This Privacy Policy explains how Voxe Desk ("Voxe Desk," "we," "us," or "our") collects, uses, discloses, and otherwise processes personal information in connection with voxedesk.com, our customer-support platform, software, APIs, widgets, and related services (collectively, the "Services").
1. Scope and our role
This Policy applies to website visitors, account holders, trial and paid customers, customer personnel, and people who communicate through a chat widget, helpdesk, or other channel powered by the Services. It does not govern a customer's own privacy practices or third-party services that a customer chooses to connect.
We may act in different privacy roles. For account administration, billing, security, and our own website operations, we generally determine why and how personal information is processed. When we process conversations, knowledge-base content, or other information on behalf of a business customer, that customer generally determines the purposes of processing and we act as its processor or service provider. If you are an end user of one of our customers, you should also review that customer's privacy notice and direct requests about its data to that customer where appropriate.
2. Information we collect
The information we process depends on how the Services are used and configured.
- Account and contact information. Name, email address, company, profile details, communications with us, password hash or OAuth account information, verification status, and account-security information such as login records and multi-factor authentication settings.
- Customer Content and support data. Messages, conversation history, tickets, contact details, agent responses, AI responses, attachments, routing information, and other content submitted through a widget, helpdesk, API, or connected communication channel.
- Knowledge-base and workflow data. Uploaded documents, filenames and file metadata, extracted text, document chunks, embeddings, summaries, system instructions, workflow settings, and business information used to configure AI and automation features.
- Widget and page context. Depending on the widget and its configuration, page title, current URL, referring URL, the page where a chat began, page type, and context update time. On our own website, support context may also include whether an account is signed in, its plan or trial status, and the account email. Customer-controlled widgets may allow the customer to enable or disable individual page-context fields.
- Integration and business-system data. Credentials, tokens, configuration, identifiers, and information returned by commerce platforms, customer relationship management systems, calendars, helpdesks, workflow tools, MCP servers, shipping services, or other APIs a customer connects.
- Calendar data. With authorization, calendar account details, calendars, availability, time zones, event information, and information needed to create or manage a requested booking.
- Billing and subscription information. Plan, subscription status, usage, account balance or credits, transaction amounts and status, and payment-provider customer, subscription, checkout, payment-intent, or invoice identifiers. Payment providers process payment-card details; we do not store full payment-card numbers or security codes on our servers.
- Technical, usage, and security information. IP address, session identifiers, browser or device information, request and diagnostic data, feature usage, timestamps, performance data, security events, error reports, and API usage and token counts.
- Cookie and referral information. Authentication and preference cookies, consent choices, chat-session information, analytics events, and referral or affiliate attribution when those features are used.
3. Sources of information
We obtain information:
- directly from account holders, customer personnel, and people who communicate through the Services;
- from business customers that configure the Services or provide Customer Content;
- from browsers, devices, cookies, widgets, logs, and security systems;
- from services a customer connects, such as Google, Stripe, Chatwoot, commerce platforms, CRMs, calendars, APIs, and MCP servers; and
- from service providers that support hosting, AI processing, workflow execution, analytics, monitoring, email, payments, and related operations.
4. How we use information
We use information as reasonably necessary to:
- create and administer accounts, authenticate users, and provide support;
- operate widgets, helpdesks, conversations, human handoff, workflows, and integrations;
- process documents, create embeddings, retrieve knowledge, and generate or route AI responses;
- access connected business data and perform customer-requested actions, including calendar scheduling;
- manage plans, usage, subscriptions, payments, credits, trials, and invoices;
- send transactional, service, security, and permitted marketing communications;
- monitor reliability, diagnose errors, prevent fraud or abuse, and protect the Services;
- understand use of and improve the Services; and
- comply with law, respond to lawful requests, and enforce our agreements.
5. AI and automated processing
The Services use automated systems and third-party AI or model providers to generate responses, create embeddings, retrieve relevant information, summarize or route conversations, and perform configured functions. Depending on the feature, information sent for processing may include prompts, conversation history, customer or end-user details, page context, system instructions, knowledge-base content, retrieved business data, and tool results.
Information is sent only when reasonably necessary for the selected feature or workflow. The provider and model may vary by configuration. Provider data-use, retention, and model-training practices may also vary and are governed by the applicable provider relationship. We do not represent that every provider or configuration has identical retention or training terms. Customers should avoid submitting information that is not needed for the requested function and should configure AI features consistently with their legal and contractual obligations.
6. Business-data and third-party integrations
When a customer connects a business API, commerce platform, CRM, calendar, helpdesk, workflow, MCP server, or another third-party service, we process credentials and data needed to configure and perform the customer's requested functions. For example, a configured workflow may retrieve selected products, orders, customer records, calendar availability, support records, or tool results, or may create a requested calendar event.
Connecting an integration does not necessarily mean that we copy or permanently store the connected service's entire database. The information actually accessed depends on the customer's permissions, selected tools, workflow, and request. However, credentials may technically permit broader access depending on the permissions granted by the third-party service. Customers should use appropriately limited permissions and review their enabled tools.
7. How we disclose information
We may disclose personal information in the following circumstances:
- Service providers and processors. Providers may support AI and model processing, hosting or object storage, databases, workflow automation, helpdesk services, email delivery, payments, analytics, monitoring, security, cookie consent, and referral attribution. Depending on deployment and configuration, these may include providers such as OpenAI, Fusion, n8n, Jina AI, Chatwoot, Stripe, Google, DigitalOcean Spaces, Sentry, Vercel Analytics, CookieYes, ReferralRocket, and a configured email provider. A provider receives only the information reasonably necessary for its applicable service or function, subject to the agreement or terms governing that provider relationship. Not every provider receives every category of information.
- Customer-enabled integrations. We exchange information with third-party services and customer-controlled endpoints as directed by the customer.
- Customers.If you communicate through a customer's widget or helpdesk, that customer and its authorized agents may access your messages and related information.
- Legal, safety, and enforcement. We may disclose information when reasonably necessary to comply with law or legal process, protect rights or safety, investigate fraud or abuse, or enforce our agreements.
- Business transactions. Information may be transferred as part of a merger, financing, acquisition, reorganization, bankruptcy, or sale of all or part of our business, subject to applicable law.
- With direction or consent. We may disclose information when a customer or individual directs us to do so or provides valid consent.
We do not sell personal information.We do not exchange personal information for monetary payment or other valuable consideration in a manner that constitutes a sale under applicable privacy law. Some laws separately define "sharing" for cross-context behavioral advertising. If an activity is subject to such a requirement, we will provide the legally required notice and choice.
8. Cookies and similar technologies
We and providers supporting the Services may use cookies, local or session storage, pixels, scripts, and similar technologies for authentication, security, preferences, chat sessions, consent management, analytics, performance, and referral attribution. For example, we may use CookieYes to manage consent, Chatwoot to support chat, Vercel Analytics when applicable, and ReferralRocket for referral attribution. Available technologies depend on the page and deployment.
You can use an available consent tool and browser controls to manage non-essential technologies. Blocking essential cookies may prevent account or Service functionality. See our Cookie Policy for additional details about current categories, providers, and controls.
9. Legal bases for EEA and UK processing
Where the GDPR or UK GDPR applies, our legal basis depends on the processing:
- Contract: to provide requested Services, administer accounts, and process subscriptions;
- Legitimate interests: to secure, maintain, support, and improve the Services, prevent abuse, and protect our users, where those interests are not overridden by individual rights;
- Consent: where we specifically request consent, including for certain cookies or communications; and
- Legal obligation: to meet applicable legal, tax, accounting, and regulatory requirements.
When we act as a processor, the relevant customer is responsible for identifying its legal basis and providing required notices to its end users.
10. Retention and deletion
We retain information only for as long as reasonably necessary for the purposes described in this Policy, to provide the Services, and to satisfy contractual, legal, security, and legitimate business requirements. Relevant factors include the type and sensitivity of the information, account status, customer configuration, operational needs, applicable limitation periods, and tax, accounting, fraud-prevention, and dispute requirements.
When an account or data is deleted, we take reasonable steps to delete or de-identify associated Customer Content from active systems, subject to applicable law and legitimate exceptions. Limited information may remain for billing or tax records, security and fraud prevention, dispute enforcement, legal obligations, backup lifecycles, and technically necessary residual periods. Deletion may not be instantaneous across every system. Information held by a customer-connected third party is also subject to that party's deletion practices.
11. Security
We use administrative, technical, and organizational safeguards designed to protect information against unauthorized access, loss, misuse, or alteration. Measures vary by system and may include access controls, authentication, credential protection, logging, monitoring, and protection of information in transit. No system is completely secure, and we cannot guarantee absolute security. Customers are responsible for protecting their credentials, configuring integrations appropriately, and limiting the information submitted to what is necessary.
12. International processing
We and our service providers may process information in countries other than the country where it was collected. Those countries may have different data-protection laws. Where applicable law requires safeguards for an international transfer, we use a lawful transfer mechanism appropriate to the relevant processing and provider relationship.
13. EEA and UK privacy rights
Subject to applicable law, individuals in the EEA or UK may have rights to access, correct, erase, or receive a portable copy of personal data; restrict or object to processing; withdraw consent without affecting earlier lawful processing; and lodge a complaint with a supervisory authority. Certain rights may be limited by law or by our role as a processor.
If we process your information for a customer, please contact that customer first. We will assist customers with requests as required by applicable law and our agreements.
14. United States state privacy rights
Residents of California and other states with applicable comprehensive privacy laws may have rights to know or access personal information, correct inaccuracies, request deletion, obtain a portable copy, and opt out of certain sale, sharing, targeted-advertising, or profiling activities. You may also have the right not to receive discriminatory treatment for exercising a privacy right and, in some states, to appeal a denied request.
We do not sell personal information. To submit a request, contact us using the information below. We may take reasonable steps to verify your identity and authority. An authorized agent may submit a request where permitted by law, but we may require proof of authorization and verification directly from the individual. If we process the information for a business customer, we may direct the request to that customer.
15. Other choices
You may update certain account information through the Services. You may unsubscribe from marketing email through the instructions in the message, while continuing to receive transactional or security communications. You may disconnect integrations through available account controls or the connected provider, subject to any information already processed and legitimate retention requirements.
16. Children's privacy
The Services are intended for businesses and are not directed to children under 13. We do not knowingly collect personal information directly from children under 13. Customers must not use the Services to collect children's personal information without the notices, permissions, and consent required by law. If you believe a child has provided personal information contrary to this section, please contact us.
17. Changes to this Policy
We may update this Privacy Policy to reflect changes in the Services, law, or our practices. We will post the revised Policy and update the "Last updated" date. If a change is material, we may provide additional notice through email, an in-product notice, or another reasonable method as required by applicable law.
18. Contact us
For privacy questions or to exercise a privacy right, contact [email protected]. Please include enough information for us to understand the request without sending unnecessary sensitive information.
Voxe Desk
- [email protected]
- Phone
- (469) 269-9057
- Our mailing address is listed in the Terms of Service.