1. Scope and our roles
- For account, workspace, billing, security, and service-contact data, chatnoww determines the purposes of processing.
- For messages and customer data a business imports or receives through connected channels, that business determines the purposes and chatnoww processes the data on its behalf to provide the CRM and unified inbox.
- This policy covers service users, team members, and end customers who message a business through a connected channel.
2. Data we collect and its sources
- Account and business data, such as name, email, username, phone number, role, workspace name, plan information, and verification status.
- Data from LINE, Facebook Messenger, and Instagram, such as user or Page identifiers, display name, profile picture, messages, attachments, timestamps, delivery status, and conversation data.
- CRM data added by a business, such as email, phone number, tags, notes, custom fields, assignee, and interaction history.
- Payment data, such as amount, reference, bank, slip image, and slip-verification result. We do not collect online-banking passwords or bank login credentials.
- Technical data, such as IP address, browser type, timestamps, event and error logs, and security signals from Cloudflare Turnstile.
- Channel access tokens and secrets are encrypted before storage.
3. Purposes and lawful bases
- We use data to create and maintain accounts, deliver the service, connect channels, receive and send messages, manage contacts, run reports and automation, and provide support.
- We use data to manage plans, verify payments, send service email, prevent fraud, secure and troubleshoot the service, and comply with law.
- We rely on contract, legal obligation, legitimate interests, and consent where required. A business using chatnoww remains responsible for an appropriate lawful basis for its customer data.
- We do not sell personal data or use customer messages for chatnoww advertising.
4. AI and OpenRouter
- When a business enables an AI feature and requests a response, relevant messages, instructions, business-provided knowledge, and necessary context may be sent to OpenRouter to generate the result.
- Every chatnoww request to OpenRouter instructs model providers to deny data collection. Users should still avoid submitting unnecessary sensitive data.
- Content is not sent to OpenRouter unless the business enables or invokes an AI feature.
5. Payments and Slip2Go
- When a slip is uploaded, the slip image, amount, and necessary reference data may be sent to Slip2Go to verify authenticity and detect duplicate slips.
- The result is used to confirm or review the transaction. Evidence may be retained as needed for transactions, fraud prevention, disputes, and legal obligations.
6. Recipients and third-party services
- Meta and LINE receive or provide information when a business connects their respective channels and process it under their own terms.
- OpenRouter supports AI features, Slip2Go verifies slips, Resend delivers service email, and Cloudflare provides traffic delivery, bot protection, and availability analytics.
- We may disclose data to infrastructure providers, advisers, or authorities only when necessary and legally permitted, with appropriate data-protection requirements.
7. International transfers
- Some providers may process data outside Thailand. We use reasonable safeguards and contractual requirements designed to protect data under applicable law.
8. Retention and security
- We retain data while an account or workspace is active and afterward only as needed for service delivery, transactions, security, disputes, and legal obligations. We then delete or de-identify it.
- We use access controls, credential encryption, event logging, backups, and other technical and organizational measures to reduce unauthorized-access risk.
- No system can guarantee absolute security. Users must protect their credentials and notify us promptly of suspected compromise.
9. Your rights and data deletion
- Subject to applicable law, you may request access, a copy, correction, portability, objection, restriction, consent withdrawal, or data deletion. We may verify identity and may decline a request where law permits.
- Messenger or Instagram users can remove the app through Facebook settings. Meta then sends a signed data deletion request; after validation, the system deletes the related conversations, messages, and channel identity and returns a confirmation code and status URL.
- A contact profile, tags, or notes separately created by a business in its CRM remain under that business's control. Contact the business directly or email [email protected] so we can coordinate and act in the appropriate role.
10. Cookies and similar technologies
- We use cookies necessary for login, security, language settings, and service operation, including Cloudflare Turnstile to prevent harmful automated activity.
11. Changes and contact
- We may update this policy when the service, providers, or law changes. We will display the latest revision date and provide appropriate notice of material changes.
- For questions, rights requests, or privacy incidents, contact [email protected].
Privacy and terms contact
For questions, privacy-rights requests, or data deletion, contact the chatnoww team at [email protected]