Security

Your customers trusted you with their words. We treat them that way.

Kingsclap processes comments that sometimes contain names, phone numbers and order details. This page explains what we do with that data, what we do not do, and the controls you have.

01Comment arrives

Over an encrypted connection from a connector, import or webhook.

02Personal details masked

Phones, emails, order IDs and card fragments replaced with tokens.

03Analysed

Themes, sentiment and severity extracted from the masked text only.

04Stored encrypted

Comments and results encrypted at rest, scoped to your workspace.

05Seen by the right people

Role and location based access decides who reads what.

Data handling

How comment and customer data is handled

Redaction before analysis

Personal details found in comments, such as phone numbers, email addresses, order and booking numbers, and partial card numbers, are masked before the comment is analysed. Themes and reply drafts are produced from the masked text. The original is kept only so authorised users can read the full comment when needed, and can be switched off per source.

No training on your data

Your comments are used to analyse your workspace only. They are not used to train models shared with other customers.

Public reviews, used by the rules

Public review data is collected and used according to each source’s terms, through official access where it is offered.

Retention you set

Choose how long raw comments are kept. Aggregated theme counts can be kept after raw text is deleted.

Export and deletion

Export everything at any time. On request, or when you leave, your workspace data is deleted from active systems.

Controls

Infrastructure and access

Encryption in transit

All traffic to and from Kingsclap uses TLS. Connectors use each source’s secure API.

Encryption at rest

Comments, results and connector credentials are encrypted at rest.

Role-based access

Admin, analyst, approver and viewer roles, scoped to brands, regions or locations.

Activity log

Logins, exports, theme edits and approved replies are logged with who and when.

Credential handling

Connector tokens are stored encrypted and never shown again after setup.

Workspace isolation

Each customer’s data is logically separated and access-checked on every request.

People in the loop

No reply is posted without a person approving it. This cannot be turned off.

Security reviews

Scale customers can request our security questionnaire responses and a review call.

FAQ

Security questions

Where is our data stored?

Data is stored with established cloud infrastructure providers. Scale customers can discuss regional hosting requirements with us.

Can we stop personal details from being stored at all?

Yes. Per source, you can choose to keep only the masked text, so the original comment with personal details is never stored.

Who at Kingsclap can see our comments?

Access by our staff is limited to support and troubleshooting you request, and is logged.

How do we report a security concern?

Use the contact page and mark the message as a security concern. It is routed to the people responsible straight away.

Next step

Need a security review before a pilot?

Tell us what your team needs to see. We will walk through data flows, redaction and access controls on a call.