Privacy policy
Last updated: [DATE]
ChannelDesk helps online shops look after the comments on their Facebook Pages: it hides spam, sorts questions and drafts replies that a person approves. This page explains what data that involves, what we do with it, who helps us run the service, how long we keep it and how to get it deleted.
Who we are
ChannelDesk is run by [COMPANY NAME], [COMPANY NUMBER, registered in England and Wales], of [REGISTERED ADDRESS] (“we”, “us”). For anything about your data, email [privacy@channeldesk.ai].
There are two kinds of data in ChannelDesk, and our role is different for each:
- Your account. When you sign up, invite teammates or pay for a plan, we decide what is collected and why, so for that data we are the controller.
- Comments on the Pages you connect. These belong to the business that connected the Page. We process them only to provide ChannelDesk to that business and only as it instructs, so for that data the business is the controller and we are its processor. If you commented on a shop’s Page and want to know what it holds about you, ask that shop first; we will help it answer.
What we collect
When you use ChannelDesk
- Account details: your name, email address and sign-in details. Sign-in is handled by Clerk; if you sign in with Google, Clerk receives your name, email address and profile picture from Google.
- Workspaces and teams: the workspaces you create, who you invite, and each person’s role.
- Billing: your plan, billing currency and the customer and subscription references Stripe gives us. Card details go straight to Stripe; we never see or store them.
- What you teach it: the rules you write, the answers you approve, the pages of your website you ask us to read, and your product catalogue (names, prices, stock and links) if you connect one.
- A record of what happened: an audit log of actions taken in your workspace, by a person or by a rule, and why.
From the Facebook Pages you connect
- Page access: the Page’s name and ID, and an access token that lets us read its comments and act on them. Page tokens are encrypted before they are stored. The personal Facebook token used to connect is exchanged for Page tokens and never stored.
- Comments: the text of each comment and reply, the commenter’s name and Facebook ID as Meta provides them, which post it was left on, and when. Meta also notifies us of new comments; we keep that notification only until the comment has been processed, and then remove its copy of the text.
- What ChannelDesk did with it: the label it gave the comment (for example “purchase question” or “spam”), which of your rules matched, any reply drafted, and whether it was hidden, answered or left for review.
When you visit channeldesk.ai
This website has no analytics, advertising or tracking scripts. It remembers whether you chose to see prices in pounds or dollars, in your own browser, and nothing is sent to us about that choice. Like any website, our hosting provider, Cloudflare, processes your IP address and basic request details to deliver the page and protect it from abuse. Signing in to the app sets the cookies needed to keep you signed in.
How we use it
- To provide ChannelDesk: sort comments, apply your rules, draft replies, and hide or answer comments on your Page when you or your rules tell us to.
- To send the emails the service needs: invitations, alerts about comments waiting for you, and account and billing messages.
- To bill you for a paid plan.
- To keep the service secure, find and fix faults, and prevent abuse.
- To answer you when you contact us.
We do not sell data, we do not use it for advertising, and we do not use the comments on your Page for anything other than providing ChannelDesk to you. Our legal bases under UK GDPR are performing our contract with you, our legitimate interest in running a secure and reliable service, and complying with the law (for example, keeping billing records).
How the AI is used
To label a comment and draft a reply, we send the comment’s text, and the parts of your website, catalogue or approved answers that are relevant to it, to AI models through OpenRouter, a service that routes requests to model providers. We use them to label comments, to draft replies, and to pick out useful passages from the website pages you give us.
- A person approves every reply before it is posted. ChannelDesk never posts a reply on its own.
- Automatic actions are limited to what your rules allow, such as hiding comments your rules mark as spam.
- We do not train AI models on your data.
Who processes data for us
We use these services to run ChannelDesk. Each receives only what it needs for its part.
| Service | What for | Where |
|---|---|---|
| Cloudflare | Hosting the app and this website, processing comments in the background, and sending the service’s emails | Worldwide network |
| PlanetScale | The database that stores your workspace | London, UK (on Amazon Web Services) |
| Clerk | Sign-in and account security | United States |
| Stripe | Payments and subscriptions | United States and elsewhere |
| OpenRouter, and the AI model providers it routes to | Labelling comments and drafting replies | United States and elsewhere |
| Meta | The Facebook Pages you connect, which is where the comments come from | United States and elsewhere |
Some of these services are outside the UK. Where data leaves the UK, we rely on the protections UK law requires, such as the UK International Data Transfer Agreement or an adequacy decision.
How long we keep it
- Comments and everything attached to them (labels, drafts and actions) are deleted automatically once they are older than your workspace’s retention setting: 30, 90, 180 or 365 days. The default is 180 days.
- Disconnecting a Page discards its access token straight away and stops new comments arriving. Comments already received stay in your history until retention removes them.
- Deleting a workspace discards every Page token and pauses everything straight away. After 7 days, the workspace and all of its comments, rules, knowledge and history are permanently deleted.
- Meta’s notifications of new comments are deleted within 30 days of being processed.
- Your account is kept while you use ChannelDesk. Billing records are kept for as long as tax law requires.
How to delete your data sets out each way to do it.
Your rights
Under UK data protection law you can ask for a copy of the data we hold about you, ask us to correct or delete it, ask us to restrict or stop using it, and ask for it in a portable format. Email [privacy@channeldesk.ai] and we will answer within [30] days. If you are unhappy with our answer, you can complain to the Information Commissioner’s Office at ico.org.uk.
Security
Data travels encrypted between your browser, our services and Meta. Page access tokens are encrypted before they are stored. Access to each workspace is limited to the people in it, and the part of ChannelDesk that serves requests can read and write data but cannot change how the database is structured.
Who ChannelDesk is for
ChannelDesk is a tool for businesses. It is not meant for children, and we do not knowingly collect data from them.
Changes to this policy
If we change what we collect or how we use it, we will update this page and its date. If a change matters, we will tell account owners by email before it takes effect.
Contact
Privacy questions and requests: [privacy@channeldesk.ai]. Everything else: [support@channeldesk.ai]. Post: [COMPANY NAME], [REGISTERED ADDRESS].