ZebChat uses a small number of trusted service providers to run the service. This page lists them, what they do and where they process data.
1. Current subprocessors
| Provider | Purpose | Data | Location |
|---|---|---|---|
| [Hosting provider] | Hosting of the application, database and cache | All Customer Data | [Hosting region] |
| [File storage provider] | Storage of chat attachments and knowledge-base files | Files sent in chats and uploaded by customers | [Hosting region] |
| [Email delivery provider] | Delivery of service emails (verification, invitations, alerts, transcripts) | Names, email addresses, message excerpts | [Location] |
| Zoho Corporation (ZeptoMail / Zoho CPaaS) | Transactional email delivery, when selected as the email provider | Names, email addresses, message content of system emails | [Region of the chosen Zoho data centre] |
| Cloudflare, Inc. | Network, content delivery, DDoS protection, approximate visitor location; optional Turnstile bot check | IP addresses and request metadata | Global network (USA) |
| Stripe, Inc. and affiliates | Card payments and subscription billing | Billing contact and payment details | USA, EU |
| PayPal (Europe) S.à r.l. et Cie, S.C.A. and affiliates | PayPal payments and subscriptions | Billing contact and payment details | EU, USA |
| Google LLC (Firebase Cloud Messaging) | Push notifications to the Android and iOS apps | Device tokens and notification content (for example a visitor name and message preview) | USA |
| Google LLC (Firebase Crashlytics) | Crash reports from the Android and iOS apps (optional, can be switched off in the app) | Error details, app version, device model and OS, a crash installation id and the internal user id; no names, emails or messages | USA |
| Google LLC (Google Analytics for Firebase) | Usage statistics for the Android and iOS apps (optional, can be switched off in the app) | Screens viewed and feature events, app-instance id, device model, OS, app version, approximate location derived from the IP address; no names, emails, messages or advertising id | USA |
| Apple Inc. (Apple Push Notification service) | Delivery of push notifications to iOS devices | Device tokens and notification content | USA |
| Browser push services (Google, Mozilla, Apple, Microsoft) | Delivery of browser notifications in the web dashboard | Encrypted notification payloads and the browser’s push address | Global |
| CARTO | Map tiles for the dashboard’s Live Map | Map requests from team members’ browsers (IP address); no visitor records | USA, EU |
| Functional Software, Inc. (Sentry), where enabled | Error monitoring of the API and background workers | Technical error data, which may include account or organization ids | USA |
2. Services you choose yourself
These providers receive data only when you connect them with your own account, key or URL. They act under your agreement with them and are not ZebChat subprocessors:
- Anthropic (Claude) and OpenAI: AI replies, summaries and grading when you add your API key; they receive conversation content and knowledge-base excerpts.
- OpenAI or Voyage AI: embeddings for your knowledge base when you add an embeddings key.
- Your webhook and AI action endpoints: the events and data you configure.
3. Changes and notifications
We update this page before a new subprocessor starts processing personal data, as described in our Data Processing Agreement. To be notified of changes by email, write to [email protected].
Contact
ZebChat is operated by Tech Avenue Labs, Hyderabad, India. See the contact page for email addresses.