Chai — Privacy Policy
⚠️ TEMPLATE — NOT LEGAL ADVICE. AI-generated starting draft. Privacy law is jurisdiction-specific (e.g., California's CCPA/CPRA and other US state laws; GDPR/UK GDPR if you have European users). Have a qualified attorney review and complete this before publishing, and replace every [BRACKETED] placeholder.
Effective date: [DATE] Last updated: [DATE]
This Privacy Policy explains how [COMPANY LEGAL NAME] ("Chai," "we," "us," "our") handles personal information in connection with the Chai services — Chai-CRM, Chai-HR, and the Chai-Hub website (the "Services").
1. Two roles: when we're the "controller" vs. the "processor"
This distinction matters, because it determines who is responsible for the data.
- When we are the controller. For personal information about our website visitors, account holders, and billing contacts, we decide how it is used, and this Policy governs it.
- When we are a service provider / processor. When our customers (insurance agencies) put personal information about their own employees, clients, prospects, or contacts into the Services ("Customer Data"), that customer is the controller — they decide what data to collect and why. We process Customer Data only to provide the Services, on the customer's instructions, as described in our [Terms of Service] and [Data Processing Addendum]. If you are an employee, client, or prospect of a business that uses Chai and you have questions about your information, please contact that business — they control that data, not us.
The rest of this Policy describes our practices as a controller.
2. Information we collect
- Account & profile information you provide: name, email, company/agency name, workspace name, role, and login credentials (passwords are stored only in hashed form).
- Billing information: processed by our payment processor, Stripe. We receive limited billing metadata (e.g., plan, status, and the last four digits or a token) but do not collect or store full payment-card numbers.
- Communications: messages you send us (e.g., support or sales emails).
- Usage and device data, collected automatically: IP address, browser and device type, pages viewed, actions taken, and timestamps, via server logs and cookies.
- Customer Data: processed as a processor (see Section 1) and governed by our Terms of Service and Data Processing Addendum, not this Policy.
3. How we use personal information (as controller)
We use it to: provide, operate, secure, and maintain the Services; authenticate users and manage accounts; process payments and send billing and transactional messages (including account emails via our email provider, Resend); provide support; understand and improve the Services; detect, prevent, and respond to fraud, abuse, and security incidents; and comply with legal obligations and enforce our agreements.
[If you have EU/UK users, add legal bases: performance of a contract, legitimate interests, consent, and legal obligation, as applicable.]
4. Cookies and similar technologies
We use strictly necessary cookies to keep you logged in and maintain your session. [If you add analytics or any non-essential cookies, describe them here and provide a way to control/opt out; some laws require consent.] The Services and website may load resources (such as web fonts) from third-party providers, which may receive your IP address as part of delivering those resources.
5. How we share personal information
We share personal information only as follows:
- Service providers / subprocessors that help us run the Services, bound by contract to protect it and use it only for us — including Cloudflare (hosting, infrastructure, and content delivery), Stripe (payment processing), and Resend (transactional email). See our Data Processing Addendum for the current subprocessor list.
- Legal and safety: to comply with law, respond to lawful requests, or protect the rights, safety, and property of Chai, our customers, or others.
- Business transfers: in connection with a merger, acquisition, financing, or sale of assets, subject to this Policy.
We do not sell your personal information, and we do not share it for cross-context behavioral advertising (as those terms are defined under California law).
6. Data retention
We keep personal information for as long as needed to provide the Services, comply with our legal obligations, resolve disputes, and enforce our agreements. Customer Data is retained according to the customer's instructions and our Terms of Service (generally deleted within [30] days after account termination), except where retention is required by law.
7. Security
We maintain commercially reasonable administrative, technical, and physical safeguards designed to protect personal information — including encryption in transit, tenant isolation, access controls, and hashed passwords. However, no system is completely secure, and we cannot guarantee absolute security. You are responsible for protecting your credentials and managing who has access to your account.
8. Your privacy rights
Depending on where you live, you may have rights to access, correct, delete, or receive a copy of your personal information, and to opt out of the sale or sharing of it (note: we do not sell or share it). These may include rights under the California Consumer Privacy Act (as amended by the CPRA), other US state privacy laws, and the EU/UK GDPR.
- To exercise a right regarding information we hold as a controller, contact us at [PRIVACY CONTACT EMAIL]. We will verify your request and respond as required by law, and we will not discriminate against you for exercising your rights.
- For Customer Data (where a business that uses Chai is the controller), please direct your request to that business; we will assist them as required.
[California residents: add a "Notice at Collection" summarizing the categories of personal information collected, the purposes, and the categories disclosed, plus your specific CCPA/CPRA rights and how to appeal a denial. Add other state-specific disclosures as needed.]
9. Children's privacy
The Services are for businesses and are not directed to children under 16. We do not knowingly collect personal information from children. If you believe a child has provided us information, contact us and we will delete it.
10. International users
We are based in the United States, and we process and store information in the US and in the locations of our service providers. If you access the Services from outside the US, you understand your information may be transferred to and processed in the US. [If you have EU/UK users, describe your transfer mechanism, e.g., Standard Contractual Clauses.]
11. Changes to this Policy
We may update this Policy from time to time. If we make material changes, we will provide notice (for example, by email or an in-product or website notice). The "Last updated" date shows the current version.
12. Contact us
[COMPANY LEGAL NAME] [Mailing address] Privacy contact: [PRIVACY CONTACT EMAIL] (e.g., privacy@chai-hub.com) General: hello@chai-hub.com