Privacy Policy

Last updated: February 26, 2026

1. Information We Collect

Chatea (“we”, “our”) collects the following information when you use our service:

  • Account data: name, email address, and profile picture (when you sign in with Google).
  • Business data: your company name, WhatsApp Business number, and CRM configurations.
  • Messages: WhatsApp messages you receive and send through our platform to provide CRM and AI features.
  • Usage data: information about how you interact with the service (pages visited, features used).

2. How We Use Your Information

We use the collected information to:

  • Provide, maintain, and improve the CRM service.
  • Process messages with artificial intelligence to generate automatic responses.
  • Send notifications related to your account and the service.
  • Protect against fraudulent or unauthorized use.
  • Comply with legal obligations.

3. Information Sharing

We do not sell your personal information. We share data only with:

  • Meta (WhatsApp Business API): to send and receive WhatsApp messages.
  • Google (Gemini AI): to process messages with artificial intelligence. Messages are sent anonymously.
  • Supabase: our database and cloud storage provider.
  • Vercel: our hosting provider.
  • Resend: for transactional email delivery.

4. Data Security

We implement security measures to protect your information:

  • AES-256-GCM encryption for sensitive tokens and credentials.
  • HTTPS connections with HSTS (HTTP Strict Transport Security).
  • Two-factor authentication (2FA) with TOTP.
  • Content Security Policy (CSP) with nonces.
  • Row Level Security (RLS) in the database for tenant data isolation.
  • CSRF protection on all requests.

5. Data Retention

We retain your data while your account is active. If you delete your account, we will delete your personal data within 30 days, except where the law requires retention.

6. Your Rights

You have the right to:

  • Access your personal data.
  • Correct inaccurate data.
  • Request deletion of your data.
  • Export your data in a readable format.
  • Revoke consent at any time.

To exercise these rights, contact us at privacy@chatea.one.

7. Cookies

We use strictly necessary cookies for the service to function (session authentication). We do not use tracking or advertising cookies.

8. Children

Our service is not directed at individuals under 18 years of age. We do not intentionally collect information from minors.

9. Changes to This Policy

We may update this policy periodically. We will notify you of significant changes by email or through a notice in the service.

10. Contact

If you have questions about this privacy policy, contact us at: