Intercom Data Handling

SkillDev tools

'Implement Intercom data handling for GDPR, contact export, data retention,

Use Intercom Data Handling in Claude, ChatGPT or Ahel Desktop

Free. Sign in, add Intercom Data Handling and connect your AI. About a minute.

Also: Claude Code · Cursor · Codex

Then ask your AI: use the Intercom Data Handling skill

Details

Instructions available. Your AI can read the instructions. Execution depends on the setup they require.

Add Ahel to your AI once: Claude, ChatGPT, Cursor, Claude Code or Codex. Then ask it to use this.

Intercom Data HandlingStart free

What this skill tells your AI

The instructions your AI receives, as published by jeremylongshore/tons-of-skills-marketplace in skills/.curated/intercom-data-handling/SKILL.md and read by Ahel’s review.

Overview

Handle sensitive contact data in Intercom integrations with GDPR/CCPA compliance: data export via the Data Export API, contact deletion with an audit trail, PII redaction in logs, and data retention policies. This skill gives you a lean map of the five workflows here; the full copy-ready TypeScript lives in references/implementation.md and worked usage in references/examples.md.

Prerequisites

  • Understanding of GDPR/CCPA requirements
  • intercom-client SDK installed
  • Database for audit logging
  • Familiarity with Intercom's contact and conversation data model

Authentication

Every call authenticates with an Intercom access token via a Bearer header. Store it as INTERCOM_ACCESS_TOKEN in the environment — never hardcode it and never log it:

import { IntercomClient } from "intercom-client";

const client = new IntercomClient({
  token: process.env.INTERCOM_ACCESS_TOKEN!,
});
// Raw REST calls use: Authorization: `Bearer ${process.env.INTERCOM_ACCESS_TOKEN}`

Grant the token the minimum scopes needed (read contacts/conversations for export, write/delete for erasure). Rotate it if it ever appears in a log or a diff.

Data Classification for Intercom

CategoryIntercom FieldsHandling
PIIemail, name, phone, locationEncrypt at rest, redact in logs
Identifiersid, external_id, user_idUse for lookups, no display
Conversation contentbody, conversation_partsMay contain PII, scan before logging
Custom attributesUser-definedDepends on content
System metadatacreated_at, updated_at, roleStandard handling

Instructions

The five workflows below compose into a compliant Intercom data lifecycle. Follow the summary here, then open references/implementation.md for the complete function bodies.

  1. DSAR export — exportContactData(contactId) gathers the contact profile, all conversations (with parts), tags, segments, and data events into one bundle. This is the "give me all my data" request.
  2. Right to deletion (Article 17) — deleteContactData(contactId) exports for the audit trail first, then deletes from Intercom and every local cache, and records a PII-free audit entry (email is hashed, not stored).
  3. Bulk data export — bulkExportMessages(start, end) kicks off the async /export/messages/data job; checkExportStatus(jobId) polls until a CSV download_url is returned.
  4. PII redaction in logs — redactIntercomData(data) masks a fixed PII_FIELDS set (including nested custom_attributes.*) before anything is logged.
  5. Retention enforcement — enforceRetention() sweeps cached records past their RETENTION window on a daily cron, and never touches the 7-year audit log.

Data minimization underpins all five: sync only the fields you need so the erasure and breach surface stays small (see references/examples.md).

Here is the entry-point skeleton — the export that DSAR and deletion both build on:

const contact = await client.contacts.find({ contactId });
const convList = await client.conversations.search({
  query: { field: "contact_ids", operator: "=", value: contactId },
});
// ...gather tags, segments, events → return one bundle

Output

Each workflow returns a structured, PII-aware result:

  • DSAR export → an object with contact, conversations[], tags[], segments[], and events[] — the full data bundle to hand to the requester.
  • Deletion → { deleted: true, auditRecord } where auditRecord holds the action, hashed email, timestamp, purged data sources, and conversation count — proof of erasure that contains no raw PII.
  • Bulk export → a job_identifier, then a { status, downloadUrl } once the CSV is ready.
  • Redaction → the same object shape with PII fields replaced by [REDACTED].
  • Retention → { deleted: { [cacheType]: count } } per swept cache type.

Error Handling

IssueCauseSolution
Export job stuck in "pending"Large datasetPoll every 30s, timeout at 1h
Deletion returns 404Already deletedLog and continue (idempotent)
PII in conversation bodiesUser-submitted contentScan with regex, redact in logs
Audit log gapFailed writeUse write-ahead log or queue

Examples

Full worked examples — fulfilling a DSAR, honoring a deletion request, polling a bulk export to completion, and redacting before logging — are in references/examples.md. The shortest one:

// A user asks for all their data — export the whole bundle to JSON.
const bundle = await exportContactData("5f3c9b2e8a1d4e0012ab34cd");
await fs.writeFile(`dsar/${bundle.contact.id}.json`, JSON.stringify(bundle, null, 2));

Resources

Next Steps

For enterprise access control and permission scoping on top of these data workflows, see the intercom-enterprise-rbac skill in this pack.

Signals

GitHub stars
3k
Forks
415
Last commit
Oct 2026
Advanced
Item type
skill
Key
intercom-data-handling
Source
github.com/jeremylongshore/tons-of-skills-marketplace