Privacy & Security at Manychat

Protection of customer data has always been our top priority. We build our platform using security and privacy best practices to ensure your data is safe.

Certifications

Manychat adheres to global security standards. Our security controls undergo external independent audits on an annual basis.

Cloud Security Alliance logo

Cloud Security Alliance

Manychat is listed as a Trusted Cloud Provider in the Cloud Security Alliance (CSA) STAR Registry.

Learn moreLearn moreLearn more
ISO/IEC 27001 logo

ISO/IEC 27001

Our Information Security Management System (ISMS) has been certified against the ISO/IEC 27001:2022 standard. You can view Manychat's ISO/IEC 27001:2022 certificate here.

Learn moreLearn moreLearn more
SOC 2 Type II logo

SOC 2 Type II

Manychat is SOC 2 Type II compliant. If you are a customer or are considering incorporating Manychat into your organization, you can obtain our SOC 2 Type II report here.

Learn moreLearn moreLearn more
ISO 42001 logo

ISO 42001

Our AI Management System has been certified against the ISO/IEC 42001:2023 standard following an independent audit by A-LIGN. You can view Manychat's ISO/IEC 42001 certificate here.

Learn moreLearn moreLearn more

Official Meta Partner

As an official Meta Business Partner, Manychat complies with Meta's security policies and guidelines, including Meta Platform data security requirements and Data Use Policy. As part of the Meta Business Partner requirements, we go through periodic Data Use Checkups and Meta compliance audits.

Meta partner badge

Data privacy

We are committed to providing a high standard of privacy protection in compliance with international regulatory requirements.

General Data Protection Regulation (GDPR) logo

General Data Protection Regulation (GDPR)

GDPR regulates the use of EU residents’ personal data.

California Consumer Privacy Act (CCPA) logo

California Consumer Privacy Act (CCPA)

CCPA secures privacy rights and sets consumer protection practices for California residents. Manychat is committed to working with you to fulfill any CCPA requirements.

Privacy Policy logo

Privacy Policy

Our Privacy Policy and Data Processing Agreement (DPA) are aligned with GDPR and other privacy-related regulations.

Our security practices

In transit

All data transmitted between your browser and Manychat is done so using strong encryption protocols. We support the latest recommended secure cipher suites to encrypt all traffic in transit, including use of TLS 1.2 protocols, AES256 encryption, and SHA2 hash functions, whenever supported by the clients.

At rest

Customer data at rest in Manychat’s production network is encrypted using FIPS 140-2 compliant encryption standards, which applies to all types of data at rest within Manychat’s systems—relational databases, file drives, backups, etc. Access to the secrets management system is authorized only for a small number IT infrastructure engineers.

Access

We manage access based on a "Need to know" and "Least privilege" principles. Our team members are only authorized to access data that they reasonably must handle in order to fulfill their current job responsibilities.

Vulnerability

We perform automated and manual application and infrastructure security testing to identify and patch potential security vulnerabilities. We also engage independent service providers to perform external penetration tests to assess the potential system security threats on an annual basis, at minimum.

Regular backups

User data is backed up continuously and encrypted. No matter what happens, your work will stay safe. There are also daily backups of the entire database that are stored separately from the main data center.

Incident response

We have incident handling policies and procedures to address service availability, integrity, security, privacy, and confidentiality issues. You can check our uptime and availability status at status.manychat.com.

Security FAQ

Yes. Manychat holds three independent certifications:

  • ISO/IEC 27001 — our Information Security Management System (ISMS) is certified by BSI Group, one of the world's leading certification bodies.
  • ISO/IEC 42001 — our AI management practices are certified by A-LIGN, confirming that how we develop, operate, and govern AI meets the requirements of the international standard for AI management systems.
  • SOC 2 Type 2 — our security, availability, and confidentiality controls have been independently audited by A-LIGN over an extended observation period, not just a point-in-time review.

You can request a copy of our SOC 2 Type 2 report by following this link.

Yes. Manychat is PCI DSS SAQ A compliant, covering our payment card processing integrations.

Yes. Manychat is certified under the EU-US Data Privacy Framework (EU-US DPF), the UK Extension to the EU-US DPF, and the Swiss-US Data Privacy Framework. This certification covers transfers of personal data from the EU, UK, and Switzerland to Manychat's US infrastructure.

You can verify our certification at dataprivacyframework.gov. Where the DPF does not apply, we rely on Standard Contractual Clauses (SCCs), as set out in our Data Processing Addendum.

Yes. Manychat conducts penetration testing annually through an independent third-party firm. Findings are used to drive remediation and are tracked to closure. We also maintain a private bug bounty program in partnership with Bugcrowd for continuous vulnerability identification.

Manychat maintains a private bug bounty program in partnership with Bugcrowd. We are committed to engaging with security researchers to identify and resolve potential vulnerabilities within our systems. Security professionals interested in contributing to our program may submit vulnerability reports accompanied with their Bugcrowd profile using our designated submission form.

Manychat stores all production data in AWS data centers in Frankfurt, EU.

Yes. Manychat utilizes TLS 1.3 and 1.2 cipher suites to encrypt data in transit. Data is encrypted at rest using AWS Platform tools supporting AES-256.

No. Manychat does not sell customer data or share it with third parties for their own purposes.

We work with a defined set of subprocessors — such as cloud infrastructure and analytics providers — who access data solely to deliver the Manychat service. All subprocessors are bound by data processing agreements and may only use customer data in accordance with Manychat's instructions.

A full list of our subprocessors is available at manychat.com/legal/service-providers.

Our full list of subprocessors — the third-party service providers we use to deliver the Manychat platform — is available at manychat.com/legal/service-providers. We notify customers of any material changes to this list in advance.

Manychat retains personal data only as long as necessary to provide the service or as required by applicable law.

  • Account closure. When you delete your account, your personal data is removed from our active systems. Billing and financial records are retained for the period required by applicable accounting and tax regulations.
  • Inactive accounts. Accounts with no activity for 18 months are automatically flagged for deletion and removed in accordance with our data retention schedule.

To exercise your right to erasure or to request details about the data we hold, contact [email protected] or visit our Privacy Policy.

Manychat's AI management practices are certified to ISO/IEC 42001, the international standard for AI management systems, audited by A-LIGN.

  • We assess risk before deploying AI features. All AI systems undergo risk and impact assessments before and during operation.
  • We maintain human oversight. AI systems operating within our platform are subject to defined human review processes to ensure outputs remain within acceptable boundaries.
  • Governance is formal and accountable. We maintain a defined governance framework with assigned ownership for all AI systems we build and operate.
Have more questions?Have more questions?Have more questions?