Privacy

Privacy Policy

Last updated: June 5, 2026

This Privacy Policy explains how LtsTalk ("LtsTalk," "we," "us," or "our") collects, uses, stores, shares, and protects personal information when you access or use our website, dashboard, chat widget, software, documentation, APIs, and related services (collectively, the "Service").

By using the Service, creating an account, installing the widget, interacting with a widget, submitting information, or otherwise using LtsTalk, you acknowledge that you have read and understood this Privacy Policy.

This Privacy Policy is intended to describe our general privacy practices. It should be reviewed by a qualified legal professional before public launch.

1. Scope of This Privacy Policy

This Privacy Policy applies to:

  1. visitors to the LtsTalk website;
  2. users who create or access a LtsTalk account;
  3. workspace owners, admins, supervisors, and agents;
  4. visitors who interact with a LtsTalk widget installed on a customer website;
  5. people who contact us for support, billing, sales, or legal inquiries.

This Privacy Policy does not apply to third-party websites, services, platforms, or integrations that we do not control.

When a LtsTalk widget is installed on a customer's website, the customer may also have its own privacy policy. The customer is responsible for explaining how it uses data collected through its own website and chat experience.

2. Our Role: Controller and Processor

Depending on the context, LtsTalk may act as a data controller or as a data processor/service provider.

Account and business data

For information related to our direct customers, account owners, billing contacts, and platform users, LtsTalk generally acts as the controller because we determine how and why that information is used to provide and manage the Service.

Visitor chat data

For conversations, visitor messages, visitor contact details, attachments, visited pages, and other information collected through a widget installed on a customer's website, LtsTalk generally processes that information on behalf of the customer.

In that context, the customer is responsible for:

  1. having a lawful basis to collect and process visitor data;
  2. providing privacy notices to visitors;
  3. obtaining any required consent;
  4. responding to visitor privacy requests;
  5. ensuring that its use of LtsTalk complies with applicable law.

LtsTalk provides the technical platform but does not control the customer's business communications, promises, policies, products, prices, or treatment of its visitors.

3. Information We Collect

We may collect different types of information depending on how the Service is used.

3.1 Account information

When you create or manage an account, we may collect:

  • name;
  • email address;
  • password or authentication credentials;
  • workspace name;
  • company or business name;
  • role or permission level;
  • profile picture or avatar;
  • account status;
  • login activity;
  • email verification status;
  • password reset activity.

3.2 Workspace, brand, and widget settings

When you configure the Service, we may collect:

  • workspace settings;
  • brand names;
  • website domains;
  • widget display names;
  • logos and launcher icons;
  • colors and design preferences;
  • welcome messages;
  • follow-up messages;
  • privacy notice text;
  • flow settings;
  • team member settings;
  • subscription and plan settings;
  • usage limits and billing status.

3.3 Visitor chat information

When a visitor interacts with a widget, we may process information such as:

  • visitor name, if provided;
  • email address, if provided;
  • phone number, if provided;
  • chat messages;
  • conversation status;
  • assigned agent;
  • message timestamps;
  • message reactions;
  • uploaded images or files;
  • conversation transcripts;
  • pages visited on the customer's website;
  • last visited page;
  • session or conversation identifiers;
  • technical data needed to operate the widget.

Visitors should avoid sharing sensitive personal information through the chat unless it is necessary and appropriate.

3.4 Page visit and widget activity

The widget may collect activity data to help the customer understand the visitor's context, such as:

  • pages viewed;
  • page titles;
  • URL path;
  • time of visit;
  • referrer or previous page, if available;
  • whether the widget was opened;
  • whether a proactive flow was triggered;
  • whether the visitor sent a message.

We do not need to display sensitive query strings, private tokens, payment session IDs, or confidential page identifiers to agents, and we may normalize or hide them when possible.

3.5 Device, browser, and technical data

We may collect technical information needed to provide and secure the Service, such as:

  • browser type;
  • device type;
  • operating system;
  • approximate device category, such as mobile, tablet, or desktop;
  • IP address or derived technical information;
  • timestamps;
  • logs;
  • error reports;
  • security events;
  • language or locale;
  • cookies or local storage identifiers.

If approximate location features are enabled in the future, we may derive general location information from an IP address, such as country, region, city, or timezone. We do not intend to collect precise GPS location through the widget unless a future feature clearly requires it and appropriate notice is provided.

3.6 Files and attachments

If users or visitors upload files, we may process:

  • file name;
  • file type;
  • file size;
  • upload timestamp;
  • secure storage path;
  • access permissions;
  • file preview or download URL;
  • metadata necessary to store, secure, and deliver the file.

Customers and visitors should not upload sensitive files unless they have a lawful and appropriate reason to do so.

3.7 Billing and payment information

When a customer subscribes to a paid plan, billing may be handled by a third-party payment provider, such as Stripe.

We may store:

  • customer billing ID;
  • subscription status;
  • plan;
  • trial status;
  • billing period;
  • payment status;
  • invoice references;
  • payment provider identifiers.

We do not intentionally store full credit card numbers on our servers. Payment information is generally processed by the payment provider according to its own terms and privacy policy.

3.8 Communications with us

If you contact us, we may collect:

  • name;
  • email;
  • phone number;
  • message content;
  • support request details;
  • attachments;
  • responses from our team;
  • metadata related to the communication.

4. Information We Do Not Intentionally Collect

LtsTalk is not designed to collect highly sensitive personal data.

Customers, agents, and visitors should not submit unnecessary sensitive information, including:

  • government identification numbers;
  • payment card numbers;
  • passwords;
  • medical information;
  • biometric data;
  • precise location;
  • financial account credentials;
  • highly sensitive personal records;
  • confidential legal or security information;
  • information about minors unless legally authorized.

If such information is submitted, we may process it only as necessary to provide the Service, secure the platform, comply with law, or remove it.

We reserve the right to delete or restrict access to content that creates legal, security, privacy, or operational risk.

5. How We Use Information

We may use information to:

  1. provide, operate, and maintain the Service;
  2. create and manage accounts;
  3. authenticate users;
  4. deliver the chat widget;
  5. route conversations to the correct workspace, brand, website, or agent;
  6. show visitor context to authorized agents;
  7. store and display conversations;
  8. support file uploads and downloads;
  9. send conversation transcripts where enabled;
  10. provide proactive flows and automations;
  11. calculate usage limits;
  12. manage subscriptions, trials, billing, and plan access;
  13. provide customer support;
  14. improve usability, reliability, and performance;
  15. prevent abuse, spam, fraud, and unauthorized access;
  16. protect the security of the Service;
  17. debug errors and monitor system health;
  18. comply with legal obligations;
  19. enforce our Terms and Conditions;
  20. communicate updates, notices, and service-related messages.

We do not use visitor chat content to make promises on behalf of customers. Customers and their agents remain responsible for the messages they send.

6. Legal Bases for Processing

Depending on applicable law and the context, we may process personal information based on:

  1. performance of a contract;
  2. consent;
  3. legitimate interests;
  4. compliance with legal obligations;
  5. protection of rights, security, and fraud prevention;
  6. instructions from our customer when acting as a processor or service provider.

When a customer installs the widget on its website, the customer is responsible for determining and communicating the legal basis for collecting and using visitor data through that website.

7. Cookies and Local Storage

The Service may use cookies, local storage, session storage, or similar technologies to:

  • keep users logged in;
  • remember widget state;
  • maintain visitor sessions;
  • store sound or notification preferences;
  • remember whether the widget is open or minimized;
  • support security and CSRF protection;
  • improve performance;
  • prevent abuse;
  • enable basic analytics and functionality.

Some browser-based features, such as audio alerts or desktop notifications, may require user interaction or browser permission.

Customers are responsible for providing any required cookie notice or consent mechanism on their own websites if required by applicable law.

8. How We Share Information

We may share information in limited circumstances.

8.1 With authorized workspace users

Information may be visible to authorized users within a customer workspace, such as owners, admins, supervisors, and agents.

The level of access may depend on user roles, brand permissions, and workspace settings.

8.2 With service providers

We may use third-party service providers to help operate the Service, including providers for:

  • hosting;
  • databases;
  • storage;
  • email delivery;
  • payment processing;
  • analytics;
  • AI services;
  • messaging services;
  • error monitoring;
  • security;
  • infrastructure;
  • customer support.

These providers may process information only as needed to provide services to us, subject to their own security and privacy obligations.

8.3 With payment processors

Billing and payment information may be shared with payment processors such as Stripe.

Payment processors may collect and process information according to their own policies.

8.4 With AI or automation providers

If AI-assisted features are enabled, limited text may be sent to an AI provider to generate suggestions, improve text, translate messages, summarize content, or support related features.

AI features may be optional, limited by plan, or disabled. Users should review AI-generated output before relying on it.

8.5 For legal, security, or compliance reasons

We may disclose information if we believe it is necessary to:

  • comply with law;
  • respond to lawful requests;
  • enforce our Terms;
  • protect rights, property, and safety;
  • investigate fraud or abuse;
  • prevent security incidents;
  • protect users, visitors, customers, or third parties.

8.6 Business transfers

If we are involved in a merger, acquisition, financing, reorganization, sale of assets, or similar transaction, information may be transferred as part of that transaction, subject to appropriate protections.

9. International Data Transfers

The Service may be operated using infrastructure, service providers, or systems located in different countries.

As a result, personal information may be processed or stored outside the country where the user, customer, or visitor is located.

Where required, we or our customers may need to rely on appropriate safeguards, contractual measures, or other lawful mechanisms for international data transfers.

Customers are responsible for ensuring that their use of the Service complies with data transfer requirements applicable to their business and visitors.

10. Data Retention

We retain information for as long as reasonably necessary to:

  1. provide the Service;
  2. maintain customer accounts;
  3. support conversations and transcripts;
  4. comply with legal obligations;
  5. resolve disputes;
  6. enforce agreements;
  7. prevent abuse;
  8. maintain backups;
  9. support billing and accounting;
  10. preserve security logs.

Retention periods may vary depending on the type of information, customer settings, plan, legal requirements, backup cycles, and operational needs.

Customers may request deletion of certain data, subject to legal, technical, backup, security, and contractual limitations.

Deleted information may remain in backups for a limited period before being overwritten or removed according to our backup practices.

11. Security

We use reasonable technical, administrative, and organizational safeguards designed to protect information against unauthorized access, misuse, loss, alteration, or disclosure.

However, no internet-based service can be guaranteed to be completely secure.

Customers are responsible for:

  • using strong passwords;
  • controlling user access;
  • assigning proper roles;
  • removing users who no longer need access;
  • securing their own websites;
  • avoiding unnecessary collection of sensitive data;
  • keeping their devices and networks secure.

We are not responsible for privacy or security incidents caused by customer misconfiguration, compromised credentials, insecure websites, unauthorized agents, third-party integrations, or misuse of the Service.

12. Customer Responsibilities

Customers using LtsTalk are responsible for:

  1. providing appropriate privacy notices to their visitors;
  2. obtaining any required consent;
  3. ensuring their use of the widget is lawful;
  4. responding to visitor privacy requests;
  5. determining what data they collect from visitors;
  6. avoiding unnecessary sensitive data collection;
  7. training agents on proper use of visitor information;
  8. complying with data protection, consumer protection, and industry-specific laws;
  9. configuring roles, brand access, and permissions correctly;
  10. ensuring their own website and business practices comply with applicable laws.

LtsTalk is not responsible for a customer's unlawful, misleading, excessive, or improper use of visitor data.

13. Visitor Rights and Requests

Depending on where you live and which laws apply, you may have rights regarding your personal information, such as the right to:

  • access your information;
  • correct inaccurate information;
  • request deletion;
  • object to certain processing;
  • restrict processing;
  • withdraw consent;
  • request portability;
  • file a complaint with a data protection authority.

If you are a visitor interacting with a widget installed on a customer website, the customer is usually the party responsible for responding to your privacy request.

If we receive a request related to visitor data processed on behalf of a customer, we may direct the requester to the customer or assist the customer as appropriate.

If you are a LtsTalk account user, you may contact us directly regarding your account information.

14. Account User Choices

Account users may be able to:

  • update profile information;
  • change password;
  • manage workspace settings;
  • invite or remove team members;
  • configure widget settings;
  • export or view conversations where available;
  • manage billing through the payment provider;
  • request deletion or correction of account data, subject to limitations.

Some requests may require verification of identity or account authority.

15. Email Communications

We may send emails related to:

  • account verification;
  • password reset;
  • security alerts;
  • billing;
  • subscription status;
  • product updates;
  • support;
  • conversation transcripts;
  • service notices.

Transactional or service-related emails may be necessary to provide the Service and may not be fully optional.

Marketing emails, if used, may include an option to unsubscribe where required.

16. Desktop Notifications, Sounds, and Browser Permissions

The Service may use browser features such as desktop notifications and sound alerts.

These features depend on browser permissions, device settings, operating system settings, and user interaction.

We do not guarantee that browser notifications or sounds will always work, be delivered, or be heard.

Users may disable these features through browser settings or Service preferences.

17. AI Features

If AI features are enabled, the Service may process limited text through third-party AI providers to provide features such as text improvement, translation, summaries, or assistance.

AI-generated results may be inaccurate, incomplete, or inappropriate.

Users are responsible for reviewing AI output before sending it or relying on it.

Customers should avoid submitting unnecessary sensitive information to AI-assisted features.

We may log technical metadata about AI requests, such as provider, model, status, and token usage, but we should avoid storing draft text or sensitive prompts unless necessary for the feature and disclosed appropriately.

18. Children's Privacy

The Service is not intended for use by children.

Customers must not knowingly use the Service to collect personal information from children unless they have a lawful basis and comply with all applicable child privacy laws.

If we become aware that personal information from a child has been collected improperly, we may delete or restrict that information.

19. Third-Party Websites and Links

The Service may contain links to third-party websites, tools, or services.

We are not responsible for the privacy practices, content, security, or policies of third parties.

Your use of third-party services is subject to their own terms and privacy policies.

20. Do Not Track Signals

Some browsers may send "Do Not Track" signals.

Because there is no universal standard for responding to such signals, the Service may not respond to them automatically.

Customers are responsible for honoring any legally required tracking preferences on their own websites where applicable.

21. Changes to This Privacy Policy

We may update this Privacy Policy from time to time.

When we make changes, we may update the "Last updated" date and, where appropriate, provide notice through the Service, by email, or on our website.

Your continued use of the Service after an updated Privacy Policy becomes effective means you acknowledge the updated policy.

22. Contact

For questions about this Privacy Policy or privacy-related requests, contact us through the support or contact channels provided by LtsTalk.

Website: https://ltstalk.io

If you are a visitor using a widget installed on a customer website, you may need to contact that website or business directly because they control how they use your information.

23. Important Notice

This Privacy Policy is a general template and may not fully reflect all legal obligations applicable to your business, jurisdiction, users, visitors, payment model, data transfers, retention practices, AI features, or industry.

Before publishing this Privacy Policy, you should obtain legal review and define:

  • legal company name;
  • business address;
  • privacy contact email;
  • governing jurisdiction;
  • data retention periods;
  • subprocessors;
  • international transfer mechanism;
  • payment provider details;
  • AI provider details;
  • cookie practices;
  • visitor rights process;
  • customer data processing terms.