Information we collect
Account & profile data
When you sign up we collect your name, work email, phone number, country, timezone, password (hashed via bcrypt), and any profile photo you upload.
Workspace & operational data
To deliver the Service we process: workspace name, connected WhatsApp numbers, broadcast templates, flow definitions, contact lists, team-member emails and roles, billing details, and audit-log events.
Customer message data
Benchil stores the messages, attachments, and metadata that flow through your workspace. You are the data controller for this content; we act as a processor under our DPA.
Usage & telemetry
Anonymous usage events (page views, feature clicks, performance metrics) and standard server logs (IP address, browser type, request time) are captured for security and product improvement.
Google Calendar (.../auth/calendar) Access
Our application accesses your Google Calendar to read, create, edit, and delete events. We only access calendars you specifically select.
Google Docs (.../auth/documents) Access
We access your Google Documents to read and write content within files you authorize.
Google Forms (.../auth/forms.body.readonly)
We view the structure, questions, and metadata of your Google Forms to analyze or display them within our platform. We do not modify your forms.
Google Sheets (.../auth/spreadsheets)
We read, modify, and create spreadsheets in your Google Drive to sync, export, or import data as requested by your actions in the application.
How we use your information
We use the data we collect to:
- Provide, maintain, and improve the Service
- Process payments, send invoices, and manage your subscription
- Respond to support requests and security incidents
- Detect, prevent, and address abuse, fraud, and security threats
- Send transactional emails (receipts, security alerts, product updates you opted into)
- Comply with legal obligations including tax, accounting, and law-enforcement requests
We use the Google data we collect to:
- Provide, maintain, and improve the core functionalities of our application
- Data is processed to automate your workflows, sync your schedules, generate reports, or format documents based on your explicit commands
We never sell your data or your customers' data.
We never use your Google user data to serve advertisements, build profiles, or track your behavior across the web.
Sharing of information
We share data only in these limited circumstances:
- Sub-processors — AWS (hosting), Stripe (payments), SendGrid (email), Anthropic + OpenAI (AI features, redacted of PII).
- Meta WhatsApp Cloud API — to dispatch messages on your behalf.
- Legal requirements — subpoenas, court orders, or to protect rights, safety, and integrity.
- Business transfers — in the event of a merger, acquisition, or sale of assets, with prior notice.
Cookies & tracking
We use first-party cookies for session management, security, and analytics. We do not use cross-site advertising cookies.
Data retention & Transfer
We retain personal data for as long as your account is active. After account termination:
- Customer data: exportable for 30 days, then deleted within 90 days
- Google data: We only retain your Google data for as long as your account is active or as needed to provide you with our services
- Audit logs: 7 years for Scale plans (regulatory) or 12 months (other plans)
- Invoices & billing records: 10 years (tax law requirement)
- Backups: encrypted, fully purged within 90 days
Data Transfer:
- Third-Party Sharing:
We do not sell, rent, or trade your Google user data to third parties. - Subprocessors:
Data is only transferred to trusted subprocessors (e.g., our cloud hosting provider) necessary to run our application services. - Legal Compliance:
We only transfer data externally if required by law, regulation, or a legally binding government request.
Data security & Protection
We implement industry-standard safeguards:
- Encryption in transit (TLS 1.3) and at rest (AES-256)
- SOC 2 Type II certified (audited annually)
- ISO 27001 certified
- Mandatory 2FA for all staff with production access
- Quarterly third-party penetration testing
- Bug bounty program — report to hello@benchil.com
Data Protection:
- Encryption:
All data transferred between our application and Google APIs is encrypted in transit using Transport Layer Security (TLS/HTTPS). Data stored on our servers is encrypted at rest using industry-standard encryption algorithms (e.g., AES-256). - Access Controls:
We implement strict internal access controls to ensure that only authorized system processes can access your tokens and data. - Token Security:
Your OAuth access and refresh tokens are stored securely using encrypted databases and environment variables.
Your rights
Depending on your jurisdiction (GDPR, CCPA, India DPDP Act 2023) you may have rights to:
- Access — request a copy of personal data we hold about you
- Rectification — correct inaccurate information
- Erasure — request deletion ("right to be forgotten")
- Portability — export data in a machine-readable format
- Objection — opt out of certain processing
- Withdraw consent — for any consent-based processing
Email hello@benchil.com to exercise any right. We respond inside 30 days.
International transfers
Customer data is hosted in the region you select (EU, US, or India on Scale plans). Where data crosses borders we rely on Standard Contractual Clauses (SCCs) approved by the European Commission and supplementary measures for adequate protection.
Children's privacy
Benchil is a business tool not intended for users under 18. We do not knowingly collect data from children. If you believe we have, email hello@benchil.com.
Changes to this policy
Material changes to this Privacy Policy will be notified by email at least 30 days before they take effect. The "Updated" date at the top reflects the latest revision.
Contact us
Data Protection Officer: hello@benchil.com