Privacy Policy
Effective date: April 14, 2026 · Last updated: September 17, 2026
Summary: Quant Desk ("we", "our", or "us") operates an omnichannel customer support SaaS platform. This Privacy Policy explains what information we collect through our website (quant-desk.app), our web application, and our mobile applications published on Google Play and the Apple App Store (collectively, the "Service"), how we use it, and the choices you have. Quant Desk integrates with multiple messaging channels including WhatsApp Business API, Facebook Messenger, Instagram Direct Messages, Telegram, SMS, and email to provide seamless customer communication. By using the Service you agree to the practices described here and acknowledge our use of third-party integrations as described in Section 5.
1. Who We Are
Quant Desk is a Software-as-a-Service (SaaS) customer engagement platform that lets businesses ("Workspace Owners" or "Customers") manage support tickets, live chat, WhatsApp Business API, Facebook Messenger, Instagram Direct Messages, Telegram, SMS, and email conversations in one unified inbox. If you are a business using Quant Desk, you are our Customer. The people whose data passes through your workspace (your end-customers and contacts) are End Users.
For the purpose of applicable data-protection law, Quant Desk is the data controller for account and billing information we collect about our Customers. For End User data processed inside a workspace, the Customer acts as the data controller and Quant Desk acts as the data processor.
2. Information We Collect
2.1 Information You Provide to Us
- Account registration: name, work email address, password (hashed), company name, workspace subdomain.
- Billing & payment: billing name, address, and payment card details (processed and stored by our payment processor; we only store the last four digits and expiry date).
- Profile information: profile photo, job title, phone number (optional).
- Support & communications: any information you include in emails, chat messages, or support requests sent to us.
- Integration credentials: API keys, OAuth tokens, and SMTP/IMAP credentials you provide in order to connect third-party services (e.g., WhatsApp Business, Twilio, Gmail).
2.2 Information We Collect Automatically
- Log data: IP address, browser type and version, operating system, referring URL, pages visited, and timestamps.
- Device data: device identifiers (for the mobile app), device model, OS version, language and timezone settings.
- Usage data: feature interactions, ticket counts, message counts, and performance telemetry used to detect errors and improve the platform.
- Session data: session cookies, authentication tokens stored in secure HTTP-only cookies or device secure storage.
- Push notification tokens: Firebase Cloud Messaging (FCM) tokens obtained when you grant notification permission on a mobile device or browser, used solely to deliver in-app and push notifications.
2.3 End-User Data Processed on Your Behalf
When your business uses Quant Desk, messages, contact records, conversation histories, and any attachments flowing through your workspace are processed by us on your behalf. This may include your customers' names, email addresses, phone numbers, WhatsApp numbers, and chat transcripts. You are responsible for having an adequate legal basis to process this data under applicable law.
3. How We Use Your Information
We use the information collected for the following purposes:
- Providing the Service: creating and managing your workspace, routing messages across channels, delivering notifications, and generating reports.
- Authentication & security: verifying your identity, detecting fraud, preventing unauthorised access, and enforcing our Terms of Service.
- Billing & subscriptions: processing payments, sending invoices, managing plan upgrades, downgrades, and cancellations.
- Customer support: responding to your enquiries, diagnosing technical issues, and providing account assistance.
- Product improvement: analysing aggregated, anonymised usage patterns to improve performance, reliability, and new features. We do not sell individual usage data.
- Communications: sending transactional emails (e.g., password reset, invoice receipts), product update announcements, and—where you have opted in—marketing newsletters. You can unsubscribe at any time.
- Legal compliance: complying with applicable laws, responding to lawful government requests, and enforcing our policies.
4. How We Share Your Information
We do not sell your personal data. We share data only in the following limited circumstances:
- Service providers (sub-processors): companies that process data on our behalf, such as cloud hosting (AWS / other providers), email delivery, payment processing (Stripe or equivalent), error monitoring (e.g., Sentry), and analytics. These sub-processors are bound by data-processing agreements and may only use data as directed by us.
- Third-party integrations you connect: when you activate an integration (e.g., WhatsApp Business API, Twilio, Termii, Google Workspace, Microsoft 365, Slack), data relevant to that integration is transmitted to the respective third party. See Section 5 for details.
- Workspace members: agents, supervisors, and admins within your workspace can view conversations and contact data according to the permissions you configure.
- Business transfers: in the event of a merger, acquisition, or sale of assets, your data may be transferred as part of that transaction. We will provide notice before such transfer and before personal data becomes subject to a different privacy policy.
- Legal requirements: we may disclose information when required by law, court order, or to enforce our legal rights.
5. Third-Party Integrations
Quant Desk connects with third-party services at your direction. Each third-party service has its own privacy policy that governs how they process data. Key integrations include:
| Integration | Purpose | Data Shared |
|---|---|---|
| WhatsApp Business API (Meta) | Sending & receiving WhatsApp messages for customer support | Phone numbers, message content, media, contact information, message metadata |
| Facebook Messenger (Meta) | Sending & receiving messages via Facebook Messenger for customer engagement | Facebook user IDs, message content, media, conversation history, user profile information (name, avatar) |
| Instagram Direct Messages (Meta) | Sending & receiving messages via Instagram for customer support and tenant/customer engagement | Instagram user IDs, message content, media, conversation history, user profile information (username, avatar) |
| Telegram Bot API | Sending & receiving messages via Telegram bot for customer communication and support | Telegram user IDs, chat IDs, message content, media, user profile information (username, first name) |
| Twilio | SMS and voice communication | Phone numbers, message content |
| Termii | SMS & messaging (Africa region) | Phone numbers, message content |
| Google Workspace / Gmail | Email sync & Google SSO | Email address, OAuth token, email content |
| Microsoft 365 / Outlook | Email sync & Microsoft SSO | Email address, OAuth token, email content |
| Slack | Ticket & conversation notifications | Notification text, ticket IDs |
| Firebase (Google) | Push notifications & analytics | Device FCM token, notification payload |
| Stripe (or equivalent) | Payment processing | Billing name, card details, address |
Third-Party Privacy Policies: Each platform has its own privacy policy governing how they process data. We recommend reviewing the privacy policies of Meta (WhatsApp, Messenger, Instagram), Telegram, and other integrated services. Quant Desk acts as a data controller for our platform and a data processor for End User data flowing through integrations, as directed by you.
Compliance Note: When connecting messaging platform integrations, you must comply with each platform's terms of service and privacy policies. Specifically, you must have the appropriate agreements and consents in place with your end-users (your customers and prospects) before their data is transmitted to these platforms through Quant Desk.
You control which integrations are active. Disconnecting an integration stops further data sharing with that third party from your workspace. Previously synced data may remain on the third-party platform according to their own retention policies.
6. Cookies & Tracking Technologies
We use cookies and similar technologies on our website and web application:
- Essential cookies: session management, CSRF protection, and authentication. These are strictly necessary and cannot be disabled.
- Preference cookies: remember your UI preferences such as dark/light mode and language.
- Analytics cookies: aggregate, anonymised usage statistics to understand how features are used. No cross-site tracking.
You can control cookies through your browser settings. Disabling essential cookies will prevent you from logging in. The mobile application uses device-local storage instead of browser cookies; no third-party advertising SDKs are embedded in the app.
7. Data Retention
- Account data: retained while your subscription is active. After cancellation or account deletion, account data is deleted within 90 days, unless we are required by law to retain it longer.
- Workspace conversation data: retained according to the plan you are subscribed to. You may export or delete conversation data at any time from your workspace settings.
- Billing records: retained for 7 years to comply with tax and accounting regulations.
- System logs: retained for up to 90 days for security and diagnostic purposes.
- Backups: encrypted backups may retain data for up to 30 additional days after deletion.
8. Data Security
We implement industry-standard technical and organisational measures to protect your data:
- All data is encrypted in transit using TLS 1.2 or higher.
- Passwords are stored using secure one-way hashing algorithms (bcrypt).
- Each workspace is logically isolated; agents can only access data within their own workspace.
- Role-based access controls (RBAC) allow workspace owners to restrict access to sensitive information.
- Regular security audits and vulnerability assessments are performed.
- Integration credentials (API keys, OAuth tokens) are encrypted at rest.
No method of electronic transmission or storage is 100% secure. If you discover a security vulnerability, please report it to security@quant-desk.app.
9. International Data Transfers
Quant Desk may process and store data in countries outside your country of residence, including countries in which our cloud infrastructure partners operate. Where personal data is transferred outside the European Economic Area (EEA) or the United Kingdom, we rely on appropriate safeguards such as Standard Contractual Clauses (SCCs) approved by the European Commission. By using the Service you acknowledge this international transfer.
Third-Party Platform Transfers: When you enable integrations with Meta (WhatsApp, Messenger, Instagram), Telegram, or other messaging platforms, End User data is transmitted to servers operated by these third parties, which may be located in multiple countries worldwide. Each platform maintains its own data transfer agreements and privacy frameworks. You are responsible for ensuring legal compliance in your jurisdiction when transmitting data to these platforms.
10. Children's Privacy
The Service is intended exclusively for business use and is directed to individuals who are at least 16 years of age (or 13 in jurisdictions where 13 is the minimum age for digital consent). We do not knowingly collect personal information from children under 13. If you believe a child under 13 has provided us with personal information, please contact us immediately at privacy@quant-desk.app and we will delete it.
11. Your Rights & Choices
Depending on your location, you may have the following rights regarding your personal data:
- Access: request a copy of the personal data we hold about you.
- Correction: request correction of inaccurate or incomplete data.
- Deletion: request deletion of your personal data ("right to be forgotten"). You may also delete your account directly from workspace settings.
- Portability: receive a machine-readable copy of your data.
- Objection / restriction: object to or restrict certain processing activities.
- Withdraw consent: where processing is based on consent, withdraw it at any time without affecting prior processing.
- Marketing opt-out: unsubscribe from marketing emails at any time via the unsubscribe link in each email or by contacting us.
- Push notifications: disable push notifications at any time in your device or browser settings.
- Integration control: enable or disable third-party integrations at any time from your workspace settings. Disabling an integration prevents future data transmission to that platform.
To exercise any of these rights, email privacy@quant-desk.app. We will respond within 30 days. We may need to verify your identity before fulfilling the request.
GDPR & EEA Residents: If you are located in the European Union, European Economic Area, or United Kingdom, you have rights under the General Data Protection Regulation (GDPR) and UK GDPR. We process data based on legitimate business interests, contractual necessity, or your consent. You have the right to lodge a complaint with your local data protection authority if you believe your rights have been violated.
California residents (CCPA): you have the right to know, delete, and opt out of the sale of personal information. We do not sell personal information. To submit a verifiable consumer request, contact us at privacy@quant-desk.app.
Other Jurisdictions: Residents of Canada (PIPEDA), Brazil (LGPD), Australia (Privacy Act), UAE (DIFC), Singapore, and other jurisdictions with data protection laws have similar rights. Please contact us for jurisdiction-specific information.
12. Push Notifications & App Permissions
The Quant Desk mobile app may request the following device permissions. Each permission is optional and you can revoke it in your device settings at any time:
- Push notifications: used to deliver real-time alerts for new messages, assigned tickets, and SLA warnings. Requires notification permission.
- Camera / photo library: used to let agents attach photos or documents to conversations. Images are uploaded to your workspace only with your explicit action; they are not accessed in the background.
- Microphone: used only if voice messaging is enabled and you initiate a voice message. Not accessed passively.
- Network access: required to communicate with Quant Desk servers.
- Biometric authentication: used as an optional unlock method for the app; biometric data is processed locally on your device by the OS and is never transmitted to our servers.
13. Changes to This Policy
We may update this Privacy Policy from time to time. When we make material changes, we will notify you by posting a notice on our website and, where required by law, by email. The "Last updated" date at the top of this page reflects the most recent revision. Continued use of the Service after the effective date of a revised policy constitutes acceptance of the changes.
14. Contact Us
If you have any questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact: