1. Introduction
This Privacy Policy explains how Agentra ("Agentra", "we", "us", or "our") collects, uses, discloses, and protects information when you use the Agentra HRM platform, including our web application at https://dev-hrm.resent.app, workspace subdomains such as yourcompany.agentraa.com, public help centers, ticket tracking pages, APIs, and related services (collectively, the "Service").
Agentra HRM is a multi-channel customer support and commerce operations platform. Businesses use it to manage conversations, tickets, orders, teams, and customer interactions across email, messaging apps, live chat, and connected storefronts.
By creating an account, accepting an invitation, connecting a channel or store, submitting a support request, or otherwise using the Service, you acknowledge that you have read this Privacy Policy. If you do not agree, please do not use the Service.
2. Our role and your role
Depending on how you interact with Agentra HRM, we may process personal information as a data controller (for example, when you sign up for a workspace, pay for a subscription, or contact us for support) or as a data processor on behalf of our business customers (for example, when end-customers message a company through Facebook Messenger, Instagram, WhatsApp, email, or a help center hosted on Agentra HRM).
Business customers (workspaces)
If you are an employee, contractor, or administrator of a company that uses Agentra HRM, your organization is generally responsible for the personal information of its customers and visitors that flows through the Service. Your organization's privacy practices may also apply. Contact your workspace administrator or the business you are interacting with for questions about how they handle your data.
End customers and visitors
If you contact a business through their Agentra HRM help center, ticket portal, live chat, email channel, or connected messaging account, we process your information to deliver messages and support requests to that business. The business decides how to use and retain that information.
3. Information we collect
3.1 Account and profile information
When you register, accept an invite, or manage your profile, we may collect:
- First and last name
- Email address
- Phone number (optional)
- Job title and short bio (optional)
- Profile avatar
- Workspace role (owner, admin, agent, or customer)
- Department and team assignments
- Password or authentication credentials (passwords are stored using one-way hashing; we do not store plaintext passwords)
3.2 Workspace and company information
Workspace administrators may provide or generate:
- Company or brand name and subdomain
- Logo, brand colors, and theme preferences
- Industry, company size, website, phone, timezone, locale, and currency
- Business address (street, city, state, postal code, country)
- Business hours and custom schedules
- Notification and support email addresses
- Onboarding questionnaire answers (team goals, channels, ticket volume, e-commerce platform, AI interest)
- Usage metrics such as user counts, ticket counts, and storage used
3.3 Support tickets, messages, and attachments
The core of the Service is conversation and ticket management. We process content you or your customers submit, including:
- Ticket titles, descriptions, statuses, priorities, tags, and internal notes
- Message bodies (plain text and HTML email content)
- File attachments (for example images, documents, and other files uploaded to tickets or messages, subject to upload size limits configured in the Service)
- Participant lists (customers, agents, and copied recipients on a ticket)
- Assignment to departments and teams
- Snooze, folder, and read/unread state
- Channel-specific metadata required to route replies (for example Facebook Page-scoped IDs, Instagram-scoped IDs, WhatsApp IDs, email Message-IDs and threading headers)
3.4 Connected channels and integrations
When a workspace connects third-party channels or stores, we receive and store information necessary to operate those integrations. This may include:
- Email: connected mailbox address, display name, IMAP/SMTP settings, and encrypted mailbox credentials or OAuth tokens; inbound and outbound email content and headers
- Facebook Messenger: connected Page ID and name, Page profile image, and encrypted access tokens; Messenger user identifiers and message content
- Instagram Direct: Instagram business account ID and username, linked Facebook Page details, encrypted access tokens, and DM content
- WhatsApp Business (Meta Cloud API): WhatsApp Business Account ID, phone number ID, display phone number, verified business name, encrypted access tokens, and message content
- Live chat and AI Agent conversations: chat session content routed through the Service
- TikTok and other channels: where enabled, account identifiers, tokens, and message content required for the integration
- Shopify: shop domain, shop name, encrypted access tokens, order and customer data synced or displayed in the inbox (including order totals, line items, shipping, taxes, fulfillment status, and payment status)
- WooCommerce and custom storefronts: store URL, encrypted API credentials, webhook secrets, and commerce data configured for sync
Sensitive credentials (such as IMAP passwords, API keys, and OAuth tokens) are encrypted at rest where supported by the Service. Access tokens are not exposed in routine API responses.
3.5 Help center and public ticket tracking
Public-facing features may collect:
- Name, email, subject, message, and priority from help center contact or ticket forms
- Ticket reference codes for tracking
- Workspace subdomain or custom help center domain used to reach the correct organization
- One-time passcodes (OTP) sent by email to verify access to ticket tracking sessions
3.6 Billing and payment information
Paid workspaces may provide billing details. Payment card data is processed by our payment provider (Paddle, as Merchant of Record). We may store subscription identifiers, plan status, billing cycle, trial dates, invoice history, and limited payment method metadata (for example card brand and last four digits), not full card numbers.
3.7 Technical, security, and activity data
We automatically collect certain technical information, including:
- IP address
- Browser type and user agent string
- Device and operating system information inferred from user agent
- Authentication events, session tokens, invitation tokens, and two-factor verification attempts
- Activity and audit log entries (event type, actor name and email, affected object, timestamps, and related metadata)
- API request logs, error reports, and rate-limiting data
- Dates of account creation, last activity, and workspace registration
3.8 Cookies and similar technologies
We use cookies and similar technologies to keep you signed in, remember preferences, protect against abuse, and operate the Service. These may include session cookies, refresh-token mechanisms, and security-related tokens. You can control cookies through your browser settings, but disabling them may limit functionality such as staying logged in.
4. How we use information
We use the information described above to:
- Provide, operate, maintain, and improve the Service
- Authenticate users and enforce workspace access controls (owner, admin, agent, customer roles)
- Route inbound messages from connected channels into unified tickets and enable agent replies
- Sync and display e-commerce order, customer, and fulfillment data alongside support conversations
- Host public help centers and ticket tracking on default or custom domains
- Send transactional emails (verification, invitations, password reset, two-factor codes, ticket updates, and relayed replies where configured)
- Process subscriptions, trials, invoices, and billing support requests
- Monitor usage against plan limits and display workspace analytics
- Record audit and activity logs for security, compliance, and workspace administration
- Detect, prevent, and respond to fraud, abuse, security incidents, and violations of our Terms
- Provide customer support to workspace administrators
- Develop AI-assisted routing, live chat, and automation features where enabled
- Comply with legal obligations and enforce our agreements
5. Legal bases for processing (EEA/UK users)
Where applicable data protection laws require a legal basis, we rely on one or more of the following:
- Performance of a contract: to provide the Service you or your organization requested
- Legitimate interests: to secure the Service, prevent abuse, improve features, and support business operations, balanced against your rights
- Consent: where required for optional features or marketing communications
- Legal obligation: where we must retain or disclose information under applicable law
7. International data transfers
Agentra may process and store information in countries other than where you live, including countries that may have different data protection laws. Where required, we implement appropriate safeguards for cross-border transfers, such as standard contractual clauses or equivalent mechanisms.
8. Data retention
We retain information only as long as needed to provide the Service, fulfill the purposes in this policy, meet legal and accounting requirements, resolve disputes, and enforce agreements. Unless a longer period is required by law, we apply the following periods:
- Account and workspace data: retained while the workspace is active, then deleted or anonymized within 90 days after workspace closure or a verified deletion request
- Tickets, live chat sessions, messages, and attachments: retained while the workspace is active; deleted with the workspace within 90 days of closure, or sooner if an authorized workspace user deletes them
- Synced store order snapshots used for support: retained while the store remains connected and for up to 90 days after disconnect or workspace closure
- Integration tokens and channel credentials: retained only while the integration remains connected, then removed promptly on disconnect
- Billing and tax records: retained for up to 7 years (or longer if required by applicable tax or accounting law)
- Security, authentication, and activity logs: retained for up to 12 months for security monitoring, abuse prevention, and investigations
Backup copies may persist for up to 30 days after deletion before being overwritten. Workspace owners may request earlier deletion of a workspace or specific data subject to technical and legal limitations by contacting agentraa0@gmail.com.
9. Security
We implement administrative, technical, and organizational measures designed to protect information, including:
- Encrypted transport (HTTPS/TLS) for data in transit
- Encryption at rest for databases and sensitive integration credentials where supported
- Password hashing for user passwords
- Role-based access controls within workspaces
- JWT-based authentication with refresh token rotation
- Rate limiting and monitoring for abusive traffic
- Selective exclusion of secrets from routine database queries
No method of transmission or storage is completely secure. You are responsible for maintaining the confidentiality of your login credentials and for configuring appropriate access within your workspace. Our security incident response procedures are described in our Security Incident Response Policy.
10. Your privacy rights
Depending on your location, you may have rights to access, correct, delete, restrict, object to, or port certain personal information, and to withdraw consent where processing is consent-based. You may also have the right to lodge a complaint with a supervisory authority.
To exercise rights relating to your Agentra account or billing relationship, contact us at agentraa0@gmail.com. For data processed on behalf of a business customer, please contact that business directly; we will assist them as required by applicable law.
We may need to verify your identity before responding. We will respond within the timeframe required by applicable law.
11. Children's privacy
The Service is not directed to children under 16 (or the minimum age required in your jurisdiction). We do not knowingly collect personal information from children. If you believe a child has provided us information, contact us and we will take appropriate steps to delete it.
12. Third-party websites and platforms
The Service links to or integrates with third-party websites and platforms (such as Shopify admin, Meta login flows, and customer storefronts). Their privacy practices are governed by their own policies. We encourage you to review those policies before connecting an integration or sharing information.
13. Changes to this policy
We may update this Privacy Policy from time to time. When we make material changes, we will post the updated policy on this page and update the "Last updated" date. Continued use of the Service after changes become effective constitutes acceptance of the revised policy. If changes materially affect how we process personal information subject to certain laws, we will provide additional notice where required.
14. Contact us
For privacy questions, requests, or complaints, contact:
Agentra
Email: agentraa0@gmail.com
Support: agentraa0@gmail.com
Web: https://dev-hrm.resent.app