Privacy
Policy
This policy outlines how Talk2Site collects, processes, secures, and retains data across our website, chatbot assistants, and third-party integrations.
1. Information We Collect
We collect only the information required to operate Talk2Site services.
- Account details such as name, email, phone, and billing metadata (including payment/order/subscription identifiers).
- Usage and diagnostic data including browser/device context and logs.
- Workspace content that you provide through URLs, files, and chatbot interactions.
2. How We Use Information
We process data to deliver and improve the platform.
- Provisioning chat assistants and retrieval workflows.
- Operating integrations such as Google Calendar, Google Site Analytics, and SMTP email.
- Supporting lead workflows, AI summaries, and reporting dashboards.
3. Google API Services User Data Policy
Talk2Site's use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
- We only request OAuth scopes necessary for the features you enable.
- Data obtained through Google APIs is never sold or used for advertising.
- You can review and revoke connected Google services from your account settings at any time.
- Learn more at Google API Services User Data Policy.
4. Smart Lead Capture and AI Summary
When enabled, Smart Lead Capture and AI Summary process chat context for follow-up workflows.
- Lead details are collected only through your configured workflow forms.
- AI Summary creates compact internal context for your team actions.
- You can disable these features per agent from the dashboard.
5. Google Calendar Integration
Talk2Site follows Google's API Services User Data Policy for connected Calendar accounts.
- Calendar access is used for booking and availability workflows only.
- You can revoke this permission from Talk2Site or Google account settings.
- We do not sell calendar data.
6. Google Site Analytics Integration
Analytics access is requested with read-only scope and used for dashboard reporting context.
- Traffic metrics are displayed to help optimize chatbot performance.
- Connected GA4 properties can be disconnected by workspace owners at any time.
- We do not use analytics data for advertising resale.
7. Email (SMTP) Integration
SMTP settings are configured by you for business messaging workflows.
- Credentials are used to send authorized notifications and follow-up emails.
- You can update, test, or remove SMTP configuration from the dashboard.
- We recommend app passwords and provider security controls.
8. Data Sharing & Third Parties
We do not sell your personal data.
- We share with trusted infrastructure partners and processors only when needed to deliver our services.
- For payments and subscriptions, we use PCI-compliant processors (such as Razorpay and PayPal) who process payment credentials securely.
- We may disclose data when required by law, subpoena, or valid legal process.
- In case of merger or acquisition, data may transfer under strict confidentiality and legal safeguards.
9. Cookies & Browser Storage Technologies
We use browser cookies, sessionStorage, and localStorage to deliver secure access and preserve settings.
- Strictly Necessary HttpOnly session cookies for protected authentication and anti-CSRF defense.
- Ephemeral sessionStorage for active conversation continuity and fast chatbot UI rendering.
- LocalStorage for preserving user preferences (such as selected currency and theme).
- Performance & Analytics (Google Analytics) to measure site traffic and improve AI accuracy.
10. Data Processor Role & Embedded Chatbots
When you embed Talk2Site on your website, we act as a Data Processor under GDPR Article 28.
- You (the workspace owner) act as the Data Controller for your website visitors' lead submissions.
- Talk2Site processes captured lead inquiries, meetings, and chat logs exclusively to execute your instructions.
- You are responsible for displaying appropriate privacy notices on your website regarding chatbot lead capture.
11. Data Security & Zero-Trust Architecture
We implement defense-in-depth security to protect your data across client and server.
- All authentication tokens are stored in HttpOnly, Secure, SameSite=Lax cookies immune to JavaScript extraction.
- All data in transit is encrypted using TLS 1.3.
- Zero sensitive credentials or unhashed tokens are ever stored in client-side localStorage.
- Periodic security audits and automated input sanitization.
12. Data Retention and Deletion
We retain data only for operational and legal requirements, then delete or anonymize where applicable.
- Account owners can request account and lead data deletion through support channels.
- Certain records may be retained for legal, tax, or fraud-prevention obligations.
13. International Transfers and Policy Updates
Data may be processed in locations where our cloud infrastructure operates. We update this page when policy changes occur.
- Continued use after updates indicates acceptance of revised policy terms.
Your Data Protection Rights
Under GDPR, CCPA, and global privacy standards, you have full control over your personal information.
Access
Request a copy of personal data associated with your account.
Correction
Request updates to inaccurate or outdated personal data.
Deletion
Request deletion of personal data, subject to legal retention obligations.
Opt-Out
Opt out of promotional emails or non-essential analytics tracking at any time.
Portability
Request export of your eligible data in a structured, machine-readable format.
Privacy & Legal Inquiries
For Data Subject Requests (DSR), data deletion, or privacy inquiries, reach out to our team.
