Legal

Privacy policy

What personal data BotFerry handles, why, and the choices you have. Last updated 28 July 2026.

The short version

We keep the email you sign in with, the settings for the bots you run, and your subscription details. To relay a Slack conversation we pass its messages through in the moment and store only the routing details needed to carry the reply back. We never store your message content, never sell your data, and run no advertising or analytics trackers. You can see, correct, export, or delete your data from your account settings or by emailing us.

Who we are

BotFerry relays Slack mentions into a private operator channel and carries operator replies back to the person who asked. The service is operated by Gabriele Maurizio Albanese, sole trader (ditta individuale), VAT IT05114130759, Viale Ugo Foscolo 14, 73100 Lecce (LE), Italy, the data controller for the account data described below. For anything in this policy, or to exercise a right, email support@botferry.com.

What we collect and why

Each item below names the data, why we hold it, and our lawful basis under Article 6 of the GDPR.

Your account

The email address you sign in with, and, while a change is pending, the new address you are moving to. We keep sign-in codes only as a hash, never in the clear, alongside the timestamps and usage counters that run your plan. We need this to give you an account and let you back into it, so the basis is performance of our contract with you (Art. 6(1)(b)), and protecting sign-in against abuse is our legitimate interest (Art. 6(1)(f)).

Single sign-on

Sign in with Google, Microsoft, or Slack and we store the account identifier that provider gives us and the email on the account, so we can recognise you next time. We do not keep the provider's access token or read your profile beyond that. The basis is performance of our contract, on the sign-in method you chose.

Your Slack connection

For each bot you set up we store its Slack workspace, channel, and bot identifiers and names, plus the bot token and signing secret that let BotFerry drive your app. Those two secrets are encrypted at rest; the rest is ordinary configuration. The basis is performance of our contract.

Billing and payments

When you subscribe, we store your plan and its status and the identifiers Stripe gives us for your customer and subscription, so we can run your billing and show it back to you. If you need Italian electronic invoicing (fatturazione elettronica), we also store what you enter for it: your VAT number (partita IVA), codice fiscale, PEC, and codice destinatario, so they can appear on the invoice. Your card details go to Stripe's checkout and stay with Stripe; BotFerry never sees or stores the card number. The basis is performance of our contract with you (Art. 6(1)(b)), and for the invoices and tax records we are required to keep, compliance with a legal obligation (Art. 6(1)(c)).

To honour the 14-day money-back guarantee only once per card, we keep a one-way fingerprint that Stripe derives from the card (never the card number itself) and check new claims against it. We hold it to prevent repeat claims, which is our legitimate interest (Art. 6(1)(f)); it is the one billing detail we keep after an account is deleted, as covered in how long we keep it.

The conversations you relay

To carry a mention to your operators and their reply back, BotFerry handles the message text and any attached files as they pass through, and stores the routing details that link the two threads: channel and thread identifiers, a permalink to the original message, the Slack user id of the person who mentioned the bot, and timestamps. Message and file content moves through our systems only to deliver it, including a processing queue it sits in for a few seconds, and we never write it to long-term storage. For this relayed data you are the controller and BotFerry is your processor; see the next section.

Sign-in security

When you request a sign-in link we check your IP address against a rate limit to stop someone flooding an inbox or guessing codes. The address lives in a short-lived counter that expires within minutes. We do not write it to the database or use it for anything else. The basis is our legitimate interest in keeping the service secure (Art. 6(1)(f)).

Email we send you

We email you sign-in links and codes, confirmations when you change your address, an alert when a bot's Slack connection breaks, and billing notices such as when a renewal payment fails or later goes through. These carry no tracking pixels.

Controller or processor

For your account, billing, and sign-in data, BotFerry decides how and why the data is used, so we are the controller (Art. 4(7)).

For the Slack conversations you relay, you decide: you own the workspace, you choose to route its mentions through BotFerry, and you set who operates the channel. There you are the controller and we act on your instructions as your processor (Art. 4(8), Art. 28). That covers the message content passing through and the routing metadata and requester identifiers we store to deliver it. If you need a data processing agreement for your own compliance, email support@botferry.com and we will provide one.

Who we share it with

We use a small set of processors to run the service, each bound by a contract under Article 28. We do not sell your data, and we run no advertising or analytics trackers.

Who What for
Slack TechnologiesThe core relay; optional Slack sign-in; bot avatars shown in your dashboard.
StripeSubscription billing, payment processing, and the customer portal for cards and invoices.
GoogleGoogle single sign-on, only if you choose it.
MicrosoftMicrosoft single sign-on, only if you choose it.
ResendSending sign-in and account emails.
ScalingoRunning the application and its database.

The full list, with locations and transfer safeguards, lives on our sub-processors page.

We also disclose data where the law requires it, such as a valid legal order.

Where your data goes

Some of the sub-processors above are in the United States. Your data reaches them under the safeguards the GDPR allows for transfers outside the EEA (Art. 46): Standard Contractual Clauses, and the EU-US Data Privacy Framework where the provider is certified. We keep the Standard Contractual Clauses in place as a fallback, since the Framework is under legal challenge. The sub-processors page lists the safeguard for each provider.

How long we keep it

We hold data only as long as it serves the purpose we collected it for (Art. 5(1)(e)).

Data Kept
Account and connection settingsUntil you delete the bot or your account
Billing and subscription dataWhile you have a subscription; cleared when you delete your account
Invoices and tax records (held by Stripe)The statutory retention period; kept even after you delete your account
Money-back card fingerprintKept to enforce the once-per-card guarantee, including after account deletion
Thread routing metadataFor the life of the bot, so late replies still find their thread; removed when the bot is deleted
Activity log entries90 days, then a nightly job removes them
Duplicate-delivery records48 hours
Message and file contentNot stored; passes through only during a relay
Sign-in IP countersMinutes, then they expire

The docs describe what a log entry can and cannot contain.

When you ask us to delete your account, we cancel any active subscription and delete your Stripe customer record, then erase everything above after a short grace period in which you can cancel the request. We keep only what the law or abuse-prevention requires: the invoices Stripe holds as immutable tax records, and the one-way card fingerprint that enforces the once-per-card money-back guarantee.

Your rights

Under the GDPR you can ask us to do any of the following with your personal data. Exercising a right costs nothing and will not count against you.

  • See it — get a copy of the data we hold about you (Art. 15).
  • Correct it — fix anything wrong or incomplete (Art. 16).
  • Delete it — have your account and its data erased (Art. 17).
  • Export it — receive it in a portable, machine-readable form (Art. 20).
  • Restrict or object — pause a use, or object to one based on our legitimate interests (Art. 18, 21).
  • Withdraw consent — where we rely on consent, take it back at any time, as easily as you gave it (Art. 7(3)).

Start a data export or a deletion from your account settings, or email support@botferry.com for any of the rest. We answer within one month (Art. 12(3)). If we relay Slack conversations for you as your processor and a request concerns those, we will point you to the customer who controls that data or help them respond.

If you think we have mishandled your data, tell us first so we can fix it. You also have the right to complain to a supervisory authority (Art. 77); ours is the Garante per la protezione dei dati personali, Italy.

Security

We encrypt your Slack bot token and signing secret at rest, serve every page over HTTPS, and store sign-in codes only as hashes (Art. 32). Because we keep no message content, there is no conversation archive to breach. The security section of the docs goes into detail.

Cookies

BotFerry sets only the cookies it needs to keep you signed in and protect its forms. The cookie policy lists each one and explains the choices you have if that ever changes.

Children

BotFerry is a workplace tool, not meant for children, and we do not knowingly collect data from anyone under 16. If you believe a child has given us data, email support@botferry.com and we will remove it.

Changes and contact

When we change this policy we update the date at the top, and for anything that affects your rights we tell you before it takes effect. Questions go to support@botferry.com.

Cookie preferences

BotFerry sets only the essential cookies below. There is nothing optional to turn on yet.