Pitstop AI Logo

Guides

Security & compliance

How your data is handled, who can access what, and what you control as the business owner.

Your API keys (BYOK)

  • LLM provider: stored in your account; used only for your agent. You pay the provider directly.
  • Meta / WhatsApp: your Business API credentials; messages flow between your customers and Meta.
  • Rotate keys in Settings → Agent if compromised. Never share keys in support tickets.

Access control

Go to Settings → Team to invite users and assign roles.

  • Permissions are granular, bookings, customers, payments, settings, accounting, etc.
  • Staff without admin access cannot change agent keys, subscription, or team invites
  • Employee portal logins are separate, limited to My Work (schedule, payslips, leave)
  • See Team & branches for role overview

Customer data

  • Customer profiles, bookings, and WhatsApp threads are stored for your business only
  • Export customer data from the dashboard when needed, see import & export
  • AI conversations may be processed by your chosen LLM provider under their privacy terms

Privacy & legal

Compliance tips for operators

  • Only invite team members who need access; remove ex-employees promptly
  • Keep Q&A content accurate, the AI quotes what you publish
  • Use branch-level tax and invoice settings where regulations differ
  • Document your own customer consent for marketing messages where required