Onebubbles Demo Help CenterPrivacy Policy — Onebubbles
One bubbles Terms
## Privacy Policy
Last updated: 20 July 2026
Onebubbles ( Onebubbles , we , us ) provides an omnichannel customer-messaging platform that lets businesses (our Customers ) receive and reply to messages from their own end-users across web chat, email, WhatsApp, Telegram, Facebook Messenger, Instagram, and Shopify storefronts. This policy explains what data we handle and why.
## 1. Who is responsible for your data
When a business uses Onebubbles to talk to its customers, that business is the data controller of those conversations; Onebubbles acts as a data processor on its behalf. For our own account holders (the people who sign up for Onebubbles), Onebubbles is the controller.
## 2. Information we collect
Account data: name, work email, password (hashed), workspace name and settings.
Conversation data: messages, attachments, contact details (name, email, phone, social handles) and metadata exchanged between our Customers and their end-users.
Channel data: access tokens and identifiers you connect (e.g. a WhatsApp number, a Facebook Page, an Instagram account) so we can send and receive messages on your behalf.
Usage & device data: IP-derived approximate location, browser and device type, and pages viewed, used to power live-visitor features and to secure the service.
## 3. How we use information
To deliver the core service: routing, storing and displaying conversations.
To provide AI-assisted replies from a Customer s own knowledge base.
To authenticate users, prevent abuse, and keep the service secure.
To provide support and to improve reliability and features.
We do not sell personal data, and we do not use message content to train third-party models.
## 4. Facebook, Instagram & WhatsApp data
When a Customer connects a Meta channel (Facebook Messenger, Instagram, or WhatsApp), we receive messages sent to that Page/account and the sender s platform-scoped id and public profile name, solely to display the conversation in the Customer s inbox and let them reply. We use this data only to provide the messaging service, retain it only as long as needed for that purpose, and do not share it with unrelated third parties. Our use complies with the Meta Platform Terms and Developer Policies. A Customer can disconnect a channel at any time from Settings → Channels, which stops further processing.
## 5. Shopify data
When a Customer installs the Onebubbles Shopify app, we receive the store s customers (name, email, phone), orders, and checkouts through Shopify s APIs and webhooks. We process the minimum needed to: show a customer s profile and order context next to their support conversations, and send abandoned-checkout recovery emails on the merchant s behalf (honouring the buyer s marketing consent). We use this data for no other purpose, never sell it, and keep it isolated per merchant. Uninstalling the app stops all synchronisation; we honour Shopify s mandatory privacy webhooks (customer data requests, customer redaction, shop redaction) and delete the associated personal data within 30 days of a valid request.
## 6. Sub-processors
We rely on trusted providers to run Onebubbles, including: Supabase (database & authentication), Vercel (hosting), Resend (email delivery), Stripe and Shopify (billing), Anthropic (AI replies), and Meta/Telegram/Shopify (channels you connect). Each processes data only as needed to provide their part of the service.
## 7. Data retention
We keep conversation and account data for as long as the account is active. Customers can delete contacts and conversations at any time; on account closure we delete or anonymise personal data within 30 days, except where retention is required by law. Test and demonstration data is kept in dedicated workspaces, separate from customer production data.
## 8. Your rights
Depending on your location (e.g. under the GDPR), you may have the right to access, correct, export, or delete your personal data, and to object to or restrict certain processing. To exercise these rights, contact us at the address below. If your data was provided through a business that uses Onebubbles, we will refer your request to them as the controller.
## 9. Security
Data is encrypted in transit (HTTPS/TLS) and at rest, including backups. Access is restricted with per-workspace isolation and row-level security; staff access to personal data is limited to what is strictly necessary and is logged. We maintain a security incident-response process: we investigate suspected incidents promptly and notify affected customers and authorities without undue delay — and within 72 hours where the GDPR requires it.
## 10. Changes
We may update this policy; we will revise the “last updated” date above and, for material changes, notify account holders.
## 11. Contact
Questions or requests: hola@onebubbles.com .
See also our Terms of Service .