Legal

Privacy Policy

Last updated: April 2026

Who we are

ManxHost is a technology platform based on the Isle of Man that provides AI-assisted guest messaging services to local businesses. When you chat with a business through a ManxHost-powered widget, that business is the data controller — they decide what happens with your data. ManxHost acts as a data processor, handling data only on the business's behalf.

This policy covers both guests who use the chat widget and businesses who use the ManxHost platform.

Data we collect from guests

When you chat through a ManxHost-powered widget on a business's website, we collect:

  • The messages you send and receive during your conversation
  • An anonymous session identifier (a randomly generated code stored in your browser for the duration of your visit — not linked to your name or email)
  • The channel you used (website chat or WhatsApp)
  • Timestamps of messages
  • Your device type, browser, and country (derived from your browser's user-agent and IP address, not stored individually)

If you contact the business via WhatsApp, your WhatsApp phone number is used as your identifier and may be visible to the business owner.

We do not collect your name, email address, or any other personal details unless you provide them within the conversation itself.

How we use guest data

  • To provide AI-generated responses to your questions on behalf of the business
  • To allow the business owner to read your conversation and reply directly if needed
  • To help the AI improve its responses over time by learning from conversations (this happens only within the same business's knowledge base)

Our lawful basis for processing this data is legitimate interests — specifically, providing the customer service you requested by starting a conversation.

AI processing

Your messages are processed by an AI system (Claude, provided by Anthropic) to generate responses. This means your message content is sent to Anthropic's API for processing. Anthropic's privacy policy governs how they handle API data. Messages are not used to train Anthropic's models.

Data we collect from business owners

If you use ManxHost as a business, we collect and store:

  • Business name, type, address, and contact details
  • Your name, email address, and WhatsApp number
  • Business information you provide during setup (room details, pricing, policies, etc.)
  • Your account login credentials (email address; password is stored as a secure hash)

This data is used solely to operate your ManxHost account and deliver the service.

Data retention

  • Guest conversation data — retained for up to 12 months from the date of the conversation, then deleted
  • Business owner data — retained for the duration of your account, plus 90 days after account closure

Sub-processors

To deliver the service, ManxHost shares data with the following third-party processors:

  • Anthropic (USA) — AI message processing via the Claude API. Guest message content is sent to Anthropic to generate responses. Anthropic does not use API data to train its models.
  • Supabase (USA/EU) — Database and authentication hosting. All business and conversation data is stored here.
  • Twilio (USA) — WhatsApp message delivery. Phone numbers and message content are processed to send and receive WhatsApp notifications.
  • Vercel (USA/EU) — Application hosting and serverless compute.
  • Resend (USA) — Transactional email delivery (account and notification emails).
  • VoyageAI (USA) — Text embedding for knowledge base search. Query text is sent to generate vector embeddings.

Each sub-processor is bound by a data processing agreement. We only share data necessary for each processor to perform its function.

International transfers

ManxHost is based on the Isle of Man. Several of our sub-processors are based in the United States or operate global infrastructure. Where data is transferred outside the Isle of Man and the UK/EEA, we rely on one or more of the following safeguards:

  • Standard Contractual Clauses (SCCs) approved by the UK ICO or EU Commission
  • The processor's certification under an adequacy framework (where applicable)

The Isle of Man has adequacy status under UK GDPR. For any queries about international transfers, contact us at the address below.

Data processing agreement

Business owners who use ManxHost are data controllers for their guests' data. ManxHost acts as a data processor on their behalf. A Data Processing Agreement (DPA) governs this relationship and is incorporated by reference into our Terms of Service. By accepting our Terms of Service, you also accept the DPA. A copy is available on request at hello@manxhost.app.

Your rights

Under the Isle of Man Data Protection Act 2018 (and equivalent EU/UK GDPR legislation), you have the right to:

  • Access — request a copy of data held about you
  • Erasure — request that your data be deleted
  • Correction — request that inaccurate data be corrected
  • Portability — request your data in a portable format

Guests: To exercise any of these rights, contact the business you chatted with directly. They are the data controller and are responsible for handling your request.

Business owners: Contact us at the address below.

Cookies and storage

The ManxHost chat widget stores a single anonymous session identifier in your browser's session storage. This is cleared automatically when you close your browser tab. No tracking cookies are set.

Contact and complaints

For any privacy queries relating to the ManxHost platform:
ManxHost, Isle of Man
Email: hello@manxhost.app

If you are not satisfied with our response, you have the right to lodge a complaint with the Isle of Man Information Commissioner:

Isle of Man Information Commissioner
P.O. Box 69, Douglas, Isle of Man, IM99 1EQ
Email: ask@inforights.im
Website: www.inforights.im

If you are based in the UK, you may also contact the UK Information Commissioner's Office (ICO) at ico.org.uk.

← Back to site