# OyeChats: full text > AI chatbot that answers visitors from your own docs, scores their intent with BANT, and routes qualified buyers to a live human. OyeChats is an AI chatbot for websites. It answers visitor questions grounded in your own documentation via retrieval-augmented generation (RAG), so replies stay accurate to your content instead of a model's training data. As each conversation unfolds, OyeChats reads it for Budget, Authority, Need, and Timeline signals and produces a composite BANT lead score from 0 to 100. When a lead heats up, the chat is handed to a live human teammate in the same thread, with the full transcript and score already attached. Installation is a single script tag on any website. Every event is delivered to your CRM or your own endpoint via HMAC-signed webhooks, and live dashboards show what actually converts. # Pricing - Free: free. - Starter: $7.99/mo international, ₹599/mo in India. - Standard: $15.99/mo international, ₹1,199/mo in India. - Professional: $45.99/mo international, ₹2,999/mo in India. - Enterprise: $89.99/mo international, ₹5,999/mo in India. # Pricing FAQ ## What's a credit? Credits are how OyeChats measures usage. Each AI chat reply uses 1 credit, each email verification uses 10 credits, each URL scan uses 5 credits, each company name lookup uses 5 credits, and each document upload uses 3 credits. System emails and live-chat operator messages are always free. ## Which currency will I be billed in? Pricing is shown in your local currency. Customers in India are billed in INR (₹); international customers are billed in USD ($). You always see a single currency based on your location. ## How do I pay? Indian customers pay via Razorpay: UPI, cards, NetBanking, and wallets are all supported. International customers pay by card in USD. You can switch payment methods any time from the Billing page. ## Is GST included in these prices? No. Every price shown is a base price. Customers in India are charged 18% GST on top at checkout, and it appears as a separate line on the tax invoice. International customers pay in USD and are not charged Indian GST; any tax due in your own country is your responsibility. Extra operator seats, the branding removal add-on, and credit top-up packs are base prices too. ## Is there a free trial? Yes. Every new account starts on a 14-day trial with the full Professional feature set, one chatbot and one operator seat, and no credit card. Training your website for the first time is free. When the trial ends the account moves to the Free plan and nothing is deleted: your chatbots, knowledge base and conversations are all kept, and knowledge above the Free allowance is paused until you upgrade. ## What happens when I run out of credits? Your bot pauses new conversations until your monthly credits reset, or you can buy a top-up pack any time from the Billing page. We hard-cap at zero (costs never run away) with a friendly message to visitors. ## Do unused credits roll over? Plan credits reset at the start of each billing cycle (use-it-or-lose-it). Top-up credits never expire and are used oldest first. ## Can I add more operator seats? Yes. Extra seats are ₹499 (or $5 for international customers) per month each, added or removed with one click from the Billing page. INR prices exclude GST, which is added at checkout. ## Can I remove the "Powered by OyeChats" branding? Yes, as a paid add-on on any paid plan. It costs ₹499 (or $5 for international customers) per month per workspace and is not bundled into any plan. Switch it on from the Billing page and the badge inside the widget disappears. ## Can I change plans at any time? Absolutely. Upgrade, downgrade, or cancel any time from your dashboard. Downgrades take effect at the end of the billing cycle. ## How does BANT scoring work? OyeChats analyzes every conversation across Budget, Authority, Need, and Timeline, scoring each dimension and combining them into a composite 0 to 100 lead score. That score drives webhook notifications and lead-tier assignments. ## Is annual billing charged upfront? Yes. Annual billing is charged as a single payment at the start of the year, giving you approximately 20% savings versus monthly. ## Do you offer discounts for startups or non-profits? Yes. Contact us at support@oyechats.com and we will work out the right pricing. # Articles ## How much does an AI chatbot actually cost? A 2026 breakdown in ₹ and $ Source: https://www.oyechats.com/blog/ai-chatbot-cost Published: 2026-07-16 Category: Buyer Guide A small team can run a capable AI chatbot on its website for anywhere from nothing to a few tens of dollars (a few thousand rupees) a month on a flat plan, and a good deal more on usage-based pricing. The wide gap comes down to one thing: whether a vendor charges you a predictable subscription or bills you per resolved conversation. Usage-based tools look cheap on the pricing page and get expensive the month your traffic spikes. This is the trap that surprises people, so it is worth walking through slowly. ## How much does an AI chatbot cost per month? For a small business, a flat-rate AI website chatbot typically ranges from a free tier up to roughly a few thousand rupees (on the order of $10 to $40) a month, depending on how many conversations, seats, and trained documents you need. Resolution-priced enterprise tools instead charge per successfully answered conversation, which can run far higher once volume climbs. The right question is not "what is the sticker price" but "what does my bill look like on a busy month". ## The three pricing models you will actually meet Almost every chatbot on the market bills in one of three ways. Knowing which one you are looking at tells you more than any headline number. ### Flat subscription You pay a fixed monthly fee for a tier, and usage inside that tier is included. Your bill is the same whether you have a quiet week or a launch week. This is the easiest model to budget against, and it is how OyeChats prices: a Free plan to start, then Starter, Standard, and Professional tiers you can read on the [pricing page](/pricing). ### Per-seat You pay for each human agent who logs in. Fine when your team is small and stable, painful when support is seasonal or you want the whole company to be able to jump into a live chat. Watch for tools that combine a per-seat fee with a usage fee on top. ### Per-resolution or per-conversation You pay each time the bot resolves a conversation. This is common at the enterprise end. It aligns cost with value in theory, but it also means a viral post or a bad-news day, exactly when volume spikes, is also when your invoice spikes. Model your worst month, not your average one, before you sign. ## What transparent pricing looks like Whatever tool you choose, favour one whose plans you can read on a single page without booking a sales call. The healthiest signs are a public pricing page, a real free tier, plain monthly figures, and a clear limit on each plan, so you can predict next month from this month. If the only way to learn the price is a demo, treat that as information too. OyeChats, for example, runs on flat monthly plans with a free tier and separate India (INR) and international (USD) rates. The current figures live on the [pricing page](/pricing) rather than in this article on purpose: prices should have one source of truth that stays up to date, not a number copied into a blog post that quietly goes stale. ## The costs that never appear on the pricing page The subscription is rarely the whole bill. Four line items quietly decide whether a cheap plan stays cheap. 1. Overage. What happens on the message, conversation, or document that goes past your tier? A flat plan absorbs it; a metered plan invoices it. 2. Seats. If everyone who might handle a live handoff needs a paid login, a "cheap" per-seat tool gets expensive as the team grows. 3. Retraining and re-crawls. Some tools charge to re-index your site when your docs change. Ask whether keeping the bot current is included. 4. Integrations. Webhooks, a REST API, and CRM connections are sometimes locked to the top tier. If routing leads into your stack matters, price the tier that unlocks it, not the entry one. ## Is an AI chatbot worth the cost? For most teams handling repeat questions or qualifying inbound leads, yes, the monthly fee is small next to a single support hire or a single closed deal. Gartner projects that by 2029 agentic AI will autonomously resolve [80% of common customer-service issues](https://www.gartner.com/en/newsroom/press-releases/2025-03-05-gartner-predicts-agentic-ai-will-autonomously-resolve-80-percent-of-common-customer-service-issues-without-human-intervention-by-20290) and cut related operational costs by around 30%. Even a fraction of that, on an entry-level flat plan, pays for itself quickly. The honest caveat, also from Gartner, is that more than 40% of agentic-AI projects are expected to be scrapped by the end of 2027, almost always because they were bought without a clear job to do. So the cost question and the value question are the same question. Pick the smallest plan that covers a specific, measurable task, prove it deflects tickets or books calls, then move up a tier. That is a far better path than buying the biggest plan and hoping. ## How to choose the plan that fits 1. Estimate your busy-month conversation volume, not your average, and check what a metered plan would bill at that number. 2. Count how many humans truly need a login versus how many just need to read transcripts. 3. Confirm whether retraining on updated docs is included or billed. 4. Check which tier unlocks the webhook or API you need to move leads into your CRM. 5. Start on the smallest plan that clears those four, and only upgrade once the bot has earned it. An AI chatbot should be one of the more predictable lines in your software budget, not one of the scary ones. If you cannot tell what next month will cost from this month, that is not a pricing detail: it is the whole decision. Once you have picked a plan, the next step is [training the bot on your own website](/blog/train-ai-chatbot-website). ### How much does an AI chatbot cost per month? For a small team, a flat-rate AI website chatbot usually ranges from a free tier up to roughly a few thousand rupees a month (on the order of $10 to $40), depending on conversation volume, seats, and how many documents it is trained on. Enterprise tools that charge per resolved conversation can cost significantly more at higher volumes. ### Are there free AI chatbots for websites? Yes. Several platforms, including OyeChats, offer a free plan that lets you train one bot on your website and run it end to end, which is enough to validate whether it deflects tickets or captures leads before you pay. ### Why is usage-based chatbot pricing risky for small businesses? Per-resolution or per-conversation pricing ties your bill to traffic, so the busy months (a launch, a viral post, an outage) are also your most expensive months. A flat subscription keeps the cost predictable regardless of volume. ### What hidden costs should I watch for? Overage fees past your tier, per-seat charges for every human agent, re-training or re-crawl fees when your content changes, and integrations (webhooks, API, CRM) locked behind higher tiers. Price the tier that includes what you actually need. ## The best AI chatbot for Indian SMBs in 2026 (pricing in ₹, WhatsApp, and Hindi) Source: https://www.oyechats.com/blog/best-ai-chatbot-india Published: 2026-07-15 Category: Buyer Guide If you run a small business in India, the best AI chatbot is the one that answers in your customer's language, prices in rupees you can predict, and turns website visitors into qualified leads without a form. That sounds obvious, but most chatbot roundups are written for US enterprises and quietly assume dollar budgets, English-only support, and a dedicated ops team. This guide is written the other way around. ## What should an Indian SMB look for in an AI chatbot? For an Indian small business, the four things that matter most are rupee-denominated flat pricing, support for Hindi and regional languages, a clean path from website chat to WhatsApp follow-up, and lead qualification built in. Ticket deflection and a fast install matter too, but those four are what separate a tool built for this market from one that merely tolerates it. ## Why the timing is good India is one of the fastest-growing conversational-AI markets in the world. The India chatbot market was valued at around [USD 243 million in 2024 and is projected to reach roughly USD 1.47 billion by 2033](https://www.imarcgroup.com/india-chatbot-market), a compound growth rate near 20% a year. That growth is not coming from large enterprises alone; it is D2C brands, clinics, coaching institutes, SaaS startups, and local service businesses adding chat to sites that used to have nothing but a contact form. The practical takeaway is that the tooling has finally caught up with small budgets. You no longer need an enterprise contract to put a competent AI agent on your site. ## Rupee pricing you can actually predict The single biggest trap for an Indian SMB is a tool priced per resolved conversation in dollars. It looks affordable at ten conversations a day and becomes a real line item the month a campaign lands. Prefer a flat monthly plan quoted in rupees, so a busy month costs the same as a quiet one. As a reference point, OyeChats uses flat monthly pricing in rupees with a free tier, and charges the same whether you are in Mumbai or Madurai. The live figures are on the [pricing page](/pricing) so they stay current. Whatever you choose, insist on seeing the rupee price before the sales call, not after. ## WhatsApp is where your customer already is India is the largest WhatsApp market on earth, and for most Indian buyers a chat on your website and a message on WhatsApp are the same conversation. The best setup answers instantly on your site, and when a visitor wants a human or a follow-up, continues the thread on WhatsApp rather than forcing an email. Even if you start with website chat only, choose a tool whose roadmap and integrations point toward that unified experience. ## Hindi, and the languages after Hindi A support bot that only speaks English is leaving trust on the table. Indian customers switch between English, Hindi, and a regional language mid-sentence, and a good bot should follow. Modern language models handle Hindi and major Indian languages well, so the question is less "can it" and more "is the bot allowed to answer in the language the customer used". Test this before you buy: open the widget, ask a question in Hindi, and see whether the answer comes back in Hindi or awkwardly in English. ## It should qualify leads, not just deflect tickets Deflecting repetitive questions about pricing, shipping, or GST is valuable, but for a growing business the bigger prize is capturing the visitor who is ready to buy. A chatbot that scores intent as the conversation happens, and flags the hot leads for a callback, turns your support widget into a sales channel. This is the difference between a tool that saves you time and one that makes you money. See [how conversational BANT scoring works](/blog/bant-scoring-ai-chatbot) for the mechanics. ## A practical shortlist for Indian SMBs Rather than rank tools by logo size, judge any candidate against this checklist. The right chatbot for your business is the one that clears all six. 1. Flat monthly pricing quoted in rupees, with a free plan to validate before you pay. 2. Answers grounded in your own website and documents, so it never invents policies or prices. 3. Hindi and regional-language answers, tested live in the widget. 4. A clear path from website chat to WhatsApp or a human handoff. 5. Built-in lead qualification that flags buyers, not just a transcript log. 6. A ten-minute install with a single script tag, and GST-compliant billing. Start with the free tier of one or two tools, train each on your real website, and ask them the ten questions your customers actually send. The winner is usually obvious within an afternoon. When you are ready, [training a bot on your own site](/blog/train-ai-chatbot-website) takes about ten minutes. ### What is the best AI chatbot for a small business in India? The best AI chatbot for an Indian SMB is one with flat rupee pricing, answers grounded in your own website, Hindi and regional-language support, a path to WhatsApp or human handoff, and built-in lead qualification. Shortlist tools against those criteria and validate on a free plan before paying. ### How much does an AI chatbot cost in India? Flat-rate plans for Indian small businesses commonly start with a free tier and run to a few thousand rupees per month. Avoid tools priced per resolved conversation in dollars, since your bill then rises with traffic and is hard to predict. ### Can an AI chatbot answer in Hindi and regional languages? Yes. Modern language models handle Hindi and major Indian languages well. The thing to verify is whether the specific bot is configured to reply in the language the customer used. Test it live in the widget before you buy. ### Can a website chatbot connect to WhatsApp? Many can continue a conversation on WhatsApp or hand off to a human there, which matters in India where WhatsApp is the primary channel. If a unified website-plus-WhatsApp experience is important, confirm it is supported or on the roadmap before choosing a tool. ## How to train an AI chatbot on your own website, step by step Source: https://www.oyechats.com/blog/train-ai-chatbot-website Published: 2026-07-14 Category: How-to You do not train an AI chatbot on your website the way you might imagine, by feeding pages into a model and waiting for it to memorise them. Modern support and sales bots use retrieval, not memorisation. You point the bot at your content, it indexes that content, and at question time it looks up the most relevant passages and answers from them. The practical upshot is that "training" is mostly about giving the bot clean content and good boundaries, and it takes minutes, not weeks. ## How do you train a chatbot on your own website? You give the bot your URLs and documents, it crawls and splits them into small passages, converts each passage into a searchable vector, and stores them. When a visitor asks something, the bot retrieves the closest passages and writes an answer grounded in them. You are not editing the model; you are curating the library it reads from, which means you stay in control of every fact it can state. ## Step 1: Point the bot at your content Start with the pages that already answer real questions: your docs, help center, pricing, FAQ, and key product pages. Most tools, OyeChats included, take a root URL and crawl outward, so you rarely list pages by hand. Add PDFs or a knowledge-base export if the answers live there too. The rule of thumb is simple: if a customer emails to ask it, the answer should be in the crawl. ## Step 2: Let it chunk and embed Behind the scenes the bot splits each page into passages a few sentences long and turns every passage into an embedding, a numerical representation of its meaning. This is what lets it match a question like "how do I cancel" to a doc that says "ending your subscription", even though the words differ. You do not configure any of this by hand; it is the part the platform handles for you. The one thing worth knowing is that cleaner source content produces better retrieval. A page that answers one thing clearly beats a sprawling page that buries the answer under marketing copy. If you improve any content before launch, improve the pages customers actually ask about. ## Step 3: Set the boundaries so it does not make things up Grounding the bot in your content is also what keeps it honest. A well-built retrieval bot answers from the passages it found and says "I am not sure" when it finds nothing relevant, rather than inventing a confident wrong answer. Configure it to refuse gracefully, hand off to a human on low confidence, and never guess at prices, policies, or availability. This single setting is the difference between a helpful bot and a liability. ## Step 4: Give it your voice Retrieval decides what the bot knows; a short instruction decides how it sounds. Tell it who it is, how formal to be, and what to do at the edges: when to offer a demo, when to escalate, what never to promise. You are not retraining anything here, just prompting the response layer. A paragraph of clear guidance usually gets you a bot that reads like your team wrote it. You can see the full set of controls on the [features page](/features). ## Step 5: Test with real questions, then install Before you ship, ask the bot the ten questions your team actually hears every week, plus a few it should refuse. Fix gaps by improving the underlying page, not by hard-coding an answer; that keeps a single source of truth. When it holds up, installing is a one-line script tag on your site, and the bot goes live on every page at once. ``` ``` ## How do you keep the bot accurate over time? Re-crawl whenever your content changes, and review real transcripts weekly for questions the bot missed or answered thinly. Because the bot reads from your content rather than a frozen snapshot inside a model, keeping it current is a documentation task, not a retraining project: update the page, re-index, and the next answer is right. - Re-index after any pricing, policy, or feature change so answers never lag your site. - Read a sample of transcripts weekly; every unanswered question is a page to write or sharpen. - Watch the low-confidence and handoff rate: a rising one usually means a content gap, not a model problem. Training an AI chatbot on your own website is really an exercise in curation. Give it good content, clear boundaries, and your voice, and the retrieval does the rest. The teams who get the most out of it treat the bot as a mirror of their documentation: improve the docs, and the bot improves with them. Curious what it costs to run? See the [full pricing breakdown](/blog/ai-chatbot-cost). ### How do you train an AI chatbot on your own website? You give the chatbot your website URLs and documents. It crawls and splits them into passages, converts each into a searchable vector, and stores them. At question time it retrieves the most relevant passages and answers from them, so you curate the content rather than retrain a model. ### Do you need to code to train a website chatbot? No. Most platforms take a root URL, crawl your site automatically, and handle the chunking and embedding for you. Installing the finished bot is typically a single script tag, so no engineering work is required to launch. ### How do you stop an AI chatbot from making things up? Ground it in your own content and configure it to answer only from retrieved passages, refuse gracefully when it finds nothing relevant, and hand off to a human on low confidence. Never let it guess at prices, policies, or availability. ### How do you keep the chatbot answers up to date? Re-crawl your site whenever content changes and review transcripts weekly for missed questions. Because the bot reads from your live content rather than a frozen model snapshot, updating a page and re-indexing is enough to correct future answers. ## BANT scoring inside an AI chatbot, without a single form question Source: https://www.oyechats.com/blog/bant-scoring-ai-chatbot Published: 2026-06-12 Category: Sales AI For decades, BANT has been the shortest useful sales framework in the world. Budget, Authority, Need, Timing. If you know those four things about a visitor, you know whether to call them today, nurture them next month, or let them keep reading. The problem was never the framework. It was the collection method. Reps had to squeeze those four answers out of a discovery call, and marketers had to bury them in a form that no visitor wanted to fill. An AI chatbot changes the economics of collection. When a visitor is already in a natural conversation about your product, BANT signals leak out on their own. The job of the bot is to notice them, structure them, and put them in front of sales before the tab is closed. ## What each BANT signal looks like in a real chat OyeChats treats each of the four dimensions as a probability, not a boolean. Every visitor message is scored against a small classifier that watches for language patterns tied to that dimension. A single confident sentence can move the score. A vague one nudges it. ### Budget Visitors rarely name a number. They name a shape. "We are a five person team", "we are on the free plan of a competitor", or "we have a small ops budget for tools this quarter" all imply a range. The bot maps that range to a plan tier and stores the raw phrase for the rep to read later. ### Authority A visitor who says "I would need to check with our head of support" is telling you exactly where they sit in the org. So is one who says "I run growth here". OyeChats tags the role, the pronoun pattern, and whether they speak in "we" or "I" when discussing purchase decisions. ### Need Need is the easiest of the four because it is the reason the visitor started chatting. The trick is separating a real pain from a feature curiosity. A person who asks "does this integrate with HubSpot?" is exploring. A person who says "our current tool is dropping tickets after eight in the evening" is bleeding. ### Timing Timing surfaces through deadlines, launch dates, and frustration intensity. Phrases like "we are rolling this out next month" or "we need to fix this before Black Friday" push the timing score sharply. So does a visitor returning three times in a week. ## Turning four numbers into a single decision Once every score has a value between zero and one, OyeChats blends them into a lead grade. High Need with high Timing but unknown Budget still deserves a call, because the sales team can qualify the number faster than a bot can. High Budget with weak Need is a nurture, not a call. The exact weighting is tunable per account. - Hot: three or four dimensions above 0.7. Route to a live operator or notify sales instantly. - Warm: two dimensions above 0.7. Deliver a scheduled follow up email with a calendar link. - Cold: one dimension confirmed, others thin. Continue the conversation, keep collecting. ## Why this beats forms A form gets you the data of the small percentage of visitors willing to fill it. A conversation gets you the shape of intent from everyone who talks. Even a visitor who never becomes a lead has told you something about the market you are selling into, and that is worth keeping. BANT was never broken. It was just waiting for a collection method that felt like a normal exchange between two humans. That is what an AI chatbot finally does at scale. ## RAG or fine tuning, when each is actually the right answer Source: https://www.oyechats.com/blog/rag-vs-fine-tuning Published: 2026-06-05 Category: AI Engineering Almost every team that picks up a large language model for the first time ends up asking the same question. Should we fine tune it on our data, or should we build a retrieval pipeline around it? The two paths look similar from a distance because they both promise the same outcome, which is answers that sound like your company wrote them. Up close they solve different problems. ## The one sentence version Fine tuning changes how the model speaks. Retrieval changes what the model knows in the moment. If your problem is tone, format, or a repeatable pattern, fine tune. If your problem is up to date facts about your product, your policies, or your customers, retrieve. ## Where RAG wins outright Any body of knowledge that changes weekly, monthly, or unpredictably belongs in retrieval. Documentation, pricing, feature flags, help center articles, and internal wikis all fall into this bucket. A retrieval pipeline lets you update a single source of truth and see the answer change on the next question. - Cost per update is roughly zero, because you are only reindexing a chunk, not retraining a model. - Attribution comes for free. You can show the visitor which document a sentence came from. - Rollback is instant. Delete the bad chunk, ask again, the model no longer knows the wrong fact. ## Where fine tuning wins outright Fine tuning earns its cost when the target is a stable pattern rather than a piece of knowledge. Turning free text into a strict JSON schema every time, matching a specific writing voice, or teaching a smaller model a specialised classification are all excellent fits. The model is learning a shape, and shapes rarely change. - The behaviour you want is repeatable across thousands of inputs, so training pays off. - You have a labelled dataset that reflects the target behaviour cleanly. - Latency matters, and you want a smaller model to punch above its weight. ## Why most production systems end up doing both Once a team is running in the real world, the split usually resolves the same way. Retrieval provides the facts. A lightly fine tuned model provides the personality and the output shape. The base model reads a small pack of relevant chunks and answers in the voice you trained it in. This is how OyeChats runs by default. Documents are chunked, embedded, and searched with a hybrid pipeline, and the response layer is prompted to sound consistent across every bot. ## A short checklist to run before you commit 1. Write down the failure you are trying to fix. If it is "the answer is out of date", RAG is your first move. 2. If it is "the answer is off brand or the wrong format", start with prompt engineering, then fine tune only if the prompt cannot get you there. 3. Estimate the update cadence. Anything faster than quarterly should live in retrieval. 4. Estimate the labelled data you can produce. Fine tuning without a real dataset almost always disappoints. 5. Plan the eval before the build. Both approaches are worthless without a way to tell if the next change made things better. Neither approach is inherently more advanced than the other. They are two different tools that people keep reaching for at the wrong moment. Pick the one that maps to the failure you actually have today, and leave the other on the shelf until you need it. ## Hybrid search, explained without the buzzwords Source: https://www.oyechats.com/blog/hybrid-search-explained Published: 2026-05-26 Category: Search Vector search gets a lot of the press in modern retrieval, and for good reason. It handles paraphrasing, synonyms, and messy human phrasing in a way that plain keyword search never could. But if you have ever watched a visitor ask a question that includes an internal product code, a version number, or an acronym, you have also seen vector search miss badly. Hybrid search exists because both methods have blind spots, and their blind spots barely overlap. ## What each method is actually good at Vector search compares meaning. It turns text into a dense numerical representation and looks for chunks whose meaning is close to the query. That is exactly what you want when a visitor asks about "cancelling my plan" and the docs use the phrase "ending your subscription". Keyword search, in the form of BM25 or a Postgres TSVECTOR index, compares literal tokens. It is exactly what you want when a visitor pastes the string "ERR_TIMEOUT_1044" and needs the doc that mentions that exact code. No embedding model is going to reliably guess that a specific error code should map to a specific troubleshooting page. ## How to combine the two The simplest and most reliable technique is reciprocal rank fusion. Run both searches, get two ranked lists, and combine them by rank rather than by raw score. A chunk that shows up near the top of either list gets credit. A chunk that shows up near the top of both lists gets a lot of credit. ``` def rrf(vector_hits, keyword_hits, k=60): scores = {} for rank, doc_id in enumerate(vector_hits): scores[doc_id] = scores.get(doc_id, 0) + 1 / (k + rank) for rank, doc_id in enumerate(keyword_hits): scores[doc_id] = scores.get(doc_id, 0) + 1 / (k + rank) return sorted(scores.items(), key=lambda x: x[1], reverse=True) ``` The k parameter is a smoothing constant. A value around 60 works well in practice. Larger values flatten the contribution of top ranked results. Smaller values sharpen it. ## The failure modes hybrid quietly fixes - Rare terminology like SKUs, error codes, and legal clause references start returning the right page again. - Paraphrased questions still land on the right chunk even when the vocabulary does not match. - A single embedding model bug no longer takes down retrieval entirely, because keyword search continues to work. ## What to measure A good hybrid rollout is boring by design. Track recall at ten for a fixed evaluation set of real questions, and compare vector only, keyword only, and hybrid. In our internal evaluation, hybrid beat vector alone on roughly nineteen of twenty question types, and beat keyword alone on all of them. The exceptions were queries where a single perfect keyword match should completely dominate the result. You do not need a research team to ship hybrid search. You need one vector index, one keyword index, one small function to fuse them, and a habit of measuring against real questions. Everything else is polish. ## Behavioural tracking for lead gen, without becoming creepy Source: https://www.oyechats.com/blog/behavioral-tracking-lead-gen Published: 2026-05-10 Category: Growth A lot of behavioural tracking dashboards are theatre. They show a wall of metrics, most of which have no predictive relationship to whether a visitor is about to buy something. If you have ever stared at a heatmap and asked yourself "what am I supposed to do with this", you already know the problem. The signals worth acting on are much narrower than the ones a tool will happily record. ## Signals that actually predict intent Across dozens of accounts, the same handful of behaviours consistently line up with visitors who eventually convert. - Return visits within seven days, especially to a pricing or comparison page. - Time spent on a single feature page above the ninetieth percentile for that page. - Copying an install snippet or a code sample to the clipboard. - Opening the FAQ or documentation from a product page rather than from the nav. - A specific referrer pattern, such as arriving from a curated newsletter or a peer review site. Notice what is not on the list. Scroll depth on a landing page. Mouse movement heatmaps. Time on a blog post. These are entertaining to look at and almost never predictive of purchase. ## The trust boundary Every behavioural signal you collect crosses a spectrum from "obvious that you are tracking it" to "surprising and a little unsettling". Return visits are on the obvious end. Any regular analytics tool tracks them, and no visitor is shocked to hear it. Real time inference of an emotional state from webcam access is on the other end. Nobody wants that in a chatbot. The right question is not "what can we capture". It is "what would we happily disclose in a one paragraph note on the site". If a signal survives that test, use it. If it does not, drop it, even if it is technically legal in your jurisdiction. ## How to act on the signals you keep The behavioural signals only matter if they change what the chatbot does next. Three actions cover almost every case. 1. Adjust the greeting. A returning visitor who spent six minutes on the pricing page yesterday should not be greeted with the same generic message as a first time reader. 2. Adjust the routing. A visitor whose behavioural profile matches your best converting cohort should be offered a live operator, not a scheduled email. 3. Adjust the qualification prompts. If the visitor already looked at three integrations pages, do not ask which integrations they care about. Behavioural tracking earns its keep when it makes the conversation smarter. If it is only feeding a report, you can probably delete half of the tags and lose nothing. ## Webhook best practices for chat platforms, from a team that ships them Source: https://www.oyechats.com/blog/webhook-best-practices Published: 2026-05-03 Category: Engineering Webhooks look simple on a whiteboard. Something happens on our side, we send a POST to your URL. In production, the same feature is where roughly a third of integration bugs quietly live. Retry storms, delivery gaps, silent signature mismatches, and endpoints that return two hundred OK while doing nothing at all. The rules below are what we have learned running webhooks across thousands of bots. ## Sign every payload, and pin the signature scheme Every webhook we send carries an HMAC SHA 256 signature over the raw request body, computed with a secret unique to the receiver. Two things matter here. First, sign the raw bytes, not the parsed JSON, because any JSON reserialisation on either side breaks verification. Second, put the scheme identifier in the header, so future rotations do not require a coordinated release. ``` X-OyeChats-Signature: v1=8f2a1c93b4d5e6f7a8b9c0d1e2f3a4b5c6d7e8f9a0b1c2d3e4f5a6b7c8d9e0f1 X-OyeChats-Timestamp: 1739299200 ``` The timestamp is not decoration. Verifiers should reject any request more than five minutes old, which kills replay attacks and also catches misconfigured servers whose clocks have drifted. ## Retry with exponential backoff and a hard cap If your receiver returns anything other than a two hundred status, we retry. Retries follow exponential backoff with jitter, and we cap the total window at twenty four hours. After that we mark the delivery as failed and expose it in the admin dashboard for manual replay. - Return a two hundred as soon as you have durably enqueued the payload. Do the real work in a background job. - Never retry from your side too. The sender is already retrying, and duplicate retries lead to duplicate side effects. - Log the delivery id so support can trace a specific event across both systems. ## Make every event safely retriable The sender does not know whether your two hundred came before or after the crash. The only safe assumption is that any event might arrive twice. Every event carries a stable delivery id and a stable event id. Store the event id on the receiver, check it before applying side effects, and skip if it has already been processed. ## Send small, coherent events Large batched payloads are tempting because they cut request volume. They also make retries expensive, encourage partial failure handling that nobody actually writes, and force the receiver to parse events they may not care about. We prefer one event per business fact. A new chat session, a new message, a status change. The receiver filters what it wants. ## Observability the receiver can trust Every webhook we send is inspectable in the admin dashboard. The receiver sees the raw payload, the response status, the response body, the delivery timestamps, and every retry attempt with its reason. When integrations break at three in the morning, that is the difference between a five minute fix and a two hour support thread. None of this is exotic. It is a small collection of habits that pay off the first time a downstream system has a bad day, which will happen sooner than you expect. # Legal ## Privacy Policy Source: https://www.oyechats.com/legal/privacy Last updated: 2026-08-17 ### Introduction OyeChats ("OyeChats," "we," "us," or "our") operates the OyeChats platform, including our website at oyechats.com, the customer dashboard at app.oyechats.com, our REST and WebSocket APIs, the OyeChats mobile application for operators, and the embeddable chat widget our customers deploy on their own websites (collectively, the "Service"). OyeChats is a brand of Digibranders Private Limited (CIN U72900MH2021PTC372344), a company incorporated in India with its registered office at Office No. 2617, 26th Floor, Solus Building, Hiranandani Estate, Ghodbunder Road, Thane West, Maharashtra 400607, India. This Privacy Policy describes how we collect, use, store, share, and protect personal information when you interact with the Service, whether you are a customer who has signed up for an OyeChats account, an end user ("Visitor") chatting with a bot on a customer's website, or simply browsing oyechats.com. By using the Service, you agree to the practices described here. ### Our Role: Controller vs. Processor Privacy law distinguishes between data "controllers" (who decide why and how data is processed) and "processors" (who handle data on a controller's instructions). Our role differs depending on whose data is involved: - Customer data: Where you have signed up for an OyeChats account, we act as the controller of the data we collect from you to operate, bill for, and improve the Service. - Visitor data: Where a Visitor interacts with a bot on a customer's website, our customer is the controller of that conversation data and we act as a processor on their behalf, governed by the Data Processing Addendum incorporated into our Terms of Service. If you are a Visitor with questions about how a specific customer uses your data, please contact that customer directly. We will assist with verified requests forwarded by the controller. ### Information We Collect We collect the following categories of information: - Account data: Name, work email address, organization name, hashed password, account role, and optionally a website URL when you register or invite team members. If you choose to sign in with Google, we receive the name, email address, and profile picture associated with that Google account. We request only the openid, email, and profile scopes; we do not request access to your Gmail, Drive, Calendar, or any other Google service. - Bot configuration: Bot name, system prompt, appearance settings, business hours, and the knowledge base content (documents you upload or URLs you ask us to crawl). - Conversation data: Chat messages between Visitors and the bot or live operators, timestamps, lead-capture form submissions (name, email, phone, company), and qualification signals derived from the conversation. - Visitor metadata: The Visitor's IP address, browser and device type, approximate geographic location (city, region, and country) derived from that address, the page URL the widget loaded on, referrer, and UTM campaign parameters. The IP address is recorded in full because it is what geolocation, abuse prevention, and deduplication of repeat visits are performed against. It is never shown in the dashboard, included in a CSV export, or returned by our API: every one of those boundaries strips it and shows only the geography. - Derived IP intelligence: From the Visitor's IP address we look up the organization or network that owns it, its autonomous system, and whether it is associated with a hosting provider, VPN, proxy, or known abusive traffic. These are inferred network signals, not a confirmed identification of a Visitor or their employer, and they are frequently wrong about individuals connecting through a consumer internet provider. - Email verification results: Where a Visitor submits an email address through a lead-capture form on a plan that includes verification, we check that address against a third-party deliverability service and store the result (valid, invalid, disposable, or unknown) alongside the lead. The check confirms whether an address can receive mail; it does not retrieve any information about the person behind it. - Operator data: For customers using live chat, the names, emails, roles, and activity logs of human operators assigned to handle visitor conversations, plus browser and mobile push notification tokens for the operators who opt in to notifications. - Usage and diagnostic data: Feature usage counters, API request volumes, error stack traces, performance metrics, and audit logs of administrative actions. - Billing data: Plan tier, billing cycle, invoice history, and the last four digits and brand of the payment instrument. Full card numbers, UPI handles, and bank account details are processed and stored by our payment provider, Razorpay, and never reach our servers. - Communications: Contents of emails or support tickets you send us. ### How We Use Your Information We use the information described above for the following purposes: - Provide, maintain, and operate the Service, including running the retrieval-augmented generation pipeline that answers Visitor questions from your knowledge base. - Authenticate users, enforce plan limits, and prevent abuse. - Generate lead-qualification signals (BANT scoring) and surface those signals to the customer who owns the conversation. - Derive geography and network signals from a Visitor's IP address, so the customer who owns the conversation can see where an enquiry came from and can distinguish genuine enquiries from automated and abusive traffic. - Verify the deliverability of email addresses submitted through lead-capture forms, so customers do not send follow-up mail to mistyped or disposable addresses. - Send transactional emails such as account verification, password resets, billing notifications, and webhook failure alerts, and deliver push notifications to operators who have opted in. - Process payments, issue invoices, and meet tax and accounting obligations. - Monitor platform health, debug errors, and investigate security incidents. - Improve the Service through aggregated, anonymized analytics. We do not use Customer or Visitor conversation content to train large language models, ours or any third party's. - Comply with applicable law and respond to lawful requests from public authorities. ### Legal Bases for Processing If you are in the European Economic Area or United Kingdom, we rely on the following legal bases under the GDPR / UK GDPR: - Performance of a contract: to deliver the Service you have signed up for. - Legitimate interests: to secure the Service, prevent abuse, debug errors, and conduct aggregated analytics, balanced against your rights and freedoms. - Consent: where required (for example, non-essential cookies on our marketing site). You may withdraw consent at any time. - Legal obligation: to retain billing records, respond to lawful authority requests, and meet tax requirements. If your data is processed under India's Digital Personal Data Protection Act, 2023, note that the Act does not provide a legitimate-interest basis. Processing of personal data under that Act is carried out on the basis of consent, or on one of the legitimate uses the Act specifies. Where OyeChats acts as a processor for a customer, that customer is responsible for obtaining the notice and consent the Act requires from its Visitors before the widget collects their data. ### Sub-processors and Data Sharing We do not sell your personal information. We share data only with the sub-processors and partners we engage to deliver the Service, each under written agreements that require equivalent protections. Categories of sub-processors include cloud infrastructure and hosting, AI model providers, web crawling and content extraction, IP and email intelligence, transactional email and push notification delivery, payment processing, and observability tooling. The current, itemized list, including each provider's name, purpose, and location, is maintained on our Subprocessors List page. We may add or change sub-processors from time to time. Material changes affecting how Customer data is handled will be communicated via email or in-product notice with at least 30 days' advance notice where reasonably possible. We may also disclose information when required by law, to protect the rights, property, or safety of OyeChats, our customers, or others, or in connection with a corporate transaction such as a merger or acquisition, in which case we will notify affected customers. ### International Data Transfers OyeChats is operated from India and uses sub-processors located in India, the United States, the European Union, and other jurisdictions. Where personal data is transferred out of the EEA, UK, or India, we rely on appropriate safeguards such as the European Commission's Standard Contractual Clauses, the UK International Data Transfer Addendum, or equivalent mechanisms permitted under the Digital Personal Data Protection Act, 2023. A copy of the relevant transfer mechanism is available on request. ### Data Retention We retain personal information only as long as needed for the purposes described in this policy: - Account data: Retained for the life of the account and deleted (or anonymized) within 30 days of account closure, except where longer retention is required by law. - Conversation history: Your plan determines how far back conversation history remains available to you, 7 days on Free, 30 days on Starter, 90 days on Standard, and 365 days on Professional. Conversation data older than your plan window is no longer accessible through the dashboard, exports, or the API. It is not automatically deleted from our database at the end of that window; it is deleted when you close your account, or earlier on request as described below. - Trial accounts: A trial that does not convert to a paid plan moves the account to the Free plan. Conversation and knowledge base data created during the trial is retained, subject to the Free plan's limits; knowledge above those limits is made inactive rather than deleted, and is restored if you upgrade. It is deleted when you delete it or close your account. - Knowledge base content: Retained until you delete it or close your account. - Visitor behavioural events (page views, return visits, campaign parameters): Retained for up to 180 days. - Diagnostic and error logs: Retained for up to 90 days. - Audit logs of administrative actions: Retained for up to 12 months. - Push notification tokens: Retained until the operator disables notifications, uninstalls the app, or the token is rejected as stale by the delivery provider. - Billing records and invoices: Retained for the period required under applicable tax and accounting law, typically 7 years. - Backups: Encrypted database backups are retained for up to 30 days before automatic rotation. You may request deletion of Visitor or account data at any time by writing to support@oyechats.com from the email address associated with your account. Requests are honored within 30 days unless a legal hold applies. Deletion is currently handled by our team on request rather than through a self-service control in the dashboard. ### Security We apply technical and organizational measures designed to protect personal information against unauthorized access, alteration, disclosure, or destruction. These include encryption in transit (TLS 1.3 for all API and widget traffic), encryption at rest for primary databases and object storage, logical isolation of each customer's data, role-based access controls on production systems, audit logging of administrative actions, and dedicated environments for production and non-production workloads. Production access is restricted to a small number of authorized personnel under multi-factor authentication. No system can be guaranteed perfectly secure. If you discover a vulnerability, please report it under our Security and Responsible Disclosure Policy, which sets out where to send a report, our safe-harbour commitment, and what is in and out of scope. ### Data Breach Notification If we become aware of a personal data breach that is likely to result in a risk to the rights and freedoms of affected individuals, we will notify our customers without undue delay. Customers are responsible for notifying their own Visitors and any applicable regulators in respect of Visitor data, with our reasonable assistance. Where the GDPR or UK GDPR applies, we will notify the relevant supervisory authority within 72 hours of becoming aware where required. Where India's Digital Personal Data Protection Act, 2023 applies to us as a Data Fiduciary, we will give the Data Protection Board of India and each affected Data Principal intimation of the breach without delay, and follow it with the detailed report the Act and its rules require. These are separate obligations from the GDPR timeline above, and we treat them as such rather than relying on one to satisfy the other. ### Your Rights Depending on where you live, you have rights over your personal information. We honor verified requests regardless of residency wherever practical. If you are in the EEA, UK, or Switzerland (GDPR / UK GDPR): the rights to access, rectification, erasure, restriction of processing, data portability, and objection; the right not to be subject to solely automated decision-making with significant effects; and the right to lodge a complaint with your local supervisory authority. If you are a California resident (CCPA / CPRA): the rights to know what we collect, to delete personal information, to correct inaccurate information, to opt out of any sale or sharing of personal information (we do not sell or share for cross-context behavioral advertising), and to limit the use of sensitive personal information. If you are in India (DPDP Act, 2023): the rights to obtain a summary of personal data processed, to correction and erasure, to nominate another individual to exercise your rights in case of incapacity, and to grievance redressal. To exercise any of these rights, write to support@oyechats.com from the email associated with your account, or contact our Grievance Officer using the details below. We will acknowledge your request within 2 business days and respond within 30 days. ### Children's Privacy OyeChats is intended for use by businesses and is not directed to children. We do not knowingly collect personal information from children under the age of 16 (or under 18 where required by local law, including India under the DPDP Act). If you believe a child has provided us personal information, please contact us and we will delete it. Because our customers choose where to deploy the chat widget, they are responsible for not deploying it to an audience they know or ought to know consists of children, and for obtaining verifiable parental consent where their own law requires it. This obligation is set out in our Terms of Service. ### Cookies and Similar Technologies We use a small number of strictly necessary cookies on oyechats.com and the customer dashboard for session management, authentication, and CSRF protection, plus an analytics category on the marketing site that runs only with your permission where consent is required. We do not use third-party advertising or cross-site tracking cookies on our own properties. The embeddable chat widget sets a first-party cookie on the customer's own domain to keep a conversation continuous when a Visitor moves between subdomains, and reads and writes short-lived cookies to work out which domain to scope it to. For the full breakdown of every cookie, including names, lifetimes, and how to control them, see our Cookie Policy. ### AI-Generated Content Answers shown to Visitors are generated by large language models from the customer's own knowledge base. Model outputs are probabilistic and can be incomplete or incorrect even when the underlying source material is accurate. Conversation messages and the retrieved knowledge base passages needed to answer them are sent to our AI model providers at query time. We do not authorize those providers to use Customer or Visitor data to train general-purpose foundation models. Where the EU AI Act applies, OyeChats is the provider of the AI system and our customer is its deployer. The widget identifies itself as an automated assistant to Visitors, and our Terms of Service prohibit customers from configuring a bot to conceal that it is automated. ### Automated Decision-Making OyeChats generates qualification signals (BANT scoring), conversation summaries, and derived IP and email signals using large language models and third-party data services. These outputs are decision-support information for the customer who owns the conversation; they do not by themselves produce legal or similarly significant effects on a Visitor. Customers remain responsible for any subsequent decisions they take based on these signals. ### Third-Party Links Our website and the chat widget may contain links to third-party sites or content provided by our customers. We are not responsible for the privacy practices of those third parties. You should review their privacy policies independently. ### Changes to This Policy We may update this Privacy Policy from time to time to reflect changes in our practices, the Service, or applicable law. The "Last updated" date at the top of this page indicates when it was last revised. Material changes will be communicated via email to account administrators or via in-product notice at least 30 days in advance where reasonably possible. ### Contact Us and Grievance Redressal For privacy questions, requests, or complaints, you may contact our Grievance Officer, who also serves as our data protection contact for the purposes of the Digital Personal Data Protection Act, 2023: - Grievance Officer and Data Protection Contact: Siddique Ahmed - Email: support@oyechats.com - Phone: +91 93206 16160 - Postal address: Digibranders Private Limited, Office No. 2617, 26th Floor, Solus Building, Hiranandani Estate, Ghodbunder Road, Thane West, Maharashtra 400607, India We acknowledge grievances within 2 business days and aim to resolve them within 30 days. For general enquiries and technical support, write to support@oyechats.com. For security reports, follow our Security and Responsible Disclosure Policy. If you are in the EEA or UK and we do not resolve your concern, you may lodge a complaint with your local data protection authority. If you are in India, you may approach the Data Protection Board of India after first raising the matter with our Grievance Officer above. ## Terms of Service Source: https://www.oyechats.com/legal/terms Last updated: 2026-08-17 ### Introduction These Terms of Service (the "Agreement") form a binding contract between Digibranders Private Limited, trading as OyeChats ("OyeChats," "we," "us," or "our"), and the entity or person agreeing to them ("Customer," "you," or "your"). OyeChats is a brand of Digibranders Private Limited (CIN U72900MH2021PTC372344), a company incorporated in India with its registered office at Office No. 2617, 26th Floor, Solus Building, Hiranandani Estate, Ghodbunder Road, Thane West, Maharashtra 400607, India. The Agreement governs your access to and use of the OyeChats platform, including our website at oyechats.com, the customer dashboard at app.oyechats.com, our REST and WebSocket APIs, the OyeChats mobile application for operators, and the embeddable chat widget our customers deploy on their own websites (collectively, the "Services"). By signing up for an account, clicking "I agree," or otherwise using the Services, you confirm that you have read, understood, and agree to be bound by this Agreement. If you are agreeing on behalf of an organization, you represent that you have authority to bind that organization to this Agreement. ### Definitions - "Account" means the account you create to access and administer the Services. - "Bot" means a chatbot instance you configure on the platform, identified by a unique bot key. - "Customer Data" means all data, content, and information that you, your Authorized Users, or your Visitors submit to or generate through the Services. - "Authorized User" means an employee, contractor, or operator you authorize to access the Services on your behalf. - "Visitor" means an end user who interacts with a Bot on a website where you have deployed the widget. - "Documentation" means the product and developer documentation OyeChats publishes for the Services at oyechats.com and in the customer dashboard, as updated from time to time. Marketing material, blog posts, roadmap statements, and support correspondence are not Documentation. - "Output" means text, summaries, qualification signals, and other content generated by the Services using a large language model. - "Order" means the online sign-up, in-product upgrade flow, or written order form by which you subscribe to a plan. - "Subscription Term" means the period for which a plan is in effect under an Order. - "Third Party Apps" means software, integrations, or services provided by a party other than OyeChats that interoperate with the Services. ### OyeChats Services and Acceptable Use Subject to your compliance with this Agreement and timely payment of fees, OyeChats grants you a non-exclusive, non-transferable, worldwide right during the Subscription Term to access and use the Services for your internal business purposes. You will not, and will not permit any Authorized User or third party to: - Use the Services to send spam, malware, or content that is unlawful, infringing, harassing, or otherwise objectionable. - Reverse-engineer, decompile, or attempt to extract the source code of the Services, except to the extent applicable law expressly permits. - Resell, sublicense, or make the Services available to any third party other than your Authorized Users and the Visitors interacting with your Bots. - Access the Services to build a competing product or to benchmark performance for publication without our prior written consent. - Exceed documented rate limits, evade plan limits, or use the Services in a way that imposes a disproportionate load on our infrastructure. - Misrepresent the Bot's identity to Visitors. Bots must be reasonably identifiable as automated, in accordance with applicable law, and you will not configure or modify a Bot so as to conceal or suppress that disclosure. - Attempt to extract another customer's system prompt, knowledge base, or conversation data, whether through prompt injection or any other means. - Deploy a Bot to an audience you know or ought reasonably to know consists of children, unless you have obtained the parental consent your applicable law requires. The full and current list of prohibited uses is set out in our Acceptable Use Policy, which forms part of this Agreement. Because misuse patterns for AI systems change faster than contracts do, we may update that policy without amending this Agreement; we will not use it to reduce the rights this Agreement grants you. ### Customer Data and Customer Obligations As between the parties, you retain all right, title, and interest in and to Customer Data. You grant OyeChats a worldwide, royalty-free license to host, copy, transmit, display, and process Customer Data solely as necessary to provide, secure, and support the Services. We will not use Customer Data, including conversation content, to train general-purpose foundation models. Where you process personal data of Visitors through the Services, you act as the controller and OyeChats acts as a processor on your behalf. The Data Processing Addendum available at oyechats.com/legal/dpa is incorporated by reference and governs that processing. You are responsible for giving your Visitors the privacy notices their law requires, for obtaining any consent required before the widget collects their data, and for the accuracy and lawfulness of the knowledge base content you upload or ask us to crawl. You confirm you have the right to use any content you supply to us for that purpose. ### AI Outputs The Services generate Output using large language models. Output is probabilistic: it can be incomplete, out of date, or factually wrong, including where the underlying knowledge base is accurate. OyeChats does not warrant the accuracy, completeness, or fitness for any purpose of any Output, and Output is expressly excluded from the limited warranty below. You are responsible for reviewing Output and for any reliance you or your Visitors place on it. Where Output could have legal, financial, medical, safety, or similarly significant consequences, you will not present it to Visitors without human review. The Services do not provide legal, medical, financial, tax, or other professional advice, and you will not configure a Bot to hold itself out as doing so. Where the EU AI Act applies to a deployment, OyeChats is the provider of the AI system and you are its deployer, and each party is responsible for the obligations the Act places on its role. The Services disclose to Visitors that they are interacting with an automated system; you are responsible for the transparency, record-keeping, and human-oversight duties that fall on a deployer, and for not disabling any disclosure the Services provide. As between you and OyeChats, you own the Output generated from your Customer Data. Output is not unique to you: the same or similar Output may be generated for other customers, and we make no claim of exclusivity in it. ### Security We will maintain commercially reasonable administrative, physical, and technical safeguards designed to protect the security, confidentiality, and integrity of Customer Data. These include encryption in transit (TLS 1.3), encryption at rest for primary databases and object storage, logical isolation of each customer's data, role-based access controls on production systems, audit logging, and a documented incident response process. Further detail, and the process for reporting a vulnerability, is set out in our Security and Responsible Disclosure Policy. ### Third-Party Platforms and Third Party Apps The Services rely on, and can be configured to integrate with, Third Party Apps. Those we engage to operate the Services include large language model and embedding providers (OpenAI, Google), web crawling and content extraction (Spider.cloud, Jina AI), IP and email intelligence (ipapi.is, Reoon), infrastructure and storage (DigitalOcean, Cloudflare, Vercel), transactional email (Brevo), push notification delivery (Expo), payment processing (Razorpay), observability (Sentry, Langfuse), and any integrations you elect to connect. The current itemized list is maintained on our Subprocessors List page. Third Party Apps are governed by their own terms and privacy policies. Enabling an integration authorizes OyeChats to transmit Customer Data to that Third Party App to the extent necessary to operate it. ### Ownership OyeChats and its licensors retain all right, title, and interest in and to the Services, the Documentation, the widget code we publish, and all underlying software, models, designs, trademarks, and know-how. This Agreement grants you only a limited right to use the Services as expressly set out herein. If you provide feedback, suggestions, or ideas about the Services, you grant us a perpetual, irrevocable, royalty-free license to use them without restriction. ### Free Plan, Trials and Promotional Credits Free plan. We offer a free plan with reduced limits. It is provided as is, without any warranty or support commitment, and we may change or discontinue it on notice. Trials. Where a plan is offered with a free trial, the trial runs for the period stated at sign-up and gives you the paid plan's features. Unless you cancel before the trial ends, the trial converts automatically to a paid subscription and the plan fee is charged to your designated payment method. You can cancel at any point during the trial from your dashboard at no charge. Pre-debit notice. Where a recurring charge is set up on an Indian card or e-mandate, we send you a notification in advance of each debit, as the applicable Reserve Bank of India requirements provide. Receiving that notice does not extend the cancellation deadline; cancel before the debit date if you do not want the charge. Trial data. A trial that does not convert to a paid plan moves the account to the Free plan. Conversation and knowledge base data created during the trial is retained subject to the Free plan's limits, and knowledge above those limits is made inactive rather than deleted. Upgrading restores it. We do not delete trial data on a timer. Promotional credits. Credits granted as part of a promotion are not purchased credits. They carry the expiry and eligibility conditions stated when they are granted, are not refundable or transferable, and may be withdrawn if the promotion's conditions are not met. ### Subscription Term, Fees and Payment Plans and renewal. Your Subscription Term begins on the start date in your Order and continues for the period specified (monthly or annually). The subscription renews automatically for successive periods of equal length at the then-current list price until you cancel. You may cancel at any time from your dashboard, effective at the end of the then-current period, as described in our Cancellation Policy. Fees and taxes. Fees are charged in advance and are non-refundable except where expressly stated in our Refund Policy or required by law. Prices listed for Indian customers are exclusive of Goods and Services Tax. GST at the applicable rate is added to the listed price at checkout, and is shown as a separate line on your tax invoice. Prices listed in other currencies are exclusive of any withholding, sales, use, VAT, or similar taxes your jurisdiction imposes, which are your responsibility. Payment. We process card, UPI, net-banking, and international payments through Razorpay. You authorize us to charge your designated payment method on a recurring basis until you cancel. Usage and overages. Your plan includes monthly limits. If you exceed a limit, the Services may degrade gracefully, and we will notify you to upgrade. We do not silently charge overages without your consent. Non-payment. If a charge fails, we will retry it and notify you. We may suspend access to the Services after a failed payment remains uncured following the notices described in our dunning process, and may terminate for non-payment under the termination provisions below. Price changes. We may adjust list prices for future Subscription Terms by giving you at least 30 days' notice before your renewal. ### Term and Termination This Agreement begins when you create an Account and continues until all Subscription Terms expire or the Agreement is terminated as described below. Termination for convenience. You may cancel your subscription at any time from your dashboard. Cancellation stops automatic renewal; the Services remain available until the end of the paid period, and we do not refund partial periods. Termination for cause. Either party may terminate this Agreement for material breach by the other party if the breach is not cured within 14 days after written notice describing it. Suspension. We may suspend your access, or a specific Bot, without prior notice where necessary to prevent material harm to the Services, to other customers, or to a third party, or where required by law. We will restore access promptly once the cause is resolved, and will tell you why we suspended it. Effect of termination. On termination, your right to access the Services ceases. On request within 30 days of termination we will provide you with an export of your Customer Data; export is currently handled by our team on request rather than through a self-service control in the dashboard. After that window, we will delete or anonymize Customer Data in line with the retention schedule in the Privacy Policy and the Data Processing Addendum. Survival. The Definitions, Ownership, AI Outputs, Limitation of Liability, Indemnification, and General Terms sections, and any accrued payment obligation, survive termination. ### Limited Warranty OyeChats warrants that the Services will perform materially in accordance with the Documentation during the Subscription Term. As your sole and exclusive remedy for breach of this warranty, we will use commercially reasonable efforts to correct the non-conformity. This warranty does not apply to the free plan, to trials, to features identified as beta, preview, or early access, or to Output. Beta features are provided as is, may be changed or withdrawn at any time, and are excluded from every warranty and service commitment in this Agreement. EXCEPT FOR THE EXPRESS WARRANTY IN THIS SECTION, THE SERVICES ARE PROVIDED "AS IS" AND "AS AVAILABLE." TO THE MAXIMUM EXTENT PERMITTED BY LAW, OYECHATS DISCLAIMS ALL OTHER WARRANTIES, EXPRESS OR IMPLIED, INCLUDING WARRANTIES OF MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE, AND NON-INFRINGEMENT. ### Limitation of Liability TO THE MAXIMUM EXTENT PERMITTED BY LAW, NEITHER PARTY WILL BE LIABLE FOR ANY INDIRECT, INCIDENTAL, CONSEQUENTIAL, SPECIAL, EXEMPLARY, OR PUNITIVE DAMAGES, OR FOR ANY LOSS OF PROFITS, REVENUE, GOODWILL, OR DATA. EACH PARTY'S AGGREGATE LIABILITY ARISING OUT OF OR RELATING TO THIS AGREEMENT WILL NOT EXCEED THE FEES YOU PAID OR WERE OBLIGATED TO PAY FOR THE SERVICES IN THE 12 MONTHS IMMEDIATELY PRECEDING THE EVENT GIVING RISE TO THE CLAIM. Nothing in this Agreement excludes or limits either party's liability where applicable law does not permit it to be excluded or limited. ### Indemnification By OyeChats. We will defend you against any third-party claim alleging that the Services, when used as authorized under this Agreement, infringe a third party's intellectual property right, and will pay damages and reasonable costs finally awarded against you or agreed in settlement. This obligation does not apply to a claim arising from Output, from Customer Data, or from your combination of the Services with anything we did not supply. By Customer. You will defend OyeChats against any third-party claim arising out of Customer Data, your use of the Services in breach of this Agreement or the Acceptable Use Policy, your reliance on or presentation of Output, or your failure to provide required notices to or obtain required consent from Visitors. ### General Terms Entire agreement. This Agreement, together with the Privacy Policy, the Acceptable Use Policy, the Data Processing Addendum, the Refund Policy, the Cancellation Policy, and any Order, is the entire agreement between the parties and supersedes any prior proposal or representation. Amendments. We may update this Agreement from time to time. For material changes, we will provide at least 30 days' notice. Governing law and venue. This Agreement is governed by the laws of India. The courts located in Thane, Maharashtra, India will have exclusive jurisdiction over any dispute. Assignment. You may not assign this Agreement without our prior written consent, except to a successor in a merger or sale of substantially all of your assets who is not our competitor. We may assign it to an affiliate or to a successor in a corporate transaction. Severability and waiver. If any provision is held unenforceable, it will be modified to the minimum extent needed to make it enforceable and the rest of the Agreement will remain in effect. A failure to enforce a provision is not a waiver of it. Independent parties. The parties are independent contractors. This Agreement creates no partnership, agency, joint venture, or employment relationship. Publicity. Neither party will use the other's name or logo in a public statement or customer list without prior written consent, except that you may state that you use the Services and we may identify you as a customer where you have given us written permission. Export control and sanctions. Each party will comply with applicable export control and economic sanctions laws. You confirm you are not located in, organized under the laws of, or ordinarily resident in a territory subject to comprehensive sanctions, and that you are not a restricted or denied party. Force majeure. Neither party will be liable for any delay or failure to perform caused by events beyond its reasonable control. Notices. Notices to OyeChats must be sent to support@oyechats.com, with a copy to Digibranders Private Limited, Office No. 2617, 26th Floor, Solus Building, Hiranandani Estate, Ghodbunder Road, Thane West, Maharashtra 400607, India. Notices to you are sent to the email address of your account administrator. ### Questions Questions about these Terms? Contact support@oyechats.com. ## Acceptable Use Policy Source: https://www.oyechats.com/legal/aup Last updated: 2026-08-17 ### Introduction This Acceptable Use Policy ("AUP") sets out what you may and may not do with the OyeChats Services. It forms part of our Terms of Service, and it applies to you, to your Authorized Users, and to any Bot you configure. It exists as a separate document for a practical reason: the ways an AI chat system can be misused change faster than a contract can be renegotiated. Keeping the list here means we can add a newly-observed abuse pattern without amending the Agreement. We will not use that flexibility to reduce the rights the Agreement grants you. ### Prohibited Content and Conduct You will not use the Services to create, store, transmit, or make available content that: - Is unlawful, defamatory, harassing, abusive, or that threatens or incites violence. - Infringes a third party's intellectual property, privacy, or publicity rights. - Constitutes spam, chain messaging, or unsolicited bulk commercial messaging. - Sexually exploits or endangers a minor, or is sexual content involving minors in any form. - Contains malware, ransomware, or code designed to disrupt or gain unauthorized access to any system. - Is designed to deceive a person about who they are dealing with, including impersonating a real individual, business, or public authority. ### Prohibited Uses of AI Features The following are specific to the AI capabilities of the Services and are prohibited: - Configuring, prompting, or modifying a Bot so that it denies being automated, or so that a Visitor who asks whether they are talking to a human is misled. - Suppressing, removing, or obscuring any disclosure the Services present to a Visitor about the automated nature of the conversation. - Using the Services to generate content presented as professional legal, medical, financial, tax, or safety advice, or to substitute for a regulated professional. - Presenting Output to Visitors without human review where an error could have legal, financial, medical, or safety consequences. - Deploying a Bot to an audience you know or ought reasonably to know consists of children, without the parental consent your applicable law requires. - Using the Services to generate content intended to manipulate an election, to produce coordinated inauthentic messaging, or to impersonate a real person's voice or writing without their consent. - Using Output to train, fine-tune, distil, or evaluate a competing machine learning model. - Using the Services for automated decisions about a person's access to employment, credit, housing, insurance, education, or essential services. ### Platform and Tenant Integrity The following protect the Services and the other customers on them: - Do not attempt to discover, extract, or infer another customer's system prompt, knowledge base content, conversation data, or configuration, whether by prompt injection, crafted input, enumeration of identifiers, or any other means. - Do not attempt to make a Bot ignore or override the instructions or restrictions its owner configured. - Do not probe, scan, or test the vulnerability of the Services except under our Security and Responsible Disclosure Policy. - Do not circumvent authentication, rate limits, credit accounting, plan entitlements, or usage metering. - Do not scrape, crawl, or bulk-extract the Services or their output other than through the documented API within your plan limits. - Do not use the Services to crawl or ingest content from a website you do not own or have permission to ingest, or in a way that breaches that site's terms or robots directives. - Do not send traffic that imposes a disproportionate load on our infrastructure, including automated load generation not agreed with us in advance. ### Reporting Abuse If you believe a Bot built on OyeChats is being used in breach of this policy, write to support@oyechats.com with the website address, a description of what you observed, and the approximate time. We investigate every report we can reproduce. Security vulnerabilities are handled separately, under our Security and Responsible Disclosure Policy. ### Enforcement Where we find a breach of this policy, our response is proportionate to what we find. In most cases we contact the account owner and ask for it to be corrected. Where a breach is causing active harm to Visitors, to other customers, or to the Services, we may suspend the affected Bot or the account without prior notice, and we will tell you why. A material or repeated breach is a material breach of the Terms of Service and may result in termination under those terms. We may also report unlawful conduct to the relevant authorities where we are required or permitted to do so. ### Changes to This Policy We may update this policy as new misuse patterns emerge. Material additions will be announced by email to account administrators or by in-product notice. The "Last updated" date above reflects the most recent revision. ### Contact Questions about this policy? Write to support@oyechats.com. ## Data Processing Addendum Source: https://www.oyechats.com/legal/dpa Last updated: 2026-08-17 ### Introduction and Applicability This Data Processing Addendum ("DPA") forms part of the Terms of Service (the "Agreement") between Digibranders Private Limited, trading as OyeChats ("OyeChats," "we," "us"), and the customer that has entered into the Agreement ("Customer," "you"). It applies whenever OyeChats processes Personal Data on your behalf in the course of providing the Services. This DPA is designed to satisfy the requirements that apply to a data processor under the Digital Personal Data Protection Act, 2023 (India) ("DPDP Act") and, where your processing is subject to it, the EU General Data Protection Regulation 2016/679 and the UK GDPR (together, "GDPR"). Where this DPA conflicts with the rest of the Agreement, this DPA prevails in respect of the processing of Personal Data. This DPA takes effect when you accept the Agreement and continues for as long as OyeChats processes Personal Data on your behalf. ### Roles of the Parties For Personal Data processed under this DPA, you are the Controller (Data Fiduciary under the DPDP Act) and OyeChats is your Processor (Data Processor). You determine the purposes and means of the processing. You are responsible for the lawfulness of the instructions you give us, for giving Data Subjects the notice their law requires, and for obtaining any consent required before the widget collects their data. This matters particularly under the DPDP Act, which does not provide a legitimate-interest basis to fall back on. Separately, OyeChats acts as an independent Controller for the account data of its own customers (such as your login credentials, billing records, and support correspondence). That processing is described in our Privacy Policy and is not governed by this DPA. ### Scope and Purpose of Processing OyeChats processes Personal Data for the following purposes and no others: - Operating the chat widget and generating AI responses to Visitor messages. - Storing chat transcripts, lead capture submissions, and Visitor metadata. - Deriving geography and network signals from a Visitor's IP address, and verifying the deliverability of email addresses submitted through lead-capture forms. - Routing conversations to your operators for live chat and delivering the notifications you configure. - Producing analytics and lead qualification scores. - Securing, supporting, and troubleshooting the Services. The categories of Data Subjects, categories of Personal Data, and duration of processing are set out in Annex I below. ### Processing on Documented Instructions OyeChats processes Personal Data only on your documented instructions. The Agreement, this DPA, the configuration choices you make in the dashboard, and your use of the Services are your instructions to us. If we consider an instruction to infringe applicable data protection law, we will inform you without undue delay, and may suspend performance of that instruction until it is confirmed or withdrawn. If applicable law requires us to process Personal Data other than on your instructions, we will inform you of that requirement before processing, unless the law prohibits us from doing so. We will not disclose Personal Data to a public authority except where legally compelled, and where permitted we will notify you and disclose only the minimum required. ### Confidentiality of Personnel OyeChats ensures that every person authorized to process Personal Data under this DPA is bound by a written obligation of confidentiality that survives the end of their engagement, has been informed of the confidential nature of the data, and receives access only on a least-privilege basis for as long as they need it. ### Security Measures OyeChats implements and maintains appropriate technical and organizational measures designed to protect Personal Data. They are set out in Annex II below. We may update those measures over time, provided we do not materially reduce the level of protection they provide. ### Sub-processors You provide a general authorization for OyeChats to engage Sub-processors to deliver the Services. Each Sub-processor is engaged under a written contract imposing data protection obligations at least as protective as those in this DPA, and OyeChats remains responsible to you for its Sub-processors' performance. The Sub-processors we currently engage are: - DigitalOcean: Application server and managed database hosting. (India) - Cloudflare: Object storage for uploaded knowledge base files, and CDN delivery of the embeddable widget. (Global edge network) - Vercel: Hosting for the marketing site and the customer dashboard front-end. (United States) - OpenAI: Large language model inference. (United States) - Google: Large language model inference (fallback) and all text embedding generation. (United States) - Spider.cloud: Web crawling and content extraction for knowledge base ingestion. (United States) - Jina AI: Web content extraction for knowledge base ingestion. (Germany / European Union) - ipapi.is: IP geolocation and network intelligence lookups. (European Union) - Reoon: Email address deliverability verification. (Singapore) - Brevo: Transactional email delivery. (European Union) - Expo: Mobile push notification delivery to operators. (United States) - Razorpay: Payment processing. (India) - Sentry: Application error monitoring. (United States) - Langfuse: LLM observability. (European Union) We will give you at least 30 days' advance notice before adding or replacing a Sub-processor that processes Personal Data. If you have a reasonable data protection objection to a new Sub-processor, tell us within that notice period and we will work with you in good faith to find an alternative. If we cannot, you may terminate the affected Services without penalty and receive a pro-rata refund of pre-paid fees for the unused remainder of the Subscription Term. ### Data Subject Requests The Services give you the ability to access, correct, export, and delete Personal Data about your Visitors, so that you can respond to a Data Subject request yourself. Where a request cannot be fulfilled through the Services, OyeChats will provide reasonable assistance, at your cost where the assistance is substantial, to help you respond within your statutory deadline. If a Data Subject contacts OyeChats directly about Personal Data we process on your behalf, we will not respond to the substance of the request. We will refer them to you and inform you promptly. ### Assistance with Your Compliance Obligations Taking into account the nature of the processing and the information available to us, OyeChats will provide reasonable assistance with: - Your obligation to keep processing secure. - Your obligations to notify Personal Data Breaches to supervisory authorities and to Data Subjects. - Your data protection impact assessments, and any prior consultation with a supervisory authority arising from one. ### Personal Data Breach Notification OyeChats will notify you without undue delay, and in any event within 72 hours, after becoming aware of a Personal Data Breach affecting Personal Data processed on your behalf. The notification will describe, to the extent then known, the nature of the breach, the categories and approximate number of Data Subjects and records affected, the likely consequences, and the measures taken or proposed. Where we cannot provide all of that at once, we will provide it in phases without further undue delay. We will reasonably cooperate with your own notification obligations to supervisory authorities, to the Data Protection Board of India, and to affected Data Subjects. Our notification is not an admission of fault or liability. ### Data Retention and Deletion During the term of the Agreement, Personal Data is retained according to the retention settings available in the dashboard and the schedule described in the Privacy Policy. Note that your plan tier governs how far back conversation history remains accessible to you; it is not an automatic deletion schedule. On termination or expiry of the Agreement, you may request an export of Personal Data within 30 days. After that window, OyeChats will delete or irreversibly anonymize all Personal Data processed on your behalf within a further 30 days, except where retention is required by applicable law, in which case we will retain only what the law requires and continue to protect it under this DPA. You may request deletion of Personal Data at any point during the term by writing to support@oyechats.com. Deletion is currently carried out by our team on request rather than through a self-service control in the dashboard, and is completed within 30 days. ### International Data Transfers Where Personal Data subject to the GDPR is transferred to a country without an adequacy decision, the European Commission's Standard Contractual Clauses (Commission Implementing Decision (EU) 2021/914) are incorporated into this DPA by reference and apply to that transfer, with Module Two (controller to processor) applying between you and OyeChats and Module Three (processor to processor) applying where you are yourself a processor. For the purposes of the Clauses: the data exporter is you, the data importer is OyeChats, Clause 7 (docking) applies, Clause 9 option 2 (general written authorization for Sub-processors) applies with the 30-day notice period set out above, Clause 11 does not include the optional independent dispute resolution body, Clause 17 selects the law of Ireland, and Clause 18(b) selects the courts of Ireland. Annex I and Annex II of the Clauses are populated by Annex I and Annex II of this DPA, and the Sub-processor list above serves as Annex III. Where Personal Data is subject to the UK GDPR, the UK International Data Transfer Addendum to the Clauses applies, with the information in Part 1 taken from this DPA and Annexes and neither party permitted to end the Addendum under Section 19. Where Personal Data is subject to the Swiss FADP, the Clauses apply with references to the GDPR read as references to the FADP and the Swiss Federal Data Protection and Information Commissioner as the competent authority. ### Audit Rights OyeChats will make available to you the information reasonably necessary to demonstrate compliance with this DPA. In the first instance, we satisfy audit requests through written responses to security and privacy questionnaires and copies of relevant policy documentation. Where that is not sufficient to demonstrate compliance, and where you are required to conduct an audit or inspection by applicable data protection law or by your supervisory authority, OyeChats will allow for and contribute to an audit of the processing, conducted by you or by an independent auditor you appoint who is not our competitor. Such an audit is subject to at least 30 days' written notice, reasonable confidentiality undertakings, scoping that avoids disruption to the Services or access to other customers' data, and no more than once in any 12-month period unless a Personal Data Breach or a regulator's direction requires otherwise. You bear the cost of the audit and of our reasonable assistance. ### Liability Each party's liability under or in connection with this DPA is subject to the exclusions and limitations of liability set out in the Agreement. Where the Standard Contractual Clauses apply, nothing in this section limits any liability the Clauses impose towards a Data Subject. ### Annex I: Details of Processing Subject matter and nature of the processing: provision of an AI chat and live-chat service embedded on the Customer's websites, including storage, retrieval, AI inference, enrichment, analytics, notification, and support. Duration: for the term of the Agreement, plus the post-termination export and deletion windows described above. Categories of Data Subjects: - Visitors to websites where the Customer has deployed the widget. - The Customer's Authorized Users and operators. Categories of Personal Data: - Identifiers and contact details submitted by a Visitor: name, email address, phone number, company. - Conversation content: messages exchanged with a Bot or an operator, timestamps, and ratings. - Technical and network data: IP address, browser and device type, derived city, region and country, derived network and organization signals, page URL, referrer, and campaign parameters. - Email verification results for addresses submitted through lead-capture forms. - Derived qualification signals and conversation summaries generated from the above. - Operator account data: name, email, role, activity logs, and push notification tokens. Sensitive Personal Data: the Services are not designed for, and the Customer must not configure a Bot to solicit, special categories of data under Article 9 GDPR, government identifiers, or payment card details. Any such data a Visitor volunteers unprompted in free text is processed as ordinary conversation content, and the Customer remains responsible for it. Frequency of transfer: continuous, on an ongoing basis for the duration of the Agreement. ### Annex II: Technical and Organizational Measures Encryption. TLS 1.3 for all API, widget, and dashboard traffic. Encryption at rest for primary databases and object storage. Encrypted database backups, rotated on a 30-day cycle. Access control. Role-based access control on the platform and on production systems, least-privilege provisioning, multi-factor authentication for production access, and separate credentials for each persona (customer, operator, widget, administrator). Tenant isolation. Every query is scoped to the owning account, and each Bot's knowledge base and conversations are logically isolated from every other tenant's. Data minimization at boundaries. Visitor IP addresses are stripped from every API response, dashboard view, CSV export, and third-party observability trace, at a single enforced point in the code. Logging and monitoring. Audit logging of administrative and operator actions, immutable transition logs for live-chat handovers, application error monitoring, and health monitoring of the platform. Environment separation. Production and non-production workloads run in separate environments with separate credentials and separate observability projects. Resilience. Automated encrypted backups, rate limiting, and graceful degradation when a plan limit or an upstream provider limit is reached. Incident response. A documented incident response process, with the breach notification commitments set out above. Personnel. Confidentiality obligations for all personnel with access to Personal Data, and least-privilege access granted for the duration of need. Sub-processor governance. Written data protection terms with every Sub-processor, and the notice and objection process set out above. ### Contact Questions about this DPA can be sent to support@oyechats.com, or to our Grievance Officer and Data Protection Contact, Siddique Ahmed, at Digibranders Private Limited, Office No. 2617, 26th Floor, Solus Building, Hiranandani Estate, Ghodbunder Road, Thane West, Maharashtra 400607, India. ## Subprocessors List Source: https://www.oyechats.com/legal/subprocessors Last updated: 2026-08-17 ### Overview A "sub-processor" is a third party we engage to process Customer Data on our behalf in order to deliver the OyeChats Services. Each one is engaged under a written agreement that requires data protection terms at least as protective as those in our Privacy Policy and Data Processing Addendum. This page is the authoritative list. Where a location is given as a country, that is where the provider processes data for us under our configuration; several providers operate globally. ### Infrastructure and Hosting - DigitalOcean: Primary application servers and managed PostgreSQL database hosting. (India) - Cloudflare: Object storage for uploaded knowledge base files via R2, and CDN delivery of the embeddable widget bundle. (Global edge network) - Vercel: Hosting for the marketing site (oyechats.com) and customer dashboard front-end (app.oyechats.com). (United States) ### AI Model Providers Conversation messages and knowledge base content are sent to these providers at query time. We do not authorize them to use Customer Data to train general-purpose foundation models. - OpenAI: Primary large language model inference for chat responses. (United States) - Google (Gemini API): Fallback large language model inference, and the sole provider of text embedding generation. Every document you upload or page we crawl, and every question a Visitor asks, is embedded by Google. (United States) ### Web Crawling and Content Extraction When you ask us to train a bot on a URL, we fetch and extract that page through a managed crawling provider rather than from our own servers. The URL and the page content are sent to the provider; where a page is behind a login or contains personal data, that content is transmitted too. - Jina AI: Primary web content extraction. (Germany / European Union) - Spider.cloud: Web crawling and content extraction, used as the alternate provider. (United States) ### IP and Email Intelligence - ipapi.is: IP geolocation and network intelligence. Receives the Visitor's IP address for every conversation, and returns the geography, the owning organization and network, and hosting, VPN, and abuse signals. (European Union) - Reoon: Email address deliverability verification. Receives email addresses submitted through lead-capture forms on plans that include verification, and returns a deliverability result. (Singapore) ### Communications and Notifications - Brevo (Sendinblue): Transactional email delivery. (European Union) - Expo: Mobile push notification delivery to operators who have enabled notifications. Receives the device push token and the notification content, which may include a preview of a Visitor message. (United States) ### Authentication - Google (Sign in with Google): Optional sign-in for customer accounts. We request only the openid, email, and profile scopes, and receive the name, email address, and profile picture on the Google account. (United States) ### Payment Processing Card numbers, UPI handles, and bank account details are processed and stored by this provider and do not reach OyeChats servers. - Razorpay: Card, UPI, net-banking, and international payment processing, for both INR and foreign-currency charges. (India) ### Monitoring and Observability - Sentry: Application error monitoring and diagnostics. (United States) - Langfuse: LLM observability. Receives prompts, retrieved context, and model responses for tracing. Visitor IP addresses are stripped before a trace is sent. (European Union) ### Optional Customer-Enabled Integrations Customers may choose to connect third-party tools (such as CRMs, ticketing systems, calendars, or analytics services) to their account. These integrations are processors of Customer Data acting on the customer's direct instructions. ### Updates to This List We may add, remove, or replace sub-processors from time to time. For material changes, we will provide at least 30 days' advance notice by email to account administrators or by in-product notice. Customers with a data protection objection to a new sub-processor have the rights set out in our Data Processing Addendum. ### Contact Questions about our sub-processors? Write to support@oyechats.com and we will respond within 14 days. ## Cookie Policy Source: https://www.oyechats.com/legal/cookies Last updated: 2026-08-17 ### Introduction This Cookie Policy explains how OyeChats uses cookies and similar technologies on our marketing site at oyechats.com, the customer dashboard at app.oyechats.com, and the embeddable chat widget our customers deploy on their own websites. If you are a customer deciding how to describe the OyeChats widget in your own cookie notice, the section on the widget below is the part you need. ### What are cookies? Cookies are small text files a website places on your device so it can remember you between visits. "Similar technologies" covers anything that does roughly the same job: localStorage and sessionStorage in the browser, the IndexedDB API, pixel tags in emails, and software development kits (SDKs). ### Cookies on our marketing site and dashboard We use a small number of strictly-necessary first-party cookies, plus one analytics category that runs only with your permission where consent is required. We do not run advertising cookies or cross-site advertising pixels on our own properties. - oyechats_session: Keeps you signed in to the customer dashboard between page loads and protects against session fixation. (Session, cleared on logout) - oyechats_csrf: Protects state-changing requests from cross-site request forgery attacks. (Session) - oyechats_consent: Remembers your cookie banner choice, on the marketing site and in the customer dashboard. (6 months) Analytics cookies, set by Google Analytics via Google Tag Manager on oyechats.com only: - _ga: Distinguishes one browser from another so we can count returning visitors. (2 years) - _ga_E5ZZ461R8T: Holds the session state for our Google Analytics property. (2 years) Visitors in the EEA, the UK, and Switzerland are asked to consent before either analytics cookie is set, and neither is set if you decline. Elsewhere they are set by default and you can turn them off at any time from "Cookie preferences" in the footer. We also treat a Global Privacy Control signal as a decline. ### The embeddable chat widget The OyeChats widget stores a single anonymous session identifier so a conversation stays continuous for the same Visitor. That identifier is not tied to a name, an email address, or an account unless the Visitor submits one through a lead-capture form. Primary storage is localStorage, under the key chat_session_id_[bot key]. Because localStorage is partitioned per origin, the widget also writes first-party cookies so a conversation survives a move between subdomains of the site it is embedded on: - oyechats_sid_[bot key]: Mirrors the anonymous session identifier, scoped to the parent domain of the site the widget is embedded on, so a Visitor moving from example.com to help.example.com keeps the same conversation. First-party, SameSite=Lax, Secure on HTTPS. (30 days) - __oye_apex_probe: A throwaway cookie written and immediately deleted the first time the widget loads on a hostname, to work out which parent domain the browser will accept a cookie for. It holds no data about the Visitor and does not persist. (Deleted immediately) These are first-party cookies on the customer's own domain, not OyeChats cookies, and they are strictly necessary for the chat function the Visitor initiated. Cross-subdomain continuity is enabled by default, using an automatically detected parent domain; customers can restrict the scope by setting an explicit share domain in the dashboard under Channels. If the browser refuses cookies, the widget falls back to localStorage alone and the chat still works, without continuity across subdomains. The widget sets no advertising, analytics, or cross-site tracking cookies, and does not track Visitors across websites belonging to different customers. Session storage is namespaced per bot, so a Visitor who chats on two OyeChats-powered sites is not linked between them. ### Your choices and controls You can control cookies in several ways: - Browser settings: most browsers let you block, delete, or be warned about cookies on a per-site basis. - Marketing site banner: if a consent banner is shown on oyechats.com in your region, you can accept or decline non-essential categories there. - In the widget: starting a new chat clears the stored session identifier and expires the continuity cookie. - Widget scope, for customers: if you operate a site that embeds the OyeChats widget, you can narrow cross-subdomain continuity to a specific domain from your dashboard under Channels. Blocking strictly-necessary cookies will break sign-in and other core flows on the dashboard. ### Do Not Track and Global Privacy Control Browsers can transmit a Do Not Track (DNT) header or a Global Privacy Control (GPC) signal. We honor GPC where transmitted: when GPC is detected, we treat it as an opt-out of any sale or sharing of personal information for the purposes covered by the CCPA / CPRA. We do not respond to DNT, which has no agreed meaning across browsers. ### Changes to this policy We may update this Cookie Policy from time to time to reflect changes in technology, applicable law, or our practices. ### Questions Have a question about how we use cookies? Write to support@oyechats.com and we will respond within 14 days. ## Security and Responsible Disclosure Policy Source: https://www.oyechats.com/legal/security Last updated: 2026-08-17 ### Introduction We would rather hear about a vulnerability from you than from an incident. This policy tells you where to send a report, what we commit to in return, and what is in and out of scope. We do not currently run a paid bug bounty. We do acknowledge every valid report, and we will credit you publicly if you would like us to. ### How to Report a Vulnerability Email support@oyechats.com with "Security" in the subject line. A useful report includes: - The affected component and URL or endpoint. - Steps to reproduce, ideally with a proof of concept. - What an attacker could achieve, and any prerequisites. - Your name or handle, if you would like to be credited. Please report in English, and please send one issue per report. ### What We Commit To - We acknowledge your report within 2 business days. - We give you an initial assessment, including whether we consider it in scope and our severity view, within 5 business days. - We keep you informed while we work on a fix, and tell you when it is deployed. - We aim to remediate critical issues within 7 days, high severity within 30 days, and everything else on a schedule we will share with you. - We will not take legal action against you for research conducted in good faith under this policy. ### Safe Harbour If you make a good-faith effort to comply with this policy during your research, we will treat your research as authorized, we will work with you to understand and resolve the issue quickly, and we will not pursue or support any legal action related to it. To stay within safe harbour, you must: - Use only your own test accounts, and stop as soon as you can demonstrate the issue. - Not access, modify, export, or retain data belonging to any other customer or Visitor. If you encounter such data incidentally, stop, report it, and delete any copy. - Not degrade the Service: no denial of service, no load or stress testing, no automated scanning at volume. - Not use social engineering, phishing, or physical attacks against our staff, our customers, or our providers. - Give us a reasonable opportunity to remediate before disclosing publicly, and coordinate the timing with us. Safe harbour covers our own systems only. It does not authorize testing against our sub-processors, or against a customer's website that happens to embed our widget. ### Scope In scope: - oyechats.com and app.oyechats.com. - Our REST and WebSocket APIs. - The embeddable chat widget and its CDN bundle. - The OyeChats mobile application for operators. Particularly interesting to us: any cross-tenant data access, authentication or authorization bypass, extraction of another customer's system prompt or knowledge base, credit or entitlement bypass, and server-side request forgery through the URL ingestion feature. Out of scope: - Reports from automated scanners with no demonstrated impact. - Missing security headers, cookie flags, or TLS configuration preferences with no demonstrated exploit. - Denial of service, rate-limit exhaustion, and volumetric testing. - Social engineering, phishing, and physical security. - Vulnerabilities in a third-party service we use; report those to that provider. - A customer's own website configuration, including how they have configured their bot or their consent banner. - Content a bot generates that is merely inaccurate or undesirable. That is a product report, not a vulnerability; send it to support@oyechats.com without the Security subject line. ### Security Measures We Operate Encryption. TLS 1.3 for all API, widget, and dashboard traffic. Encryption at rest for primary databases and object storage. Encrypted, rotated database backups. Access control. Role-based access control, least-privilege provisioning, multi-factor authentication for production access, and separate credentials for each persona. Tenant isolation. Every query is scoped to the owning account; knowledge bases and conversations are logically isolated between tenants. Data minimization. Visitor IP addresses are stripped at every outbound boundary, including API responses, dashboard views, CSV exports, and third-party observability traces. Monitoring. Audit logging of administrative and operator actions, immutable transition logs for live-chat handovers, application error monitoring, and platform health monitoring. Environment separation. Production and non-production workloads run in separate environments with separate credentials. We do not currently hold a SOC 2 or ISO 27001 certification, and we will not claim one until we do. We answer security questionnaires in writing, and the audit rights available to customers are set out in our Data Processing Addendum. ### Contact Security reports and questions about this policy: support@oyechats.com, with "Security" in the subject line. ## Refund Policy Source: https://www.oyechats.com/legal/refund Last updated: 2026-08-17 ### Introduction This Refund Policy applies to all payments made to OyeChats, a brand of Digibranders Private Limited. It should be read together with our Terms of Service and Cancellation Policy. ### General Policy All fees paid to OyeChats are non-refundable except in the specific circumstances described below. This includes fees for subscription plans (monthly or annual) and one-time top-up credit purchases. We encourage you to evaluate OyeChats using our free plan before upgrading to a paid subscription. Where a free trial is offered on a plan, it provides a full-featured experience before any charge is made, and you can cancel during the trial at no charge. Prices listed for Indian customers are exclusive of GST, so the amount charged is the listed price plus GST at the applicable rate. A refund returns the full amount you were actually charged, base fee and GST together, and the tax component is adjusted through a credit note. ### Subscription Payments Monthly plans. Monthly subscription fees are charged in advance at the start of each billing cycle. If you cancel during a billing cycle, your subscription remains active until the end of the paid period; no partial-month refund is issued for the unused days. Annual plans. Annual subscription fees are charged upfront for the full year. If you cancel an annual subscription before the end of the term, no refund is issued for the remaining months, except in the eligible circumstances listed below. Plan upgrades. When you upgrade from a lower to a higher plan mid-cycle, any unused credit from the current cycle is applied as a prorated credit toward the new plan. No cash refund is issued for this adjustment. ### Top-Up Credits Top-up credit packs are non-refundable once purchased. Credits are valid for 12 months from the date of purchase and roll over month-to-month within that window. Promotional credits granted as part of an offer are not purchased credits, carry the conditions stated when they are granted, and are not refundable. If you believe credits were deducted in error, contact us at support@oyechats.com within 30 days and we will investigate. ### Eligible Refunds A refund may be issued in the following circumstances: - Duplicate charge. If you were charged more than once for the same billing period due to a payment processing error, we will refund the duplicate amount in full. - Charge after cancellation. If you cancelled before a renewal date and were charged anyway, we will refund that charge in full. - Warranty remedy. If OyeChats cannot resolve a material non-conformance of the Services within a reasonable time, you may be entitled to a pro-rata refund of pre-paid fees for the unused remainder of your Subscription Term. - Service termination by OyeChats. If we terminate your subscription for reasons other than your breach, we will refund any pre-paid fees covering the period after termination. - Sub-processor objection. If you terminate affected Services because we could not resolve a reasonable data protection objection to a new sub-processor, you receive a pro-rata refund as set out in our Data Processing Addendum. - Erroneous billing. If we charged you an amount different from what was displayed at checkout due to a system error on our side, we will refund the difference. - Statutory rights. Nothing in this policy limits any rights you have under applicable law. ### How to Request a Refund To request a refund, email us at support@oyechats.com with the subject line "Refund Request" and include: - The email address associated with your OyeChats account. - The date and amount of the charge in question. - The reason for your refund request. - Any supporting evidence (for example, a screenshot of a duplicate charge). We will acknowledge your request within 2 business days and aim to resolve eligible refunds within 7 business days. Approved refunds are processed back to the original payment method. Once we issue the refund, your bank or card issuer typically takes a further 5 to 7 business days to credit it, and that part is outside our control. ### Contact For questions about this policy, contact us at support@oyechats.com. For an unresolved grievance, contact our Grievance Officer and Data Protection Contact, Siddique Ahmed, at Digibranders Private Limited, Office No. 2617, 26th Floor, Solus Building, Hiranandani Estate, Ghodbunder Road, Thane West, Maharashtra 400607, India. ## Cancellation Policy Source: https://www.oyechats.com/legal/cancellation Last updated: 2026-08-17 ### Introduction This Cancellation Policy explains how to cancel your OyeChats subscription and what happens when you do. ### How to Cancel You can cancel your subscription at any time directly from your dashboard, no need to contact support. To cancel: - Log in to your account at app.oyechats.com. - Go to Billing in the left sidebar. - Select Cancel subscription. - Confirm the cancellation when prompted. You will see the cancellation reflected in your dashboard immediately, along with the date your access ends. If you are unable to cancel through the dashboard, contact us at support@oyechats.com and we will process the cancellation for you within 1 business day. ### Effect of Cancellation Cancellation stops automatic renewal, you will not be charged again after the current billing period ends. Your subscription remains fully active until the last day of the period you have already paid for. For example, if you are on a monthly plan billed on the 1st of each month and you cancel on the 15th, your account stays active until the end of that month. On the 1st of the following month, your plan downgrades to Free automatically. We do not issue refunds for unused days in the current billing period. See our Refund Policy for the specific circumstances where a refund may apply. ### Your Payment Mandate Cancelling in the dashboard takes effect immediately as an instruction to us: no further charge will be raised. The underlying payment mandate or subscription at our payment provider is closed shortly before your paid period ends, rather than on the day you cancel. This means that if you check your bank, card, or UPI app in the meantime, you may still see the OyeChats mandate listed as active. That is expected and no charge will be taken against it. The benefit of doing it this way is that if you change your mind before your period ends, you can reactivate with a single click instead of setting up a new mandate and re-authorising it. If you would prefer the mandate closed immediately, tell us at support@oyechats.com and we will do it. You will then need to re-authorise a new mandate if you later come back. ### Annual Plans If you are on an annual plan, cancelling stops the renewal at the end of the annual term. Your subscription continues until the end of the year you have paid for. No refund is issued for the remaining months of an annual plan on voluntary cancellation. If you need to cancel an annual plan early due to exceptional circumstances, contact support@oyechats.com and we will review your case on its merits. ### Credits After Cancellation Plan credits. Monthly plan credits (included with your subscription) expire at the end of the billing cycle and are not carried forward after cancellation. Top-up credits. Top-up credits you have purchased separately are not affected by subscription cancellation. They remain in your account and are valid for 12 months from their purchase date. Promotional credits. Credits granted as part of a promotion end with the promotion and are not carried forward. ### Your Data After Cancellation When your paid plan ends and your account downgrades to Free, your bots, knowledge base documents, chat history, and leads are retained in your account subject to the Free plan's limits. Note that the Free plan's 7-day window governs how far back conversation history is visible to you; it does not delete anything. If you want your data deleted rather than downgraded, write to support@oyechats.com and we will delete it within 30 days. If you close your account entirely, you can request an export of your data within 30 days of closure. ### Reactivation You can reactivate a paid subscription at any time by going to Billing in your dashboard and selecting a plan. If you reactivate before your cancellation takes effect at the end of the paid period, it is a single click and your existing payment mandate continues. After that, you will be asked to authorise payment again. Your previous configuration, bots, and knowledge base will still be there, provided you have not asked us to delete them. ### Contact For questions about cancellation or your account, contact us at support@oyechats.com.