Privacy Policy
Last updated: September 28, 2026
1. Data collected through the chat widget
When you chat with a business through a Hodhod-powered widget on their website, we (on that business's behalf) may collect:
- Your name, email address, and phone number, if you provide them or the pre-chat form asks for them.
- The content of your messages and any files you send, and the same for the agent's replies.
- Technical data sent by your browser: browser and device type, operating system, page URL, referrer, and language.
- Your IP address, used to keep the conversation session secure and, where enabled, to show the agent an approximate location.
- A small amount of data stored in your browser (see "Cookies and local storage" below) so the widget remembers your conversation between page loads.
This data is stored in the workspace of the specific business you're chatting with. We do not use it for advertising, and we do not sell it. Each business's data is kept separate from every other business using Hodhod.
2. Data collected from companies, agents, and admins
If your business uses Hodhod, we collect the data needed to run your workspace:
- Account and profile data for each agent and admin: name, email, password (stored hashed, never in plain text), and avatar if uploaded.
- Authentication data: session tokens, and — if you enable it — a two-factor authentication secret and backup codes, stored encrypted.
- Contacts, conversations, notes, labels, and reports that your team creates or that come in through connected channels (website widget, and, if you connect one, a Telegram account).
- Configuration you set: inbox settings, working hours, canned responses, automation rules, and similar preferences.
3. If you connect a personal Telegram account
Hodhod offers an optional feature letting a company connect one of its own Telegram accounts so incoming Telegram messages appear in Hodhod and agents can reply from there. If you use this feature:
- Messages sent to and from that Telegram account (and the sender's Telegram profile info: name, username, and user ID) are relayed into Hodhod and stored in your workspace, the same as any other conversation.
- The Telegram session created when you connect the account is stored encrypted and is only used to send and receive messages for that account.
- This feature talks to Telegram's own servers directly; Telegram's own privacy policy also applies to that account.
- Disconnecting the account ends the session; past conversations remain in your workspace unless you delete them.
4. Demo requests and sign-ups
If you fill out the "Request a demo" or sign-up form on this site, we collect your name, company name, email, phone number (optional), and message, so we can respond to your request. We don't use this for anything else.
5. Cookies and local storage
We use a small number of first-party cookies and browser local-storage entries — not third-party advertising trackers:
- A session cookie so you stay signed in to the dashboard.
- A widget conversation token, so a returning visitor sees their conversation history instead of starting over.
- Your chosen language and light/dark theme preference for this site and, where applicable, the widget.
6. How we protect data
- All traffic is encrypted in transit (HTTPS).
- Passwords are hashed, never stored in plain text.
- Sensitive fields — two-factor secrets and connected Telegram sessions — are encrypted at rest.
- Each company's workspace is isolated from every other company's.
- Companies can optionally require two-factor authentication and restrict dashboard access to specific IP addresses.
7. How long we keep data
Data stays in a company's workspace for as long as that company's account is active, or until an admin deletes it. If a company's account is closed, we delete its data within a reasonable period afterward, except where we need to keep something longer to meet a legal obligation.
8. Your rights
Depending on where you're located, you may have the right to:
- Ask what data we (or a business using Hodhod) hold about you, and get a copy of it.
- Ask for inaccurate data to be corrected.
- Ask for your data to be deleted.
- Object to or ask us to restrict certain processing.
If your request is about a conversation with a specific business, the quickest path is usually to ask that business directly, since they control their own workspace. You can also contact us using the details below and we'll help route the request.
9. Children's privacy
Hodhod isn't directed at children, and we don't knowingly collect data from children under 13.
10. Changes to this policy
We may update this policy as the product changes. We'll update the date at the top when we do; significant changes will be highlighted here.
11. Contact us
Questions about this policy or your data can be sent to privacy@hodhod.chat.