MyHelpDesk

Privacy Policy

Last updated September 27, 2026

Effective date: September 27, 2026

This Privacy Policy explains how MyHelpDesk Inc. ("MyHelpDesk", "we", "us") collects, uses, and protects information when you visit myhelpdesk.us, buy a subscription, or use a help desk we host for an organization (the "Service").

1. Who this policy covers

MyHelpDesk is used by organizations ("Customers") to run their own support help desks. Two kinds of information are involved:

  • Account information about our Customers and their administrators: who bought the subscription, how to reach them, and billing details. For this information, MyHelpDesk decides how it is used and is responsible for it.
  • Customer Data: everything a Customer and its users put into their help desk, such as tickets, replies, internal notes, attachments, knowledge-base articles, and the names and email addresses of the people who submit tickets. We process Customer Data on behalf of the Customer and only to provide the Service. The Customer controls it and decides what goes in.

If you submitted a ticket to an organization that uses MyHelpDesk, that organization is responsible for your information. Please contact it directly with questions or requests. We will help it respond.

2. Information we collect

Information you give us

  • Account and contact details: name, email address, company name, and the help desk address you choose.
  • Billing details: billing address and subscription plan. Payments are processed by Stripe. Your full card number is entered on Stripe's checkout and is never stored on our servers.
  • Customer Data entered into a help desk (see Section 1).
  • Integration settings an administrator configures, such as mailbox settings for email-to-ticket, SMTP details for outgoing mail, and Microsoft Entra ID (Azure AD) / Microsoft 365 app registration details for single sign-on or mail. Stored passwords and client secrets are encrypted.
  • Support communications you send to us.

Information collected automatically

  • Log and security data: IP address, browser type, pages requested, login attempts, and actions recorded in audit logs. We use this to keep the Service secure, prevent abuse, and troubleshoot.
  • Cookies: we use only essential cookies. These keep you signed in, protect forms against cross-site request forgery, and remember display preferences. We do not use advertising or cross-site tracking cookies.
  • Bot protection: some forms use Cloudflare Turnstile, which checks your browser to tell people from automated traffic.

Information from others

  • If an organization enables Microsoft single sign-on, we receive basic profile details from Microsoft when you sign in: your name, email address, and account identifier.
  • If an organization connects a mailbox, we receive the emails sent to it so they can become tickets.

3. How we use information

  • To provide, operate, and maintain the Service, including creating and updating help desk instances.
  • To process payments and manage subscriptions.
  • To send service messages, such as ticket notifications, security alerts, billing receipts, and notices about changes.
  • To keep the Service secure: detecting and preventing fraud, abuse, and unauthorized access.
  • To provide support and respond to requests.
  • To improve performance and reliability, using aggregated or de-identified information.
  • To comply with law and enforce our Terms of Service.

We do not sell personal information, share it for cross-context behavioral advertising, or use Customer Data to build advertising profiles.

4. How we share information

We share information only as needed to run the Service:

  • Service providers who work for us under confidentiality and data-protection obligations. These include Stripe (payments) and Cloudflare (network security, bot protection, and delivery). Help desk pages also load standard software libraries and fonts from public content-delivery networks (cdnjs, jsDelivr, unpkg, Tailwind CSS, and Google Fonts), which receive your IP address when your browser requests those files.
  • Services a Customer connects, such as Microsoft 365 or the Customer's own mail servers. Data flows to them because the Customer enabled the integration.
  • Within a Customer's help desk, according to the roles and permissions its administrators set.
  • Legal and safety reasons: to comply with law, legal process, or a lawful government request, or to protect the rights, property, or safety of MyHelpDesk, our Customers, or others.
  • Business transfers: if MyHelpDesk is involved in a merger, acquisition, or sale of assets, information may transfer as part of that transaction. It remains subject to this policy.

5. Where data is stored

The Service is hosted on servers located in the United States. If you use the Service from outside the U.S., your information will be transferred to, stored, and processed in the U.S.

6. Security

  • Data is encrypted in transit using HTTPS (TLS).
  • User passwords are stored only as salted one-way hashes (Argon2id).
  • Stored mail passwords and API client secrets are encrypted at rest.
  • Two-factor authentication, rate limiting on sign-in, and audit logging are available.
  • Each Customer's help desk runs in its own separate database.
  • We take regular backups so the Service can be restored after a failure.

No system is perfectly secure. If we learn of a security incident affecting your information, we will notify affected Customers as required by law.

7. How long we keep information

  • Customer Data is kept for as long as the Customer's subscription is active and the Customer keeps it in the help desk. After a subscription ends, we delete the help desk and its Customer Data within 90 days. A Customer may request a copy of its data during the first 30 days after the subscription ends.
  • Backups age out on a rolling schedule, currently about 30 days, so deleted data may remain in backups until then.
  • Billing records are kept as long as required for tax and accounting purposes.
  • Logs are kept for a limited period for security and troubleshooting, then deleted or rotated.

8. Your choices and rights

Depending on where you live, you may have the right to access, correct, delete, or receive a copy of your personal information, or to object to or limit certain uses of it.

  • Customers and administrators can view and update most account information in their help desk and account portal, or contact us.
  • People who submitted tickets to an organization should contact that organization first. We will support its response as its service provider.

To make a request, email [email protected]. We may need to verify your identity before acting on a request. We will not discriminate against you for exercising your privacy rights.

9. Children

The Service is designed for businesses and is not directed to children under 16. We do not knowingly collect personal information from children. If you believe a child has provided us information, contact us and we will delete it.

10. Changes to this policy

We may update this Privacy Policy from time to time. The date at the top of this page shows when it last changed. If a change is significant, we will notify Customers by email or in the Service before it takes effect.

11. Contact us

Questions or requests about privacy:

MyHelpDesk Inc.
Email: [email protected]
Website: https://myhelpdesk.us

See also: Terms of Service