Plain-English explanation of what data we collect, why, and how you can control it.
Last updated: August 21, 2026
TalkForce, Inc. ("TalkForce", "we", "our", or "us") operates the website https://talkforce.ioand the TalkForce conversational commerce platform, including any mobile apps, APIs, and related services (collectively, the "Service").
We are the data controller for personal data collected through the Service. Questions about this policy can be sent to info@talkforce.io.
When you register or use our Service we collect: name, email address, phone number, company name, job title, and billing address.
To deliver our inbox and AI-agent features we process: message content sent and received through connected channels (WhatsApp, Instagram, Facebook Messenger, email), conversation metadata (timestamps, channel, read/delivery status), and contact profiles created from inbound messages.
We automatically collect: IP address, browser type, device identifiers, pages viewed, features used, error logs, and session duration. This data is used solely for security and product improvement.
If you purchase paid services from TalkForce, we may process billing and transaction information required to provide the subscription or service. We do not intentionally store full payment card numbers in TalkForce.
Data you upload to TalkForce — product catalogs, contact lists, workflow configurations, AI training examples — is stored and processed as part of delivering the Service.
We use personal data to:
We do notsell personal data to third parties. We do not use your customers' messaging data to train AI models for purposes outside of providing your contracted Service.
For users in the European Economic Area (EEA), we process data under the following lawful bases:
| Purpose | Legal Basis |
|---|---|
| Delivering the Service | Performance of contract |
| Billing & payments | Performance of contract |
| Marketing emails | Consent (opt-in) |
| Security & fraud prevention | Legitimate interest |
| Product analytics | Legitimate interest |
| Legal compliance | Legal obligation |
We may share personal data only to the extent needed to operate, secure, support, and improve the Service, or where disclosure is required by law. Depending on the feature you use, this may include infrastructure and hosting providers, database and storage providers, authentication providers, messaging and communications platforms, AI service providers used for user-enabled features, and professional advisors or legal authorities where required.
We do not sell personal data to advertisers, data brokers, or information resellers.
TalkForce is an official Meta Business Solution Provider (BSP). When you connect a WhatsApp Business Account, Instagram, or Facebook Page through our platform:
When a user connects a Gmail account to TalkForce, we access the Gmail data needed to provide the email-client features the user requests. This may include the connected email address; message and thread identifiers; sender, recipient, subject, date, and routing headers; message bodies; attachment metadata and attachment content synchronized for display and user-authorized download; drafts; Gmail system labels and user-created labels; read, unread, starred, archived, spam, and trash state; and synchronization metadata such as Gmail history identifiers.
We use Gmail data only to display and synchronize the user's mailbox in TalkForce; allow the user to search, organize, label, read, mark unread, star, archive, restore, draft, send, and reply to email; preserve Gmail threading; and provide user-enabled AI-assisted drafting or auto-reply features. We do not use Google Workspace data to create, train, or improve any generalized artificial intelligence or machine-learning model.
We do not sell Google user data and do not transfer it to advertisers, data brokers, or information resellers. We transfer only the minimum data required to contracted infrastructure and service processors that operate TalkForce's user-facing features. When a user enables AI-assisted email drafting, the relevant Gmail content may be processed by Google Gemini solely to generate the requested draft or configured reply. Gmail content is not used for advertising, credit decisions, data brokerage, or generalized analytics unrelated to these user-facing email features.
OAuth credentials are encrypted and handled only on trusted server-side systems. Gmail data is encrypted in transit and protected at rest. Disconnecting Gmail stops future API access and synchronization. A user or workspace administrator may request deletion of cached Gmail data and OAuth credentials through account controls or by contacting info@talkforce.io. Deletion requests are processed according to this Privacy Policy, except where limited retention is required by law, security, fraud prevention, or backup-recovery obligations.
Google Limited Use: The use of raw or derived user data received from Google Workspace APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
We keep personal data for as long as your account is active or as needed to provide the Service:
Depending on your jurisdiction you may have the right to:
Request a copy of all personal data we hold about you.
Ask us to correct inaccurate or incomplete data.
Request that we delete your personal data ("right to be forgotten").
Receive your data in a machine-readable format.
Object to processing based on legitimate interest.
Ask us to restrict processing while a dispute is resolved.
To exercise any right, email info@talkforce.io. We will respond within 30 days. You also have the right to lodge a complaint with your local supervisory authority (e.g., the ICO in the UK, or the CNIL in France).
To delete your TalkForce account and all associated personal data:
Upon receiving a deletion request we will remove all personal data within 30 days, except where retention is required by law (e.g., billing records).
We use the following categories of cookies:
| Type | Purpose | Required |
|---|---|---|
| Strictly necessary | Session management, authentication, security (CSRF) | Yes |
| Functional | Remember preferences (language, theme) | No |
| Analytics | Aggregate page-view and feature-usage stats | No |
| Marketing | Not used | N/A |
We implement reasonable technical and organizational security measures designed to protect personal data against unauthorized access, loss, misuse, alteration, or disclosure. These measures include encryption in transit, access controls, and operational safeguards appropriate to the nature of the data we process.
In the event of a data breach that affects your personal data we will notify you and the relevant supervisory authority within 72 hours as required by GDPR.
The Service is not directed to children under 16. We do not knowingly collect personal data from anyone under 16. If you believe we have collected data from a child, please contact us and we will delete it promptly.
Your data may be processed outside of your country of residence, including in the United States. When we transfer data from the EEA, UK, or Switzerland, we use appropriate safeguards including Standard Contractual Clauses (SCCs) approved by the European Commission.
We may update this Privacy Policy from time to time. When we make material changes we will notify you by email and/or a prominent notice on the Service at least 30 days before the change takes effect. The "Last updated" date at the top of this page reflects the most recent revision.
For any questions, requests, or complaints regarding this Privacy Policy: