Pricing Docs Live Demo Contact

Privacy Policy

Last updated: August 13, 2026

1. Overview

WhizzTalk ("we", "us") provides a platform that lets businesses ("tenants") build and embed chatbots on their own websites. This policy explains what data we collect, from whom, and how it's used — both from tenants who run a dashboard account, and from end visitors who chat with a tenant's embedded widget.

2. Information we collect

  • Account data: name, email, and password (hashed, never stored in plain text) when you register a tenant account.
  • Configuration data: the chat flows, questions, categories, and recommendation content you build. AI provider API keys are encrypted at rest and are never displayed back to you or exposed in any API response after you save them.
  • Chat session data: when an end visitor uses a tenant's embedded widget, their answers (which may include a name, phone number, or email address if the tenant's flow asks for one) are stored against that chat session so the tenant can view leads and conversation history.
  • Contact form submissions: if you submit our contact form, we store your name, email, phone (if given), and message so we can respond.
  • Cookies: we use a session cookie to keep you signed in to the dashboard, and a local-storage flag to remember that you've dismissed the cookie notice. We don't use third-party advertising or tracking cookies.

3. How we use it

Account and configuration data is used solely to operate your dashboard and run your chatbot(s). Chat session data belongs to the tenant whose widget collected it — we don't use it for our own marketing or share it across tenants. If a tenant enables phone or email verification (OTP), the destination is used only to deliver that one-time code.

4. Third-party providers

Where a tenant connects their own AI provider (OpenAI, Gemini) or uses our shared key, the text of a visitor's answer may be sent to that provider to power features like name validation or recommendation matching, subject to that provider's own data-handling terms. Where OTP delivery is configured, a phone number or email address is passed to the relevant SMS/email provider solely to deliver the code.

5. Data retention

Account and chat data is retained for as long as the tenant's account is active. A tenant can delete individual leads, categories, or their entire account by contacting us. Contact form submissions are retained until resolved.

6. Your rights

You can request a copy of, correction to, or deletion of your personal data by contacting us. Tenants are the data controller for the chat data their own widget collects from their site's visitors; we act as the processor on their behalf.

7. Changes to this policy

We'll update the date at the top of this page whenever this policy changes. Continued use of WhizzTalk after a change means you accept the updated policy.

8. Contact

Questions about this policy? Reach out to us here.