NewWhatsApp Cloud API voice calling is live across the EU.See what's new →
talkforce.io
Legal

Privacy Policy

Plain-English explanation of what data we collect, why, and how you can control it.

Last updated: May 22, 2026

1. Who We Are

TalkForce, Inc. ("TalkForce", "we", "our", or "us") operates the website https://talkforce.ioand the TalkForce conversational commerce platform, including any mobile apps, APIs, and related services (collectively, the "Service").

We are the data controller for personal data collected through the Service. Questions about this policy can be sent to privacy@talkforce.io.

2. Data We Collect

2.1 Account & Identity Data

When you register or use our Service we collect: name, email address, phone number, company name, job title, and billing address.

2.2 Messaging & Communication Data

To deliver our inbox and AI-agent features we process: message content sent and received through connected channels (WhatsApp, Instagram, Facebook Messenger, email), conversation metadata (timestamps, channel, read/delivery status), and contact profiles created from inbound messages.

2.3 Usage & Technical Data

We automatically collect: IP address, browser type, device identifiers, pages viewed, features used, error logs, and session duration. This data is used solely for security and product improvement.

2.4 Payment Data

Payment card details are processed directly by Stripe, our PCI-DSS Level 1 certified payment processor. We only store a masked card number, expiry, and transaction reference.

2.5 User-Generated Content

Data you upload to TalkForce — product catalogs, contact lists, workflow configurations, AI training examples — is stored and processed as part of delivering the Service.

3. How We Use Your Data

We use personal data to:

  • Provide, operate, and improve the Service
  • Process transactions and send billing notices
  • Authenticate users and enforce security
  • Power AI features including the conversational agent and catalog search
  • Send transactional emails (password reset, invoice, alerts)
  • Send product updates and marketing communications — only with your consent, and you can opt out at any time
  • Comply with legal obligations
  • Investigate abuse, fraud, and security incidents

We do notsell personal data to third parties. We do not use your customers' messaging data to train AI models for purposes outside of providing your contracted Service.

4. Legal Basis for Processing (GDPR)

For users in the European Economic Area (EEA), we process data under the following lawful bases:

PurposeLegal Basis
Delivering the ServicePerformance of contract
Billing & paymentsPerformance of contract
Marketing emailsConsent (opt-in)
Security & fraud preventionLegitimate interest
Product analyticsLegitimate interest
Legal complianceLegal obligation

5. Data Sharing & Sub-processors

We share data with the following categories of third-party service providers solely to operate the Service. All sub-processors are bound by data processing agreements requiring GDPR-equivalent protections.

Sub-processorPurposeLocation
VercelWeb hosting & edge networkUSA / Global
RailwayBackend infrastructureUSA
Supabase / PostgreSQLDatabase storageUSA
Upstash RedisCaching & queuesUSA / EU
Google Cloud (Gemini)AI completions & embeddingsUSA / EU
Mistral AIAI fallback completionsEU (France)
Meta PlatformsWhatsApp / Instagram / Facebook messaging deliveryUSA
ClerkAuthentication & SSOUSA
StripePayment processingUSA
LiveKitReal-time voice (WebRTC)USA
Vercel BlobFile storageUSA / Global

6. Messaging Platform Data (Meta / WhatsApp)

TalkForce is an official Meta Business Solution Provider (BSP). When you connect a WhatsApp Business Account, Instagram, or Facebook Page through our platform:

  • Message content and metadata are transmitted through Meta's APIs under Meta's platform policies.
  • We store message history in your TalkForce account database to power your inbox.
  • We do not access your connected accounts for any purpose other than providing the agreed Service.
  • End-users of your WhatsApp/Instagram channels may request deletion of their message history by contacting you directly; you can then use TalkForce's data-deletion tools or contact us at the email below.
  • User data obtained through Meta APIs is not used to train general-purpose AI models or shared with third parties beyond sub-processors listed above.

7. Data Retention

We keep personal data for as long as your account is active or as needed to provide the Service:

  • Account data: retained for the lifetime of your account plus 30 days after deletion.
  • Message history: retained per your account plan settings (default 12 months); configurable in-app.
  • Billing records: retained for 7 years to comply with financial regulations.
  • Server logs: retained for 90 days.

8. Your Rights

Depending on your jurisdiction you may have the right to:

Access

Request a copy of all personal data we hold about you.

Correction

Ask us to correct inaccurate or incomplete data.

Deletion

Request that we delete your personal data ("right to be forgotten").

Portability

Receive your data in a machine-readable format.

Objection

Object to processing based on legitimate interest.

Restriction

Ask us to restrict processing while a dispute is resolved.

To exercise any right, email privacy@talkforce.io. We will respond within 30 days. You also have the right to lodge a complaint with your local supervisory authority (e.g., the ICO in the UK, or the CNIL in France).

9. Data Deletion

To delete your TalkForce account and all associated personal data:

  1. Option 1: Log in to app.talkforce.io → Settings → Account → Delete Account, or
  2. Option 2: Email privacy@talkforce.io with subject line "Account Deletion Request" and include your registered email address.

Upon receiving a deletion request we will remove all personal data within 30 days, except where retention is required by law (e.g., billing records).

10. Cookies

We use the following categories of cookies:

TypePurposeRequired
Strictly necessarySession management, authentication, security (CSRF)Yes
FunctionalRemember preferences (language, theme)No
AnalyticsAggregate page-view and feature-usage statsNo
MarketingNot usedN/A

11. Security

We implement industry-standard security measures including TLS 1.3 for data in transit, AES-256 encryption for sensitive data at rest, role-based access controls, SOC 2 Type II audit compliance, and regular penetration testing by independent third parties.

In the event of a data breach that affects your personal data we will notify you and the relevant supervisory authority within 72 hours as required by GDPR.

12. Children

The Service is not directed to children under 16. We do not knowingly collect personal data from anyone under 16. If you believe we have collected data from a child, please contact us and we will delete it promptly.

13. International Transfers

Your data may be processed outside of your country of residence, including in the United States. When we transfer data from the EEA, UK, or Switzerland, we use appropriate safeguards including Standard Contractual Clauses (SCCs) approved by the European Commission.

14. Changes to This Policy

We may update this Privacy Policy from time to time. When we make material changes we will notify you by email and/or a prominent notice on the Service at least 30 days before the change takes effect. The "Last updated" date at the top of this page reflects the most recent revision.

15. Contact Us

For any questions, requests, or complaints regarding this Privacy Policy: