This policy explains what data Coffee Bot ("Service", "we", "us") collects when it is installed in a Slack workspace, why we collect it, who it is shared with, and how it can be removed. It applies to the bot itself and to coffeebot.work.
The organisation whose Slack workspace installs Coffee Bot decides what the Service is used for and is the controller of the workspace member data described below. We process that data on the organisation's behalf. If you are a member of a workspace that uses Coffee Bot and you want your data removed, the fastest route is usually your workspace administrator; you may also contact us directly using the address in section 10.
Coffee Bot reads workspace and channel membership through Slack's API and stores the following:
| Data | Why it is stored |
|---|---|
| Slack workspace (team) ID and workspace name | To keep each workspace's channels, rounds and billing separate. |
| Slack channel IDs and names | To know which channels the bot runs rounds in and to show them in the dashboard. |
| Slack user ID, display name, real name, email address and time zone for members of channels the bot has been added to | To identify participants, address them by name in Slack messages and in participation reports, schedule rounds in a sensible time zone, and contact workspace administrators about their subscription. This information comes from the Slack profile the member already maintains. |
| Channel membership and opt-out status | To include or exclude a member from pairing. |
| Round history, pairings and readiness responses | To avoid repeating recent pairs, to run the current round, and to produce the participation analytics shown in the dashboard. |
| An administrative activity log: which workspace member performed an action, the action type, the channel it applied to, and the time | To troubleshoot problems and to keep an accountable record of configuration changes. |
| Subscription and usage records, including Stripe customer and subscription identifiers and monthly counts of active members | To operate paid plans and calculate charges. |
| The OAuth access token issued by Slack when the bot is installed | To call the Slack API on the workspace's behalf. It is not shared with anyone. |
Where data-protection law such as the GDPR applies, we process this data because it is necessary to provide the service your organisation has asked for, and because we and your organisation have a legitimate interest in running the pairing service and keeping it secure and accountable. Your organisation is responsible for informing its members that it uses Coffee Bot.
We share data only with the providers needed to run the Service:
We may also disclose data if we are legally required to, or where it is necessary to establish or defend legal claims.
Member and pairing data is kept while the bot remains installed, because round history is what lets the Service avoid repeating recent pairs and produce participation analytics. Removing the bot from a channel, or uninstalling the app, stops any further collection, but it does not by itself erase what was already stored. To have a workspace's data deleted, write to us at the address in section 10 and we will remove it. Records we are required to retain for accounting or legal reasons are kept for as long as that obligation lasts.
Depending on where you live, you may have the right to access the personal data we hold about you, to have it corrected or deleted, to object to or restrict how it is processed, and to receive a copy in a portable format. Workspace administrators can export a channel's participation history from the dashboard at any time. To exercise any of these rights, contact us at the address in section 10; we will respond within the period required by applicable law. You also have the right to complain to your local data-protection authority.
Data is transmitted over encrypted connections and access to production systems is limited to people who need it to operate the Service. Slack access tokens are stored so that only the Service can use them. No system is perfectly secure, and we cannot guarantee absolute security, but we work to protect your data and will notify affected workspaces of a breach where the law requires it.
Data may be processed in a country other than the one you live in. Where required, we rely on appropriate safeguards for such transfers. Coffee Bot is a workplace tool and is not directed at children; we do not knowingly collect data from anyone under 16.
Questions, requests or complaints about this policy can be sent to [email protected].
We may update this policy as the Service changes. Material changes will be announced to workspace administrators, and the effective date above will be updated. See also our Terms of Service.