Security & data handling

Your data stays yours.

Connecting your business systems to anything deserves a straight explanation. Here's ours.

Data handling summaryv1 · 2026
Access model
Narrowest scope each platform allows; read-only where offered
In transit
Encrypted in transit using current industry standards
At rest
Encrypted at rest using current industry standards
Credentials
Held in a dedicated secrets manager, kept separate from application data
Model training
Never on your business data
Audit log
AI requests and cost changes logged and attributable
Revocation
Disconnect an account yourself; workspace deletion on request

What we access, and why

ChannelHawk requests the narrowest access each platform allows for the job it's doing. We read your orders, costs, spend and traffic data because that's what produces the answers. Where a platform offers a read-only scope, we use it. Every connector's exact permissions are listed on integrations, before you authorize anything.

What we never do

We never use your business data to train AI models — ours or anyone else's.

We never sell, share or aggregate your data for the benefit of another customer.

We never place orders, change ad spend, or edit your accounting records without an action you explicitly authorize.

We never keep access after you revoke it.

How the platform handles your data

How AI models handle your data

ChannelHawk uses leading commercial AI models to interpret questions and generate answers. Data sent to those providers is covered by enterprise agreements that prohibit training on it and require deletion after processing. The models never receive credentials, and only the specific data needed to answer a given question.

Our AI sub-processors are listed in our privacy policy and data processing agreement.

Storage and encryption

  • Encrypted in transit and at rest
  • Credentials and tokens held in a dedicated secrets manager, kept separate from application data
  • Securely hosted with established infrastructure providers held to high security and availability standards
  • Backups are encrypted and retained on a regular schedule

Access controls

  • Role-based access with per-user permissions
  • Every AI request logged and attributable, with cost changes kept in full history
  • Two-factor authentication with an authenticator app
  • Disconnect any connected account yourself at any time; workspace deletion and data removal on request

Compliance

  • A data processing agreement covering sub-processors, international transfers and data subject rights
  • Personal data minimized by design — AI providers receive anonymized, aggregated metrics, never your customer records
  • Documented retention limits, deletion on request and breach notification

Have a security question we haven't answered?

Email [email protected] and a person will answer it.