upfall
Skip to content
Documents

Privacy and security

What the widget stores in the visitor's browser, the conversation records a business can view, rules for managing widget keys, and the consent items at sign-up.

Conversation data has two layers

The most common question when adopting the widget is where visitor conversations are stored. The answer has two layers: what stays in the visitor's browser, and what the business can view.

The two layers differ in scope. Data stored in the visitor's browser exists only in that browser, and the screens a business can view depend on the channel.


What stays in the visitor's browser

ItemWhere it is storedWhen it is removed
Conversation contentPer-tab storageWhen the tab is closed
Visit count, last visit timeBrowserWhen browser data is cleared
Widget identification dataBrowserWhen browser data is cleared

Conversation content exists only in that visitor's tab. The same conversation is not visible on another device or in another browser.

The visit count and last visit time are used for the return greeting and for the 30-minute re-entry check.


Conversation records a business can view

In the Shopify app, you can review conversations between visitors and the agent in the "Conversations" tab of the app admin.


Managing widget keys

Widget keys are issued per domain and work only on the domain they were issued for. The key value is shown only to the admin account. For Editors and Viewers, it is hidden with "The key is visible to admins only".

If a key is exposed, reissue it. The moment you reissue, the previous key becomes invalid, and the new key is shown on screen only once. The installation code on your site must also be replaced with the new key for the widget to appear again.

When installing with React, the key is included in the bundle sent to the browser. Manage it with an environment variable instead of writing it directly in the source code.


Scope of and responsibility for persona instructions

The persona's role and prohibition rules are managed by voidX and are not disclosed. Business instructions sit on top of them and cannot replace the base role and prohibition rules.

What you write in business instructions is reflected in answers, so the business that wrote the instructions is responsible for their content.


Regulated industries

Sites in regulated industries such as finance and healthcare are outside the service scope. This notice and a "View Terms of Service" link always appear on the casting screen and the Cafe24 onboarding screen.

It is the user's responsibility to check whether their site falls under one of these industries. Per the Terms of Service, the company is not responsible for issues arising from connecting such a site without notice.


ItemRequired
I agree to the Terms of ServiceRequired
I agree to the collection and use of personal informationRequired
I agree to receive marketing communicationsOptional

Click "View" next to each item to read the full text. You can change your marketing preference after sign-up under "Receive service notifications" in the account screen.

Send requests from visitors or businesses to view or delete personal information through the contact page.


Next steps

Next steps

Widget key and domainsHow a widget key is tied to a domain, who can see it, what happens when you reissue it, and where the widget code is loaded from.