Privacy Policy
Effective date: October 4, 2026
The short version: we collect only what we need to run TalkingDot, we never sell personal data or use it for advertising, and the chat messenger sets no cookies. If you chatted with a business through a TalkingDot messenger, that business controls your data, so please contact it first.
Who we are and what this policy covers
TalkingDot is operated by TalkingDot ("we", "us", "our"). This policy explains how we handle personal data in two different roles.
- As a controller. We decide how and why personal data is used for people who visit https://talkingdot.com, create an account, join a workspace as a teammate, contact us or chat with our own support team.
- As a processor. When a business (our "customer") installs the TalkingDot messenger on its website, the customer decides what data is collected about its visitors and why. We process that data only on the customer's behalf and on its instructions, under our Data Processing Addendum.
If you chatted through a TalkingDot messenger on someone else's website, send requests about your data to the business that runs it. If you cannot reach it, write to us and we will pass your request on.
The data we collect
If you have an account or are a teammate
- Account details: your name, email address and password. Passwords are stored only as a one-way hash, never in readable form. You can also add a profile photo, job title and time zone.
- Security data: your two-factor authentication settings and recovery codes, the IP address you signed up from and last signed in from, and when you last signed in and were active.
- Workspace content: what you and your teammates create in a workspace, such as messenger settings, office hours, teams, saved replies, tags, chatbots, rules, automatic messages, help-center articles, notes and the messages you send. API keys are stored as hashes.
- Notification data: if you turn on browser push notifications, the subscription details your browser provides and a short description of the browser.
- Audit records: a log of administrative actions in a workspace, with the time, the person and the IP address.
If you visit our website or contact us
- Technical data your browser sends with every request, such as your IP address, browser type and the page you asked for. Our hosting provider may record this in short-lived server logs.
- Messages you send us through the contact form or the abuse report form: your name and email address (if you give them), your message and the IP address it came from.
- Analytics data, only if we have enabled Google Analytics and you accept it in the cookie banner. See our Cookie Policy.
- Chats with our support team. If our own messenger appears on our website and you use it, we collect the messenger data described below, and for those chats we are the controller.
Messenger data we process for our customers
When someone uses a TalkingDot messenger on a customer's website or on a hosted chat page, the following data may be processed:
- Contact profile: a random visitor identifier, plus any name, email address, phone number or company the visitor provides, or that the customer supplies (for example for its signed-in users).
- Custom attributes and events the customer chooses to send, and notes and tags its teammates add.
- Conversations: messages, files and images, answers to chatbots and pre-chat forms, and satisfaction ratings and comments. If the customer turns on "sneak peek", its teammates can see what a visitor is typing before pressing send. These previews are not saved as messages and are removed from our real-time event stream, normally within an hour.
- Browsing context: the address and title of pages viewed on the customer's website while the messenger is loaded, the first page visited and the referring address, the number of visits, and the page a conversation started on.
- Device information: browser, operating system and device type (worked out from the browser's user-agent string), plus the language and time zone the browser reports.
- Approximate location: country, region and city, derived from the IP address using headers from Cloudflare (when the service runs behind Cloudflare) or a GeoIP database stored on our own server. We do not send IP addresses to a third-party lookup service.
- IP address: stored in full, truncated (with the last part removed) or not at all, as each customer chooses for its workspace.
If a visitor leaves an email address, the customer can have TalkingDot email them replies they missed and conversation transcripts they ask for. Notification emails include an unsubscribe link.
How we use data and our legal bases
Where data-protection laws such as the GDPR or the UK GDPR apply, we rely on the following legal bases for the data we control.
| Purpose | Legal basis |
|---|---|
| Creating and running your account and workspaces, and delivering messages and notifications | Performance of our contract with you |
| Keeping the service secure: preventing spam, fraud and abuse, rate limiting, audit logs and enforcing our Terms | Our legitimate interest in a safe and reliable service |
| Service emails such as address verification, password resets, teammate invitations and notice of important changes | Performance of our contract, and our legitimate interests |
| Answering contact-form messages and handling abuse reports | Our legitimate interest in responding to you and protecting others |
| Measuring visits to our public website with analytics | Your consent, which you can withdraw at any time |
| Meeting legal obligations, such as answering lawful requests from authorities | Legal obligation |
For messenger data, the customer decides the purposes and is responsible for having a valid legal basis. We use that data only to provide the service to the customer, keep it secure and comply with the law, never for our own marketing or for advertising.
How long we keep data
- Account data is kept while your account exists.
- Workspace content is kept until it is deleted or the workspace itself is deleted. Deleting a workspace removes its conversations, contacts, files and settings.
- Anonymous visitors who never started a conversation are deleted, together with their page views and events, after 30 days without a visit.
- Page-view history is kept for 90 days by default.
- Conversations are kept until the customer deletes them or the workspace's retention setting removes them. Each workspace can choose to have closed conversations deleted automatically after a set number of days.
- Logs are short-lived: real-time events are kept for about an hour, rate-limit counters for minutes, webhook delivery logs for 14 days, error logs, email logs and in-app notifications for 90 days, and the workspace audit log for one year.
- Contact-form messages are kept for two years. Abuse reports are kept for as long as needed to handle them and to keep a record of any action taken.
Deleted data may remain in backups for a limited time until those backups are overwritten.
Cookies and local storage
Our website and dashboard use a few essential cookies to keep you signed in and protect forms. The messenger sets no cookies: it keeps a random visitor token in the website's local storage. Google Analytics runs only on our public website, if enabled, and only after you accept. Details are in our Cookie Policy.
Who we share data with
- Subprocessors. Companies that help us run the service, such as our hosting and email delivery providers, process data on our behalf under contract. They are listed on our subprocessors page.
- Services a customer connects. If a workspace sets up webhooks, the REST API, or Slack, Discord or Telegram notifications, conversation data is sent to the destinations the customer chooses. Those connections are the customer's decision and responsibility.
- Browser push services. Push notifications for teammates travel through the push service of the teammate's browser maker. The content is encrypted end to end, so the push service cannot read it.
- Legal requirements. We may disclose data when the law requires it, or when it is necessary to protect the rights, property or safety of our users, the public or us. Where we are allowed to, we will tell the affected customer first.
- Business changes. If TalkingDot is involved in a merger, acquisition or sale of assets, data may be transferred as part of it, and this policy will continue to apply.
Our staff access account and workspace data only when needed to provide support you ask for, to investigate abuse or security issues, or to keep the service running. We do not sell personal data, we do not share it for advertising, and we do not show ads.
International transfers
Data is stored with the hosting provider named on our subprocessors page, and some subprocessors may process data in other countries. When personal data from the European Economic Area, the United Kingdom or Switzerland is transferred to a country without an adequacy decision, we use Standard Contractual Clauses or another lawful transfer mechanism.
Security
We protect data with password hashing, optional two-factor authentication, role-based access, CSRF protection, a strict Content-Security-Policy and rate limiting. No system is completely secure; our Security page explains what we do.
Your rights
Depending on where you live, you may have the right to access your personal data, receive a copy in a portable format, correct it, have it erased, restrict or object to its use, and withdraw consent at any time. You can also complain to your local data-protection authority.
- Account holders and teammates can update their profile in account settings. For anything else, including a copy of your data or closing your account, email privacy@talkingdot.com from the address on your account.
- People who chatted with a customer should contact that business. Customers can export a contact's data and erase a contact, including their conversations, from the Contacts area of the dashboard. If you write to us instead, we will forward your request to the customer.
We may need to verify your identity before acting on a request. We will respond within the time the law requires, usually one month.
Children
TalkingDot is a business tool and is not intended for children. You must be at least 16 to create an account. We do not knowingly collect personal data from children; if you believe a child has given us personal data, contact us and we will delete it.
Changes to this policy
We may update this policy as the service or the law changes. We will change the effective date at the top of this page and, for significant changes, tell account holders by email or with a notice in the dashboard before the changes take effect.
Contact us
For privacy questions or requests, email privacy@talkingdot.com. You can also write to us by post:
TalkingDot