← Back to Supportify

Privacy Policy

Effective September 7, 2026

This Privacy Policy explains what information Supportify collects when you use QA Sentinel and CRM (together, the "Service"), and how we use, share, and protect it.

1. Information we collect

  • Account information: name, work email, password (stored as a salted hash, never in plain text), and organization details you provide at signup.
  • Customer Data: the client records, tickets, messages, and other content you or your team add to the Service, including support ticket conversations imported from Zendesk for QA Sentinel to review.
  • Billing information: handled directly by Stripe — we store a reference to your Stripe customer and subscription, never your full card number.
  • Usage data: log-in activity, feature usage, and audit-log entries recorded for security and to operate the Service.

2. How we use it

We use this information to provide the Service (including generating AI ticket reviews), secure your account (including two-factor authentication and audit logging), process payments, send transactional email (verification, password reset, receipts), and respond to support requests. We do not sell your data.

3. Third-party processors

We share data with the following processors, only as needed to provide the Service:

  • Anthropic — ticket conversation content is sent to Anthropic's Claude API to generate QA Sentinel's AI reviews and scores.
  • Stripe — payment processing and subscription management.
  • Resend — delivery of transactional email.
  • Zendesk (when you connect it) — we read ticket conversations you authorize us to access, using credentials you provide, encrypted at rest.
  • WorkOS (only if your organization enables Single Sign-On) — handles authentication with your identity provider.

4. Data security

Passwords are hashed, never stored in plain text. Sensitive credentials (Zendesk tokens, webhook signing secrets, two-factor authentication secrets) are encrypted at rest with AES-256-GCM. Access to another organization's data is not possible through the Service — every record is scoped to your organization.

5. Data retention and deletion

We retain Customer Data for as long as your organization has an active account. You can export your organization's data at any time from Settings, and request deletion of your organization and its data, which we will act on within a reasonable time, except where we're required to retain records by law (for example, billing records).

6. Your choices

You can update your account information, enable two-factor authentication, and export or delete your data from the Service's Settings pages at any time.

7. Changes to this policy

We may update this policy from time to time. If we make material changes, we'll notify you by email or in-app before they take effect.

8. Contact

Questions about this policy can be sent to privacy@supportify.co.in.