Team and organization
Sensitive-data notice
An optional owner-authored notice warns visitors what they should not submit before or during a chat.
- Availability
- All plans
- Configured in
- Dashboard → Team → Privacy & retention → Privacy notice
- Category
- Team and organization
- Reference status
- Current
What the notice does
When enabled, Stand presents organization-authored cautionary text in the visitor chat experience so a visitor can avoid sharing categories of information the team does not want to receive.
The notice is informational. Stand still processes messages the visitor chooses to send, so the organization must pair it with appropriate product design, instructions, and operating policy.
Enable and edit the notice
- Open Team as the owner and edit Privacy & retention.
- Turn on the privacy notice.
- Write direct visitor-facing guidance, such as asking people not to send passwords or payment-card details.
- Keep the text within the 500-character counter and non-blank while enabled.
- Save the privacy settings and verify the notice in the installed visitor widget.
What to say
- Name the concrete data categories visitors should not enter.
- Use language appropriate to the website and audience.
- Provide a safer channel or next step when the team has one.
- Avoid promising technical protections the notice itself does not provide.
Relationship to other controls
- Retention determines how long submitted chat content stays searchable; it does not prevent collection.
- AI instructions can tell Stand-ins not to request sensitive data; they cannot reliably stop a visitor from volunteering it.
- Authentication and authorization must remain in the customer application, outside page-known identity or private prompt context.
- Organization privacy and regulatory obligations still apply to exports and downstream tools.