Privacy Policy
Last updated: June 10, 2026
This policy explains how Yakware ("we", "us") handles personal data in connection with YakDesk. YakDesk plays two distinct roles, and this policy covers both:
- Yakware as controller — for data about you: your account, billing, and your visits to our own websites.
- Yakware as processor — for data about your visitors, which our chat widget and session recorder collect on your websites on your behalf. For that data, you are the controller.
1. Data we collect as controller
Account data
When you register we collect your email address, a password (stored only as a salted hash), and optionally an account or display name. We use this data to operate your account, secure it, and send you service emails (verification, password reset, important service notices).
Billing data
Payments are processed by Stripe. We receive and store your subscription status and a Stripe customer reference — never your card number. Stripe's handling of your payment details is described in Stripe's own privacy policy.
Our websites
Our marketing and application pages set only the cookies strictly necessary to operate the site (see the Cookie Policy). We do not run advertising or third-party analytics trackers on our own sites.
2. Data we process on your behalf
When you install the chat widget or the session recorder on your websites, we process your visitors' data solely on your instructions, to provide the Service to you:
- Chat conversations — message contents, the time of the conversation, and coarse technical metadata used to route and display the chat (such as the page the visitor was on and approximate location derived from IP).
- Session recordings — page navigation, clicks, scrolls, and rendered page structure, captured so you can replay what a visitor experienced. The recorder is built privacy-first: form input values are masked by default (you must explicitly whitelist a field to record it), it honors the browser's Do Not Track setting automatically, and it supports a consent-gating mode in which nothing is captured until your cookie banner grants consent.
As the controller for this data, you are responsible for disclosing your use of chat and session recording to your visitors and for obtaining any legally required consents. We do not use your visitors' data for our own purposes, and we do not sell it.
3. Subprocessors and hosting
We use a small number of service providers to operate YakDesk:
- Hetzner — cloud infrastructure hosting the Service and its data.
- Stripe — payment processing.
We will update this list before adding subprocessors that handle personal data.
4. Retention
Account data is retained while your account exists and deleted within 90 days of account deletion, except where law requires longer retention (for example, invoicing records). Chat transcripts and session recordings are retained while your account is active so you can access your history; you may request deletion of specific conversations or recordings at any time.
5. Your rights
Depending on your jurisdiction (for example, under the GDPR), you may have the right to access, correct, export, restrict, or delete your personal data, and to object to processing. Contact us at the address below to exercise these rights; we respond within 30 days. If your request concerns data we process on behalf of one of our customers (for example, a chat you had on a customer's website), we will refer you to that customer, who controls the data.
6. Legal bases
Where the GDPR applies, we process account and billing data to perform our contract with you, service emails on the basis of legitimate interest in operating the Service, and data processed on your behalf under your instructions as processor.
7. Security
Data is encrypted in transit. Access to production systems is restricted to authorized personnel. Passwords are stored as salted hashes; payment card data never touches our servers.
8. Children
The Service is not directed at children under 16, and we do not knowingly collect their data.
9. Changes
We will post changes to this policy here and, for material changes, notify you by email or in the Service before they take effect.
SMS / mobile messaging
If you enable SMS verification, we use your mobile number only to send one-time verification codes and account/security notifications. We do not sell, rent, or share your mobile number or SMS opt-in with third parties or affiliates for their marketing. Message frequency varies. Message and data rates may apply. Reply STOP to cancel, HELP for help.
10. Contact
Privacy questions and data-subject requests: support@yakware.com.