Product details

Security and privacy operations

Review current security and privacy operations behavior, availability, limits, and operating details for Slash Social.

Overview

This page summarizes how Slash Social isolates customer data, where admins start privacy actions, and when to escalate to support or security.

What it includes

Tenant isolation

Boundary Rule
Organization Billing, limits, and organization-wide settings; all queries scoped by organization ID
Brand Content, accounts, pillars, campaigns, inbox, and media scoped by brand ID
Slack workspace Bot tokens and workspace context keyed by Slack team ID (not organization ID alone)

Users see brands and actions allowed by their roles. Data from one organization is not returned to another.

Data categories stored

The service stores Slack workspace metadata, Slack user identifiers, workflow and content state, brand configuration, connected social account tokens, drafts and media references, approval and audit history, inbox and conversation records, analytics snapshots, billing and usage records, and operational logs needed to run the product.

Slack message content in customer channels and data on social networks remain governed by those providers’ terms.

Transport and credentials

  • Customer traffic uses encrypted transport (HTTPS).
  • Connected account tokens are stored to enable publishing and inbox retrieval; revoking access happens when you disconnect a profile or uninstall the app from Slack. Uninstall is not a deletion request: it disconnects the Slack integration, while workspace, brand, content, billing, audit, and backup data follow the separate verified export/deletion process.
  • Do not paste passwords, private API tokens, or unrelated sensitive personal data into Slack messages or support forms.

Privacy policy and AI processing

The public Privacy Policy describes collection, subprocessors, retention, regional rights, and AI-assisted processing. Slash Social does not sell customer workspace content for advertising profiles. AI inputs are processed to deliver requested outputs; they are not used to train foundation models for other customers.

Audit and compliance features

Plan Audit capability
Team and above Standard audit history for settings and content actions
Current public catalog Advanced audit export is not currently sold

Role-gated audit export is limited to organization owners and billing owners. See Permissions and personas.

How to use it

Billing admins start privacy actions from Settings > Billing & Plan in /social. See Manage billing and upgrades for the workflow.

Action Purpose
Export organization data Portability export for the organization
Request organization deletion Start organization teardown (subject to confirmation, legal hold, and cooldown)
Cancel organization deletion Stop a pending organization deletion
Request user deletion Remove a specific Slack user’s data from the organization

Backups and audit records may persist for a limited period where required for security, billing, or compliance. See Data, security, and privacy for the admin-facing model.

Details

Support and escalation

Situation Contact path
Routine export, deletion, or access questions Organization billing admin via in-product flows; otherwise privacy request form
Confirmed data breach or security incident Security review form on the Support page (not routine deletion tickets)
Export or deletion flow is unavailable Privacy request form with workspace, organization, requester, and request type

Public help center

Ask Slash Social

Answers come from Slash Social’s public help center.

Ask about setup, Slack workflows, approvals, publishing, billing, or troubleshooting.

Use public questions only. Don’t share workspace content, credentials, or personal data.