Nightshift (“Nightshift”, “we”, “us”) provides a done-for-you website assistant that answers visitor questions, captures enquiries, and notifies business owners. This policy explains what data we handle, why, and your rights over it.
Contact: For any privacy question or request, contact hello@nightshiftchat.com.
1. Whose data this covers
- Our clients — the business owners who buy Nightshift.
- Website visitors — the customers who chat with an assistant on a client's site.
For website-visitor data, our client is the data controller and Nightshift acts as their data processor. For client account data, Nightshift is the controller.
2. What we collect
- From clients: name, business details, email, billing information, and the content of your website (used to train your assistant).
- From website visitors: the messages they send to the assistant, and any contact details they choose to provide (typically name and phone or email) so the business can follow up.
3. Why we process it (lawful basis under GDPR)
- To provide the service (contract).
- To capture and deliver leads to the business (legitimate interests of the business / consent of the visitor, as applicable).
- To protect the service from abuse, e.g. rate limiting (legitimate interests).
- To bill clients and keep records (contract / legal obligation).
4. Who we share it with (sub-processors)
We use a small set of trusted providers to run the service. We do not sell personal data. Our sub-processors are:
- Supabase — secure database hosting for accounts, conversations, and leads.
- Vercel — application hosting.
- Anthropic (Claude API) — powers the assistant's responses.
- Resend — sends lead-notification emails.
- Firecrawl — reads a client's public website during setup to train the assistant.
- Upstash — rate limiting (when enabled).
- Stripe — payment processing for client subscriptions (once billing is live).
5. How long we keep it
- Client data: for as long as you're a customer, and up to 30 days after cancellation for records, then deleted (we may retain minimal billing records where the law requires).
- Visitor conversations and leads: retained while the client is active; on cancellation we export the client's captured leads to them and delete the associated conversations and leads within 30 days.
On cancellation, we export a client's captured leads to them and then remove their data in line with this policy.
6. Your rights (GDPR / UK GDPR and similar)
You can request access to, correction of, export of, or deletion of your personal data, and object to or restrict certain processing. Email hello@nightshiftchat.com and we'll respond within the legally required timeframe. Website visitors should contact the business they chatted with (the data controller); we'll support that business in fulfilling the request.
7. Security
Data is stored on established, access-controlled infrastructure and transmitted over encrypted connections.
8. International operation
Nightshift serves clients worldwide, so data may be processed in countries other than your own. Where required, we rely on appropriate safeguards for international transfers.
9. Changes
We'll post any changes here and update the date above.
Questions: hello@nightshiftchat.com