Privacy policy
Chanlytics OS is a receptionist for small businesses: it answers a business's customers on WhatsApp, by phone and by text, keeps the conversations where the owner can read them, and helps the owner reply to reviews and reach customers who asked to hear from them. This policy says what we hold to do that, why, who else touches it, and what you can do about it.
Who we are
Chanlytics ("we", "us") operates Chanlytics OS at app.chanlytics.com. When a business ("the workspace owner") signs up, it is the controller of its customers' data; we process that data on its behalf and under its instructions. Questions about this policy go to privacy@chanlytics.com.
What we hold
- Account data: the owner's name and work email, the team members they invite, the business's name, address, hours, services and the facts the receptionist answers with.
- Conversations: messages customers send to the business's connected numbers and the replies sent back, call transcripts and, where the owner enables it, call recordings, together with the phone number or account that sent them.
- Customer records: the people who wrote or called, their number, the name they gave, whether they said yes to offers and when, and notes the owner adds.
- Connected services: what a connected service tells us — a WhatsApp number's status, a phone line's state, a Google Business Profile's reviews and the replies posted to them, the events in a calendar feed the owner pastes.
- Billing: the plan, the subscription's status and the card's brand and last four digits. Card numbers never reach us; Stripe holds them.
- Usage: sign-ins, the actions taken in the product, and the technical logs needed to keep it working and secure.
Why we hold it
- To answer the business's customers, on the channels the owner connected, within the rules the owner set.
- To show the owner what was said and done, and to let a person take over a conversation.
- To send messages the owner asked us to send, only to people who agreed to receive them, with a way to stop at any time.
- To bill the workspace, to secure the service, and to meet legal obligations.
We do not sell personal data, and we do not use a workspace's conversations to advertise to anyone.
Automated replies
The receptionist's replies are drafted by an AI model from the business's facts and the conversation. The owner decides how much it may do on its own; a person can read, correct and take over at any time. Conversations may be sent to the AI model providers named below to produce a reply; they process them to provide the service and do not use them to train their models.
Who else processes it
We use the following services to run the product. Each holds only what its part needs.
- Supabase (database and sign-in) and Vercel (hosting).
- Meta (WhatsApp Business Platform) for WhatsApp messages and templates.
- Twilio for phone numbers and text messages, and Retell for phone calls.
- Google (Business Profile and Maps) for reviews and replies, when the owner connects them.
- Anthropic and OpenAI for the receptionist's drafts.
- Stripe for billing, and Resend for the emails we send you.
Google user data
When a workspace owner connects a Google Business Profile, we ask Google for permission to manage that business's listings. We use it to read the business's reviews, to show them to the owner, and to post the replies the owner writes or approves. We store the access Google grants so the connection keeps working, and we remove it when the owner disconnects. Chanlytics' use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
Text messages
A business's customers receive texts only when they contacted the business first, or when they agreed to receive offers by texting a keyword or on the business's sign-up page. Message and data rates may apply. Reply STOP to stop and HELP for help. No mobile information will be shared with third parties or affiliates for marketing or promotional purposes; all other categories of sharing exclude text-messaging originator opt-in data and consent, which will not be shared with any third parties.
How long we keep it
Account and conversation data stays while the workspace exists. Call recordings are kept for 90 days. An owner can export a workspace's data and can ask us to delete the workspace, after which its data is removed within 30 days, except what the law requires us to keep.
Your rights
You can ask what we hold about you, ask for it to be corrected or deleted, and object to how it is used, by writing to privacy@chanlytics.com. If you are a customer of a business that uses Chanlytics, the business is the controller of your data; we will pass your request to it and help it answer.
Security
Data travels encrypted and is stored encrypted at rest. Credentials for connected services are kept in a vault the product's pages cannot read. Access inside Chanlytics is limited to what running and supporting the service requires.
Changes
When this policy changes, the date above changes with it and workspace owners are told in the product.
Chanlytics OS · Terms of service · chanlytics.com