Security and Data Protection
Last updated: September 14, 2026
This page explains how TripleTick, operated by Future Condos Inc., protects the data you and your contacts trust it with.
How does TripleTick protect customer data?
TripleTick hosts production data in Australia, encrypts it in transit and at rest, isolates each workspace from every other workspace, limits staff access to recorded support sessions that expire on their own, and never trains or fine-tunes AI models on your data.
1. Infrastructure and Regions
The production database and application hosting run in Sydney, Australia.
Other service providers process data in the locations their own terms set out, which may include the United States, and each one is listed on the Sub-processors page.
TripleTick is operated by Future Condos Inc., a Canadian company.
- Data is encrypted in transit with TLS.
- Data is encrypted at rest by the database provider.
- The database is backed up automatically.
- API keys and secrets are kept out of source code.
2. Access and Controls
Row-level security in the database keeps each workspace's data isolated from every other workspace.
Every team member has a role, and the role decides what they can do, such as connecting a channel, exporting contacts, or managing billing.
Actions taken inside a workspace are recorded in an audit log.
When TripleTick staff open your workspace to help with a support request, the session needs a stated reason, is recorded in the audit log, and expires on its own.
The cookies that mark a support session, and how long each one lasts, are listed in the Cookie Policy.
Payments run through Stripe's hosted checkout, and TripleTick does not store your full card number.
You connect WhatsApp through Meta's official Embedded Signup, and Instagram through Meta's own business login.
TripleTick is an Official Meta Tech Partner.
Webhooks from Meta and Stripe are checked against their signatures, and any request that fails the check is rejected.
3. AI Data Handling
TripleTick never trains or fine-tunes AI models on customer data.
AI providers process the data TripleTick sends them under their API terms.
Each AI provider, and the data it receives, is listed on the Sub-processors page.
When someone on your team takes over a conversation, the Agent stops replying in it until the conversation is handed back.
4. Reporting a Vulnerability
If you find a security vulnerability in TripleTick, email security@tripletick.ai with a description and the steps to reproduce it.
Report it privately, and give TripleTick reasonable time to fix it before you disclose it publicly.
While you test, do not access, change, or delete data that does not belong to you.
TripleTick does not currently offer a bug bounty.
The same contact is published at /.well-known/security.txt.
5. Related Documents
You can delete contacts and conversations in the app, and request full account deletion as described in the Data Deletion Policy.