Privacy policy

Last updated 11 October 2026

Who we are

Hobson is a customer support service for businesses. This policy explains what personal data we handle, why, and the choices you have. Questions go to privacy@hobson.support.

Our two roles

For the people who sign up and use Hobson, we are the controller of their account data. For the conversations our customers bring into Hobson, the business using Hobson is the controller and we act as their processor, only handling that data on their instructions and under a data processing agreement.

What we collect

  • Account data: name, email address, workspace and role, and sign-in details.
  • Support content our customers connect: emails, chat, Instagram and Messenger messages, form submissions, attachments, customer contact details and order information.
  • Usage data: actions taken in the app, which we keep as an audit log, and basic technical logs.
  • Billing data: the plan you choose and your billing contact. Card details are handled by our payment provider, Stripe, and never reach our servers.

How we use it

  • To provide the service: sorting, drafting and sending replies, and showing context such as order history.
  • To keep the service secure, prevent abuse and investigate problems.
  • To contact account holders about the service.

We do not sell personal data, use customer conversations for advertising, or use one customer's data to train models for another customer. Tone profiles are built only from a workspace's own replies and stay within that workspace.

Where it is stored

Data is stored in the European Union, encrypted in transit and at rest. Our sub-processors are Hetzner (hosting the API), Vercel (hosting the web app), Neon (database), Amazon Web Services in Ireland (email delivery and file storage), Cloudflare (network protection and bot checks), Stripe (payments), TypeSafe (classifying messages), Anthropic (drafting replies and triage), Voyage AI (search vectors for finding related answers), Reducto through its EU service (reading uploaded documents), ScrapingBee (reading web pages a workspace adds as knowledge) and PostHog in the EU (product analytics and error reports). Shopify, Slack, Linear, Meta (Instagram and Messenger) and Gorgias receive or provide conversation details only when a workspace connects them. Anthropic and Voyage AI process the text we send them in the United States. Where a sub-processor handles data outside the UK or EU, we rely on appropriate safeguards such as standard contractual clauses. The full list, with what each one does and where, is on our sub-processors page.

Product analytics

We use PostHog, hosted in the EU, to understand how our website and dashboard are used and to catch errors. Events carry internal ids, counts and settings, never message content, subjects, email addresses or names. The dashboard never sets analytics cookies and never records sessions. On this website, analytics run without cookies unless you choose Accept in the cookie banner; only then do we set analytics cookies and record sessions. To change your choice later, clear this site’s data in your browser and the banner will ask again. Session recordings mask every piece of text and every form field. We honour Do Not Track, and none of this runs on anything your own customers see.

Early access list

If you join the early access list, we keep your email address, the helpdesk you told us you use (if you chose one), the page you joined from and any campaign tags in the link you arrived by. We also keep a record of your consent: the wording you agreed to and when you agreed and confirmed. We don't store your IP address. We use this to email you when Hobson opens and to send the occasional product update, no more than once a month.

Our lawful basis is your consent. We only add you once you click the link in our confirmation email. Emails are sent through Amazon Web Services (SES) in Ireland, and the form uses Cloudflare Turnstile to check you're not a bot. If you don't confirm within 30 days, we delete your details. You can withdraw at any time with the unsubscribe link in any of our emails or by emailing privacy@hobson.support. When you unsubscribe we keep only your email address and the dates you joined and left, so we never email you again by mistake.

How long we keep it

Raw inbound email is deleted after seven days once processed. Conversations and attachments are kept while a workspace is active or until the customer deletes them. When a workspace is deleted, its data and files are removed.

Your rights

Under UK and EU data protection law you can ask to access, correct, delete or export your personal data, and object to or restrict how it is used. If your data reached us through one of our customers, we will pass your request to them. You can also complain to the Information Commissioner's Office.

Changes

We will update this page when our practices change and note the date at the top.