Onebubbles Demo Help Center

Privacy Policy — Onebubbles

Privacy Policy — Onebubbles One bubbles Terms ## Privacy Policy Last updated: 20 July 2026 Onebubbles ( Onebubbles , we , us ) provides an omnichannel customer-messaging platform that lets businesses (our Customers ) receive and reply to messages from their own end-users across web chat, email, WhatsApp, Telegram, Facebook Messenger, Instagram, and Shopify storefronts. This policy explains what data we handle and why. ## 1. Who is responsible for your data When a business uses Onebubbles to talk to its customers, that business is the data controller of those conversations; Onebubbles acts as a data processor on its behalf. For our own account holders (the people who sign up for Onebubbles), Onebubbles is the controller. ## 2. Information we collect Account data: name, work email, password (hashed), workspace name and settings. Conversation data: messages, attachments, contact details (name, email, phone, social handles) and metadata exchanged between our Customers and their end-users. Channel data: access tokens and identifiers you connect (e.g. a WhatsApp number, a Facebook Page, an Instagram account) so we can send and receive messages on your behalf. Usage & device data: IP-derived approximate location, browser and device type, and pages viewed, used to power live-visitor features and to secure the service. ## 3. How we use information To deliver the core service: routing, storing and displaying conversations. To provide AI-assisted replies from a Customer s own knowledge base. To authenticate users, prevent abuse, and keep the service secure. To provide support and to improve reliability and features. We do not sell personal data, and we do not use message content to train third-party models. ## 4. Facebook, Instagram & WhatsApp data When a Customer connects a Meta channel (Facebook Messenger, Instagram, or WhatsApp), we receive messages sent to that Page/account and the sender s platform-scoped id and public profile name, solely to display the conversation in the Customer s inbox and let them reply. We use this data only to provide the messaging service, retain it only as long as needed for that purpose, and do not share it with unrelated third parties. Our use complies with the Meta Platform Terms and Developer Policies. A Customer can disconnect a channel at any time from Settings → Channels, which stops further processing. ## 5. Shopify data When a Customer installs the Onebubbles Shopify app, we receive the store s customers (name, email, phone), orders, and checkouts through Shopify s APIs and webhooks. We process the minimum needed to: show a customer s profile and order context next to their support conversations, and send abandoned-checkout recovery emails on the merchant s behalf (honouring the buyer s marketing consent). We use this data for no other purpose, never sell it, and keep it isolated per merchant. Uninstalling the app stops all synchronisation; we honour Shopify s mandatory privacy webhooks (customer data requests, customer redaction, shop redaction) and delete the associated personal data within 30 days of a valid request. ## 6. Sub-processors We rely on trusted providers to run Onebubbles, including: Supabase (database & authentication), Vercel (hosting), Resend (email delivery), Stripe and Shopify (billing), Anthropic (AI replies), and Meta/Telegram/Shopify (channels you connect). Each processes data only as needed to provide their part of the service. ## 7. Data retention We keep conversation and account data for as long as the account is active. Customers can delete contacts and conversations at any time; on account closure we delete or anonymise personal data within 30 days, except where retention is required by law. Test and demonstration data is kept in dedicated workspaces, separate from customer production data. ## 8. Your rights Depending on your location (e.g. under the GDPR), you may have the right to access, correct, export, or delete your personal data, and to object to or restrict certain processing. To exercise these rights, contact us at the address below. If your data was provided through a business that uses Onebubbles, we will refer your request to them as the controller. ## 9. Security Data is encrypted in transit (HTTPS/TLS) and at rest, including backups. Access is restricted with per-workspace isolation and row-level security; staff access to personal data is limited to what is strictly necessary and is logged. We maintain a security incident-response process: we investigate suspected incidents promptly and notify affected customers and authorities without undue delay — and within 72 hours where the GDPR requires it. ## 10. Changes We may update this policy; we will revise the “last updated” date above and, for material changes, notify account holders. ## 11. Contact Questions or requests: hola@onebubbles.com . See also our Terms of Service .