Privacy Policy
Last updated: 2026-09-21
How EspressoDesk collects, uses and shares personal data, and the rights you have under the GDPR, the UK GDPR and the CCPA/CPRA.
1. Who we are
EspressoDesk operates the helpdesk platform available at getespressodesk.com. For account and website data we act as a data controller. For the ticket, chat and contact data your agents handle inside a workspace we act as a data processor on your instructions.
Privacy contact: info@getespressodesk.com.
2. Data we collect
Account data: name, work email, organisation, language preference, role and authentication identifiers.
Billing data: plan, subscription status and invoice history. Card details are entered on Lemon Squeezy's checkout and never reach our servers.
Service data: tickets, chat transcripts, internal notes, knowledge base articles and the email addresses of the end customers you support.
Attachment data: files uploaded by your agents or received from your customers by e-mail are stored in a private, per-workspace bucket together with their file name, type, size and the ticket they belong to. They are never public: every download goes through a short-lived signed link issued only to a member of that workspace.
E-mail routing data: the Cc, Bcc and forwarding addresses an agent enters on a reply or forward are stored with that ticket message so the workspace keeps a record of who received it.
Technical data: IP address, browser and device metadata, and audit logs used for security and abuse prevention.
Internal service notifications: when a new account is registered or a new trial workspace is created, our own team receives an internal notification containing the account e-mail address, the workspace and company name, the country and the trial end date. It is used solely to operate and support the service and is never shared with third parties for marketing.
Product data created by your team: internal team chat messages, satisfaction (CSAT) ratings and comments left by your customers, and records of which version of these documents each account owner accepted, with date and IP address.
Task data: internal tasks created by your agents (title, notes, priority, due date, assignee, optional ticket or contact link). Completed tasks are deleted 90 days after completion; open tasks are kept until deleted by you or with the workspace.
Notification data: alerts generated for your agents (type, ticket reference, read state) and each agent's notification preferences. Read alerts are deleted after 30 days and all alerts after 90 days, and they are deleted with the workspace.
Customer portal data: the e-mail address a customer verifies with a one-time code, the short-lived portal session token, and any replies or files they upload from the portal. Portal sessions expire after 24 hours; the uploaded files follow the attachment rules above.
Security data: two-factor authentication settings and trusted-device records created when an agent chooses to skip the second factor for 30 days on a given browser.
Desktop app data: when an agent connects EspressoDesk Capture, we store the device token as a hash, an optional device name, the date of last use, and a hashed anonymous identifier of that computer used to keep one token bound to one machine. Screenshots are never uploaded unless the agent presses Send to EspressoDesk, and they then go to that workspace's own ticket storage. Keyboard shortcuts you define in Capture stay on your own computer and are not sent to us.
Capture Cloud data: if the workspace has Capture Pro and an agent uses Upload & copy link, the screenshot is stored in a private cloud bucket of your workspace together with the file size, the uploading agent, an optional password kept only as a hash, and an expiry date based on the link lifetime chosen in the workspace. Share links use a random 128-bit address and are opened through short-lived signed URLs; an agent can delete a shot or revoke its link at any time, and expired shots are deleted automatically every night. These files count towards the workspace storage allowance.
Integration data: if you connect Jira, Trello or Slack, the credentials are stored encrypted and are never shown again in the interface. Each escalation or notification sends the ticket number, subject, first message, reporter e-mail and ticket link to that provider; nothing else is transferred and we do not import data back except the identifier and URL of the created issue or card. You can disconnect an integration at any time, which deletes the stored credentials.
Telegram data: if you connect the Telegram channel, we store your bot token encrypted plus, for each conversation, the Telegram chat identifier, the sender's Telegram display name and username where provided, and the message text and files, which become ticket messages like any other channel. The chat identifier is used as the customer address for that ticket. Disconnecting the bot removes the webhook and deletes the stored token.
Remote support data: the AnyDesk and TeamViewer IDs saved on a contact or ticket are stored as plain identifiers so an agent can open the remote client. No session is routed through us, and we hold no screen content, keystrokes or recordings from those sessions.
Google sign-in data: if an agent signs in with Google, we receive and store only the e-mail address, name and profile picture from that Google account, and a link between it and the EspressoDesk account. We never receive the Google password and request no access to Gmail or other Google services.
Appearance data: the colour theme an agent selects, including the individual colours of a custom theme, is stored on that agent's profile so the panel looks the same on every device. It contains no personal content beyond the colour values.
3. Why we use it and on what legal basis
To provide and secure the service and to bill it — performance of a contract.
To prevent fraud and abuse, and to improve reliability — legitimate interests.
To check the e-mail address given at registration against a list of known disposable/temporary providers, in order to prevent trial abuse — legitimate interests. The check compares only the domain part of the address.
To verify at registration that the person signing up is human, we use Cloudflare Turnstile — legitimate interests. The check is processed by Cloudflare; we do not receive or store any interactive challenge answers.
To send service-related transactional emails, such as welcome, payment confirmation and account notices — performance of a contract.
To send product and marketing email where required — consent, withdrawable at any time from the footer of each message.
To measure the performance of our advertising and website usage with Google Ads and Google Analytics — consent in regions that require it, otherwise legitimate interests; you can withdraw or change consent through the cookie notice at the bottom of the page.
To meet accounting, tax and legal obligations — legal obligation.
4. Subprocessors we share data with
Supabase — hosting of the application database, authentication and file storage.
Lovable — application hosting, platform e-mail delivery for account and notification messages, and the AI gateway that routes text submitted to the AI assistant features (tone improvement, summaries, auto-drafts) to the underlying model providers. Content is sent for inference only and is not used to train models.
Lemon Squeezy — merchant of record for checkout, subscriptions, invoices and tax handling.
Your own mail provider — when you connect a company mailbox (Gmail, Microsoft 365, any IMAP/SMTP host, or a sending API such as Postmark, SendGrid, Resend, Brevo, Mailgun, Amazon SES, Elastic Email, Mailjet or Mailchimp Transactional/Mandrill), customer e-mail is retrieved from and sent through that mailbox. That provider is your own subprocessor under your contract with them; we only hold the access credentials, encrypted with AES-256-GCM, and act on your instructions.
Twilio — only when you connect the WhatsApp channel with your own Twilio account. WhatsApp messages and the customer phone numbers used as ticket identifiers pass through Twilio under your own contract with them; we store your Twilio credentials encrypted with AES-256-GCM and act on your instructions.
Telegram Messenger — only when you connect the Telegram channel with your own bot. Messages and the Telegram profile data of the people who write to your bot pass through Telegram's network under their own terms; we store your bot token encrypted with AES-256-GCM and act on your instructions.
Google — (a) when an agent chooses Sign in with Google, Google authenticates the agent and returns the e-mail address, name and profile picture to us; no other Google data is accessed; (b) for advertising and analytics measurement, Google Ads and Google Analytics receive page views, conversion events and device/browser identifiers through cookies or similar technologies. You can control or withdraw consent for advertising and analytics cookies through the cookie notice.
AnyDesk and TeamViewer — no data is sent to them by us. Remote sessions are opened locally from the agent's computer with the ID you stored, and the session itself runs between you, your customer and that software under its own terms.
Each subprocessor we engage is bound by a written data processing agreement. We publish material changes to this list before they take effect.
5. International transfers
Some subprocessors are located in the United States. Transfers out of the EEA or the UK rely on the EU Standard Contractual Clauses and the UK Addendum, together with supplementary technical measures such as encryption in transit and at rest.
6. Retention
Workspace content is kept while the subscription is active and for 30 days after cancellation, then deleted from live systems and purged from backups within 90 days.
Internal team chat messages are deleted automatically 30 days after they are sent. Trusted-device records expire after 30 days. Legal acceptance records are kept for the life of the account plus the statutory limitation period, because they are the proof of the contract.
Ticket attachments may be purged 12 months after the ticket they belong to was closed. Invoices and tax records are retained for the period required by law. Security logs are kept for 12 months.
7. Your rights
Under the GDPR and UK GDPR you may request access, rectification, erasure, restriction, portability, and object to processing based on legitimate interests. You may also lodge a complaint with your supervisory authority.
Under the CCPA/CPRA, California residents may request disclosure of the categories and specific pieces of personal information collected, request deletion or correction, and opt out of sharing. We do not sell personal information. We share limited data with Google for advertising measurement and analytics; you can disable these cookies through the cookie notice at the bottom of the page or via the Google opt-out mechanisms linked there. We will not discriminate against you for exercising these rights.
To exercise a right, email info@getespressodesk.com. We respond within 30 days. If we process your data on behalf of a customer, we will refer the request to that customer.
8. Security
Data is encrypted in transit with TLS and at rest. Tenant isolation is enforced at the database layer with row-level security so one organisation can never read another's tickets. Suspected vulnerabilities can be reported to security@getespressodesk.com.
Agents can enable two-factor authentication on their own account, and workspace owners can restrict each agent to the sections they need. Access to production data is limited to staff who need it, protected by multi-factor authentication and logged. We will notify affected customers of a personal data breach without undue delay and within 72 hours where legally required.
9. Cookies
We use strictly necessary cookies for session authentication, plus local storage for preferences such as language, dark mode, colour palette or custom theme colours, whether chat notification sounds are on, which side panels you collapsed and the few canned responses you used most recently. A trusted-device token is stored for 30 days only if an agent asks us to remember the browser for two-factor authentication.
We use Google Ads and Google Analytics cookies to measure the performance of our advertising and how visitors use the site. In regions where the law requires it, we show a cookie notice and only enable these advertising and analytics cookies if you accept. You can change or withdraw your choice at any time by using the cookie notice at the bottom of the page or by clearing local storage for this site.
10. Children and changes
The service is not directed at children under 16 and we do not knowingly collect their data.
We will post any update to this policy here with a new date and, for material changes, notify account owners by email.
This page describes how EspressoDesk operates today. It is general information, not legal advice; for a bespoke data processing agreement contact info@getespressodesk.com.

