Privacy & Security at Manychat
Certifications
Manychat adheres to global security standards. Our security controls undergo external independent audits on an annual basis.

Cloud Security Alliance
Manychat is listed as a Trusted Cloud Provider in the Cloud Security Alliance (CSA) STAR Registry.

ISO/IEC 27001
Our Information Security Management System (ISMS) has been certified against the ISO/IEC 27001:2022 standard. You can view Manychat's ISO/IEC 27001:2022 certificate here.

SOC 2 Type II
Manychat is SOC 2 Type II compliant. If you are a customer or are considering incorporating Manychat into your organization, you can obtain our SOC 2 Type II report here.

ISO 42001
Our AI Management System has been certified against the ISO/IEC 42001:2023 standard following an independent audit by A-LIGN. You can view Manychat's ISO/IEC 42001 certificate here.
Official Meta Partner
As an official Meta Business Partner, Manychat complies with Meta's security policies and guidelines, including Meta Platform data security requirements and Data Use Policy. As part of the Meta Business Partner requirements, we go through periodic Data Use Checkups and Meta compliance audits.

Data privacy
We are committed to providing a high standard of privacy protection in compliance with international regulatory requirements.
General Data Protection Regulation (GDPR)
GDPR regulates the use of EU residents’ personal data.
California Consumer Privacy Act (CCPA)
CCPA secures privacy rights and sets consumer protection practices for California residents. Manychat is committed to working with you to fulfill any CCPA requirements.
Privacy Policy
Our Privacy Policy and Data Processing Agreement (DPA) are aligned with GDPR and other privacy-related regulations.
Our security practices
Security FAQ
Yes. Manychat holds three independent certifications:
- ISO/IEC 27001 — our Information Security Management System (ISMS) is certified by BSI Group, one of the world's leading certification bodies.
- ISO/IEC 42001 — our AI management practices are certified by A-LIGN, confirming that how we develop, operate, and govern AI meets the requirements of the international standard for AI management systems.
- SOC 2 Type 2 — our security, availability, and confidentiality controls have been independently audited by A-LIGN over an extended observation period, not just a point-in-time review.
You can request a copy of our SOC 2 Type 2 report by following this link.
Yes. Manychat is PCI DSS SAQ A compliant, covering our payment card processing integrations.
Yes. Manychat is certified under the EU-US Data Privacy Framework (EU-US DPF), the UK Extension to the EU-US DPF, and the Swiss-US Data Privacy Framework. This certification covers transfers of personal data from the EU, UK, and Switzerland to Manychat's US infrastructure.
You can verify our certification at dataprivacyframework.gov. Where the DPF does not apply, we rely on Standard Contractual Clauses (SCCs), as set out in our Data Processing Addendum.
Yes. Manychat conducts penetration testing annually through an independent third-party firm. Findings are used to drive remediation and are tracked to closure. We also maintain a private bug bounty program in partnership with Bugcrowd for continuous vulnerability identification.
Manychat maintains a private bug bounty program in partnership with Bugcrowd. We are committed to engaging with security researchers to identify and resolve potential vulnerabilities within our systems. Security professionals interested in contributing to our program may submit vulnerability reports accompanied with their Bugcrowd profile using our designated submission form.
Manychat stores all production data in AWS data centers in Frankfurt, EU.
Yes. Manychat utilizes TLS 1.3 and 1.2 cipher suites to encrypt data in transit. Data is encrypted at rest using AWS Platform tools supporting AES-256.
No. Manychat does not sell customer data or share it with third parties for their own purposes.
We work with a defined set of subprocessors — such as cloud infrastructure and analytics providers — who access data solely to deliver the Manychat service. All subprocessors are bound by data processing agreements and may only use customer data in accordance with Manychat's instructions.
A full list of our subprocessors is available at manychat.com/legal/service-providers.
Our full list of subprocessors — the third-party service providers we use to deliver the Manychat platform — is available at manychat.com/legal/service-providers. We notify customers of any material changes to this list in advance.
Manychat retains personal data only as long as necessary to provide the service or as required by applicable law.
- Account closure. When you delete your account, your personal data is removed from our active systems. Billing and financial records are retained for the period required by applicable accounting and tax regulations.
- Inactive accounts. Accounts with no activity for 18 months are automatically flagged for deletion and removed in accordance with our data retention schedule.
To exercise your right to erasure or to request details about the data we hold, contact [email protected] or visit our Privacy Policy.
Manychat's AI management practices are certified to ISO/IEC 42001, the international standard for AI management systems, audited by A-LIGN.
- We assess risk before deploying AI features. All AI systems undergo risk and impact assessments before and during operation.
- We maintain human oversight. AI systems operating within our platform are subject to defined human review processes to ensure outputs remain within acceptable boundaries.
- Governance is formal and accountable. We maintain a defined governance framework with assigned ownership for all AI systems we build and operate.