Privacy Policy

What we collect, what we do with it, who else touches it, and how to take it back or have it erased.

Last updated 2 August 2026

1Who this covers

CustoDesk (“CustoDesk”, “we”) operates custodesk.com and the workspace software behind it. This policy covers the marketing site, the product, and the customer-facing surfaces we host for you — portals, help centres, review widgets and chat.

There are two very different kinds of data here, and the difference decides your rights and ours:

  • Account data — who signed up, your billing details, how the product is used. We decide what happens to this, so for it we are the controller.
  • Workspace data — the contacts, tickets, invoices, files and messages you put into CustoDesk, including personal data about your customers. You decide what happens to this. You are the controller; we only ever act as your processor, on your instructions. We do not sell it, mine it, or use it to build anything of our own.

2What we collect

  • Account information — name, work email, company name, hashed password, and any teammates you invite.
  • Billing information — plan, apps enabled, invoices. Card details go directly to Stripe; we never see or store a card number.
  • Workspace content — everything you or your customers create in the product.
  • Technical logs — IP address, browser, timestamps and error traces, used to keep the service running and to enforce rate limits and abuse protections.
  • Support correspondence — what you send us when you ask for help.

We do not use advertising trackers or third-party analytics cookies on the product. Cookies we set are the ones the service needs: your session, your theme, and the demo-return cookie if you built a demo workspace.

3Why we process it

To provide the service and the apps you switch on; to bill you; to send transactional messages such as receipts, security alerts and trial notices; to keep the platform secure and available; and to comply with the law. Where you have asked for it, to send you product updates — which you can stop at any time without affecting your account.

We do not sell personal data, and we do not share it for cross-context behavioural advertising.

4Who else touches your data

Running the service means using a small number of vendors. This is the complete list, what each is for, and what reaches it. If we add one, this list changes at the same time.

ProviderPurposeWhat it sees
RailwayApplication hosting and the PostgreSQL databaseAll workspace data at rest
CloudflareDNS, TLS termination and CDN in front of the appRequest metadata in transit
Cloudflare R2File and media storageFiles you or your customers upload
Anthropic (Claude)AI features — reply drafts, summaries, triage, receipt scanningOnly the content of the item being processed; can be switched off entirely
StripeCard payments you take from your own customers, and CustoDesk billingPayment details, handled by Stripe — CustoDesk never stores card numbers
Resend / Amazon SESSending transactional and marketing email on your behalfRecipient address and message content
TwilioSMS, where you switch it onRecipient number and message content
ShopifyStore integration, where you connect oneOrders, customers and products you authorise

We may also disclose data if the law compels us to. Where we are permitted to tell you first, we will.

5AI, and how to switch it off

CustoDesk uses Claude (Anthropic) for reply drafts, summaries, triage, help-centre answers and receipt scanning. Only the content of the item being processed is sent — not your database, and not your contact list.

You can turn AI off entirely at Settings → AI Copilot: a master switch, a toggle per feature, and a monthly spend cap you set. With AI off, those features fall back to non-AI behaviour rather than breaking.

6Where your data lives, and how it's protected

The application and database run on Railway infrastructure, with Cloudflare in front. Files are stored in Cloudflare R2. Depending on where those providers host their regions, data may be processed outside your country; where that involves personal data from the EEA or UK, transfers rely on Standard Contractual Clauses or an equivalent lawful mechanism.

Passwords are hashed, two-factor secrets and connected-service credentials are encrypted at rest, API keys are stored only as hashes, and every workspace is isolated at the query level. The detail is on our Trust & security page.

7How long we keep it

  • While your workspace is open — for as long as you keep it, because it is your working record.
  • After you close it — deleted within 30 days, other than what we must keep for tax and accounting.
  • Demo workspaces — automatically expire and are wound down; they hold sample data, not your business.
  • Billing records — retained as long as tax law requires, typically seven years.
  • Logs — kept short-term for security and debugging.

8Your rights

Depending on where you live — under the GDPR and UK GDPR, PIPEDA in Canada, and the CCPA/ CPRA in California — you may have the right to access, correct, delete, restrict or object to processing, to portability, and not to be discriminated against for exercising any of them.

For account data, write to [email protected]. For workspace data you don't need to ask us at all:

  • Export — Settings → Data & privacy → Export everything gives you the whole workspace as CSV in a ZIP, on any plan including a free trial.
  • Delete — the same screen deletes a contact and their history, or the workspace entirely.

If one of your customers asks you to produce or erase their data, you can do it yourself from those screens. Where you need us to act, we will, without charge, and within the statutory time limit.

9Children

CustoDesk is a business tool and is not directed at children. We do not knowingly collect personal data from anyone under 16. If you believe a child's data has reached us, tell us and we will remove it.

10Changes, and how to reach us

If we change this policy materially we will say so in the product and by email before it takes effect, rather than changing the date and hoping you re-read it.

Privacy questions and requests: [email protected]. Security reports: [email protected]. We answer privacy requests within the time limit that applies to you, and we don't charge for them. If you are in the EEA or UK and are not satisfied with our response, you may complain to your local supervisory authority.