Workspace isolation
Chats, visitors, contacts, and projects belong to a workspace. Agents only see the workspace they were invited to. Super admin operators can manage the platform; they are not a substitute for your internal access policy. Do not share owner passwords. Invite seats instead.
Authentication
Email and password are stored as a hash, not reversible text. Google sign-in is available when the platform has OAuth configured. Optional two-factor authentication adds an authenticator code at sign-in. You can review sessions from security settings and sign out other devices.
Roles
Owners control billing, projects, and who is on the team. Agents handle conversations. Suspended users cannot sign in. That is the access model — short on purpose, so it is enforceable.
Widget and visitor data
The snippet talks to your ChatDix API for that project. Page URL, device, and messages are processed to deliver the chat. We do not sell visitor lists. See the privacy policy for retention and rights. You are responsible for a privacy notice on sites where you embed the widget, especially if you collect email in the panel.
Payments
Card and PayPal run on those providers. Bank and crypto references are stored so a reviewer can match a transfer. Never send card PAN data to ChatDix support mail.
Report an issue
Email hello@chatdix.com with “Security” in the subject. Include steps, not secrets in the first message if the inbox might be forwarded.