matchat

Legal

Privacy Policy

This page explains the product data boundaries in Matchat and the controls available to account owners for managing visitor and lead data.

Data We Process

Matchat processes account details, school profile data, chatbot configuration, knowledge sources, conversations, leads, billing records, support requests, and provider status needed to operate the product.

How Data Is Used

Data is used to authenticate users, operate tenant-isolated dashboards, answer chatbot enquiries, prepare lead and conversation views, support billing workflows, and maintain service security and health.

Sub-processors

Matchat relies on the following sub-processors to operate provider-backed features: Supabase (hosting, Postgres database, and authentication), configured AI providers for chatbot replies and website analysis (Google Gemini, OpenAI, Anthropic, or OpenRouter, depending on workspace configuration), Meta WhatsApp Cloud API (WhatsApp messaging), Resend (transactional email), and Razorpay (billing and checkout). Provider-backed features operate only when the required credentials, webhook secrets, and operational settings are configured.

Data Retention

Short-lived operational records expire automatically: widget rate-limit counters and expired visitor sessions are removed after 1 day, notification read receipts and processed checkout webhook events after 90 days, and admin audit events after 365 days. Conversations, messages, leads, students, and visitor records have no automatic expiry; they are retained until a workspace owner exports or deletes them with the dashboard privacy tools.

Chat Widget and the Visitor's Browser

When a visitor uses the chat widget on a school's website, the widget saves two small items in that visitor's browser so the same chat can carry on when they move to another page. The first is a short-lived chat pass, kept together with whether the visitor agreed to the privacy notice, whether they left or skipped their contact details, and whether the chat window was open. It expires after 30 minutes without activity and never lasts longer than 12 hours. The second is a random visitor number that lets the school see that a returning visitor is using the same browser; it stays until the visitor clears their browser data. Neither item contains chat messages, names, email addresses, or phone numbers. Nothing is saved until the visitor has used the chat, and where a privacy notice is shown, nothing is saved until the visitor agrees to it.

Privacy Controls

Workspace owners can use dashboard privacy tools to export or delete matched visitor data by email or phone. Access is constrained by tenant membership and role checks.

Grievance Officer

Privacy questions, complaints, and data requests that cannot be resolved with the dashboard tools can be raised with the designated Grievance Officer: Matchat Grievance Officer, reachable at vriddhirksh@gmail.com. Complaints are acknowledged and addressed within the timelines required by applicable law.

Create AccountTerms of Service