What we collect, what we do with it, who else touches it, and how to take it back or have it erased.
Last updated 2 August 2026
CustoDesk (“CustoDesk”, “we”) operates custodesk.com and the workspace software behind it. This policy covers the marketing site, the product, and the customer-facing surfaces we host for you — portals, help centres, review widgets and chat.
There are two very different kinds of data here, and the difference decides your rights and ours:
We do not use advertising trackers or third-party analytics cookies on the product. Cookies we set are the ones the service needs: your session, your theme, and the demo-return cookie if you built a demo workspace.
To provide the service and the apps you switch on; to bill you; to send transactional messages such as receipts, security alerts and trial notices; to keep the platform secure and available; and to comply with the law. Where you have asked for it, to send you product updates — which you can stop at any time without affecting your account.
We do not sell personal data, and we do not share it for cross-context behavioural advertising.
Running the service means using a small number of vendors. This is the complete list, what each is for, and what reaches it. If we add one, this list changes at the same time.
| Provider | Purpose | What it sees |
|---|---|---|
| Railway | Application hosting and the PostgreSQL database | All workspace data at rest |
| Cloudflare | DNS, TLS termination and CDN in front of the app | Request metadata in transit |
| Cloudflare R2 | File and media storage | Files you or your customers upload |
| Anthropic (Claude) | AI features — reply drafts, summaries, triage, receipt scanning | Only the content of the item being processed; can be switched off entirely |
| Stripe | Card payments you take from your own customers, and CustoDesk billing | Payment details, handled by Stripe — CustoDesk never stores card numbers |
| Resend / Amazon SES | Sending transactional and marketing email on your behalf | Recipient address and message content |
| Twilio | SMS, where you switch it on | Recipient number and message content |
| Shopify | Store integration, where you connect one | Orders, customers and products you authorise |
We may also disclose data if the law compels us to. Where we are permitted to tell you first, we will.
CustoDesk uses Claude (Anthropic) for reply drafts, summaries, triage, help-centre answers and receipt scanning. Only the content of the item being processed is sent — not your database, and not your contact list.
You can turn AI off entirely at Settings → AI Copilot: a master switch, a toggle per feature, and a monthly spend cap you set. With AI off, those features fall back to non-AI behaviour rather than breaking.
The application and database run on Railway infrastructure, with Cloudflare in front. Files are stored in Cloudflare R2. Depending on where those providers host their regions, data may be processed outside your country; where that involves personal data from the EEA or UK, transfers rely on Standard Contractual Clauses or an equivalent lawful mechanism.
Passwords are hashed, two-factor secrets and connected-service credentials are encrypted at rest, API keys are stored only as hashes, and every workspace is isolated at the query level. The detail is on our Trust & security page.
Depending on where you live — under the GDPR and UK GDPR, PIPEDA in Canada, and the CCPA/ CPRA in California — you may have the right to access, correct, delete, restrict or object to processing, to portability, and not to be discriminated against for exercising any of them.
For account data, write to [email protected]. For workspace data you don't need to ask us at all:
If one of your customers asks you to produce or erase their data, you can do it yourself from those screens. Where you need us to act, we will, without charge, and within the statutory time limit.
CustoDesk is a business tool and is not directed at children. We do not knowingly collect personal data from anyone under 16. If you believe a child's data has reached us, tell us and we will remove it.
If we change this policy materially we will say so in the product and by email before it takes effect, rather than changing the date and hoping you re-read it.
Privacy questions and requests: [email protected]. Security reports: [email protected]. We answer privacy requests within the time limit that applies to you, and we don't charge for them. If you are in the EEA or UK and are not satisfied with our response, you may complain to your local supervisory authority.