Back to Home

Privacy Policy

Platform compliance and developer data usage guidelines.

ChatLab Privacy Policy

Effective Date: June 19, 2026

This Privacy Policy explains how ChatLab ("we", "us", or "our") collects, uses, processes, and protects your information when you use our omnichannel chatbot platform, customer support agent desk, and integrations with Meta APIs (including Facebook Messenger and WhatsApp Business APIs).

1. Information We Collect and Process

To provide our automated communication and support desk services, we process the following categories of data:

  • Account Information: For registered business administrators and customer support agents, we collect names, email addresses, business names, passwords, and profile photos to manage account access.
  • Meta Integration Data: To enable automated replies and agent handovers on social channels, we process Page-Scoped IDs (PSID) from Facebook Messenger and WhatsApp phone numbers from the WhatsApp Business API. This technical data is required to map incoming messages to chat threads and route automated or manual responses back to the visitor.
  • Communication Content & Logs: We store the content of incoming and outgoing chat messages, message metadata (timestamps, delivery status), and user-uploaded media (such as voice notes, images, and document attachments) to display conversations in the agent desk and power AI bot responses.
  • System Interaction Data: Technical logs, including client IP addresses and user agent headers, are collected for system security, rate limiting, and domain-authorization checks of the chat widget.

2. How the System Operates and Uses Data

ChatLab processes data for specific functional purposes to help businesses serve their users:

  • AI Chatbot Generation: When a user sends a message to a connected business chatbot, the message text is forwarded to large language model (LLM) engines (specifically Google Gemini or OpenAI APIs) to generate an automated contextual reply. No personally identifying account data or access tokens are shared with these AI providers.
  • Live Handoff and Escalations: If the AI chatbot cannot answer a question or if a visitor requests a human, the system logs an escalation. This allows human agents to claim the conversation, review the recent message history, and respond directly via our agent desk.
  • E-commerce and Sitemap Syncing: If configured, our system accesses client-configured sitemaps or product databases to scrape public product details (e.g. item availability and pricing) and answer visitor queries accurately.

3. Third-Party Data Sharing and Processors

We do not rent, sell, or trade personal data or visitor identifiers. We share information only with trusted processors necessary to deliver our services, including:

  • AI API Providers: Google Gemini and OpenAI are used solely for the real-time generation of chatbot responses.
  • Hosting and Database Infrastructure: Data is hosted securely on encrypted cloud servers with industry-standard access controls.

4. Compliance with Meta Developer Policies

Our Meta integrations strictly comply with Meta's Developer Policies. Page-Scoped IDs (PSIDs) and WhatsApp contact identifiers are processed solely for the functional purpose of message delivery and thread organization. We do not use Facebook or WhatsApp data for marketing profiling, retargeting, or advertising.

5. Data Retention and Deletion Request Instructions

We retain conversation data and logs as long as the respective business's account is active, or as required by our clients. If you wish to request the deletion of your personal data or conversation records, you may do so at any time:

How to Request Deletion: Send a written deletion request to our support team at info@chat-lab.labxit.com. We will process and confirm your request, including the removal of all associated social media identifiers (PSIDs, phone numbers, and chat logs) from our database within 30 days of receipt.

6. Security Measures

We implement rigorous technical and organizational security measures, including transport layer security (HTTPS) and encryption of credentials at rest, to prevent unauthorized access, alteration, or disclosure of communications and tokens.

7. Policy Updates

We may update this Privacy Policy to reflect changes in our service or regulatory updates. Any changes will be published on this page with an updated effective date.

8. Contact Information

For questions, feedback, or inquiries regarding this policy, please reach out to us at info@chat-lab.labxit.com.

© 2026 ChatLab. All rights reserved.