Privacy Policy
Last updated 3 August 2026
What Channelflow is
Channelflow is a customer-messaging application operated by PT. Unicorn Food and Services, Ubud, Bali, Indonesia. It brings the messages a business receives on WhatsApp, Instagram, TikTok and email into one inbox, and answers many of them with an AI assistant. This policy covers the data that passes through it.
Our TikTok integration
Channelflowuses TikTok's Business Messaging API to read and reply to the direct messages sent to a TikTok Business Account, and only ever on behalf of the account owner who has authorised us. Nothing happens without that authorisation, and it covers that account alone. A conversation is always started by the TikTok user; we reply inside the window TikTok allows, and we send no promotional broadcasts and no automated reminders on TikTok.
From TikTok we receive the conversation, the message and its text or image, the sender's TikTok username, and the identifiers TikTok assigns to the conversation and the account. We use them to show the conversation to the business's staff and to compose a reply. TikTok message data is never sold, never used for advertising or profiling, never shared with another business using Channelflow, and never used for any purpose beyond answering that conversation and keeping a record of how it was handled.
Data about the people who message us
- The identifier their message arrives with — phone number, email address, or the account or conversation id the platform gives us — and the display name it carries.
- Message content, including attached images. Voice notes are transcribed so staff can read them, and the transcript is stored in place of the audio.
- Reservation details they provide: name, date and time, party size, contact details, requests.
- A record of how each message was handled: which reply was sent, whether the AI or a person sent it, and why a conversation was handed to a human.
Data about staff
Name, work email, a hashed password, role and permissions, and session records. Staff see only what their role allows. Credentials for connected channels are stored encrypted and are never shown back in full — only whether they are set.
Why we use it
To deliver and answer messages, manage reservations, and review the quality and safety of the replies our own assistant produces. We do not sell data, use it for advertising, or use it to build profiles beyond what answering the conversation requires.
Who else processes it
Only providers acting on our instructions: the messaging platforms a business connects (TikTok, Meta for Instagram, our WhatsApp Business provider, the business's own mail server), the AI providers that generate replies and transcribe voice notes, a notification service that alerts staff to conversations needing a person, and our hosting provider. Everything else stays on servers we control.
How we protect it
Traffic to and from Channelflow runs over encrypted connections. The credentials for each connected channel are encrypted before they are stored and are never displayed back in full, even to an administrator. Incoming webhooks are rejected unless they carry a valid signature from the platform that claims to have sent them. Staff sign in with individual accounts, see only what their role permits, and attachments are served only to a signed-in staff member — never from a public link. Data is held on servers we control, and access to them is limited to the people who operate the service.
How long we keep it
Messages, reservations and handling records are kept for 24 months, then deleted. Staff accounts are kept while the account is active.
Disconnecting a channel or withdrawing authorisation
A business can disconnect a channel at any time from within Channelflow, and can withdraw an app's authorisation from the platform itself — on TikTok, from the account's own settings. Either one stops us immediately: no further messages are received or sent for that account, and the stored access credentials for it are deleted. Conversations already received stay in the business's inbox until the retention period above ends. To have them removed sooner, email us at welcome@thisbali.com — from the business, or from the person who wrote the messages — and we delete them.
Children
Channelflow is a tool for businesses and the adults who staff them, and it is not directed at children. We do not knowingly collect data from anyone under 13, and we delete it if we learn we have.
Who is responsible
PT. Unicorn Food and Services operates Channelflow and is responsible for it under the laws of the Republic of Indonesia. Where we handle messages for a business that uses Channelflow, we do so on that business's instructions and for its purposes; that business decides what is collected from its own customers and how long we keep it, within the limits set out here.
Requests and contact
To ask for a copy of your data, to correct it, or to have it deleted, write to welcome@thisbali.com. Deleting data cancels any reservation it belongs to. If a change to this policy is material, we announce it here and update the date at the top.