HomeProduct privacy

How Squash handles product data

Squash processes data from service desk and connected systems to provide, secure, and support the workflows a customer chooses to enable. This policy explains what is processed, why it is needed, and what choices customers have.

Last updated August 30, 2026

Granular access control

Set scopes and permissions for Squash just as you would for a technician on your team. You decide which systems, clients, and actions Squash can access.

Your tools remain the source of truth

Squash works with your existing tech stack and retrieves data when a workflow needs it. It retains only the configuration, audit records, and limited operational data needed to provide and secure the service.

No secondary use

Squash does not sell product data, use it for advertising, or use customer data, prompts, or outputs to train models. The foundation model providers Squash uses are not permitted to train on that data either.

How this policy applies

This policy covers product services provided by Squash AI, Inc. It applies when a customer configures Squash, uses the product, or connects a system that the customer has authorized.

Customers are responsible for having the authority to provide this data. Squash processes it under the customer's instructions and applicable agreement. If a signed customer agreement contains more specific terms for a covered service, that agreement controls.

What Squash processes

The exact data depends on the integrations and workflows a customer enables. These are the main categories used by the product.

Account and access data

Name, work email, role, authentication details, workspace, tenant, and product permissions.

Source
Provided by the customer, its users, and the authentication service.
Purpose
Sign users in, enforce access, administer the workspace, provide support, and investigate security events.

Service desk and connected-system data

MSP and client records, tickets, messages, attachments, documentation, approvals, and operational data used by an enabled workflow.

Source
Provided by the customer or retrieved from PSA, Microsoft, RMM, documentation, communication, and other customer-authorized systems.
Purpose
Keep work in the correct customer and client context, understand requests, carry out approved actions, and return results.

Audit, usage, and diagnostic data

Logins, chat submissions, tool calls, policy checks, approvals, action results, errors, request IDs, and security logs.

Source
Generated when customers and Squash services use the product.
Purpose
Keep actions reviewable, operate and secure the service, troubleshoot problems, and understand product reliability.

Integration secrets

Tokens, credentials, and secret references needed to authenticate a customer-authorized connection.

Source
Provided or generated when a customer configures an integration.
Purpose
Authenticate the connection and perform the operations the customer has authorized.

Where product data may go

Squash uses service providers for cloud hosting, authentication, workflow processing, AI model processing, monitoring, support, security, and compliance. They receive only the data needed to provide their part of the service under agreements with Squash.

Squash also exchanges data with the PSA, Microsoft, RMM, documentation, communication, and other systems a customer chooses to connect. Those providers process data under the customer's own relationship with them.

Relevant ticket and system context may be sent to AI model providers to generate plans, summaries, responses, or actions. Squash does not use customer data, prompts, or outputs to train foundation models.

Squash does not sell customer product data, use it for third-party advertising, or share one customer's product data with another. Information may still be disclosed when required by law, to protect the service or people, or as part of a financing, acquisition, or similar business transaction.

Where data is stored and how it is protected

Squash primarily stores product data in U.S. cloud regions and uses administrative, technical, and organizational safeguards to protect it.

Read the security overview or review current evidence in the Trust Center.

Data is kept for a defined service or recordkeeping need

Squash retains product data for as long as needed to provide and secure the service, meet its customer agreements, resolve disputes, maintain required records, or comply with law. Retention periods vary by the type of record and why it is needed.

After service ends, Squash deletes or returns customer data as required by the applicable agreement or an authorized request. Limited information may be retained where required for legal, security, backup, or recordkeeping purposes.

How to ask about product data

Customers can ask Squash to access, correct, export, or delete product data by emailing legal@squash.ai. Include the customer or workspace and enough detail to identify the request. Do not send passwords or access tokens.

If you use Squash through your employer or MSP, that organization may control the product data and may need to handle your request first. Squash may verify the requester's identity and authority before acting. Depending on location, a person may also have rights to access, correct, delete, restrict, or object to certain processing.

Website data

When someone visits squash.ai, requests a demo, or contacts Squash, we use their contact details, messages, and basic website activity to respond, provide support, secure the site, and understand website performance. Website tools may use cookies or similar technologies, and marketing emails include an unsubscribe link.

Questions about this policy

Email legal@squash.ai with privacy questions or requests. Squash may update this policy as the product, providers, or legal requirements change. The date at the top shows the latest revision.