Feature referenceTeam and organization · 05 of 06

Team and organization

Sensitive-data notice

An optional owner-authored notice warns visitors what they should not submit before or during a chat.

Availability
All plans
Configured in
Dashboard → Team → Privacy & retention → Privacy notice
Category
Team and organization
Reference status
Current
01

What the notice does

When enabled, Stand presents organization-authored cautionary text in the visitor chat experience so a visitor can avoid sharing categories of information the team does not want to receive.

The notice is informational. Stand still processes messages the visitor chooses to send, so the organization must pair it with appropriate product design, instructions, and operating policy.

02

Enable and edit the notice

  • Open Team as the owner and edit Privacy & retention.
  • Turn on the privacy notice.
  • Write direct visitor-facing guidance, such as asking people not to send passwords or payment-card details.
  • Keep the text within the 500-character counter and non-blank while enabled.
  • Save the privacy settings and verify the notice in the installed visitor widget.
03

What to say

  • Name the concrete data categories visitors should not enter.
  • Use language appropriate to the website and audience.
  • Provide a safer channel or next step when the team has one.
  • Avoid promising technical protections the notice itself does not provide.
04

Relationship to other controls

  • Retention determines how long submitted chat content stays searchable; it does not prevent collection.
  • AI instructions can tell Stand-ins not to request sensitive data; they cannot reliably stop a visitor from volunteering it.
  • Authentication and authorization must remain in the customer application, outside page-known identity or private prompt context.
  • Organization privacy and regulatory obligations still apply to exports and downstream tools.
05

Not a compliance feature by itself