles
- Our own data (controller). For website visitors, contact-form senders and account holders, we decide how the data is used.
- Our customers’ data (processor). When a business connects WhatsApp, the messages, names and phone numbers of its customers are processed by us on that business’s instructions. The business is the controller and is responsible for informing its customers and having a lawful basis.
2. What we collect
- Account data: your email address, name, role and workspace details.
- Workspace content: knowledge-base entries, leads, notes, campaign and template content you add.
- Conversation data: WhatsApp messages (text, voice notes, images), sender name and phone number, timestamps and delivery status.
- Billing data: subscription and plan status. Card details are handled by Stripe; we never see or store full card numbers.
- Contact messages: your name, email and message when you write to us.
- Technical data: a session cookie that keeps you signed in, and basic server logs (IP address, browser, pages requested) used for security and debugging.
3. How we use it
- To provide the Service: authenticate you, show conversations, and generate and send AI replies.
- To take payment and manage your plan.
- To send sign-in links, needs-a-human alerts and other service emails.
- To respond to your enquiries and provide support.
- To secure the Service, prevent abuse and meet legal obligations.
We do not sell personal data. As a processor we use your customers’ conversations only to provide the Service to you — never for our own purposes, advertising, or to train AI models.
4. Who we share it with
We use a small number of service providers, only as needed to run the Service:
- Meta (WhatsApp Business Platform) — delivers and receives WhatsApp messages.
- OpenAI — generates AI replies and transcribes voice notes. Message content and relevant knowledge-base text are sent to OpenAI for that purpose only. We do not use this data to train or improve AI models, and we use OpenAI’s API under terms that do not permit OpenAI to train on it.
- Stripe — processes subscription payments.
- Hostinger — sends and receives our email (including sign-in links and contact messages) and provides hosting infrastructure.
We may also disclose data if required by law or to protect rights, safety and the security of the Service.
5. International transfers
Our providers operate globally, so data may be processed outside your country. Where required, we rely on appropriate safeguards such as standard contractual clauses.
6. Retention
We keep workspace data while your account is active. When a workspace is deleted, we delete or anonymise its data within a reasonable period, except where we must keep records (for example billing records) for legal reasons. Raw webhook deliveries from Meta and Stripe are kept for 30 days for debugging and then deleted. WhatsApp access tokens are stored encrypted. Sign-in links expire within minutes and are single-use. Contact messages are kept as long as needed to handle your request.
7. Security
We use encryption in transit, encryption at rest for WhatsApp access tokens and PINs, signed and HTTP-only session cookies, verified webhook signatures, and access controls between workspaces. No system is perfectly secure; if we become aware of a breach affecting you, we will notify you as the law requires.
8. Cookies
We use only a strictly necessary session cookie to keep you signed in. We do not use advertising or third-party tracking cookies on this site.
9. Your rights
Depending on where you live, you may have the right to access, correct, delete or export your personal data, to object to or restrict certain processing, and to complain to your data-protection authority. To exercise these rights, email info@squidfy.com. If you are a customer of a business that uses Squidfy, please contact that business first — it controls your conversation data — and we will help it respond. See also our data deletion instructions and our Data Processing Addendum.
10. Children
The Service is intended for businesses and is not directed at children under 16. We do not knowingly collect their data.
11. Changes
We may update this policy and will change the “last updated” date above. For material changes we will notify account holders by email or in the app.
12. Contact
Privacy questions: info@squidfy.com or our contact page. See also our Terms of Service.
