OyeChats
FeaturesSolutionsIntegrationsPricingDocsCase studiesBlogContact us

Privacy Policy

OyeChats Privacy Policy, how we collect, use, store, share, and protect your data.

Last updated · v1.0

Introduction

OyeChats ("OyeChats," "we," "us," or "our") operates the OyeChats platform, including our website at oyechats.com, the customer dashboard at app.oyechats.com, our REST and WebSocket APIs, the OyeChats mobile application for operators, and the embeddable chat widget our customers deploy on their own websites (collectively, the "Service"). OyeChats is a brand of Digibranders Private Limited (CIN U72900MH2021PTC372344), a company incorporated in India with its registered office at Office No. 2617, 26th Floor, Solus Building, Hiranandani Estate, Ghodbunder Road, Thane West, Maharashtra 400607, India.

This Privacy Policy describes how we collect, use, store, share, and protect personal information when you interact with the Service, whether you are a customer who has signed up for an OyeChats account, an end user ("Visitor") chatting with a bot on a customer's website, or simply browsing oyechats.com. By using the Service, you agree to the practices described here.

Our Role: Controller vs. Processor

Privacy law distinguishes between data "controllers" (who decide why and how data is processed) and "processors" (who handle data on a controller's instructions). Our role differs depending on whose data is involved:

  • Customer data: Where you have signed up for an OyeChats account, we act as the controller of the data we collect from you to operate, bill for, and improve the Service.
  • Visitor data: Where a Visitor interacts with a bot on a customer's website, our customer is the controller of that conversation data and we act as a processor on their behalf, governed by the Data Processing Addendum incorporated into our Terms of Service.

If you are a Visitor with questions about how a specific customer uses your data, please contact that customer directly. We will assist with verified requests forwarded by the controller.

Information We Collect

We collect the following categories of information:

  • Account data: Name, work email address, organization name, hashed password, account role, and optionally a website URL when you register or invite team members. If you choose to sign in with Google, we receive the name, email address, and profile picture associated with that Google account. We request only the openid, email, and profile scopes; we do not request access to your Gmail, Drive, Calendar, or any other Google service.
  • Bot configuration: Bot name, system prompt, appearance settings, business hours, and the knowledge base content (documents you upload or URLs you ask us to crawl).
  • Conversation data: Chat messages between Visitors and the bot or live operators, timestamps, lead-capture form submissions (name, email, phone, company), and qualification signals derived from the conversation.
  • Visitor metadata: The Visitor's IP address, browser and device type, approximate geographic location (city, region, and country) derived from that address, the page URL the widget loaded on, referrer, and UTM campaign parameters. The IP address is recorded in full because it is what geolocation, abuse prevention, and deduplication of repeat visits are performed against. It is never shown in the dashboard, included in a CSV export, or returned by our API: every one of those boundaries strips it and shows only the geography.
  • Derived IP intelligence: From the Visitor's IP address we look up the organization or network that owns it, its autonomous system, and whether it is associated with a hosting provider, VPN, proxy, or known abusive traffic. These are inferred network signals, not a confirmed identification of a Visitor or their employer, and they are frequently wrong about individuals connecting through a consumer internet provider.
  • Email verification results: Where a Visitor submits an email address through a lead-capture form on a plan that includes verification, we check that address against a third-party deliverability service and store the result (valid, invalid, disposable, or unknown) alongside the lead. The check confirms whether an address can receive mail; it does not retrieve any information about the person behind it.
  • Operator data: For customers using live chat, the names, emails, roles, and activity logs of human operators assigned to handle visitor conversations, plus browser and mobile push notification tokens for the operators who opt in to notifications.
  • Usage and diagnostic data: Feature usage counters, API request volumes, error stack traces, performance metrics, and audit logs of administrative actions.
  • Billing data: Plan tier, billing cycle, invoice history, and the last four digits and brand of the payment instrument. Full card numbers, UPI handles, and bank account details are processed and stored by our payment provider, Razorpay, and never reach our servers.
  • Communications: Contents of emails or support tickets you send us.

How We Use Your Information

We use the information described above for the following purposes:

  • Provide, maintain, and operate the Service, including running the retrieval-augmented generation pipeline that answers Visitor questions from your knowledge base.
  • Authenticate users, enforce plan limits, and prevent abuse.
  • Generate lead-qualification signals (BANT scoring) and surface those signals to the customer who owns the conversation.
  • Derive geography and network signals from a Visitor's IP address, so the customer who owns the conversation can see where an enquiry came from and can distinguish genuine enquiries from automated and abusive traffic.
  • Verify the deliverability of email addresses submitted through lead-capture forms, so customers do not send follow-up mail to mistyped or disposable addresses.
  • Send transactional emails such as account verification, password resets, billing notifications, and webhook failure alerts, and deliver push notifications to operators who have opted in.
  • Process payments, issue invoices, and meet tax and accounting obligations.
  • Monitor platform health, debug errors, and investigate security incidents.
  • Improve the Service through aggregated, anonymized analytics. We do not use Customer or Visitor conversation content to train large language models, ours or any third party's.
  • Comply with applicable law and respond to lawful requests from public authorities.

Sub-processors and Data Sharing

We do not sell your personal information. We share data only with the sub-processors and partners we engage to deliver the Service, each under written agreements that require equivalent protections. Categories of sub-processors include cloud infrastructure and hosting, AI model providers, web crawling and content extraction, IP and email intelligence, transactional email and push notification delivery, payment processing, and observability tooling.

The current, itemized list, including each provider's name, purpose, and location, is maintained on our Subprocessors List page.

We may add or change sub-processors from time to time. Material changes affecting how Customer data is handled will be communicated via email or in-product notice with at least 30 days' advance notice where reasonably possible. We may also disclose information when required by law, to protect the rights, property, or safety of OyeChats, our customers, or others, or in connection with a corporate transaction such as a merger or acquisition, in which case we will notify affected customers.

International Data Transfers

OyeChats is operated from India and uses sub-processors located in India, the United States, the European Union, and other jurisdictions. Where personal data is transferred out of the EEA, UK, or India, we rely on appropriate safeguards such as the European Commission's Standard Contractual Clauses, the UK International Data Transfer Addendum, or equivalent mechanisms permitted under the Digital Personal Data Protection Act, 2023. A copy of the relevant transfer mechanism is available on request.

Data Retention

We retain personal information only as long as needed for the purposes described in this policy:

  • Account data: Retained for the life of the account and deleted (or anonymized) within 30 days of account closure, except where longer retention is required by law.
  • Conversation history: Your plan determines how far back conversation history remains available to you, 7 days on Free, 30 days on Starter, 90 days on Standard, and 365 days on Professional. Conversation data older than your plan window is no longer accessible through the dashboard, exports, or the API. It is not automatically deleted from our database at the end of that window; it is deleted when you close your account, or earlier on request as described below.
  • Trial accounts: Conversation and knowledge base data created during a free trial that does not convert to a paid plan is deleted 15 days after the trial ends.
  • Knowledge base content: Retained until you delete it or close your account.
  • Visitor behavioural events (page views, return visits, campaign parameters): Retained for up to 180 days.
  • Diagnostic and error logs: Retained for up to 90 days.
  • Audit logs of administrative actions: Retained for up to 12 months.
  • Push notification tokens: Retained until the operator disables notifications, uninstalls the app, or the token is rejected as stale by the delivery provider.
  • Billing records and invoices: Retained for the period required under applicable tax and accounting law, typically 7 years.
  • Backups: Encrypted database backups are retained for up to 30 days before automatic rotation.

You may request deletion of Visitor or account data at any time by writing to support@oyechats.com from the email address associated with your account. Requests are honored within 30 days unless a legal hold applies. Deletion is currently handled by our team on request rather than through a self-service control in the dashboard.

Security

We apply technical and organizational measures designed to protect personal information against unauthorized access, alteration, disclosure, or destruction. These include encryption in transit (TLS 1.3 for all API and widget traffic), encryption at rest for primary databases and object storage, logical isolation of each customer's data, role-based access controls on production systems, audit logging of administrative actions, and dedicated environments for production and non-production workloads. Production access is restricted to a small number of authorized personnel under multi-factor authentication.

No system can be guaranteed perfectly secure. If you discover a vulnerability, please report it under our Security and Responsible Disclosure Policy, which sets out where to send a report, our safe-harbour commitment, and what is in and out of scope.

Data Breach Notification

If we become aware of a personal data breach that is likely to result in a risk to the rights and freedoms of affected individuals, we will notify our customers without undue delay. Customers are responsible for notifying their own Visitors and any applicable regulators in respect of Visitor data, with our reasonable assistance.

Where the GDPR or UK GDPR applies, we will notify the relevant supervisory authority within 72 hours of becoming aware where required.

Where India's Digital Personal Data Protection Act, 2023 applies to us as a Data Fiduciary, we will give the Data Protection Board of India and each affected Data Principal intimation of the breach without delay, and follow it with the detailed report the Act and its rules require. These are separate obligations from the GDPR timeline above, and we treat them as such rather than relying on one to satisfy the other.

Your Rights

Depending on where you live, you have rights over your personal information. We honor verified requests regardless of residency wherever practical.

If you are in the EEA, UK, or Switzerland (GDPR / UK GDPR): the rights to access, rectification, erasure, restriction of processing, data portability, and objection; the right not to be subject to solely automated decision-making with significant effects; and the right to lodge a complaint with your local supervisory authority.

If you are a California resident (CCPA / CPRA): the rights to know what we collect, to delete personal information, to correct inaccurate information, to opt out of any sale or sharing of personal information (we do not sell or share for cross-context behavioral advertising), and to limit the use of sensitive personal information.

If you are in India (DPDP Act, 2023): the rights to obtain a summary of personal data processed, to correction and erasure, to nominate another individual to exercise your rights in case of incapacity, and to grievance redressal.

To exercise any of these rights, write to support@oyechats.com from the email associated with your account, or contact our Grievance Officer using the details below. We will acknowledge your request within 2 business days and respond within 30 days.

Children's Privacy

OyeChats is intended for use by businesses and is not directed to children. We do not knowingly collect personal information from children under the age of 16 (or under 18 where required by local law, including India under the DPDP Act). If you believe a child has provided us personal information, please contact us and we will delete it.

Because our customers choose where to deploy the chat widget, they are responsible for not deploying it to an audience they know or ought to know consists of children, and for obtaining verifiable parental consent where their own law requires it. This obligation is set out in our Terms of Service.

Cookies and Similar Technologies

We use a small number of strictly necessary cookies on oyechats.com and the customer dashboard for session management, authentication, and CSRF protection, plus an analytics category on the marketing site that runs only with your permission where consent is required. We do not use third-party advertising or cross-site tracking cookies on our own properties.

The embeddable chat widget sets a first-party cookie on the customer's own domain to keep a conversation continuous when a Visitor moves between subdomains, and reads and writes short-lived cookies to work out which domain to scope it to. For the full breakdown of every cookie, including names, lifetimes, and how to control them, see our Cookie Policy.

AI-Generated Content

Answers shown to Visitors are generated by large language models from the customer's own knowledge base. Model outputs are probabilistic and can be incomplete or incorrect even when the underlying source material is accurate. Conversation messages and the retrieved knowledge base passages needed to answer them are sent to our AI model providers at query time. We do not authorize those providers to use Customer or Visitor data to train general-purpose foundation models.

Where the EU AI Act applies, OyeChats is the provider of the AI system and our customer is its deployer. The widget identifies itself as an automated assistant to Visitors, and our Terms of Service prohibit customers from configuring a bot to conceal that it is automated.

Automated Decision-Making

OyeChats generates qualification signals (BANT scoring), conversation summaries, and derived IP and email signals using large language models and third-party data services. These outputs are decision-support information for the customer who owns the conversation; they do not by themselves produce legal or similarly significant effects on a Visitor. Customers remain responsible for any subsequent decisions they take based on these signals.

Changes to This Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, the Service, or applicable law. The "Last updated" date at the top of this page indicates when it was last revised. Material changes will be communicated via email to account administrators or via in-product notice at least 30 days in advance where reasonably possible.

Contact Us and Grievance Redressal

For privacy questions, requests, or complaints, you may contact our Grievance Officer, who also serves as our data protection contact for the purposes of the Digital Personal Data Protection Act, 2023:

  • Grievance Officer and Data Protection Contact: Siddique Ahmed
  • Email: support@oyechats.com
  • Phone: +91 93206 16160
  • Postal address: Digibranders Private Limited, Office No. 2617, 26th Floor, Solus Building, Hiranandani Estate, Ghodbunder Road, Thane West, Maharashtra 400607, India

We acknowledge grievances within 2 business days and aim to resolve them within 30 days.

For general enquiries and technical support, write to support@oyechats.com. For security reports, follow our Security and Responsible Disclosure Policy.

If you are in the EEA or UK and we do not resolve your concern, you may lodge a complaint with your local data protection authority. If you are in India, you may approach the Data Protection Board of India after first raising the matter with our Grievance Officer above.