Privacy policy
This document explains what data Cobbi handles, what for, who it is shared with, and what you can do about it. It is written to be understood, not to cover us.
1. There are two kinds of data, and they are not the same
This is the most important part, and the one almost no policy explains properly.
Your data. Your business and your own details as the owner: your name, your mobile number, your email, your tax ID, how you use the product. We are the controller of this data.
Your customers' data. Names, mobile numbers, invoices, amounts, payment receipts. You upload this, and you are the controller. Cobbi acts as a processor: we handle it under your instructions, to provide the service, and for nothing else.
That distinction has concrete consequences:
- You are responsible for having a legitimate reason to hold that data and to message those people.
- We do not use your customers' data for our own purposes, we do not sell it to anyone, and we do not cross-reference it between businesses.
- If one of your customers asks us for their data or its deletion, we pass the request on to you, because the decision is yours. What we do handle immediately and on our own is a request to stop receiving messages.
2. What we collect
From your account: business name, verified mobile number, email, tax ID if you provide one, country, time zone and language.
From your acceptance of these documents: the date you accepted, the version you were shown, and the IP address and browser you accepted from. It is the record that you accepted, and without those last two it does not hold up.
From your receivables: the charges you create or that arrive through your email inbox, with your customer's name and mobile number, the amount, the description, the due date, and the electronic invoice when there is one.
From messages: the content of what is sent over WhatsApp and of what comes back, with its delivery status (sent, delivered, read, failed). This is the record of what happened and it is part of the product: without it there is no way to explain why a reminder did not go out.
From the payments you record: amounts, dates, references, and the images of the receipts your customers send.
From your subscription: your Stripe customer identifier and your plan status. We never see or store your card details: Stripe handles them directly.
From your usage: IP address, browser type, pages visited and in-app events, so we can understand what works and what does not.
3. What we use it for
To provide the service: schedule and send reminders, receive replies and receipts, reconcile payments and show you your receivables. To bill your plan and track your usage. To support you when you ask. To improve the product using aggregate data. And to meet legal obligations where they apply.
We do not use your data or your customers' data for advertising, and we do not sell it.
4. Use of artificial intelligence
When your customer sends an image of a payment receipt, that image is processed by a third-party artificial intelligence model to extract the amount, the date and the reference. The same applies if you dictate a charge by voice.
Two things about that:
- The providers we use are under agreements that prohibit them from training their models on what we send.
- We never send a full receipt unnecessarily: only what is needed to read it.
If you would rather your account's receipts never went through a model, write to us and we will turn it off. You will lose automatic reconciliation, but you will still be able to record payments by hand.
5. Who it is shared with
Only with the providers the service needs in order to work, and under agreements that prohibit them from using it for anything else:
- Meta (WhatsApp Business Platform): sending and receiving messages.
- Amazon Web Services: file storage and inbound email.
- Railway: infrastructure where the application runs.
- Stripe: charging your subscription.
- OpenAI, Anthropic: reading receipts and images.
- PostHog, Sentry: product analytics and error detection. PostHog also records how the application is used (clicks, scrolling, which screen you stop on) so we can see where the product gets in your way. Inside the panel that recording is blind: your customers' names, phone numbers and amounts are replaced by blocks before they leave your browser, and never reach PostHog. What you type into a field is never recorded, on any screen.
- HeyCatch: application usage analytics. It records page views, clicks and which channel you arrived through, identified by your company's code. It does not receive your name, your email, your phone number or any data about your customers.
- Resend: transactional email, such as the sign-in link.
We also share data if a competent authority requires it through a valid request, or if it is needed to defend a legal right.
We do not sell your information or your customers', to anyone, for any reason.
6. Where it is stored
Our infrastructure is in the United States. If you operate from another country, your data is transferred there so we can provide the service. By using Cobbi you accept that transfer. Our providers are bound by agreements requiring equivalent protection measures.
7. How long we keep it
While your account is active, and afterwards for as long as the law requires or as needed to resolve a dispute.
If you close your account, we delete personal data from our production systems within 30 days. Backups are overwritten on their normal cycle, which does not exceed 90 days.
The log of sent messages is kept separately for 24 months: it is the proof of what was sent and when, and it serves both you and us if someone complains.
8. Security
Everything travels encrypted. Files are stored in a private bucket and are only reachable through temporary links that expire in five minutes. Phone numbers, tokens and message content are never written in full to our technical logs. Internal access to customer data requires a second factor, is audited, and is limited to what support actually needs.
No system is infallible. If a breach affecting your data occurs, we will tell you.
9. Your rights
You can request access to your data, correct it, ask us to delete it, object to certain uses, and take a copy in a readable format. Write to us and we will respond within the deadlines your country's law requires; if there is none, within 30 days.
If you are a customer of a business that uses Cobbi and you received a message from us: reply BAJA in that same chat and we will not write to you again. It is immediate and you need do nothing else. To access, correct or delete your data, the request goes to the business that is charging you, because they are the ones who decide about it; if you write to us, we pass it on.
In Colombia, the detail of these rights and how to exercise them is in our data processing policy.
10. Cookies and analytics
We use the cookies needed to keep your session open, and analytics tools to know which parts of the product get used. We do not use advertising cookies or cross-site tracking.
11. Minors
Cobbi is a work tool and is not directed at anyone under 18. We do not knowingly collect data from minors.
12. Changes
If we change anything material we will tell you by email or inside the application before it takes effect. The date above says when it was last updated.
13. Contact
For anything about privacy, including exercising your rights, write to us.