Privacy Policy
Last updated: 14 July 2026
GrapeChat ("we", "our", the "Service") is an omnichannel customer-messaging platform that lets businesses receive and reply to customer conversations from channels such as LINE, Facebook Messenger, and Instagram in one place. This policy explains what data we process, why, and the choices you have.
1. Who this policy covers
It covers two groups: (a) business users — the shop owners, supervisors, and agents who use GrapeChat to answer chats; and (b) end customers — the people who message a business through a connected channel. We act as a data processor on behalf of the business for end-customer data.
2. Data we collect
- Account data (business users): name, email, password hash, role, and team.
- Channel connection data: the credentials or access tokens you provide (or authorize via "Connect with Facebook") so we can receive and send messages on your behalf.
- Conversation data: messages sent to or from your connected channels, the sender's public profile (display name and avatar as provided by the channel), timestamps, and delivery status.
- Operational data: assignment history, SLA timings, agent presence, and audit logs of significant actions.
We do not collect payment card numbers or other special-category data through the Service.
3. How we use data
- Route incoming messages to the right agent and show a continuous conversation history.
- Send replies back to the customer on the originating channel.
- Measure response-time commitments (SLA) and produce team performance dashboards.
- Secure the Service, prevent abuse, and maintain audit records.
We do not sell personal data, and we do not use message content for advertising.
4. Platform data (Meta, LINE)
When you connect a Meta (Facebook / Instagram) or LINE account, we receive data through their official APIs and handle it in line with their platform terms. Page and channel access tokens are stored encrypted at rest (AES-256-GCM) and are used only to deliver the messaging features you enabled. We request the minimum permissions needed to receive and send messages for your connected accounts.
5. Sharing
We share data only with infrastructure sub-processors that host and run the Service (for example, our cloud and database providers), under confidentiality obligations, and with the messaging platforms themselves as required to deliver your messages. We may disclose data where required by law.
6. Retention & deletion
Conversation and account data are retained for as long as your workspace is active. You can disconnect a channel at any time in Connections, which stops further data collection from it. To request deletion of a workspace or of a specific end customer's data, email [email protected] from the account owner's address; we action verified requests within 30 days.
7. Security
Access tokens and channel secrets are encrypted at rest. Passwords are hashed. Access to the Service is authenticated and scoped per workspace, so one business cannot see another's conversations.
8. Contact
Questions or requests: [email protected].