This page explains, in plain terms, exactly what happens to data when you chat with a Beeve chat widget on one of our customers' websites. It is a companion to our Privacy Policy and Cookie Policy, written specifically for the widget so you can see what we collect, where it goes, and what we store on your device.
Short version: the widget processes only what it needs to hold a conversation and connect you with the business you're talking to. It doesn't set advertising cookies, and it doesn't track you around the web.
Questions? Reach us any time at contact@beeve.ai.
1. Who is responsible for your data
- The business whose website you're visiting is the data controller. They decide why the widget is there and what happens to the conversations.
- Beeve is the data processor. We run the widget and store conversations on the controller's behalf, following their instructions.
- We use a small number of trusted sub-processors (listed in section 6) to power AI replies and real-time delivery.
2. What the widget processes
2.1 Information you provide in the chat
- Your messages – the text you type into the chat, which is sent to our servers so the assistant (or a human agent) can reply.
- Contact details you share – if you fill in a lead form inside the chat, we process whatever fields the business chose to ask for (for example name, email, phone or company). These fields are configured by the business, not by Beeve.
- Booking details – if you book a time through the chat, we process the name and email you enter so the meeting can be scheduled.
Anything you share in the chat is made available to the business you're talking to, for example so they can answer your question or follow up on a request.
2.2 Information processed automatically
To run the conversation reliably, the widget also handles a small amount of technical data:
- A conversation ID and a random session identifier so your messages stay linked to the right conversation.
- The website address (domain) where the widget is loaded, used to confirm the widget is allowed to run on that site.
- Basic technical metadata such as language and timestamps.
- Standard server logs (which may include an IP address) that our infrastructure keeps to operate the service securely and prevent abuse.
The widget does not build advertising profiles, and it does not follow you across other websites.
3. What we store on your device
The widget does not set tracking or advertising cookies. Instead, it stores a few strictly necessary items in your browser's local storage, purely so the chat keeps working as you navigate. These are functional and stay on your device:
| Item | Purpose |
|---|---|
beeve-widget-store | Remembers your current conversation so it isn't lost on refresh – the conversation ID, recent messages of an active conversation, unread count, and minor UI preferences (such as whether you dismissed the intro screen). |
beeve-widget-store-conversation-id | A backup of the active conversation ID so the chat can reconnect. |
beeve-widget-store-unread-state | Remembers how many unread replies to show on the chat button. |
beeve_visitor_session_id | A randomly generated identifier used to deliver replies to your chat in real time. |
beeve-widget:debug | Only present if diagnostics are manually switched on. Stores no personal data. |
Security tokens used to authenticate your chat session are kept in memory only for the duration of your visit. They are never written to local storage and are re-issued each session.
You can remove these items at any time by clearing your browser's site data for the website you're visiting.
4. AI processing
To generate automated replies, the content of your conversation is sent to our AI infrastructure provider, OpenAI. Depending on how the business has configured Beeve, this may include:
- The text of messages in the conversation
- Limited context, such as previous messages and the system instructions needed to reply
- Technical metadata, such as language and timestamps
- OpenAI acts as a data processor and processes data only to provide the AI service.
- We have a Data Processing Agreement with OpenAI covering security, confidentiality and European data protection law.
- For API-based use, OpenAI does not use your data to train its publicly available models.
5. Real-time delivery & hosting
Conversations are stored and delivered using Supabase, which provides our database and the real-time connection that pushes new replies to your chat instantly. Supabase acts as a data processor and stores data on our instructions under an appropriate data protection agreement.
Conversation data is hosted in Frankfurt, Germany (EU).
6. Sub-processors
The widget relies on the following sub-processors:
| Provider | Purpose |
|---|---|
| OpenAI | Generating automated AI replies |
| Supabase | Database hosting and real-time message delivery |
Where a provider processes data outside the European Economic Area, we rely on appropriate safeguards such as the EU Standard Contractual Clauses. Contact us at contact@beeve.ai for details.
7. Data minimisation & security
We've built the widget to handle as little data as possible and to protect what it does handle:
- API requests use token-based authentication in request headers – the widget does not rely on cookies.
- Session tokens live in memory only and are re-issued each visit.
- The widget only runs on website domains that the business has authorised, enforced by an origin allowlist.
- Diagnostic and error reports are automatically scrubbed of sensitive values – such as tokens and email addresses – before being recorded.
- Data is encrypted in transit.
- Our processing is designed to align with the GDPR, including data minimisation, purpose limitation, and appropriate safeguards for any transfers outside the EU.
8. Data retention
Conversations and the data you share are retained for as long as the business (the data controller) configures in their Beeve workspace, and as needed to provide the service. The items stored in your browser remain until you clear your site data.
If you'd like a conversation deleted, please contact the business whose website you used the widget on, as they control retention.
9. Your choices & rights
- You can clear the widget's local storage at any time via your browser's site-data settings.
- You don't have to share contact details to ask a question – they're only used when you choose to provide them.
- Your data protection rights (access, correction, deletion and more) are exercised with the business that operates the widget, as the data controller. We support them in responding to such requests.
Full details of your rights are in our Privacy Policy.
10. Contact us
If you have any questions about how the Beeve widget handles data, contact us at:
Email: contact@beeve.ai
We may update this page from time to time. If we make material changes, we'll update the "Last updated" date at the top.