Fetchply Docs
Account and settings

Security and privacy

Understand how Fetchply protects your data and the practical steps your team should take.

Your data stays yours. Fetchply protects account access, customer conversations, agent knowledge, and connected-service credentials while giving you clear control over access, exports, retention, and deletion.

Fetchply does not sell your data. We do not use private agent content or customer conversations to train a shared Fetchply model.

What Fetchply protects

  • Workspace privacy: Agent content, conversations, leads, and settings stay scoped to the correct workspace.
  • Account access: Roles and permissions limit what each teammate can view, change, export, or delete.
  • Sensitive connections: Supported credentials are protected before storage and are not shown again after setup.
  • Data in transit: Fetchply uses encrypted connections when your browser, widget, and connected services exchange information.
  • Data control: You can export supported records, remove connected services, delete agents, and request account deletion.

Protect your account

  1. Use a unique password and protect the email or social account linked to Fetchply.
  2. Invite only people who need access. Remove former teammates and expired invitations promptly.
  3. Give each teammate the least-privileged role that lets them do their work.
  4. Review export and deletion permissions carefully because those actions can expose or permanently remove customer data.
  5. Never share sign-in sessions, recovery links, or connected-service credentials.

Protect connected services

Use the official connection flow for messaging, commerce, notification, and automation services. Do not paste credentials into chats, agent knowledge, screenshots, or support messages.

If a credential may have been exposed:

  1. Revoke or rotate it with the connected service immediately.
  2. Disconnect the affected integration in Fetchply.
  3. Reconnect using a new credential.
  4. Review recent activity and remove access that is no longer needed.

Functions and webhooks should use public HTTPS destinations that you control. Keep credentials out of URLs and use the supported authentication fields instead.

Handle customer data responsibly

Conversations, leads, analytics, channel messages, and exports may contain personal data.

  • Tell visitors how you use Fetchply and provide any notice or consent required in their location.
  • Collect only the information you need for a clear customer-support or business purpose.
  • Avoid payment-card details, government identifiers, health information, or other sensitive data unless you have a valid legal basis and suitable safeguards.
  • Restrict inbox, lead, analytics, and export access to teammates who need it.
  • Review retention and deletion choices as your legal obligations or business needs change.

Export, retention, and deletion

Export important records before deleting an agent or account. Deletion is permanent and may also remove conversations, knowledge, leads, settings, and connected-service records.

Disconnect services you no longer use. This reduces unnecessary access and makes ownership clear when teammates or vendors change.

For details about data categories, processing purposes, sharing, retention, and individual rights, read the Privacy Policy.

Report a security concern

If you suspect unauthorized access or exposed data:

  1. Secure the affected account or connected service first.
  2. Preserve useful details such as the time, affected workspace, and actions you observed.
  3. Contact Fetchply support promptly without including passwords, tokens, private keys, or full customer records in the message.

We will review the report, contain verified risks, and guide you through any recovery steps that require your action.

Quick security check

  • Former teammates and stale invitations are removed.
  • Roles match each person's current responsibilities.
  • Connected services are still needed and owned by the right person.
  • Sensitive credentials do not appear in agent knowledge, chats, URLs, or screenshots.
  • Visitor notices, consent, retention, exports, and deletion match your obligations.