Privacy Policy
Effective June 26, 2026
1. Introduction
Ruby Relay ("we", "us", "our") operates a live chat widget service that routes website visitor conversations to Slack. This Privacy Policy explains how we collect, use, store, and protect your information when you use our Service.
This policy applies to Ruby Relay account holders and to visitors who interact with chat widgets powered by Ruby Relay. It should be read alongside our Terms of Service and Cookie Policy.
2. Information We Collect
Account Information
When you create an account, we collect your name, email address, organization name, and billing information. This information is necessary to provide the Service and manage your subscription.
Chat & Conversation Data
When visitors use your chat widget, we process the messages sent between visitors and your team. This includes message content, timestamps, and conversation metadata. This data is routed through our servers to deliver messages to your connected platform.
For accounts on Growth or Scale plans with the Save Conversations feature enabled, we additionally archive conversation snapshots (messages, senders, timestamps, client name, email and unique ID, workspace and channel names, and inline images) to your private storage. Archives are retained for 90 days from the moment a conversation ends, then automatically deleted. The feature is off by default and can be toggled at any time from your billing settings.
When Ongoing Conversations mode is enabled, a conversation can remain open and actively processed for longer, up to 14 days of inactivity or 90 days in total, before it is archived. The 90-day archive-retention window described above then applies from the point of archival.
Visitor Data
We collect limited information about visitors who interact with the chat widget, including their browser type, operating system, referring URL, and the page they initiated the chat from. Visitor IP addresses may be temporarily processed in server logs for security and abuse prevention but are not stored long-term or used for tracking purposes.
Usage Data
We collect anonymized usage data to improve the Service, including widget load times, aggregate conversation volumes, and widget lifecycle events such as loads, load failures, opens, closes, idle timeouts, and errors. We also record message-level metadata, such as counts of attachments and screenshots sent, and the site the event originated from. Usage events never include message content.
3. How We Use Your Information
We use the information we collect to:
- Provide, maintain, and improve the Service
- Route chat messages between visitors and your connected platforms
- Process payments and manage subscriptions
- Send transactional emails (account confirmations, billing receipts, service updates)
- Provide customer support
- Monitor and prevent abuse of the Service
- Generate anonymized, aggregated analytics
We do not sell your personal information. We do not use conversation data for advertising purposes.
4. Legal Basis for Processing (EEA/UK Users)
If you are located in the European Economic Area or the United Kingdom, we process personal data under the following legal bases:
- Contractual necessity: Account information, billing information, and chat/conversation data are processed to fulfill our contract with you (providing the Service, managing your subscription, and routing messages).
- Legitimate interest: Visitor data (including browser information and referring URLs) and usage data are processed based on our legitimate interest in improving the Service, maintaining security, and preventing abuse. You may object to processing based on legitimate interest by contacting us.
- Consent: Where required by applicable law, we obtain consent before setting non-essential browser storage (such as the visitor recognition identifier described in our Cookie Policy). You may withdraw consent at any time.
- Legal obligation: We may retain certain billing and account data as required by tax, accounting, or other applicable laws.
5. Data Routing & Sub-Processors
The core function of Ruby Relay is to route messages to Slack. When you connect your Slack workspace, conversation data is transmitted to Slack according to their privacy policy and terms of service.
We use the following third-party sub-processors:
- Slack — Message routing and delivery to your team's workspace.
- Stripe — Payment processing. Your payment details are transmitted directly to Stripe and are not stored on our servers.
- Amazon Web Services (AWS) — Cloud infrastructure, data hosting, and authentication services (US-East region).
We will update this list if we add new sub-processors that handle personal data.
6. Data Retention
Routed conversation data is processed in transit and not retained after delivery to your connected platform. For accounts with Save Conversations enabled (Growth and Scale plans), archived conversation snapshots are retained for 90 days from the moment a conversation ends, then automatically deleted. Account holders can also manually delete individual archived conversations at any time.
If your free trial expires without subscribing, your data will be retained for 30 days before permanent deletion. If you cancel your subscription, your data will be retained through the end of your billing period and then deleted within 30 days.
Account information (name, email) may be retained for up to 90 days after account deletion for fraud prevention and legal compliance purposes.
7. Your Rights
Depending on your jurisdiction, you may have the following rights regarding your personal data:
- Access: Request a copy of the personal data we hold about you
- Correction: Request that we correct inaccurate or incomplete data
- Export: Download your data in a portable format from your account settings
- Deletion: Request that we delete your personal data, subject to legal retention requirements
- Objection: Object to the processing of your data for specific purposes
- Restriction: Request that we restrict processing of your data while a complaint is being resolved
To exercise any of these rights, contact us at support@rubyrelay.com. We will respond to requests within 30 days.
If you are located in the EEA or UK and believe we have not adequately addressed your data protection concerns, you have the right to lodge a complaint with your local data protection supervisory authority.
8. California Privacy Rights (CCPA/CPRA)
If you are a California resident, you have additional rights under the California Consumer Privacy Act and the California Privacy Rights Act:
- Right to know: You may request that we disclose what personal information we have collected, the sources, the business purposes, and the categories of third parties with whom we share it.
- Right to correct: You may request that we correct inaccurate personal information we hold about you.
- Right to delete: You may request deletion of your personal information, subject to certain legal exceptions.
- Right to opt out of sale or sharing: We do not sell or share your personal information as defined by the CCPA/CPRA.
- Right to non-discrimination: We will not discriminate against you for exercising any of your privacy rights.
To submit a request, contact us at support@rubyrelay.com. We will verify your identity before processing any request and respond within 45 days.
9. Data Processing Roles
When you use Ruby Relay to collect chat messages from your website visitors, you act as the data controller for your visitors' personal data, and Ruby Relay acts as a data processor on your behalf. As the controller, you determine the purposes for which visitor data is collected and are responsible for ensuring that your use of the chat widget complies with applicable privacy laws, including providing appropriate notice to your visitors.
For Ruby Relay account holders, we act as the data controller for your account information.
If you require a Data Processing Agreement (DPA) for compliance purposes, contact us at support@rubyrelay.com.
10. Data Security
We implement industry-standard security measures to protect your data, including:
- Encryption of data in transit (TLS) and at rest
- Hashed and salted passwords
- Role-based access controls for internal systems
- Regular security audits and vulnerability assessments
While we take reasonable precautions to protect your data, no method of transmission or storage is 100% secure. We cannot guarantee absolute security.
11. Data Breach Notification
In the event of a data breach that affects personal data, we will notify affected account holders by email without unreasonable delay. If the breach is likely to result in a high risk to the rights and freedoms of individuals, we will also notify affected data subjects where feasible. Where required by law (such as GDPR), we will notify the relevant supervisory authority within 72 hours of becoming aware of the breach. Notifications will include the nature of the breach, likely consequences, and measures taken or proposed to address it.
12. Cookies & Browser Storage
The Ruby Relay widget uses minimal browser storage (which may include cookies, session storage, or local storage) to maintain conversation state for visitors. This data does not track users across sites and is not used for advertising. Our marketing site does not use analytics or advertising cookies. For full details, see our Cookie Policy.
13. Children's Privacy
The Service is not directed at individuals under the age of 16. We do not knowingly collect personal information from children. If you believe a child has provided us with personal data, please contact us at support@rubyrelay.com and we will promptly delete it.
14. International Data Transfers
Ruby Relay processes data in the United States using Amazon Web Services (US-East region). If you are located outside the United States, your data will be transferred to and processed in the United States.
For transfers of personal data from the European Economic Area or the United Kingdom, we implement appropriate transfer mechanisms as required by applicable data protection law, such as Standard Contractual Clauses (SCCs) approved by the European Commission, to ensure your data is adequately protected.
15. Changes to This Policy
We may update this Privacy Policy from time to time. When we make material changes, we will notify you by email at least 30 days before the changes take effect and update the effective date at the top of this page. Where required by applicable law, we will obtain your consent before applying material changes to how we process your personal data.
16. Contact
If you have questions about this Privacy Policy or our data practices, contact us at support@rubyrelay.com.