What data enters the system
The following types of data are processed and stored:
- Conversation data: Message text, images, and documents (document support coming soon)
- Order retrieval data: Customer IDs, names, and phone numbers required for order lookups
- Product database: Your complete product catalog
How we store data
All data is stored in secure, monitored environments with comprehensive logging.
The widget uses 30-day cookies and localStorage elements in the end user’s browser for session management.
Continuous aggregation
We maintain only aggregated statistics at the monthly level, such as the total number of messages in a given month.
Source data is not retained unnecessarily after aggregation is complete.
System and observability data
Logs and sessions
- Duration: 30 days
- Scope: IP addresses, session data, application logs
- Storage: Grafana Cloud
- Application: Uniform across all customers
Email communications
- Duration: 30 days
- Platform: Customer.io
- Application: Uniform across all customers
Database backups
- Duration: 90 days
- Process: Backups older than 90 days are automatically deleted
Continuous monitoring
Our monitoring system continuously verifies that scheduled processes execute successfully. If any issues are detected, an automatic alert triggers our incident management process.
Configuring retention periods
The default retention period for end-customer support data is 2 years for each widget. If your organization requires a shorter retention period, such as 90 days, please contact our support team at hey@molin.ai to configure the widget.
The retention period starts from a ticket’s most recent activity. Once it expires, automated cleanup removes the ticket, its messages, linked interaction data, and linked files from active systems. Failed external-file deletion is retried automatically.
An end-customer profile and its notes are removed only after the retention period has elapsed since the last contact and no retained ticket references the profile.
The widget retention period doesn’t delete the merchant account, widget, preferences, settings, inbox folder definitions, integrations, product catalog, FAQs, or service documents.
Reducing a widget’s retention period applies to existing data. Tickets already older than the new period can be deleted during the next hourly cleanup, and deletion can’t be undone.
Compliance
This data retention policy is designed to comply with GDPR and other data protection regulations. For more information about our GDPR compliance, see our GDPR documentation.