How Squash handles product data
Squash processes data from service desk and connected systems to provide, secure, and support the workflows a customer chooses to enable. This policy explains what is processed, why it is needed, and what choices customers have.
Last updated August 30, 2026
Granular access control
Set scopes and permissions for Squash just as you would for a technician on your team. You decide which systems, clients, and actions Squash can access.
Your tools remain the source of truth
Squash works with your existing tech stack and retrieves data when a workflow needs it. It retains only the configuration, audit records, and limited operational data needed to provide and secure the service.
No secondary use
Squash does not sell product data, use it for advertising, or use customer data, prompts, or outputs to train models. The foundation model providers Squash uses are not permitted to train on that data either.
How this policy applies
This policy covers product services provided by Squash AI, Inc. It applies when a customer configures Squash, uses the product, or connects a system that the customer has authorized.
Customers are responsible for having the authority to provide this data. Squash processes it under the customer's instructions and applicable agreement. If a signed customer agreement contains more specific terms for a covered service, that agreement controls.
What Squash processes
The exact data depends on the integrations and workflows a customer enables. These are the main categories used by the product.
Account and access data
Name, work email, role, authentication details, workspace, tenant, and product permissions.
- Source
- Provided by the customer, its users, and the authentication service.
- Purpose
- Sign users in, enforce access, administer the workspace, provide support, and investigate security events.
Service desk and connected-system data
MSP and client records, tickets, messages, attachments, documentation, approvals, and operational data used by an enabled workflow.
- Source
- Provided by the customer or retrieved from PSA, Microsoft, RMM, documentation, communication, and other customer-authorized systems.
- Purpose
- Keep work in the correct customer and client context, understand requests, carry out approved actions, and return results.
Audit, usage, and diagnostic data
Logins, chat submissions, tool calls, policy checks, approvals, action results, errors, request IDs, and security logs.
- Source
- Generated when customers and Squash services use the product.
- Purpose
- Keep actions reviewable, operate and secure the service, troubleshoot problems, and understand product reliability.
Integration secrets
Tokens, credentials, and secret references needed to authenticate a customer-authorized connection.
- Source
- Provided or generated when a customer configures an integration.
- Purpose
- Authenticate the connection and perform the operations the customer has authorized.
Where product data may go
Squash uses service providers for cloud hosting, authentication, workflow processing, AI model processing, monitoring, support, security, and compliance. They receive only the data needed to provide their part of the service under agreements with Squash.
Squash also exchanges data with the PSA, Microsoft, RMM, documentation, communication, and other systems a customer chooses to connect. Those providers process data under the customer's own relationship with them.
Relevant ticket and system context may be sent to AI model providers to generate plans, summaries, responses, or actions. Squash does not use customer data, prompts, or outputs to train foundation models.
Squash does not sell customer product data, use it for third-party advertising, or share one customer's product data with another. Information may still be disclosed when required by law, to protect the service or people, or as part of a financing, acquisition, or similar business transaction.
Where data is stored and how it is protected
Squash primarily stores product data in U.S. cloud regions and uses administrative, technical, and organizational safeguards to protect it.
Read the security overview or review current evidence in the Trust Center.
Data is kept for a defined service or recordkeeping need
Squash retains product data for as long as needed to provide and secure the service, meet its customer agreements, resolve disputes, maintain required records, or comply with law. Retention periods vary by the type of record and why it is needed.
After service ends, Squash deletes or returns customer data as required by the applicable agreement or an authorized request. Limited information may be retained where required for legal, security, backup, or recordkeeping purposes.
How to ask about product data
Customers can ask Squash to access, correct, export, or delete product data by emailing legal@squash.ai. Include the customer or workspace and enough detail to identify the request. Do not send passwords or access tokens.
If you use Squash through your employer or MSP, that organization may control the product data and may need to handle your request first. Squash may verify the requester's identity and authority before acting. Depending on location, a person may also have rights to access, correct, delete, restrict, or object to certain processing.
Website data
When someone visits squash.ai, requests a demo, or contacts Squash, we use their contact details, messages, and basic website activity to respond, provide support, secure the site, and understand website performance. Website tools may use cookies or similar technologies, and marketing emails include an unsubscribe link.
Questions about this policy
Email legal@squash.ai with privacy questions or requests. Squash may update this policy as the product, providers, or legal requirements change. The date at the top shows the latest revision.