PepoChat

Privacy and GDPR notes

What the widget and lead capture collect, where it goes, how long data is kept, and what to put in your own privacy policy.

This page describes what the widget collects and where it goes, so you can describe PepoChat correctly in your own privacy policy. It is practical guidance, not legal advice. PepoChat's own policy is at pepochat.com/privacy.

What the widget collects

When a visitor opens the chat, the widget creates an anonymous session and records: browser and operating system, screen and viewport size, language, timezone, whether cookies are enabled, the page's origin as reported by the browser, and the widget's own address. If you use blocked countries, the widget also asks its hosting platform for the visitor's country as a two-letter code, derived from the IP address, and stores that code on the session; the IP address itself is not stored. Nothing is read from your page's content or cookies; the chat runs in a separate frame.

As the visitor chats, their messages are stored with the conversation. If they verify an email, give a name and email while booking, or share details through lead capture, those are stored on the session and, together with a phone number or company when asked for, as a contact in your workspace's Contacts list. Votes (👍 / 👎) are stored with the conversation.

What the widget does not do

  • It sets no cookies on your site. Its session identifier lives in the widget's own browser storage.
  • It does not track visitors across sites.
  • It does not send anything until the chat window is opened; a preloaded widget only reads your public widget settings.
  • It never asks for contact details unless you switch lead capture on, and the consent text you write is shown with the form.

Where data goes

Messages go to PepoChat's servers so the agent can reply and your team can follow up. Replies are generated by OpenAI models; the content sent is the conversation, the retrieved passages from your knowledge base and your agent instructions. Emails are sent through Resend: verification codes to visitors; escalation and assignment notices to your team members, which quote the visitor's name and email when known and the last three messages of the conversation; and, on the visitor's request after a resolved conversation, a copy of the transcript to the visitor's verified email address only. If you connect integrations, the inputs the agent collects (an order number, an email) are sent to that tool over HTTPS, and only the fields you allow come back. Content you sync from Notion or Google Drive is stored in your knowledge base like an upload.

Retention

  • Visitor sessions last 24 hours and are extended while the visitor chats. A session with no conversation is deleted a day after it expires; sessions attached to a conversation are kept with it.
  • Conversations stay in your team inbox until you remove them, unless you set Data retention on the Team page. It is off by default; set it to 30, 90, 180 or 365 days and, every day, resolved conversations that started more than that long ago are deleted permanently, transcript included. The age counts from the conversation's first message, not from when it was resolved, and open or escalated conversations are never deleted. Only owners and admins can change it. See Team members and roles.
  • Contacts stay in your Contacts list until removed; there is no delete action on the page yet, so ask support to remove one.
  • Test chats from the Test the agent drawer are stored like other conversations, hidden from the inbox and analytics, and follow the same retention setting.
  • Knowledge sources are yours to delete at any time; deleting one removes its content from the agent immediately. Disconnecting Notion or Google Drive deletes every page it synced.
  • Finished import jobs are cleaned up after 30 days.

Exports

Export CSV in the inbox produces a file with visitor names, emails and full transcripts for a date range; the download link works for one hour and the file is then deleted. Export CSV on the Contacts page downloads the listed contacts. Both are copies of personal data outside PepoChat: store and share them with the same care as the inbox itself.

For your privacy policy

State that your site uses PepoChat for support chat; that messages typed into the chat, and any name, email, phone or company the visitor chooses to give, are processed by PepoChat (operated by PepoCloud LLC) to answer and route the conversation and to let your team follow up; and name the connected tools whose data the agent looks up on the visitor's request. If you block countries, mention that the visitor's approximate location (country) is checked. Link to PepoChat's privacy policy and terms. If you operate under GDPR, list PepoChat as a processor and the AI model provider as a sub-processor.

We do not currently claim a specific hosting region, a signed DPA template, or certifications such as SOC 2 or ISO 27001. If your procurement needs one of those, ask sales@pepochat.com about current status rather than assuming.

Something missing or wrong on this page? Tell us and we will fix it.