Chai-Hub

Chai — Privacy Policy

⚠️ TEMPLATE — NOT LEGAL ADVICE. AI-generated starting draft. Privacy law is jurisdiction-specific (e.g., California's CCPA/CPRA and other US state laws; GDPR/UK GDPR if you have European users). Have a qualified attorney review and complete this before publishing, and replace every [BRACKETED] placeholder.

Effective date: [DATE] Last updated: [DATE]

This Privacy Policy explains how [COMPANY LEGAL NAME] ("Chai," "we," "us," "our") handles personal information in connection with the Chai services — Chai-CRM, Chai-HR, and the Chai-Hub website (the "Services").


1. Two roles: when we're the "controller" vs. the "processor"

This distinction matters, because it determines who is responsible for the data.

The rest of this Policy describes our practices as a controller.


2. Information we collect


3. How we use personal information (as controller)

We use it to: provide, operate, secure, and maintain the Services; authenticate users and manage accounts; process payments and send billing and transactional messages (including account emails via our email provider, Resend); provide support; understand and improve the Services; detect, prevent, and respond to fraud, abuse, and security incidents; and comply with legal obligations and enforce our agreements.

[If you have EU/UK users, add legal bases: performance of a contract, legitimate interests, consent, and legal obligation, as applicable.]


4. Cookies and similar technologies

We use strictly necessary cookies to keep you logged in and maintain your session. [If you add analytics or any non-essential cookies, describe them here and provide a way to control/opt out; some laws require consent.] The Services and website may load resources (such as web fonts) from third-party providers, which may receive your IP address as part of delivering those resources.


5. How we share personal information

We share personal information only as follows:

We do not sell your personal information, and we do not share it for cross-context behavioral advertising (as those terms are defined under California law).


6. Data retention

We keep personal information for as long as needed to provide the Services, comply with our legal obligations, resolve disputes, and enforce our agreements. Customer Data is retained according to the customer's instructions and our Terms of Service (generally deleted within [30] days after account termination), except where retention is required by law.


7. Security

We maintain commercially reasonable administrative, technical, and physical safeguards designed to protect personal information — including encryption in transit, tenant isolation, access controls, and hashed passwords. However, no system is completely secure, and we cannot guarantee absolute security. You are responsible for protecting your credentials and managing who has access to your account.


8. Your privacy rights

Depending on where you live, you may have rights to access, correct, delete, or receive a copy of your personal information, and to opt out of the sale or sharing of it (note: we do not sell or share it). These may include rights under the California Consumer Privacy Act (as amended by the CPRA), other US state privacy laws, and the EU/UK GDPR.

[California residents: add a "Notice at Collection" summarizing the categories of personal information collected, the purposes, and the categories disclosed, plus your specific CCPA/CPRA rights and how to appeal a denial. Add other state-specific disclosures as needed.]


9. Children's privacy

The Services are for businesses and are not directed to children under 16. We do not knowingly collect personal information from children. If you believe a child has provided us information, contact us and we will delete it.


10. International users

We are based in the United States, and we process and store information in the US and in the locations of our service providers. If you access the Services from outside the US, you understand your information may be transferred to and processed in the US. [If you have EU/UK users, describe your transfer mechanism, e.g., Standard Contractual Clauses.]


11. Changes to this Policy

We may update this Policy from time to time. If we make material changes, we will provide notice (for example, by email or an in-product or website notice). The "Last updated" date shows the current version.


12. Contact us

[COMPANY LEGAL NAME] [Mailing address] Privacy contact: [PRIVACY CONTACT EMAIL] (e.g., privacy@chai-hub.com) General: hello@chai-hub.com