Legal

Privacy Policy

Last updated: July 15, 2026

This Privacy Policy explains how Chat Celeste Inc., d/b/a Customer Served AI, collects, uses, discloses, and protects personal information in connection with Support Desk. If you are a merchant using Support Desk, you are responsible for providing your own privacy notice to your customers and for making sure you have a lawful basis to process their information through the Service.

1. Scope and Roles

This policy applies to personal information we process for our own business purposes, such as account management, billing, support, security, analytics, and marketing. Customer support tickets, Shopify order context, imported Freshdesk history, attachments, and similar information that merchants submit about their own customers are usually processed by us on behalf of the merchant as described in the Data Processing Addendum.

2. Information We Collect

Where United Kingdom data protection law applies, our lawful bases for our own processing are performance of a contract, compliance with legal obligations, and legitimate interests in operating, securing, supporting, and improving a business service. We use consent when the law requires it, including before optional non-essential analytics. Merchants determine the lawful basis for Customer Data that we process on their behalf.

  • Account information, such as name, email address, Firebase authentication identifiers, role, workspace membership, and login/session metadata.
  • Workspace information, such as brand name, support email, support instructions, Brand Brain content, mailbox configuration, domain verification records, Shopify store domain, and integration settings.
  • Customer support content, such as inbound and outbound emails, ticket metadata, customer names, customer email addresses, attachments, internal notes, tags, assignments, AI drafts, macros, and satisfaction follow-up content.
  • Shopify information, such as store identity, order identifiers, customer/order/product/fulfillment context, returns, variants, tracking numbers, and actions that authorized users choose to take.
  • Imported information, such as Freshdesk tickets, conversations, product IDs, email configuration IDs, and historical response examples.
  • Tracking information, such as shipment identifiers, courier data, tracking status, and Ship24 refresh results.
  • Billing and usage information, such as Stripe customer IDs, subscription status, invoices, checkout state, usage events, billable tickets, AI drafts, outbound replies, attachment bytes, overage calculations, and billing portal activity.
  • Technical and security information, such as IP address, device/browser metadata, logs, audit events, request metadata, error traces, queue/job status, and rate-limit data.
  • Communications with us, including support requests, feedback, sales questions, legal requests, and operational notices.

3. How We Use Information

We do not sell personal information. We do not share personal information for cross-context behavioral advertising, and we do not use Customer Data for third-party advertising. If those practices ever change, we will update this policy and provide any notice and opt-out mechanism required by law before the change.

  • Provide, operate, maintain, secure, and improve the Service.
  • Authenticate users, manage workspaces, process onboarding, and enforce permissions.
  • Route inbound email, send outbound replies, verify domains, process attachments, and provide exports.
  • Display Shopify, tracking, Freshdesk, and other enabled integration context inside the support workflow.
  • Generate, evaluate, and store AI-assisted drafts, classifications, summaries, support-instruction suggestions, and Brand Brain content.
  • Process subscriptions, trials, invoices, taxes, usage, overages, and billing support.
  • Monitor availability, debug issues, prevent abuse, investigate incidents, and enforce our Terms and Acceptable Use Policy.
  • Comply with legal obligations and respond to lawful requests.
  • Send service, security, billing, onboarding, product, and administrative communications.

4. AI Processing

AI features may send relevant support content, workspace instructions, Shopify context, tracking context, historical examples, and user prompts to AI model providers or routing providers so they can generate drafts, summaries, classifications, or recommendations. AI output can be inaccurate or inappropriate. Merchants and their authorized users are responsible for reviewing AI output before sending it to customers or acting on it.

Do not submit information to AI features unless you have the right to process that information for support operations. Do not use AI features for medical, legal, financial, employment, housing, credit, education, or other high-risk decisions unless you have independent legal approval and appropriate safeguards.

5. How We Share Information

  • Service providers and subprocessors that host, secure, process, store, transmit, or support the Service.
  • Stripe for checkout, subscriptions, invoices, billing portal, taxes, fraud prevention, and payment processing.
  • Postmark for inbound and outbound email, domain verification, bounce handling, and delivery events.
  • PostHog for limited product and funnel analytics when analytics is configured; support ticket bodies, attachment contents, credentials, and integration tokens are not intended analytics fields.
  • Firebase/Google for authentication and related security services.
  • Shopify, Freshdesk, Ship24, Cloudflare, OpenRouter, model providers, and other integrations you connect or enable.
  • Professional advisors, insurers, auditors, and legal, tax, or compliance service providers.
  • Government, law enforcement, courts, regulators, or private parties when we believe disclosure is legally required or necessary to protect rights, safety, security, or integrity.
  • A successor or potential successor in connection with a merger, acquisition, financing, reorganization, bankruptcy, or sale of assets.

6. Cookies and Similar Technologies

The Service uses cookies and similar technologies for authentication, session management, security, and product operation. Those technologies are necessary to provide the Service. Optional analytics is disabled for the limited launch. Before enabling optional analytics, we will provide a control that allows people to accept, reject, and later withdraw consent without losing access to the Service. Blocking required cookies may prevent authenticated features from working.

7. Retention, Export, and Deletion

  • Active workspace and Customer Data is retained while the workspace is active and as needed to provide the Service.
  • A verified owner may use the permanent deletion workflow or submit a deletion request. Active workspace records and private attachments are removed as part of that workflow; a support-assisted request is ordinarily completed within 30 days after identity and authority are verified.
  • Database backups rotate automatically: daily backups are retained for six days, weekly backups for one month, and monthly backups for up to three months. Deleted data may remain in encrypted recovery backups until that cycle expires and is not restored except for disaster recovery; if restored, the deletion must be re-applied.
  • Billing, tax, fraud-prevention, and transaction records may be retained for the period required by law, ordinarily up to seven years.
  • Security, incident, audit, and privacy-request records may be retained for up to two years, or longer when reasonably necessary for an active investigation, dispute, or legal hold.
  • When we no longer need personal information, we delete it or de-identify it using a legally permitted method.

8. Meta Platform Data

Facebook, Instagram, and WhatsApp support integrations are not enabled in the current v1 launch. We do not process Meta Platform Data through the current launch offering. Meta-related data deletion instructions are available at /meta/data-deletion.

9. Security

We use technical and organizational safeguards designed to protect information, including access controls, encryption for selected secrets and tokens, audit logs, domain verification, private attachment storage, webhook authentication, and operational monitoring. No method of transmission or storage is perfectly secure, and we cannot guarantee absolute security.

10. International Processing

We and our subprocessors may process information in Canada, the United States, and the other locations identified on our Subprocessors page. Those countries may have privacy laws different from the laws where you or your customers live. Where a transfer mechanism is legally required, we rely on an adequacy regulation, contractual safeguards, or another legally recognized mechanism and perform the required transfer or privacy-risk assessment.

11. Privacy Rights

Depending on where you live, you may request access, correction, deletion, restriction, objection, or portability, and may withdraw consent where processing is based on consent. We will not discriminate against you for exercising a privacy right. To make a request, contact customerservedai@gmail.com. We ordinarily respond within 30 days after verifying identity and authority, subject to any different period or permitted extension under applicable law. If we process information on behalf of a merchant, we may direct the request to that merchant and assist the merchant as its processor.

Canadian residents may complain to the Office of the Privacy Commissioner of Canada or the applicable provincial regulator, including Quebec's Commission d'accès à l'information. UK residents may complain to the Information Commissioner's Office. Australian residents may complain to the Office of the Australian Information Commissioner after first giving us a reasonable opportunity to respond. US residents, including California residents when applicable, may exercise legally available rights to know, access, delete, correct, opt out of sale or sharing, limit certain uses of sensitive information, and receive equal service.

12. Children

The Service is intended for businesses and is not directed to children. Do not use the Service to knowingly collect information from children where doing so would violate applicable law.

13. Changes

We may update this Privacy Policy from time to time. The updated version will be posted here with a new last updated date. If we make material changes, we may provide additional notice through the Service or by email.

14. Contact

Chat Celeste Inc.'s Privacy Officer is responsible for the privacy management program. Questions, requests, or complaints can be sent to the Privacy Officer at customerservedai@gmail.com, or by mail to Chat Celeste Inc., 12465 Louise Dechene, Montreal, Quebec, Canada H1C 2K5.