Privacy Policy
Last updated: 2026-08-10
How EspressoDesk collects, uses and shares personal data, and the rights you have under the GDPR, the UK GDPR and the CCPA/CPRA.
1. Who we are
EspressoDesk operates the helpdesk platform described at espressodesk.com. For account and website data we act as a data controller. For the ticket, chat and contact data your agents handle inside a workspace we act as a data processor on your instructions.
Privacy contact: info@getespressodesk.com.
2. Data we collect
Account data: name, work email, organisation, language preference, role and authentication identifiers.
Billing data: plan, subscription status and invoice history. Card details are entered on Lemon Squeezy's checkout and never reach our servers.
Service data: tickets, chat transcripts, internal notes, knowledge base articles and the email addresses of the end customers you support.
Technical data: IP address, browser and device metadata, and audit logs used for security and abuse prevention.
3. Why we use it and on what legal basis
To provide and secure the service and to bill it — performance of a contract.
To prevent fraud and abuse, and to improve reliability — legitimate interests.
To send product and marketing email where required — consent, withdrawable at any time from the footer of each message.
To meet accounting, tax and legal obligations — legal obligation.
4. Subprocessors we share data with
Supabase — hosting of the application database, authentication and file storage.
Lovable — application hosting, platform e-mail delivery for account and notification messages, and the AI gateway that routes text submitted to the AI assistant features (tone improvement, summaries, auto-drafts) to the underlying model providers. Content is sent for inference only and is not used to train models.
Lemon Squeezy — merchant of record for checkout, subscriptions, invoices and tax handling.
Your own mail provider — when you connect a company mailbox (Gmail, Microsoft 365, any IMAP/SMTP host, or a sending API such as Postmark, SendGrid, Resend or Brevo), customer e-mail is retrieved from and sent through that mailbox. That provider is your own subprocessor under your contract with them; we only hold the access credentials, encrypted with AES-256-GCM, and act on your instructions.
Each subprocessor we engage is bound by a written data processing agreement. We publish material changes to this list before they take effect.
5. International transfers
Some subprocessors are located in the United States. Transfers out of the EEA or the UK rely on the EU Standard Contractual Clauses and the UK Addendum, together with supplementary technical measures such as encryption in transit and at rest.
6. Retention
Workspace content is kept while the subscription is active and for 30 days after cancellation, then deleted from live systems and purged from backups within 90 days.
Invoices and tax records are retained for the period required by law. Security logs are kept for 12 months.
7. Your rights
Under the GDPR and UK GDPR you may request access, rectification, erasure, restriction, portability, and object to processing based on legitimate interests. You may also lodge a complaint with your supervisory authority.
Under the CCPA/CPRA, California residents may request disclosure of the categories and specific pieces of personal information collected, request deletion or correction, and opt out of sharing. We do not sell personal information and we do not share it for cross-context behavioural advertising. We will not discriminate against you for exercising these rights.
To exercise a right, email info@getespressodesk.com. We respond within 30 days. If we process your data on behalf of a customer, we will refer the request to that customer.
8. Security
Data is encrypted in transit with TLS and at rest. Tenant isolation is enforced at the database layer with row-level security so one organisation can never read another's tickets.
Access to production data is limited to staff who need it, protected by multi-factor authentication and logged. We will notify affected customers of a personal data breach without undue delay and within 72 hours where legally required.
9. Cookies
We use strictly necessary cookies for session authentication, plus local storage for language and theme preferences. We do not run advertising trackers.
10. Children and changes
The service is not directed at children under 16 and we do not knowingly collect their data.
We will post any update to this policy here with a new date and, for material changes, notify account owners by email.
This page describes how EspressoDesk operates today. It is general information, not legal advice; for a bespoke data processing agreement contact info@getespressodesk.com.

