Privacy

Privacy Policy

This policy explains what ChargeBell collects, why we use it, who receives it, how long we keep it, and the choices available to you.

Last updated: July 14, 2026

Scope and our role

This Privacy Policy applies to ChargeBell's public website, authenticated application, integrations, billing, support communications, and related services. It does not govern Stripe, Slack, Google, Cloudflare, or other third parties, which publish their own privacy notices.

ChargeBell acts as a controller or business for account, website, billing, security, and support information. When an organization connects Stripe or Slack and asks ChargeBell to process information for its alerting workflow, that organization determines which accounts, events, channels, and recipients are involved. Depending on the applicable law and context, ChargeBell may act as that organization's processor or service provider for this customer-directed data.

If you use ChargeBell for an organization, the organization may administer your membership and access shared settings, integrations, alert history, and other organization data. Direct privacy questions about the organization's own use of that information to the organization as well as to ChargeBell where appropriate.

Information we collect and its sources

  • Account and authentication information you provide, including name, email address, password authentication record, passkey public credential data, profile image, session information, and account timestamps.
  • Organization and preference information you or an administrator provides, including organization name, membership and role, invitation email, timezone, currency, alert rules, thresholds, quiet hours, digest schedule, selected destinations, and requested future integrations.
  • Google sign-in information, if you choose Google OAuth, including the account identifier, email address, name, profile image, tokens, token expiry, and scopes Google returns for authentication.
  • Stripe connection and event information obtained from Stripe at the organization's direction, including connected account identifiers and names, OAuth credentials and scope, mode, event and object identifiers, event type and status, customer name or email when Stripe includes it, amounts, fees, currency, subscription changes, payout information, error details, and timestamps.
  • Slack connection and channel metadata obtained from Slack at the organization's direction, including workspace identifier and name, bot user identifier and token, available channel identifiers and names, private or archived status, selected destinations, message timestamps returned after delivery, and connection timestamps. ChargeBell does not request or ingest Slack message history.
  • Slack slash-command payload data processed when someone invokes a ChargeBell command, which may include workspace, channel, user, command, and response metadata supplied by Slack. ChargeBell uses the command text and workspace identifier to respond and does not persist the inbound command payload as application data.
  • Billing information received from Stripe, including billing customer and subscription identifiers, plan, billing interval, subscription status, trial and renewal dates, and cancellation status. ChargeBell does not directly store full payment-card numbers.
  • Technical and security information collected automatically, such as IP address, user agent, device and browser information, cookie and session identifiers, authentication timestamps, request metadata, application logs, error details, and security events.
  • Support and legal-request information you send us, including contact information, messages, issue descriptions, and attachments you choose to provide.

How we use information

  • Create and secure accounts, authenticate users, maintain sessions, support passkeys and account recovery, and administer organization membership and permissions.
  • Connect customer-directed Stripe and Slack accounts, receive Stripe events, calculate alert and digest information, route notifications to selected destinations, answer supported Slack commands, maintain delivery history, retry failures, and troubleshoot the integration.
  • Operate dashboards, organization settings, plan limits, scheduled workflows, outbound webhooks, and customer-requested features.
  • Administer subscriptions, checkout, renewals, taxes, invoices, upgrades, downgrades, cancellations, and payment support through Stripe.
  • Maintain, monitor, debug, secure, and improve the service; detect fraud and abuse; enforce our Terms; and protect ChargeBell, customers, and third parties.
  • Respond to support, privacy, security, legal, and copyright requests and comply with applicable law and binding legal process.

Legal bases for processing

Where laws such as the GDPR require a legal basis, ChargeBell relies on performance of a contract to provide the service you or your organization requested; legitimate interests in securing, maintaining, supporting, and improving ChargeBell; compliance with legal obligations; and consent where the law requires it. You may withdraw consent for future processing, but withdrawal does not affect processing already completed or processing supported by another lawful basis.

Our legitimate interests include preventing abuse, maintaining service reliability, understanding and supporting account use, protecting legal rights, and improving relevant product functionality. We balance those interests against the rights and reasonable expectations of affected individuals.

Cookies, sessions, and local storage

ChargeBell uses necessary cookies and similar local storage to keep users signed in, protect requests, remember theme and interface preferences, preserve onboarding choices, and support core application behavior. Authentication sessions generally expire after seven days and may refresh during active use. Some non-authentication preferences may remain on the device until the user clears them or the application replaces them.

ChargeBell does not currently use advertising cookies or sell information collected through cookies. The public marketing site does not currently include third-party advertising or behavioral-analytics trackers. If that changes, we will update this policy and provide any consent or opt-out controls required by law.

How we disclose information

We disclose information only as needed to provide and secure the service, follow customer instructions, comply with law, protect rights and safety, or complete a corporate transaction. We do not allow service providers to use customer data for their own unrelated advertising.

  • Sub-processors and service providers that host, store, secure, monitor, email, authenticate, support, bill, or otherwise operate ChargeBell. The current list and our engagement guidelines are available on the Sub-processors page.
  • Stripe and Slack when an organization connects those services, requests data from them, or directs ChargeBell to transmit an alert, digest, command response, or other payload to a selected destination.
  • Google when you choose Google OAuth and Google must authenticate or maintain access to your Google account connection.
  • Organization owners, administrators, and members according to their role and the shared workspace features they can access.
  • A customer-configured webhook recipient when an organization directs ChargeBell to send alerts to that endpoint. The organization controls and is responsible for that recipient.
  • Professional advisers, authorities, courts, regulators, or counterparties when reasonably necessary to comply with law or protect legal rights, safety, and security.
  • A buyer, investor, successor, or adviser in connection with a merger, financing, reorganization, sale of assets, or similar transaction, subject to appropriate confidentiality and use restrictions.

No sale, targeted advertising, or significant automated decisions

ChargeBell does not sell personal information, Stripe data, Slack data, Google OAuth data, customer data, or sales data. ChargeBell does not share personal information for cross-context behavioral advertising and does not use it for data-broker activity, credit decisions, or unrelated marketing.

ChargeBell uses rules selected by the organization to classify events, enforce plan limits, hold notifications during quiet hours, and route alerts. ChargeBell does not use personal information to make solely automated decisions that produce legal or similarly significant effects about individuals.

Retention

We retain each category of information only for as long as reasonably necessary for the purpose collected, including providing an active account or organization, maintaining alert and billing history, securing and troubleshooting the service, complying with law, resolving disputes, and enforcing agreements. Retention depends on the record rather than one period for all data.

  • Authentication sessions generally expire after seven days and may refresh during active use. Short-lived verification and recovery records expire according to the relevant authentication flow.
  • Slack OAuth credentials, workspace connection records, cached channel metadata, and Slack destinations remain while the integration is connected. Disconnecting Slack removes those records from the active application database; previously generated alert-delivery history remains with the organization.
  • Disconnecting a connected Stripe account stops future access by clearing its OAuth credentials. ChargeBell retains limited connection identifiers, disconnection status, and previously generated alert history so existing records remain understandable and duplicate events can be prevented.
  • Account, organization, billing, alert, delivery, and support records generally remain while the relevant account or organization is active and afterward only as reasonably necessary for legal, tax, billing, security, fraud-prevention, backup, or dispute purposes.
  • Cloud infrastructure logs, caches, and backups may persist for limited operational rotation periods after information is removed from the active application database.

Deletion and integration controls

Organization owners and administrators can disconnect Stripe or Slack in ChargeBell. Slack disconnection attempts to revoke or uninstall the Slack authorization and deletes the bot token, workspace connection, cached channel metadata, and Slack destinations from the active database. Stripe disconnection clears the stored access and refresh credentials while retaining limited non-secret connection and historical records.

A user can delete their individual ChargeBell account from the profile page. This removes the user's account access, authentication records, and organization memberships, but it does not delete an organization or its shared alert history when other members or legitimate business records remain. An authorized organization representative may request deletion of organization data by emailing privacy@chargebell.com.

We verify the requester's identity and authority before fulfilling access or deletion requests. We may retain information that applicable law permits or requires us to keep, and we will explain a material denial where required.

Security

We use safeguards designed to protect information, including encrypted transport, provider-managed encryption at rest, organization-scoped authorization, role checks for sensitive changes, signed OAuth state, verification of Slack requests, signing of supported outbound webhook deliveries, restricted server-side credentials, passkey support, and operational logging. OAuth tokens and integration secrets are not exposed in client-side code or made available to ordinary users.

No service can guarantee absolute security. You are responsible for protecting account credentials, configuring organization access appropriately, and notifying security@chargebell.com promptly if you suspect unauthorized access.

International data transfers

ChargeBell and its service providers may process information in countries other than where you live. Cloud infrastructure may process requests on a global network, and the current primary application database region is Eastern North America without a fixed jurisdiction restriction. Where required, ChargeBell relies on appropriate contractual or legal transfer mechanisms and expects recipients to protect information consistently with this policy and applicable law.

Your privacy rights

Depending on where you live, you may have rights to know or access personal information, receive a portable copy, correct inaccurate information, request deletion, restrict or object to processing, withdraw consent, opt out of sale, sharing, or targeted advertising, limit certain uses of sensitive information, and avoid discriminatory treatment for exercising a right. Because ChargeBell does not sell personal information or share it for cross-context behavioral advertising, there is no sale or advertising-sharing opt-out needed for our current practices.

To exercise a right, email privacy@chargebell.com and describe the request and account or organization involved. We may verify your identity, authority, and relationship to the organization. An authorized agent may submit a request where permitted by law, subject to proof of authorization. You may appeal a denied request by replying to our decision. We will respond within the period required by applicable law.

Individuals in the EEA or UK may also complain to their local data-protection authority and may object to processing based on legitimate interests. Rights are not absolute; exceptions may apply when information is needed to comply with law, protect others, or establish, exercise, or defend legal claims.

Children

ChargeBell is a business service intended only for adults. You must be at least 18 years old to create or administer an account. We do not knowingly collect personal information from children under 13 or knowingly offer the service directly to children. Contact privacy@chargebell.com if you believe a child provided information to ChargeBell.

Changes and contact

We may update this policy to reflect product, legal, or operational changes. The date above identifies the latest revision. If a change materially affects how we use personal information, we will provide notice through the service, by email, or by another reasonable method before the change takes effect when required.

For privacy questions, requests, or complaints, email privacy@chargebell.com. For security reports, email security@chargebell.com.