Published document · PortalSix-approved for release
Plain-language summary
The short version, before the full policy.
Five questions an admin or security reviewer typically asks first. The complete policy follows below.
What data is processed?
Account and support contact details, Slack workspace identifiers, post drafts and media, encrypted connected-account credentials, approval history, brand configuration, publishing records, and product usage needed to provide the service.
Why is it processed?
Only to operate the workflows your team configures: approvals, publishing, inbox triage, planning, and reporting. No cross-customer profiling, advertising, or data sale.
How does deletion work?
Account credentials are invalidated when you disconnect an account. Uninstalling Slack disconnects the integration but does not erase workspace data. Authorized owners can request export or deletion through the product or privacy request form. Some billing, security, legal, audit, and backup records may be retained as described below.
Does customer content train AI models?
No. Slash Social does not use customer content to train cross-customer or foundation models. OpenAI is the current active AI recipient. Anthropic is not an active recipient and cannot process Customer Personal Data unless the recipient review, notice, and runtime-approval controls are completed.
How do I contact security?
Use the support form and begin the message with “Security report.” Do not include passwords, access tokens, or unnecessary personal data.
For OAuth scopes, subprocessors, SOC 2 status, DPA availability, and the copyable admin packet:
Slash Social provides Slack-based social media operations software for planning, approvals, publishing readiness, inbox triage, and reporting. In this policy, "Slash Social," "we," "us," and "our" refer to PortalSix, LLC, a Maryland limited liability company, as provider of the website, Slack app, support channels, and related services.
If your organization uses Slash Social, your organization controls the workspace, brand, social account, and user access decisions. Slash Social processes customer data to provide the service on behalf of that organization.
Information we collect
We collect account and contact information you provide, including name, work email, company, support messages, billing contact details, and workspace setup details.
We collect Slack workspace and user identifiers, team and channel metadata, app installation details, commands, interactions, workflow state, and other Slack content only when it is needed to operate configured workflows.
We collect brand configuration, connected social account metadata, publishing targets, drafts, media references, approval decisions, rejection reasons, inbox items, reporting data, audit history, plan and usage records, device and log data, and security events.
How we use information
We use information to provide, secure, support, bill for, and improve Slash Social. This includes routing work, managing approvals, preparing publishing jobs, showing analytics, detecting failures, responding to support requests, preventing abuse, debugging incidents, and enforcing terms.
We do not sell customer workspace data, social account data, drafts, approvals, inbox content, or analytics records. We do not use customer content for cross-customer advertising profiles.
Slack and social platform data
Slash Social processes Slack and social platform data only as needed to deliver workflows you configure. Examples include creating drafts from Slack context, routing approvals, checking connected account health, importing or referencing media, retrieving inbox items, preparing reports, and sending status updates back into Slack.
Slack and social platforms are independent services. Their own privacy policies and platform terms apply to your use of those services, including any data that remains in Slack or on connected social platforms.
AI-assisted features
When you use AI-assisted features, relevant prompts, context, files, drafts, instructions, and generated outputs may be processed by AI service providers through product infrastructure approved for Slash Social. AI assistance is used to support drafting, classification, summarization, moderation assistance, reply suggestions, and reporting workflows.
Customer workspace data, social account data, prompts, drafts, media, analytics, and outputs are not used to train Slash Social models or third-party AI foundation models. AI providers process submitted inputs to return requested outputs and help operate the requested AI feature.
AI output can be inaccurate, incomplete, or similar to other generated content. You are responsible for reviewing AI-assisted output before approval, publishing, or external use. We do not represent that AI output is unique, non-infringing, or suitable for a regulated use without human review.
Service providers and subprocessors
We share information with service providers and subprocessors that help us host, secure, monitor, support, bill for, and operate Slash Social. Service providers may process information only for the services they provide to Slash Social, unless you independently interact with them or direct us to connect your data to them.
Current subprocessors are Cloudflare, Inc., HubSpot, Inc., and OpenAI OpCo, LLC. Independent controllers are Stripe, LLC and Google LLC. Customer-directed platforms are Slack Technologies, LLC, HubSpot, Inc., Salesforce, Inc., Meta Platforms, Inc., TikTok Inc., X Corp., Google LLC, LinkedIn Corporation, Pinterest, Inc., Bluesky Social, PBC, Canva Pty Ltd, Adobe Inc., and Google LLC and receive data only when you use, connect, or configure the relevant platform workflow. The canonical recipient schedule identifies each provider's role and purpose.
We may also share information when required by law, to protect rights and security, with professional advisors, or as part of a merger, acquisition, financing, or sale of assets.
Cookies, forms, and website data
Our website and support form may process browser data, page URL, form fields, and cookies set by service providers such as HubSpot. We also load fonts and static assets needed to render the site.
We use a first-party preference cookie to remember your cookie choice for up to 180 days. With your Analytics choice, we also use first-party journey, session, and attribution storage to understand page use and referral sources and to improve the website. We do not load this analytics storage or send growth analytics events until you choose Analytics.
You can choose essential-only use, allow Analytics, or change your choice at any time through Cookie settings in the website footer. If you switch to essential-only use after allowing Analytics, we remove our website growth identifiers from your browser and stop analytics after the page reloads.
Retention and deletion
We keep information only for as long as reasonably necessary and proportionate to provide the service, comply with legal obligations, resolve disputes, enforce agreements, maintain billing and audit records, and protect the service. Retention depends on the data category, workspace configuration, customer instructions, legal requirements, and whether a shorter automated cleanup rule applies.
Temporary workflow records, draft sessions, processing records, generated files, and expired content may be removed automatically after they are no longer needed. Other customer data is retained under the criteria above until the workspace or organization requests deletion or the data is no longer needed. Uninstalling the Slack app is an access and integration disconnect; it is not, by itself, a deletion request.
When a workspace uninstalls Slash Social, we invalidate the workspace integration and may disconnect related service operations, but org, brand, content, billing, audit, and backup records are not automatically erased. An authorized owner can request export or deletion through the product or support form. We delete, anonymize, or de-identify eligible data after verification and any applicable cooldown, unless retention is required for security, fraud prevention, billing, tax, legal, backup, or audit purposes. Backups and logs may persist for a limited period before routine deletion.
Security
We use administrative, technical, and organizational safeguards designed to protect information, limit access, monitor reliability, and reduce unnecessary data exposure. No service can guarantee absolute security.
Customers should avoid sending passwords, private access tokens, secrets, or unnecessary personal data through support messages or Slack workflows.
Your choices and rights
You may request access, correction, export, restriction, objection, or deletion of certain information by contacting support. If your organization controls the relevant workspace or brand, we may direct the request to that organization or ask for information needed to verify the request.
Depending on where you live, you may have additional privacy rights under laws such as the GDPR, UK GDPR, CCPA, CPRA, or similar laws. We will not discriminate against you for exercising privacy rights. Some records may need to be retained where required for security, compliance, billing, tax, legal, or audit purposes.
California privacy rights
If you are a California resident and Slash Social is subject to the CCPA/CPRA for your information, you may have the right to know, access, correct, delete, and obtain a copy of certain personal information; to opt out of sale or sharing; to limit certain uses of sensitive personal information; and to be free from discrimination for exercising those rights.
The categories of personal information we may collect include identifiers; customer records; commercial and billing information; internet, device, and network activity; approximate location or timezone information; professional or employment-related information; user-generated content and media you or your organization submit; inferences and analytics derived from product use; and sensitive personal information such as account tokens, authentication data, contents of communications sent through configured workflows, or information included in submitted media.
We collect these categories from you, your organization, Slack, connected platforms, service providers, logs, and product interactions. We use them for the business and commercial purposes described in this policy, including providing, securing, supporting, billing for, and improving Slash Social.
We disclose personal information to service providers and subprocessors for business purposes. We do not sell personal information or share personal information for cross-context behavioral advertising. We do not use or disclose sensitive personal information to infer characteristics except as necessary to provide, secure, support, and improve requested services.
To exercise California privacy rights, use the support form. We may need to verify your identity, workspace, organization, and authority. Authorized agents may submit requests if they provide proof of authorization and we can verify the request.
International transfers
Slash Social and its service providers may process information in the United States and other countries where we or our providers operate. Where required, we rely on appropriate transfer mechanisms for international data transfers.
Children
Slash Social is intended for business use and is not directed to children. Do not use Slash Social to knowingly submit personal information about children unless your organization has a lawful basis and has configured the service for that use.
Changes
We may update this policy as the product, legal requirements, or operating practices change. The updated policy will show a new effective date. Material changes will be communicated through reasonable channels when required by law or contract.
Contact
Review the current Data Processing Addendum and recipient schedule. For privacy requests, security questions, objections, or an execution copy, use the support form. Include the Slack workspace, organization, and brand context needed to route the request.